Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

System Windows se vypne za necelou minutu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
gledy
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 17 čer 2008 14:16

System Windows se vypne za necelou minutu

#1 Příspěvek od gledy »

Zdravim,

dnes jsem si nainstaloval .NET Framework a po restartu kdyz se prihlasim mi system napise hlasku "System Windows se vypne za necelou minutu" a vypne se. Mam system Windows 7 x64. Dela to CMD, nejdriv se otevre, potom se zavre a pote se objevi ta chyba a vypne se. Zde je ta chyba:
http://img690.imageshack.us/img690/6402/p1070 233.jpg

gledy
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 17 čer 2008 14:16

Re: System Windows se vypne za necelou minutu

#2 Příspěvek od gledy »

jeste jsem zapomel dodat, ze me to pusti jen do Nouzoveho rezimu

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: System Windows se vypne za necelou minutu

#3 Příspěvek od motji »

Hezký podvečer :)

V nouzovém režimu provedte

arrow: Stahněte OTL http://oldtimer.geekstogo.com/OTL.exe
-uložte ho na plochu a spustte soubor OTL.exe.
- otevře se okno, v něm zaškrtněte Scan All Users ,
-do bílého okna dole skopírujte tento skript:

Kód: Vybrat vše

netsvcs
%SYSTEMDRIVE%\*.exe
%SYSTEMDRIVE%\eventlog.dll /s /md5
%SYSTEMDRIVE%\scecli.dll /s /md5
%SYSTEMDRIVE%\netlogon.dll /s /md5
%SYSTEMDRIVE%\cngaudit.dll /s /md5
%SYSTEMDRIVE%\sceclt.dll /s /md5
%SYSTEMDRIVE%\ntelogon.dll /s /md5
%SYSTEMDRIVE%\logevent.dll /s /md5
%SYSTEMDRIVE%\iaStor.sys /s /md5
%SYSTEMDRIVE%\nvstor.sys /s /md5
%SYSTEMDRIVE%\atapi.sys /s /md5
%SYSTEMDRIVE%\IdeChnDr.sys /s /md5
%SYSTEMDRIVE%\viasraid.sys /s /md5
%SYSTEMDRIVE%\AGP440.sys /s /md5
%SYSTEMDRIVE%\vaxscsi.sys /s /md5
%SYSTEMDRIVE%\nvatabus.sys /s /md5
%SYSTEMDRIVE%\viamraid.sys /s /md5
%SYSTEMDRIVE%\nvata.sys /s /md5
CREATERESTOREPOINT
-klikněte na tlačítko Run scan.
-proběhne sken a objeví se dva logy, obsah obou vložte zde :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

gledy
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 17 čer 2008 14:16

Re: System Windows se vypne za necelou minutu

#4 Příspěvek od gledy »

tak, zde jsou ty logy

Extras

Kód: Vybrat vše

OTL Extras logfile created on: 11.3.2010 18:20:18 - Run 1
OTL by OldTimer - Version 3.1.36.1     Folder = C:\Users\Petr\Desktop
64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
 
2,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 77,00% Memory free
4,00 Gb Paging File | 4,00 Gb Available in Paging File | 89,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 149,04 Gb Total Space | 118,11 Gb Free Space | 79,25% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 596,17 Gb Total Space | 423,19 Gb Free Space | 70,98% Space Free | Partition Type: NTFS
Drive F: | 999,72 Mb Total Space | 988,58 Mb Free Space | 98,89% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: PETRPC
Current User Name: Petr
Logged in as Administrator.
 
Current Boot Mode: SafeMode
Scan Mode: All users
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
 
[color=#E56717]========== Extra Registry (SafeList) ==========[/color]
 
 
[color=#E56717]========== File Associations ==========[/color]
 
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
[HKEY_USERS\S-1-5-21-642521359-2119642944-3776796898-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
[color=#E56717]========== Shell Spawning ==========[/color]
 
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[color=#E56717]========== Security Center Settings ==========[/color]
 
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
 
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[color=#E56717]========== Authorized Applications List ==========[/color]
 
 
[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64
"{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64
"{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64
"{7E71D556-4D87-36D5-A905-E6D98E115F45}" = Microsoft .NET Framework 4 Client Profile
"{80AF4051-BBDC-3F38-BF0C-4D6EB0927781}" = Microsoft .NET Framework 4 Extended
"{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64
"{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4
"{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4
"{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0405-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Czech) 2007
"{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4
"{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64
"{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)
"{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{098A2A49-7CF3-4F08-A38D-FB879117152A}" = Adobe Color NA Extra Settings CS4
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
"{0DC0E85F-36E4-463B-B3EA-4CD8ED2222A1}" = Adobe Color EU Recommended Settings CS4
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{35B93ACD-7414-43E0-9D1E-F925DC900360}" = Opera 10.50
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{90120000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2007
"{90120000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2007
"{90120000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2007
"{90120000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2007
"{90120000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2007
"{90120000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2007
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0405-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2007
"{90120000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2007
"{90120000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2007
"{90120000-00BA-0405-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2007
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{E4848436-0345-47E2-B648-8B522FCDA623}" = Adobe Photoshop CS4
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_faf656ef605427ee2f42989c3ad31b8" = Adobe Photoshop CS4
"avast5" = avast! Free Antivirus
"Centrum.cz Toolbar_is1" = Centrum.cz Toolbar 1.202.012.001
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Mozilla Firefox (3.6)" = Mozilla Firefox (3.6)
"NSS" = Norton Security Scan
"PSPad editor_is1" = PSPad editor
"Steam App 240" = Counter-Strike: Source
"Steam App 320" = Half-Life 2: Deathmatch
"Steam App 340" = Half-Life 2: Lost Coast
"The KMPlayer" = The KMPlayer (remove only)
"WinRAR archiver" = WinRAR
"winscp3_is1" = WinSCP 4.2.7
 
[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]
 
[HKEY_USERS\S-1-5-21-642521359-2119642944-3776796898-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"QIP 2005" = QIP 2005 8095
 
[color=#E56717]========== Last 10 Event Log Errors ==========[/color]
 
[ Application Events ]
Error - 6.3.2010 6:31:20 | Computer Name = petrpc | Source = Application Error | ID = 1000
Description = Název chybující aplikace: hl2.exe, verze: 0.0.0.0, časové razítko:
 0x4445c334  Název chybujícího modulu: filesystem_steam.dll_unloaded, verze: 0.0.0.0,
 časové razítko: 0x47e2d72b  Kód výjimky: 0xc0000005  Posun chyby: 0x0032553e  ID chybujícího
 procesu: 0xcd0  Čas spuštění chybující aplikace: 0x01cabd16eb2f6447  Cesta k chybující
 aplikaci: c:\program files (x86)\steam\steamapps\gledy\counter-strike source\hl2.exe
Cesta
 k chybujícímu modulu: filesystem_steam.dll  ID zprávy: 66f1f9f4-290b-11df-be35-001d72064c22
 
Error - 6.3.2010 8:59:18 | Computer Name = petrpc | Source = Application Hang | ID = 1002
Description = Program WinSCP.exe verze 4.2.7.758 přestal spolupracovat se systémem
 Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto
 problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.    ID procesu:
 108c    Čas spuštění: 01cabd2c6b3e9261    Čas ukončení: 22    Cesta k aplikaci: C:\Program 
Files (x86)\WinSCP\WinSCP.exe    ID hlášení: 0ee6c742-2920-11df-be35-001d72064c22  
 
Error - 6.3.2010 9:08:38 | Computer Name = petrpc | Source = Application Hang | ID = 1002
Description = Program WinSCP.exe verze 4.2.7.758 přestal spolupracovat se systémem
 Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto
 problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.    ID procesu:
 11e0    Čas spuštění: 01cabd2dcadb0b60    Čas ukončení: 22    Cesta k aplikaci: C:\Program 
Files (x86)\WinSCP\WinSCP.exe    ID hlášení: 5d84437b-2921-11df-be35-001d72064c22  
 
Error - 6.3.2010 17:19:48 | Computer Name = petrpc | Source = Application Error | ID = 1000
Description = Název chybující aplikace: hl2.exe, verze: 0.0.0.0, časové razítko:
 0x4445c334  Název chybujícího modulu: filesystem_steam.dll_unloaded, verze: 0.0.0.0,
 časové razítko: 0x47e2d72b  Kód výjimky: 0xc0000005  Posun chyby: 0x005c553e  ID chybujícího
 procesu: 0x1338  Čas spuštění chybující aplikace: 0x01cabd6cc7ac6f5d  Cesta k chybující
 aplikaci: c:\program files (x86)\steam\steamapps\gledy\counter-strike source\hl2.exe
Cesta
 k chybujícímu modulu: filesystem_steam.dll  ID zprávy: fe2e5f45-2965-11df-be35-001d72064c22
 
Error - 7.3.2010 4:31:27 | Computer Name = petrpc | Source = Application Error | ID = 1000
Description = Název chybující aplikace: hl2.exe, verze: 0.0.0.0, časové razítko:
 0x4445c334  Název chybujícího modulu: filesystem_steam.dll_unloaded, verze: 0.0.0.0,
 časové razítko: 0x47e2d72b  Kód výjimky: 0xc0000005  Posun chyby: 0x02c4553e  ID chybujícího
 procesu: 0x1318  Čas spuštění chybující aplikace: 0x01cabdcf77952dd6  Cesta k chybující
 aplikaci: c:\program files (x86)\steam\steamapps\gledy\counter-strike source\hl2.exe
Cesta
 k chybujícímu modulu: filesystem_steam.dll  ID zprávy: d1f8f27d-29c3-11df-be35-001d72064c22
 
Error - 8.3.2010 15:18:09 | Computer Name = petrpc | Source = Application Error | ID = 1000
Description = Název chybující aplikace: hl2.exe, verze: 0.0.0.0, časové razítko:
 0x4445c334  Název chybujícího modulu: filesystem_steam.dll_unloaded, verze: 0.0.0.0,
 časové razítko: 0x47e2d72b  Kód výjimky: 0xc0000005  Posun chyby: 0x01e2553e  ID chybujícího
 procesu: 0x1200  Čas spuštění chybující aplikace: 0x01cabeefdbe9cc49  Cesta k chybující
 aplikaci: c:\program files (x86)\steam\steamapps\gledy\counter-strike source\hl2.exe
Cesta
 k chybujícímu modulu: filesystem_steam.dll  ID zprávy: 54626ea0-2ae7-11df-be35-001d72064c22
 
Error - 9.3.2010 12:20:12 | Computer Name = petrpc | Source = Application Error | ID = 1000
Description = Název chybující aplikace: hl2.exe, verze: 0.0.0.0, časové razítko:
 0x4445c334  Název chybujícího modulu: filesystem_steam.dll_unloaded, verze: 0.0.0.0,
 časové razítko: 0x47e2d72b  Kód výjimky: 0xc0000005  Posun chyby: 0x02b2553e  ID chybujícího
 procesu: 0x248  Čas spuštění chybující aplikace: 0x01cabfa11cf20a96  Cesta k chybující
 aplikaci: c:\program files (x86)\steam\steamapps\gledy\counter-strike source\hl2.exe
Cesta
 k chybujícímu modulu: filesystem_steam.dll  ID zprávy: a2eadc7f-2b97-11df-be35-001d72064c22
 
Error - 9.3.2010 13:06:43 | Computer Name = petrpc | Source = Application Error | ID = 1000
Description = Název chybující aplikace: iexplore.exe, verze: 8.0.7600.16385, časové
 razítko: 0x4a5bc69e  Název chybujícího modulu: IEToolbar.dll_unloaded, verze: 0.0.0.0,
 časové razítko: 0x4b750cff  Kód výjimky: 0xc0000005  Posun chyby: 0x1009160a  ID chybujícího
 procesu: 0x9f4  Čas spuštění chybující aplikace: 0x01cabfaae1675f7b  Cesta k chybující
 aplikaci: C:\Program Files (x86)\Internet Explorer\iexplore.exe  Cesta k chybujícímu
 modulu: IEToolbar.dll  ID zprávy: 22905c95-2b9e-11df-be35-001d72064c22
 
Error - 10.3.2010 13:15:36 | Computer Name = petrpc | Source = Application Error | ID = 1000
Description = Název chybující aplikace: hl2.exe, verze: 0.0.0.0, časové razítko:
 0x4445c334  Název chybujícího modulu: datacache.dll, verze: 0.0.0.0, časové razítko:
 0x46439c7b  Kód výjimky: 0xc0000005  Posun chyby: 0x0000b423  ID chybujícího procesu:
 0x8a4  Čas spuštění chybující aplikace: 0x01cac06f53d0f68d  Cesta k chybující aplikaci:
 c:\program files (x86)\steam\steamapps\gledy\counter-strike source\hl2.exe  Cesta
 k chybujícímu modulu: c:\program files (x86)\steam\steamapps\gledy\counter-strike
 source\bin\datacache.dll  ID zprávy: 8a32178b-2c68-11df-bdee-001e4c064eab
 
Error - 10.3.2010 14:45:38 | Computer Name = petrpc | Source = Application Error | ID = 1000
Description = Název chybující aplikace: hl2.exe, verze: 0.0.0.0, časové razítko:
 0x4445c334  Název chybujícího modulu: filesystem_steam.dll_unloaded, verze: 0.0.0.0,
 časové razítko: 0x47e2d72b  Kód výjimky: 0xc0000005  Posun chyby: 0x027f553e  ID chybujícího
 procesu: 0xda0  Čas spuštění chybující aplikace: 0x01cac07cf7b014ad  Cesta k chybující
 aplikaci: c:\program files (x86)\steam\steamapps\gledy\counter-strike source\hl2.exe
Cesta
 k chybujícímu modulu: filesystem_steam.dll  ID zprávy: 1df92ac0-2c75-11df-bdee-001e4c064eab
 
[ System Events ]
Error - 11.3.2010 12:39:42 | Computer Name = petrpc | Source = Service Control Manager | ID = 7001
Description = Služba Služba seznamu sítí závisí na službě Sledování umístění v síti
 (NLA), která neuspěla při spuštění v důsledku následující chyby:   %%1068
 
Error - 11.3.2010 12:39:42 | Computer Name = petrpc | Source = Service Control Manager | ID = 7001
Description = Služba Služba seznamu sítí závisí na službě Sledování umístění v síti
 (NLA), která neuspěla při spuštění v důsledku následující chyby:   %%1068
 
Error - 11.3.2010 12:39:43 | Computer Name = petrpc | Source = DCOM | ID = 10005
Description = 
 
Error - 11.3.2010 12:39:44 | Computer Name = petrpc | Source = DCOM | ID = 10005
Description = 
 
Error - 11.3.2010 12:39:44 | Computer Name = petrpc | Source = Service Control Manager | ID = 7001
Description = Služba Služba seznamu sítí závisí na službě Sledování umístění v síti
 (NLA), která neuspěla při spuštění v důsledku následující chyby:   %%1068
 
Error - 11.3.2010 12:39:45 | Computer Name = petrpc | Source = Service Control Manager | ID = 7001
Description = Služba Služba seznamu sítí závisí na službě Sledování umístění v síti
 (NLA), která neuspěla při spuštění v důsledku následující chyby:   %%1068
 
Error - 11.3.2010 12:39:45 | Computer Name = petrpc | Source = Service Control Manager | ID = 7001
Description = Služba Služba seznamu sítí závisí na službě Sledování umístění v síti
 (NLA), která neuspěla při spuštění v důsledku následující chyby:   %%1068
 
Error - 11.3.2010 12:39:45 | Computer Name = petrpc | Source = Service Control Manager | ID = 7001
Description = Služba Služba seznamu sítí závisí na službě Sledování umístění v síti
 (NLA), která neuspěla při spuštění v důsledku následující chyby:   %%1068
 
Error - 11.3.2010 12:39:45 | Computer Name = petrpc | Source = Service Control Manager | ID = 7001
Description = Služba Služba seznamu sítí závisí na službě Sledování umístění v síti
 (NLA), která neuspěla při spuštění v důsledku následující chyby:   %%1068
 
Error - 11.3.2010 12:39:45 | Computer Name = petrpc | Source = Service Control Manager | ID = 7001
Description = Služba Služba seznamu sítí závisí na službě Sledování umístění v síti
 (NLA), která neuspěla při spuštění v důsledku následující chyby:   %%1068
 
 
< End of report >

gledy
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 17 čer 2008 14:16

Re: System Windows se vypne za necelou minutu

#5 Příspěvek od gledy »

OTL

Kód: Vybrat vše

2,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 77,00% Memory free
4,00 Gb Paging File | 4,00 Gb Available in Paging File | 89,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 149,04 Gb Total Space | 118,11 Gb Free Space | 79,25% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 596,17 Gb Total Space | 423,19 Gb Free Space | 70,98% Space Free | Partition Type: NTFS
Drive F: | 999,72 Mb Total Space | 988,58 Mb Free Space | 98,89% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: PETRPC
Current User Name: Petr
Logged in as Administrator.
 
Current Boot Mode: SafeMode
Scan Mode: All users
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
 
[color=#E56717]========== Processes (SafeList) ==========[/color]
 
PRC - [2010.03.11 18:17:58 | 000,554,496 | ---- | M] (OldTimer Tools) -- C:\Users\Petr\Desktop\OTL.exe
 
 
[color=#E56717]========== Modules (SafeList) ==========[/color]
 
MOD - [2010.03.11 18:17:58 | 000,554,496 | ---- | M] (OldTimer Tools) -- C:\Users\Petr\Desktop\OTL.exe
MOD - [2009.07.14 02:15:07 | 000,486,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\comdlg32.dll
MOD - [2009.07.14 02:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll
 
 
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
 
SRV:[b]64bit:[/b] - [2010.02.27 08:54:18 | 001,038,088 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:[b]64bit:[/b] - [2010.02.11 19:53:39 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Stopped] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV:[b]64bit:[/b] - [2010.02.11 19:53:39 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Stopped] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV:[b]64bit:[/b] - [2010.02.11 19:53:39 | 000,040,384 | ---- | M] (ALWIL Software) [Auto | Stopped] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV:[b]64bit:[/b] - [2009.08.18 02:36:20 | 000,203,264 | ---- | M] (AMD) [Auto | Stopped] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:[b]64bit:[/b] - [2009.07.14 02:41:59 | 000,229,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wwansvc.dll -- (WwanSvc)
SRV:[b]64bit:[/b] - [2009.07.14 02:41:56 | 000,202,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wbiosrvc.dll -- (WbioSrvc)
SRV:[b]64bit:[/b] - [2009.07.14 02:41:56 | 000,195,072 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\umrdp.dll -- (UmRdpService)
SRV:[b]64bit:[/b] - [2009.07.14 02:41:56 | 000,163,840 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\umpo.dll -- (Power)
SRV:[b]64bit:[/b] - [2009.07.14 02:41:55 | 000,044,544 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\themeservice.dll -- (Themes)
SRV:[b]64bit:[/b] - [2009.07.14 02:41:54 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sppuinotify.dll -- (sppuinotify)
SRV:[b]64bit:[/b] - [2009.07.14 02:41:54 | 000,029,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sensrsvc.dll -- (SensrSvc)
SRV:[b]64bit:[/b] - [2009.07.14 02:41:53 | 001,361,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\PeerDistSvc.dll -- (PeerDistSvc)
SRV:[b]64bit:[/b] - [2009.07.14 02:41:53 | 000,327,168 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\pnrpsvc.dll -- (PNRPsvc)
SRV:[b]64bit:[/b] - [2009.07.14 02:41:53 | 000,327,168 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\pnrpsvc.dll -- (p2pimsvc)
SRV:[b]64bit:[/b] - [2009.07.14 02:41:53 | 000,187,904 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\provsvc.dll -- (HomeGroupProvider)
SRV:[b]64bit:[/b] - [2009.07.14 02:41:53 | 000,067,072 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\SysNative\RpcEpMap.dll -- (RpcEptMapper)
SRV:[b]64bit:[/b] - [2009.07.14 02:41:53 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\pnrpauto.dll -- (PNRPAutoReg)
SRV:[b]64bit:[/b] - [2009.07.14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:[b]64bit:[/b] - [2009.07.14 02:41:18 | 000,231,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ListSvc.dll -- (HomeGroupListener)
SRV:[b]64bit:[/b] - [2009.07.14 02:41:11 | 000,023,552 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\irmon.dll -- (Irmon)
SRV:[b]64bit:[/b] - [2009.07.14 02:40:54 | 001,127,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\FntCache.dll -- (FontCache)
SRV:[b]64bit:[/b] - [2009.07.14 02:40:28 | 000,314,368 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\dhcpcore.dll -- (Dhcp)
SRV:[b]64bit:[/b] - [2009.07.14 02:40:28 | 000,291,328 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\defragsvc.dll -- (defragsvc)
SRV:[b]64bit:[/b] - [2009.07.14 02:40:24 | 000,689,152 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\cscsvc.dll -- (CscService)
SRV:[b]64bit:[/b] - [2009.07.14 02:40:13 | 000,083,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\bthserv.dll -- (bthserv)
SRV:[b]64bit:[/b] - [2009.07.14 02:40:10 | 000,100,864 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\SysNative\bdesvc.dll -- (BDESVC)
SRV:[b]64bit:[/b] - [2009.07.14 02:40:05 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AxInstSv.dll -- (AxInstSV)
SRV:[b]64bit:[/b] - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:[b]64bit:[/b] - [2009.07.14 02:40:01 | 000,032,256 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appidsvc.dll -- (AppIDSvc)
SRV:[b]64bit:[/b] - [2009.07.14 02:39:51 | 001,503,744 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wbengine.exe -- (wbengine)
SRV:[b]64bit:[/b] - [2009.07.14 02:39:28 | 003,524,608 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\sppsvc.exe -- (sppsvc)
SRV:[b]64bit:[/b] - [2009.07.14 02:39:11 | 000,689,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\FXSSVC.exe -- (Fax)
SRV - [2010.03.10 16:17:38 | 000,332,720 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010.02.27 08:54:10 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010.01.28 05:45:24 | 000,044,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30128\aspnet_state.exe -- (aspnet_state)
SRV - [2010.01.28 03:04:48 | 001,017,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30128\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
SRV - [2010.01.28 03:04:48 | 000,138,576 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30128\mscorsvw.exe -- (clr_optimization_v4.0.30128_64)
SRV - [2010.01.28 01:51:52 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30128\mscorsvw.exe -- (clr_optimization_v4.0.30128_32)
SRV - [2009.07.14 04:20:14 | 000,000,000 | ---D | M] [On_Demand | Stopped] -- C:\Windows\Vss -- (VSS)
SRV - [2009.07.14 04:20:14 | 000,000,000 | ---D | M] [Unknown | Stopped] -- C:\Windows\SysWOW64\Msdtc -- (MSDTC) Služba DTC (Distributed Transaction Coordinator)
SRV - [2009.07.14 02:16:12 | 000,165,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\provsvc.dll -- (HomeGroupProvider)
SRV - [2009.07.14 02:15:11 | 000,253,440 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysWOW64\dhcpcore.dll -- (Dhcp)
SRV - [2009.07.13 21:30:11 | 000,061,056 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\wbem\vds.mof -- (vds)
SRV - [2009.06.10 21:39:58 | 000,089,920 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_64)
SRV - [2006.10.27 00:47:54 | 000,065,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service)
 
 
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
 
DRV:[b]64bit:[/b] - [2010.02.27 08:38:51 | 000,834,544 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:[b]64bit:[/b] - [2010.02.11 19:42:38 | 000,051,280 | ---- | M] (ALWIL Software) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:[b]64bit:[/b] - [2010.02.11 19:42:19 | 000,120,912 | ---- | M] (ALWIL Software) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:[b]64bit:[/b] - [2010.02.11 19:39:04 | 000,028,752 | ---- | M] (ALWIL Software) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\aswRdr.sys -- (aswRdr)
DRV:[b]64bit:[/b] - [2010.02.11 19:38:49 | 000,063,568 | ---- | M] (ALWIL Software) [File_System | Auto | Stopped] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:[b]64bit:[/b] - [2010.02.11 19:38:25 | 000,022,096 | ---- | M] (ALWIL Software) [File_System | Auto | Stopped] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:[b]64bit:[/b] - [2009.08.18 03:48:48 | 006,037,504 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:[b]64bit:[/b] - [2009.07.14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2009.07.14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2009.07.14 02:48:04 | 000,153,152 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ksecpkg.sys -- (KSecPkg)
DRV:[b]64bit:[/b] - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009.07.14 02:48:04 | 000,014,416 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\hwpolicy.sys -- (hwpolicy)
DRV:[b]64bit:[/b] - [2009.07.14 02:47:49 | 000,055,376 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fsdepends.sys -- (FsDepends)
DRV:[b]64bit:[/b] - [2009.07.14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2009.07.14 02:45:56 | 000,022,096 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wimmount.sys -- (WIMMount)
DRV:[b]64bit:[/b] - [2009.07.14 02:45:55 | 000,217,680 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vhdmp.sys -- (vhdmp)
DRV:[b]64bit:[/b] - [2009.07.14 02:45:55 | 000,200,272 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmbus.sys -- (vmbus)
DRV:[b]64bit:[/b] - [2009.07.14 02:45:55 | 000,046,672 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vmstorfl.sys -- (storflt)
DRV:[b]64bit:[/b] - [2009.07.14 02:45:55 | 000,036,432 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vdrvroot.sys -- (vdrvroot)
DRV:[b]64bit:[/b] - [2009.07.14 02:45:55 | 000,034,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\storvsc.sys -- (storvsc)
DRV:[b]64bit:[/b] - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2009.07.14 02:45:46 | 000,214,096 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\rdyboost.sys -- (rdyboost)
DRV:[b]64bit:[/b] - [2009.07.14 02:45:45 | 000,050,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pcw.sys -- (pcw)
DRV:[b]64bit:[/b] - [2009.07.14 02:43:14 | 000,460,504 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\cng.sys -- (CNG)
DRV:[b]64bit:[/b] - [2009.07.14 02:43:13 | 000,223,448 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\fvevol.sys -- (fvevol)
DRV:[b]64bit:[/b] - [2009.07.14 01:17:46 | 000,024,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rdpbus.sys -- (rdpbus)
DRV:[b]64bit:[/b] - [2009.07.14 01:16:35 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\RDPREFMP.sys -- (RDPREFMP)
DRV:[b]64bit:[/b] - [2009.07.14 01:10:24 | 000,060,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\agilevpn.sys -- (RasAgileVpn) WAN Miniport (IKEv2)
DRV:[b]64bit:[/b] - [2009.07.14 01:09:26 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\wfplwf.sys -- (WfpLwf)
DRV:[b]64bit:[/b] - [2009.07.14 01:09:02 | 000,120,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\irda.sys -- (irda)
DRV:[b]64bit:[/b] - [2009.07.14 01:08:13 | 000,035,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ndiscap.sys -- (NdisCap)
DRV:[b]64bit:[/b] - [2009.07.14 01:07:22 | 000,059,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\vwififlt.sys -- (vwififlt)
DRV:[b]64bit:[/b] - [2009.07.14 01:07:21 | 000,024,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vwifibus.sys -- (vwifibus)
DRV:[b]64bit:[/b] - [2009.07.14 01:07:13 | 000,227,840 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\1394ohci.sys -- (1394ohci)
DRV:[b]64bit:[/b] - [2009.07.14 01:07:00 | 000,350,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HdAudio.sys -- (HdAudAddService)
DRV:[b]64bit:[/b] - [2009.07.14 01:07:00 | 000,184,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbvideo.sys -- (usbvideo) Zobrazovací zařízení USB (WDM)
DRV:[b]64bit:[/b] - [2009.07.14 01:07:00 | 000,118,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthpan.sys -- (BthPan) Zařízení Bluetooth (síť PAN)
DRV:[b]64bit:[/b] - [2009.07.14 01:06:57 | 000,551,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthport.sys -- (BTHPORT)
DRV:[b]64bit:[/b] - [2009.07.14 01:06:56 | 000,158,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rfcomm.sys -- (RFCOMM) Zařízení Bluetooth (RFCOMM protokol TDI)
DRV:[b]64bit:[/b] - [2009.07.14 01:06:53 | 000,041,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthenum.sys -- (BthEnum)
DRV:[b]64bit:[/b] - [2009.07.14 01:06:52 | 000,079,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BTHUSB.SYS -- (BTHUSB)
DRV:[b]64bit:[/b] - [2009.07.14 01:06:52 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\umpass.sys -- (UmPass)
DRV:[b]64bit:[/b] - [2009.07.14 01:06:24 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidkmdf.sys -- (mshidkmdf)
DRV:[b]64bit:[/b] - [2009.07.14 01:05:37 | 000,112,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WUDFPf.sys -- (WudfPf)
DRV:[b]64bit:[/b] - [2009.07.14 01:02:08 | 000,015,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\MTConfig.sys -- (MTConfig)
DRV:[b]64bit:[/b] - [2009.07.14 01:00:34 | 000,038,912 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CompositeBus.sys -- (CompositeBus)
DRV:[b]64bit:[/b] - [2009.07.14 01:00:13 | 000,006,656 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\beep.sys -- (Beep)
DRV:[b]64bit:[/b] - [2009.07.14 00:52:39 | 000,061,440 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\appid.sys -- (AppID)
DRV:[b]64bit:[/b] - [2009.07.14 00:50:17 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | Unknown | Stopped] -- C:\Windows\SysNative\drivers\scfilter.sys -- (scfilter)
DRV:[b]64bit:[/b] - [2009.07.14 00:42:58 | 000,006,656 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vms3cap.sys -- (s3cap)
DRV:[b]64bit:[/b] - [2009.07.14 00:42:44 | 000,021,760 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VMBusHID.sys -- (VMBusHID)
DRV:[b]64bit:[/b] - [2009.07.14 00:37:18 | 000,040,448 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\discache.sys -- (discache)
DRV:[b]64bit:[/b] - [2009.07.14 00:31:10 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:[b]64bit:[/b] - [2009.07.14 00:31:06 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidbatt.sys -- (HidBatt)
DRV:[b]64bit:[/b] - [2009.07.14 00:31:03 | 000,017,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CmBatt.sys -- (CmBatt)
DRV:[b]64bit:[/b] - [2009.07.14 00:27:17 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipmi.sys -- (AcpiPmi)
DRV:[b]64bit:[/b] - [2009.07.14 00:24:27 | 000,514,048 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\csc.sys -- (CSC)
DRV:[b]64bit:[/b] - [2009.07.14 00:19:25 | 000,060,928 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdppm.sys -- (AmdPPM)
DRV:[b]64bit:[/b] - [2009.06.10 22:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)
DRV:[b]64bit:[/b] - [2009.06.10 22:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
DRV:[b]64bit:[/b] - [2009.06.10 22:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
DRV:[b]64bit:[/b] - [2009.06.10 21:35:33 | 000,389,120 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:[b]64bit:[/b] - [2009.06.10 21:34:38 | 001,311,232 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:[b]64bit:[/b] - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:[b]64bit:[/b] - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:[b]64bit:[/b] - [2008.06.27 07:51:10 | 000,088,632 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\adfs.sys -- (adfs)
DRV:[b]64bit:[/b] - [2008.01.19 06:36:14 | 000,036,352 | ---- | M] (National Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nscirda.sys -- (NSCIRDA)
DRV - [2010.02.24 16:31:32 | 000,000,000 | ---D | M] [Kernel | System | Stopped] -- C:\Windows\CSC -- (CSC)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2009.07.14 02:16:02 | 000,014,336 | ---- | M] (Microsoft Corporation) [File_System | System | Stopped] -- C:\Windows\SysWOW64\netbios.dll -- (NetBIOS)
DRV - [2009.06.10 22:28:14 | 000,001,088 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\wbem\mpsdrv.mof -- (mpsdrv)
DRV - [2009.06.10 22:15:18 | 000,003,066 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysWOW64\wbem\tcpip.mof -- (Tcpip)
 
 
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
 
 
[color=#E56717]========== Internet Explorer ==========[/color]
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-642521359-2119642944-3776796898-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
IE - HKU\S-1-5-21-642521359-2119642944-3776796898-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
IE - HKU\S-1-5-21-642521359-2119642944-3776796898-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
IE - HKU\S-1-5-21-642521359-2119642944-3776796898-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.cz/
IE - HKU\S-1-5-21-642521359-2119642944-3776796898-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = cs
IE - HKU\S-1-5-21-642521359-2119642944-3776796898-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 8D 92 C9 6B EA B6 CA 01  [binary data]
IE - HKU\S-1-5-21-642521359-2119642944-3776796898-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
IE - HKU\S-1-5-21-642521359-2119642944-3776796898-1000\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-642521359-2119642944-3776796898-1000\..\URLSearchHook: {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files (x86)\CentrumczToolbar\IEToolbar.dll ()
IE - HKU\S-1-5-21-642521359-2119642944-3776796898-1000\..\URLSearchHook: {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Petr\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
IE - HKU\S-1-5-21-642521359-2119642944-3776796898-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
[color=#E56717]========== FireFox ==========[/color]
 
FF - prefs.js..browser.search.defaultenginename: "Centrum.cz Search"
FF - prefs.js..browser.search.selectedEngine: "Centrum.cz Search"
FF - prefs.js..extensions.enabledItems: Cetrumcz@igeared:1.202.012.001
FF - prefs.js..keyword.URL: "http://search.centrum.cz/index.php?toolbar=centrum-1.0.0&q="
 
FF - HKLM\software\mozilla\Firefox\Extensions\\Cetrumcz@igeared: C:\Program Files (x86)\CentrumczToolbar\Firefox\Cetrumcz@igeared [2010.02.26 14:51:28 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010.02.26 14:51:45 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010.03.03 14:05:31 | 000,000,000 | ---D | M]
 
[2010.02.26 14:52:02 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Mozilla\Extensions
[2010.02.26 14:52:02 | 000,000,000 | ---D | M] -- C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\ryiaca77.default\extensions
[2010.02.27 08:39:05 | 000,002,059 | ---- | M] () -- C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\ryiaca77.default\searchplugins\daemon-search.xml
[2010.02.26 14:51:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2010.02.12 00:11:32 | 000,001,425 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\Cetrumcz_igeared.xml
[2010.01.16 01:50:40 | 000,000,638 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.01.16 01:50:40 | 000,001,687 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.01.16 01:50:40 | 000,001,367 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.01.16 01:50:40 | 000,000,654 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.01.16 01:50:40 | 000,001,179 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\wikipedia-cz.xml
 
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (CentrumczToolbar BHO) - {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files (x86)\CentrumczToolbar\IEToolbar.dll ()
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (QIPBHO Class) - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Petr\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
O3 - HKLM\..\Toolbar: (Centrum.cz Toolbar) - {D5D47440-0750-463D-BAEF-A47D02414806} - C:\Program Files (x86)\CentrumczToolbar\IEToolbar.dll ()
O3 - HKU\S-1-5-21-642521359-2119642944-3776796898-1000\..\Toolbar\WebBrowser: (Centrum.cz Toolbar) - {D5D47440-0750-463D-BAEF-A47D02414806} - C:\Program Files (x86)\CentrumczToolbar\IEToolbar.dll ()
O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:[b]64bit:[/b] - HKLM..\Run: [Skytel] C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-642521359-2119642944-3776796898-1000..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-642521359-2119642944-3776796898-1000..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found
O4 - Startup: C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Jabbim.lnk = C:\Program Files (x86)\Jabbim\jabbim.exe ()
O4 - Startup: C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Windows.lnk = C:\Windows\SysWOW64\shutdown.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysNative\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysWOW64\wshbth.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O18:[b]64bit:[/b] - Protocol\Handler\centrumcztoolbar {61A97628-7C82-4315-957A-C74C2CDD85DF} - Reg Error: Key error. File not found
O18:[b]64bit:[/b] - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:[b]64bit:[/b] - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:[b]64bit:[/b] - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\centrumcztoolbar {61A97628-7C82-4315-957A-C74C2CDD85DF} - C:\Program Files (x86)\CentrumczToolbar\IEToolbar.dll ()
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30:[b]64bit:[/b] - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010.02.19 10:25:27 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
 
NetSvcs:[b]64bit:[/b] Ias - C:\Windows\SysNative\ias [2009.07.14 04:20:14 | 000,000,000 | ---D | M]
NetSvcs:[b]64bit:[/b] Irmon - C:\Windows\SysNative\irmon.dll (Microsoft Corporation)
NetSvcs:[b]64bit:[/b] Wmi - C:\Windows\SysNative\wmi.dll (Microsoft Corporation)
NetSvcs:[b]64bit:[/b] Themes - C:\Windows\SysNative\themeservice.dll (Microsoft Corporation)
NetSvcs:[b]64bit:[/b] BDESVC - C:\Windows\SysNative\bdesvc.dll (Microsoft Corporation)
NetSvcs:[b]64bit:[/b] AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
NetSvcs: Ias - C:\Windows\SysWOW64\ias.dll (Microsoft Corporation)
NetSvcs: Wmi - C:\Windows\SysWOW64\wmi.dll (Microsoft Corporation)
OTL cannot create restorepoints on Vista OSs!
 
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
 
[2010.03.11 18:19:37 | 000,554,496 | ---- | C] (OldTimer Tools) -- C:\Users\Petr\Desktop\OTL.exe
[2010.03.11 15:40:39 | 001,942,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dfshim.dll
[2010.03.11 15:40:39 | 001,130,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dfshim.dll
[2010.03.11 15:40:39 | 000,320,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationHost.exe
[2010.03.11 15:40:39 | 000,295,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationHost.exe
[2010.03.11 15:40:39 | 000,109,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationHostProxy.dll
[2010.03.11 15:40:39 | 000,099,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationHostProxy.dll
[2010.03.11 15:40:39 | 000,049,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netfxperf.dll
[2010.03.11 15:40:39 | 000,048,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netfxperf.dll
[2010.03.11 15:21:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Win down
[2010.03.10 15:41:06 | 000,409,088 | R--- | C] (Realtek Semiconductor Corp.) -- C:\Windows\RTKVAA64.EXE
[2010.03.10 15:40:53 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\RTCOM
[2010.03.10 15:40:38 | 000,150,528 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSWOW64.dll
[2010.03.10 15:40:37 | 001,826,816 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SkyTel.exe
[2010.03.10 15:40:37 | 001,364,480 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\RtlUpd64.exe
[2010.03.10 15:40:37 | 000,791,552 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtPgEx64.dll
[2010.03.10 15:40:37 | 000,598,528 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RTSnMg64.cpl
[2010.03.10 15:40:37 | 000,513,536 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSX64.dll
[2010.03.10 15:40:37 | 000,211,376 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSH64.dll
[2010.03.10 15:40:37 | 000,193,536 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSHP64.dll
[2010.03.10 15:40:36 | 001,261,568 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkAPO64.dll
[2010.03.10 15:40:36 | 000,368,672 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkApi64.dll
[2010.03.10 15:40:36 | 000,040,960 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RCoInst64.dll
[2010.03.10 15:40:35 | 006,342,688 | ---- | C] (Realtek Semiconductor) -- C:\Windows\RAVCpl64.exe
[2010.03.10 15:40:35 | 000,245,248 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO20.dll
[2010.03.10 15:40:35 | 000,160,768 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysNative\FMAPO64.dll
[2010.03.10 15:40:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek
[2010.03.10 15:40:34 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information
[2010.03.10 15:40:31 | 000,520,192 | R--- | C] (Realtek Semiconductor Corp.) -- C:\Windows\RtlExUpd.dll
[2010.03.10 15:40:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
[2010.03.09 18:17:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DivX Shared
[2010.03.09 18:17:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DivX
[2010.03.09 16:46:07 | 000,525,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\DIFxAPI.dll
[2010.03.09 16:45:21 | 000,315,392 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\HideWin.exe
[2010.03.07 11:07:57 | 000,000,000 | ---D | C] -- C:\Users\Petr\Documents\Graphics
[2010.03.07 09:59:49 | 000,000,000 | ---D | C] -- C:\Users\Petr\Desktop\mp33
[2010.03.06 13:56:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinSCP
[2010.03.05 13:55:10 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Local\Diagnostics
[2010.03.04 14:08:33 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Roaming\jabbim
[2010.03.04 14:08:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Jabbim
[2010.03.03 14:25:43 | 000,000,000 | ---D | C] -- C:\Users\Petr\Desktop\mp3
[2010.03.02 16:18:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Symantec Shared
[2010.03.02 14:51:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2010.03.02 14:50:26 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2010.03.02 14:47:59 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2010.03.02 14:47:11 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Local\Microsoft Help
[2010.03.02 14:47:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2010.03.02 14:47:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2010.03.02 14:45:37 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2010.03.02 13:50:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Symantec
[2010.03.02 13:50:18 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\NSSx64
[2010.03.02 13:50:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Norton Security Scan
[2010.03.02 13:50:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
[2010.03.02 13:50:18 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\NSSx64\0207030.022
[2010.03.02 13:50:15 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller
[2010.03.02 13:50:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NortonInstaller
[2010.03.02 13:48:27 | 000,000,000 | ---D | C] -- C:\Users\Petr\Documents\The KMPlayer
[2010.03.02 13:47:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\The KMPlayer
[2010.03.02 05:41:48 | 000,000,000 | ---D | C] -- C:\Users\Petr\Documents\Deaxon.CoomingSoon.XHTML.Template.RIP-CST
[2010.02.27 21:45:09 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Adobe
[2010.02.27 09:05:22 | 000,000,000 | ---D | C] -- C:\ProgramData\FLEXnet
[2010.02.27 09:02:08 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2010.02.27 08:57:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2010.02.27 08:56:47 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\spool
[2010.02.27 08:55:07 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Local\Adobe
[2010.02.27 08:54:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2010.02.27 08:54:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Macrovision Shared
[2010.02.27 08:54:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2010.02.27 08:54:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Macrovision Shared
[2010.02.27 08:50:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2010.02.27 08:38:51 | 000,834,544 | ---- | C] (Duplex Secure Ltd.) -- C:\Windows\SysNative\drivers\sptd.sys
[2010.02.27 08:38:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Lite
[2010.02.27 08:37:53 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Roaming\DAEMON Tools Lite
[2010.02.27 08:37:51 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite
[2010.02.27 00:05:13 | 000,475,136 | ---- | C] (Share-rapid.com) -- C:\Users\Petr\Desktop\SRDownloader.exe
[2010.02.26 18:25:31 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Roaming\PSpad
[2010.02.26 17:43:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PSPad editor
[2010.02.26 17:36:33 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Local\GHISLER
[2010.02.26 14:52:07 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Local\Centrum.cz Toolbar
[2010.02.26 14:51:45 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Roaming\Mozilla
[2010.02.26 14:51:45 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Local\Mozilla
[2010.02.26 14:51:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2010.02.26 14:51:28 | 000,000,000 | ---D | C] -- C:\ProgramData\CentrumczToolbar
[2010.02.26 14:51:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CentrumczToolbar
[2010.02.26 14:48:20 | 000,000,000 | ---D | C] -- C:\Users\Petr\Documents\admin
[2010.02.25 08:05:15 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc.dll
[2010.02.25 08:05:15 | 000,422,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_isv.dll
[2010.02.25 08:05:15 | 000,369,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc.dll
[2010.02.25 08:05:15 | 000,365,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_isv.dll
[2010.02.25 08:05:14 | 000,357,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_isv.exe
[2010.02.25 08:05:14 | 000,356,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate.exe
[2010.02.25 08:05:14 | 000,324,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_isv.exe
[2010.02.25 08:05:14 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate.exe
[2010.02.25 08:05:14 | 000,306,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp.exe
[2010.02.25 08:05:14 | 000,305,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp_isv.exe
[2010.02.25 08:05:14 | 000,277,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp_isv.exe
[2010.02.25 08:05:14 | 000,121,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp_isv.dll
[2010.02.25 08:05:14 | 000,121,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp.dll
[2010.02.25 08:05:14 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp_isv.dll
[2010.02.25 08:05:14 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp.dll
[2010.02.25 08:05:13 | 000,280,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp.exe
[2010.02.25 08:05:08 | 014,629,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll
[2010.02.25 08:05:05 | 011,406,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll
[2010.02.25 08:05:04 | 001,975,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CertEnroll.dll
[2010.02.25 08:05:03 | 001,320,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CertEnroll.dll
[2010.02.25 08:05:00 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmploc.DLL
[2010.02.25 08:04:59 | 012,625,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmploc.DLL
[2010.02.25 08:04:54 | 000,366,080 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll
[2010.02.25 08:04:54 | 000,293,888 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll
[2010.02.25 08:04:54 | 000,148,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\t2embed.dll
[2010.02.25 08:04:54 | 000,108,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\t2embed.dll
[2010.02.25 08:04:54 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fontsub.dll
[2010.02.25 08:04:54 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fontsub.dll
[2010.02.25 08:04:53 | 002,870,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe
[2010.02.25 08:04:52 | 002,614,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\explorer.exe
[2010.02.25 08:04:52 | 000,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winlogon.exe
[2010.02.25 08:04:51 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
[2010.02.25 08:04:50 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2010.02.25 08:04:50 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2010.02.25 08:04:50 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
[2010.02.25 08:04:49 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2010.02.25 08:04:48 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2010.02.25 08:04:40 | 001,572,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\quartz.dll
[2010.02.25 08:04:40 | 001,328,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\quartz.dll
[2010.02.25 08:04:40 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\avifil32.dll
[2010.02.25 08:04:40 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mciavi32.dll
[2010.02.25 08:04:40 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iyuv_32.dll
[2010.02.25 08:04:40 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msvidc32.dll
[2010.02.25 08:04:40 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msyuv.dll
[2010.02.25 08:04:40 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrle32.dll
[2010.02.25 08:04:40 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tsbyuv.dll
[2010.02.25 08:04:39 | 000,852,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2010.02.25 08:04:38 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2010.02.25 08:04:29 | 001,192,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wininet.dll
[2010.02.25 08:04:28 | 000,977,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wininet.dll
[2010.02.25 08:04:28 | 000,445,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iedkcs32.dll
[2010.02.25 08:04:28 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iedkcs32.dll
[2010.02.25 08:04:28 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedsbs.dll
[2010.02.25 08:04:28 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedsbs.dll
[2010.02.25 08:04:24 | 000,960,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CPFilters.dll
[2010.02.25 08:04:24 | 000,641,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CPFilters.dll
[2010.02.25 08:04:24 | 000,613,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psisdecd.dll
[2010.02.25 08:04:24 | 000,552,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdri.dll
[2010.02.25 08:04:24 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSNP.ax
[2010.02.25 08:04:24 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSNP.ax
[2010.02.25 08:04:23 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisdecd.dll
[2010.02.25 08:04:22 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msasn1.dll
[2010.02.24 17:45:18 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Roaming\WinRAR
[2010.02.24 17:44:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinRAR
[2010.02.24 17:19:10 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Roaming\GHISLER
[2010.02.24 17:15:16 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Roaming\skypePM
[2010.02.24 17:04:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam
[2010.02.24 17:04:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Steam
[2010.02.24 17:03:01 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Roaming\Skype
[2010.02.24 17:02:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2010.02.24 17:02:48 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2010.02.24 17:02:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2010.02.24 17:01:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QIP
[2010.02.24 16:59:42 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Roaming\Macromedia
[2010.02.24 16:59:42 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Roaming\Adobe
[2010.02.24 16:59:08 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed
[2010.02.24 16:58:42 | 000,120,912 | ---- | C] (ALWIL Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2010.02.24 16:58:42 | 000,022,096 | ---- | C] (ALWIL Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2010.02.24 16:58:41 | 000,051,280 | ---- | C] (ALWIL Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2010.02.24 16:58:41 | 000,028,752 | ---- | C] (ALWIL Software) -- C:\Windows\SysNative\drivers\aswRdr.sys
[2010.02.24 16:58:38 | 000,063,568 | ---- | C] (ALWIL Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2010.02.24 16:58:04 | 000,153,184 | ---- | C] (ALWIL Software) -- C:\Windows\SysWow64\aswBoot.exe
[2010.02.24 16:58:04 | 000,038,848 | ---- | C] (ALWIL Software) -- C:\Windows\SysWow64\avastSS.scr
[2010.02.24 16:58:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Alwil Software
[2010.02.24 16:58:01 | 000,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2010.02.24 16:53:48 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Roaming\Opera
[2010.02.24 16:53:48 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Local\Opera
[2010.02.24 16:53:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Opera 10.50 Beta
[2010.02.24 16:52:31 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2010.02.24 16:48:16 | 000,000,000 | R--D | C] -- C:\Users\Petr\Searches
[2010.02.24 16:48:05 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Roaming\Identities
[2010.02.24 16:48:00 | 000,000,000 | R--D | C] -- C:\Users\Petr\Contacts
[2010.02.24 16:47:58 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Local\VirtualStore
[2010.02.24 16:47:42 | 000,000,000 | -HSD | C] -- C:\Users\Petr\AppData\Local\Temporary Internet Files
[2010.02.24 16:47:42 | 000,000,000 | -HSD | C] -- C:\Users\Petr\Šablony
[2010.02.24 16:47:42 | 000,000,000 | -HSD | C] -- C:\Users\Petr\Soubory cookie
[2010.02.24 16:47:42 | 000,000,000 | -HSD | C] -- C:\Users\Petr\SendTo
[2010.02.24 16:47:42 | 000,000,000 | -HSD | C] -- C:\Users\Petr\Poslední
[2010.02.24 16:47:42 | 000,000,000 | -HSD | C] -- C:\Users\Petr\Okolní tiskárny
[2010.02.24 16:47:42 | 000,000,000 | -HSD | C] -- C:\Users\Petr\Okolní síť
[2010.02.24 16:47:42 | 000,000,000 | -HSD | C] -- C:\Users\Petr\Documents\Obrázky
[2010.02.24 16:47:42 | 000,000,000 | -HSD | C] -- C:\Users\Petr\Nabídka Start
[2010.02.24 16:47:42 | 000,000,000 | -HSD | C] -- C:\Users\Petr\Local Settings
[2010.02.24 16:47:42 | 000,000,000 | -HSD | C] -- C:\Users\Petr\Documents\Hudba
[2010.02.24 16:47:42 | 000,000,000 | -HSD | C] -- C:\Users\Petr\AppData\Local\History
[2010.02.24 16:47:42 | 000,000,000 | -HSD | C] -- C:\Users\Petr\Documents\Filmy
[2010.02.24 16:47:42 | 000,000,000 | -HSD | C] -- C:\Users\Petr\Dokumenty
[2010.02.24 16:47:42 | 000,000,000 | -HSD | C] -- C:\Users\Petr\Data aplikací
[2010.02.24 16:47:42 | 000,000,000 | -HSD | C] -- C:\Users\Petr\AppData\Local\Data aplikací
[2010.02.24 16:47:41 | 000,000,000 | --SD | C] -- C:\Users\Petr\AppData\Roaming\Microsoft
[2010.02.24 16:47:41 | 000,000,000 | R--D | C] -- C:\Users\Petr\Videos
[2010.02.24 16:47:41 | 000,000,000 | R--D | C] -- C:\Users\Petr\Saved Games
[2010.02.24 16:47:41 | 000,000,000 | R--D | C] -- C:\Users\Petr\Pictures
[2010.02.24 16:47:41 | 000,000,000 | R--D | C] -- C:\Users\Petr\Music
[2010.02.24 16:47:41 | 000,000,000 | R--D | C] -- C:\Users\Petr\Links
[2010.02.24 16:47:41 | 000,000,000 | R--D | C] -- C:\Users\Petr\Favorites
[2010.02.24 16:47:41 | 000,000,000 | R--D | C] -- C:\Users\Petr\Downloads
[2010.02.24 16:47:41 | 000,000,000 | R--D | C] -- C:\Users\Petr\Documents
[2010.02.24 16:47:41 | 000,000,000 | R--D | C] -- C:\Users\Petr\Desktop
[2010.02.24 16:47:41 | 000,000,000 | -H-D | C] -- C:\Users\Petr\AppData
[2010.02.24 16:47:41 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Local\Temp
[2010.02.24 16:47:41 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Local\Microsoft
[2010.02.24 16:47:41 | 000,000,000 | ---D | C] -- C:\Users\Petr\AppData\Roaming\Media Center Programs
[2010.02.24 16:45:57 | 000,000,000 | -HSD | C] -- C:\ProgramData\Šablony
[2010.02.24 16:45:57 | 000,000,000 | -HSD | C] -- C:\ProgramData\Plocha
[2010.02.24 16:45:57 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Obrázky
[2010.02.24 16:45:57 | 000,000,000 | -HSD | C] -- C:\ProgramData\Oblíbené položky
[2010.02.24 16:45:57 | 000,000,000 | -HSD | C] -- C:\ProgramData\Nabídka Start
[2010.02.24 16:45:57 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Hudba
[2010.02.24 16:45:57 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Filmy
[2010.02.24 16:45:57 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumenty
[2010.02.24 16:45:57 | 000,000,000 | -HSD | C] -- C:\ProgramData\Data aplikací
[2010.02.24 16:33:55 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2010.02.24 16:30:28 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2010.02.24 16:29:04 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2010.02.22 20:28:14 | 000,000,000 | ---D | C] -- C:\dell
[2010.02.22 16:17:31 | 000,000,000 | ---D | C] -- C:\totalcmd
[2010.02.19 13:27:20 | 000,000,000 | -HSD | C] -- C:\Recovery
[2010.02.19 13:06:53 | 000,000,000 | -HSD | C] -- C:\Boot
[2010.02.19 11:48:00 | 000,000,000 | ---D | C] -- C:\ATI
[2010.02.19 10:56:19 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2010.02.19 10:39:21 | 000,000,000 | ---D | C] -- C:\inetpub


gledy
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 17 čer 2008 14:16

Re: System Windows se vypne za necelou minutu

#6 Příspěvek od gledy »

OTL Druha polovina

Kód: Vybrat vše

 
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
 
[2010.03.11 18:23:00 | 001,575,230 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010.03.11 18:23:00 | 000,665,706 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2010.03.11 18:23:00 | 000,651,450 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010.03.11 18:23:00 | 000,139,402 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2010.03.11 18:23:00 | 000,120,382 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010.03.11 18:22:19 | 003,407,872 | -HS- | M] () -- C:\Users\Petr\NTUSER.DAT
[2010.03.11 18:17:58 | 000,554,496 | ---- | M] (OldTimer Tools) -- C:\Users\Petr\Desktop\OTL.exe
[2010.03.11 17:37:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.03.11 17:37:38 | 1609,125,888 | -HS- | M] () -- C:\hiberfil.sys
[2010.03.11 16:56:33 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.03.11 16:45:24 | 000,779,380 | -H-- | M] () -- C:\Users\Petr\AppData\Local\IconCache.db
[2010.03.11 16:02:39 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010.03.11 16:02:39 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010.03.11 15:47:50 | 000,012,816 | ---- | M] () -- C:\Users\Petr\Desktop\SRDownloader.nast
[2010.03.11 15:46:50 | 001,554,580 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010.03.10 16:11:05 | 003,022,664 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2010.03.10 15:40:40 | 000,525,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\DIFxAPI.dll
[2010.03.10 15:39:33 | 000,000,007 | ---- | M] () -- C:\ISACER.id
[2010.03.09 16:45:21 | 000,315,392 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\HideWin.exe
[2010.03.06 19:59:00 | 000,041,291 | ---- | M] () -- C:\Users\Petr\Documents\DOKLAD O ZAPLACENI.docx
[2010.03.06 17:36:00 | 000,000,496 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Petr.job
[2010.03.06 13:56:17 | 000,000,600 | ---- | M] () -- C:\Users\Petr\AppData\Roaming\winscp.rnd
[2010.03.04 14:08:25 | 000,001,015 | ---- | M] () -- C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Jabbim.lnk
[2010.03.03 17:12:41 | 003,438,700 | ---- | M] () -- C:\Users\Petr\Documents\Bez názvu-1.psd
[2010.03.02 18:21:20 | 000,110,040 | ---- | M] () -- C:\Users\Petr\AppData\Local\GDIPFONTCACHEV1.DAT
[2010.03.02 14:47:33 | 000,000,478 | ---- | M] () -- C:\Windows\win.ini
[2010.03.02 13:50:18 | 000,000,172 | ---- | M] () -- C:\Windows\SysNative\drivers\NSSx64\0207030.022\isolate.ini
[2010.02.27 08:38:51 | 000,834,544 | ---- | M] (Duplex Secure Ltd.) -- C:\Windows\SysNative\drivers\sptd.sys
[2010.02.27 00:05:13 | 000,475,136 | ---- | M] (Share-rapid.com) -- C:\Users\Petr\Desktop\SRDownloader.exe
[2010.02.26 14:55:58 | 258,400,708 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010.02.26 14:51:50 | 000,000,000 | ---- | M] () -- C:\Windows\nsreg.dat
[2010.02.26 14:51:42 | 000,001,939 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010.02.26 12:32:22 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010.02.24 17:15:16 | 000,000,056 | -H-- | M] () -- C:\ProgramData\ezsidmv.dat
[2010.02.24 17:04:29 | 000,524,288 | -HS- | M] () -- C:\Users\Petr\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010.02.24 17:04:29 | 000,524,288 | -HS- | M] () -- C:\Users\Petr\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010.02.24 17:04:29 | 000,065,536 | -HS- | M] () -- C:\Users\Petr\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010.02.24 17:04:14 | 000,002,539 | ---- | M] () -- C:\Users\Public\Desktop\Steam.lnk
[2010.02.24 17:02:52 | 000,002,533 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2010.02.24 16:58:38 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2010.02.24 16:47:42 | 000,000,020 | -HS- | M] () -- C:\Users\Petr\ntuser.ini
[2010.02.24 16:46:07 | 000,000,012 | RHS- | M] () -- C:\win7.ld
[2010.02.24 16:46:05 | 000,203,464 | RHS- | M] () -- C:\grldr
[2010.02.24 16:35:54 | 000,061,655 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2010.02.24 16:35:54 | 000,061,655 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2010.02.24 16:33:42 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
[2010.02.24 16:28:52 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2010.02.19 13:06:54 | 000,000,357 | RHS- | M] () -- C:\Boot.ini.saved
[2010.02.19 10:25:27 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2010.02.19 10:25:27 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010.02.19 10:25:27 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2010.02.19 10:25:27 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2010.02.19 10:18:45 | 000,000,213 | -H-- | M] () -- C:\Boot.BAK
[2010.02.11 19:53:57 | 000,038,848 | ---- | M] (ALWIL Software) -- C:\Windows\SysWow64\avastSS.scr
[2010.02.11 19:53:36 | 000,153,184 | ---- | M] (ALWIL Software) -- C:\Windows\SysWow64\aswBoot.exe
[2010.02.11 19:42:38 | 000,051,280 | ---- | M] (ALWIL Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2010.02.11 19:42:19 | 000,120,912 | ---- | M] (ALWIL Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2010.02.11 19:39:04 | 000,028,752 | ---- | M] (ALWIL Software) -- C:\Windows\SysNative\drivers\aswRdr.sys
[2010.02.11 19:38:49 | 000,063,568 | ---- | M] (ALWIL Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2010.02.11 19:38:25 | 000,022,096 | ---- | M] (ALWIL Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
 
[color=#E56717]========== Files Created - No Company Name ==========[/color]
 
[2010.03.11 15:46:35 | 001,554,580 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010.03.11 15:21:39 | 000,002,510 | ---- | C] () -- C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Windows.lnk
[2010.03.10 15:42:02 | 000,000,553 | R--- | C] () -- C:\Windows\USetup.iss
[2010.03.10 15:40:39 | 000,001,694 | R--- | C] () -- C:\Windows\RtDefLvl.ini
[2010.03.10 15:40:39 | 000,000,852 | R--- | C] () -- C:\Windows\SysNative\drivers\RTKHDRC0.dat
[2010.03.10 15:40:39 | 000,000,520 | R--- | C] () -- C:\Windows\SysNative\drivers\RTEQEX1.dat
[2010.03.10 15:40:39 | 000,000,520 | R--- | C] () -- C:\Windows\SysNative\drivers\RTEQEX0.dat
[2010.03.10 15:40:39 | 000,000,008 | R--- | C] () -- C:\Windows\SysNative\drivers\rtkhdaud.dat
[2010.03.10 15:40:36 | 000,666,112 | ---- | C] () -- C:\Windows\SysNative\RTCOM64.dll
[2010.03.10 15:39:33 | 000,000,007 | ---- | C] () -- C:\ISACER.id
[2010.03.06 19:55:52 | 000,041,291 | ---- | C] () -- C:\Users\Petr\Documents\DOKLAD O ZAPLACENI.docx
[2010.03.06 13:56:17 | 000,000,600 | ---- | C] () -- C:\Users\Petr\AppData\Roaming\winscp.rnd
[2010.03.04 14:08:25 | 000,001,015 | ---- | C] () -- C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Jabbim.lnk
[2010.03.03 17:12:39 | 003,438,700 | ---- | C] () -- C:\Users\Petr\Documents\Bez názvu-1.psd
[2010.03.02 13:50:23 | 000,000,496 | -H-- | C] () -- C:\Windows\tasks\Norton Security Scan for Petr.job
[2010.03.02 13:50:18 | 000,000,172 | ---- | C] () -- C:\Windows\SysNative\drivers\NSSx64\0207030.022\isolate.ini
[2010.02.27 00:17:30 | 000,012,816 | ---- | C] () -- C:\Users\Petr\Desktop\SRDownloader.nast
[2010.02.26 14:55:58 | 258,400,708 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010.02.26 14:51:50 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010.02.26 14:51:42 | 000,001,939 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010.02.26 12:32:22 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010.02.24 17:15:16 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010.02.24 17:04:14 | 000,002,539 | ---- | C] () -- C:\Users\Public\Desktop\Steam.lnk
[2010.02.24 17:02:52 | 000,002,533 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2010.02.24 16:58:38 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt
[2010.02.24 16:47:42 | 000,524,288 | -HS- | C] () -- C:\Users\Petr\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010.02.24 16:47:42 | 000,000,020 | -HS- | C] () -- C:\Users\Petr\ntuser.ini
[2010.02.24 16:47:41 | 003,407,872 | -HS- | C] () -- C:\Users\Petr\NTUSER.DAT
[2010.02.24 16:47:41 | 000,524,288 | -HS- | C] () -- C:\Users\Petr\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010.02.24 16:47:41 | 000,065,536 | -HS- | C] () -- C:\Users\Petr\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010.02.24 16:33:42 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010.02.19 13:27:40 | 000,000,012 | RHS- | C] () -- C:\win7.ld
[2010.02.19 13:27:36 | 000,203,464 | RHS- | C] () -- C:\grldr
[2010.02.19 13:08:15 | 1609,125,888 | -HS- | C] () -- C:\hiberfil.sys
[2010.02.19 13:06:55 | 000,008,192 | RHS- | C] () -- C:\BOOTSECT.BAK
[2010.02.19 13:06:54 | 000,000,213 | -H-- | C] () -- C:\Boot.BAK
[2010.02.19 13:06:53 | 000,383,562 | RHS- | C] () -- C:\bootmgr
[2010.02.19 10:56:42 | 000,000,357 | RHS- | C] () -- C:\Boot.ini.saved
[2010.02.19 10:25:27 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2010.02.19 10:25:27 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
[2010.02.19 10:25:27 | 000,000,000 | ---- | C] () -- C:\CONFIG.SYS
[2010.02.19 10:25:27 | 000,000,000 | ---- | C] () -- C:\AUTOEXEC.BAT
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
 
[color=#E56717]========== Custom Scans ==========[/color]
 
 
[color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]
 
[color=#A23BEC]< %SYSTEMDRIVE%\eventlog.dll /s /md5 >[/color]
 
[color=#A23BEC]< %SYSTEMDRIVE%\scecli.dll /s /md5 >[/color]
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
 
[color=#A23BEC]< %SYSTEMDRIVE%\netlogon.dll /s /md5 >[/color]
[2009.07.14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll
[2009.07.14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll
[2009.07.14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009.07.14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll
 
[color=#A23BEC]< %SYSTEMDRIVE%\cngaudit.dll /s /md5 >[/color]
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
 
[color=#A23BEC]< %SYSTEMDRIVE%\sceclt.dll /s /md5 >[/color]
 
[color=#A23BEC]< %SYSTEMDRIVE%\ntelogon.dll /s /md5 >[/color]
 
[color=#A23BEC]< %SYSTEMDRIVE%\logevent.dll /s /md5 >[/color]
 
[color=#A23BEC]< %SYSTEMDRIVE%\iaStor.sys /s /md5 >[/color]
 
[color=#A23BEC]< %SYSTEMDRIVE%\nvstor.sys /s /md5 >[/color]
[2009.07.14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009.07.14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys
 
[color=#A23BEC]< %SYSTEMDRIVE%\atapi.sys /s /md5 >[/color]
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
 
[color=#A23BEC]< %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 >[/color]
 
[color=#A23BEC]< %SYSTEMDRIVE%\viasraid.sys /s /md5 >[/color]
 
[color=#A23BEC]< %SYSTEMDRIVE%\AGP440.sys /s /md5 >[/color]
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys
 
[color=#A23BEC]< %SYSTEMDRIVE%\vaxscsi.sys /s /md5 >[/color]
 
[color=#A23BEC]< %SYSTEMDRIVE%\nvatabus.sys /s /md5 >[/color]
 
[color=#A23BEC]< %SYSTEMDRIVE%\viamraid.sys /s /md5 >[/color]
 
[color=#A23BEC]< %SYSTEMDRIVE%\nvata.sys /s /md5 >[/color]
< End of report >

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: System Windows se vypne za necelou minutu

#7 Příspěvek od motji »

:arrow: Spustte OTL
-do bílého okna dole skopírujte tento skript:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
IE - HKU\S-1-5-21-642521359-2119642944-3776796898-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
IE - HKU\S-1-5-21-642521359-2119642944-3776796898-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
IE - HKU\S-1-5-21-642521359-2119642944-3776796898-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
IE - HKU\S-1-5-21-642521359-2119642944-3776796898-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
IE - HKU\S-1-5-21-642521359-2119642944-3776796898-1000\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-642521359-2119642944-3776796898-1000\..\URLSearchHook: {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files (x86)\CentrumczToolbar\IEToolbar.dll ()
IE - HKU\S-1-5-21-642521359-2119642944-3776796898-1000\..\URLSearchHook: {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Petr\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
O2 - BHO: (CentrumczToolbar BHO) - {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files (x86)\CentrumczToolbar\IEToolbar.dll ()
O2 - BHO: (QIPBHO Class) - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Petr\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
O3 - HKLM\..\Toolbar: (Centrum.cz Toolbar) - {D5D47440-0750-463D-BAEF-A47D02414806} - C:\Program Files (x86)\CentrumczToolbar\IEToolbar.dll ()
O3 - HKU\S-1-5-21-642521359-2119642944-3776796898-1000\..\Toolbar\WebBrowser: (Centrum.cz Toolbar) - {D5D47440-0750-463D-BAEF-A47D02414806} - C:\Program Files (x86)\CentrumczToolbar\IEToolbar.dll ()
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found
O4 - Startup: C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Jabbim.lnk = C:\Program Files (x86)\Jabbim\jabbim.exe ()
O4 - Startup: C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Windows.lnk = C:\Windows\SysWOW64\shutdown.exe (Microsoft Corporation)
O13 - gopher Prefix: missing
O18:[b]64bit:[/b] - Protocol\Handler\centrumcztoolbar {61A97628-7C82-4315-957A-C74C2CDD85DF} - Reg Error: Key error. File not found
O18:[b]64bit:[/b] - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:[b]64bit:[/b] - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:[b]64bit:[/b] - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\centrumcztoolbar {61A97628-7C82-4315-957A-C74C2CDD85DF} - C:\Program Files (x86)\CentrumczToolbar\IEToolbar.dll ()
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.

:COMMANDS
[Reboot]
-klikněte na tlačítko Run fix.
-Následně se pc restartuje.
- Log vložte zde :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

gledy
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 17 čer 2008 14:16

Re: System Windows se vypne za necelou minutu

#8 Příspěvek od gledy »

Dekuji moc, uz to nedela, ja vedel ze VIRY.cz Fórum nezklame :wink:

Kód: Vybrat vše

========== OTL ==========
No active process named explorer.exe was found!
Unable to set value : HKU\S-1-5-21-642521359-2119642944-3776796898-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E!
Unable to set value : HKU\S-1-5-21-642521359-2119642944-3776796898-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Search_URL| /E!
Unable to set value : HKU\S-1-5-21-642521359-2119642944-3776796898-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E!
Unable to set value : HKU\S-1-5-21-642521359-2119642944-3776796898-1000\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E!
Registry value HKEY_USERS\S-1-5-21-642521359-2119642944-3776796898-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-642521359-2119642944-3776796898-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A}\ deleted successfully.
C:\Program Files (x86)\CentrumczToolbar\IEToolbar.dll moved successfully.
Registry value HKEY_USERS\S-1-5-21-642521359-2119642944-3776796898-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}\ deleted successfully.
C:\Users\Petr\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A}\ not found.
File C:\Program Files (x86)\CentrumczToolbar\IEToolbar.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}\ not found.
File C:\Users\Petr\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D5D47440-0750-463D-BAEF-A47D02414806} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D5D47440-0750-463D-BAEF-A47D02414806}\ deleted successfully.
File C:\Program Files (x86)\CentrumczToolbar\IEToolbar.dll not found.
Registry value HKEY_USERS\S-1-5-21-642521359-2119642944-3776796898-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D5D47440-0750-463D-BAEF-A47D02414806} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D5D47440-0750-463D-BAEF-A47D02414806}\ not found.
File C:\Program Files (x86)\CentrumczToolbar\IEToolbar.dll not found.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Jabbim.lnk moved successfully.
C:\Program Files (x86)\Jabbim\jabbim.exe moved successfully.
C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Windows.lnk moved successfully.
File move failed. C:\Windows\SysWOW64\shutdown.exe scheduled to be moved on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
File C:\Program Files (x86)\CentrumczToolbar\IEToolbar.dll not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\centrumcztoolbar\ deleted successfully.
Invalid CLSID key: C:\Program Files (x86)\CentrumczToolbar\IEToolbar.dll
File C:\Program Files (x86)\CentrumczToolbar\IEToolbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
========== COMMANDS ==========
 
OTL by OldTimer - Version 3.1.36.1 log created on 03122010_060350

Files\Folders moved on Reboot...
File move failed. C:\Windows\SysWOW64\shutdown.exe scheduled to be moved on reboot.

Registry entries deleted on Reboot...
Ale pc je ted trochu pomaly :o

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: System Windows se vypne za necelou minutu

#9 Příspěvek od motji »

Pomalý :o , to může být i po té aktualizaci.
Nevím čím to bylo zposobeno, ale měl jste nastaveno po startu, aby se počítač restartoval :roll:
O4 - Startup: C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Windows.lnk = C:\Windows\SysWOW64\shutdown.exe


:arrow: Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

Obrázekzáložka čistič
-nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
-po analýze klikněte na Spustit Ccleaner

Obrázekzáložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy :arrow: ok :arrow: zavřít

Obrázek Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.

Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.


:arrow: A napište, zda se to zlepšilo. Pokud ne, zkuste ještě, jestli něco nenajde SAS


:arrow: Stahněte SAS http://portable.superantispyware.com/sassaferun.php
-proveďte aktualizaci a dejte uplný sken.
-Co najde, smažte,a napište co našel.
(tato verze se neinstaluje, je v angličtině. Pokud potřebujete uplný návod, klikněte mi v podpisu na SAS)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: System Windows se vypne za necelou minutu

#10 Příspěvek od motji »

Jak to tu vypadá? :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

fousek
Návštěvník
Návštěvník
Příspěvky: 1
Registrován: 19 led 2012 13:37

Re: System Windows se vypne za necelou minutu

#11 Příspěvek od fousek »

mam stejny problem delal sem to podle navodu ale neslo mi to .. tady josu ty logy co potrebujes a posli mi pls ten posledni krok v tom OTL diky moc :)

extras:

OTL Extras logfile created on: 19.1.2012 13:30:27 - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Minikobzol\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

4,00 Gb Total Physical Memory | 3,48 Gb Available Physical Memory | 87,03% Memory free
8,00 Gb Paging File | 7,52 Gb Available in Paging File | 94,04% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 71,55 Gb Total Space | 6,27 Gb Free Space | 8,76% Space Free | Partition Type: NTFS
Drive E: | 980,05 Mb Total Space | 18,64 Mb Free Space | 1,90% Space Free | Partition Type: FAT32

Computer Name: MINIKOBZOL-PC | User Name: Minikobzol | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (All) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm[@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation)
.hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta[@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html[@ = ChromeHTML] -- Reg Error: Key error. File not found
.inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.js[@ = JSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.reg[@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation)
.txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- "%1" %*
.chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cmd [@ = cmdfile] -- "%1" %*
.com [@ = comfile] -- "%1" %*
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.exe [@ = exefile] -- "%1" %*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
.inf [@ = inffile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- C:\Windows\SysWow64\rundll32.exe (Microsoft Corporation)
.js [@ = JSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.pif [@ = piffile] -- "%1" %*
.reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation)
.scr [@ = scrfile] -- "%1" /S
.txt [@ = txtfile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- Reg Error: Key error.
https [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- Reg Error: Key error.
https [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0031FC73-643E-19DB-0A34-F7FF70B2F1E7}" = ccc-utility64
"{401E03EC-1644-1B0A-B8D3-C40477ADCEC4}" = AMD Drag and Drop Transcoding
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{6681A016-C62A-DD7B-7F56-25B1A55CE12A}" = AMD Media Foundation Decoders
"{72DECC0F-58E0-0618-C857-43B4D3DB7B75}" = AMD Catalyst Install Manager
"{790E02A1-145A-3843-8C13-A4F41C9B48B7}" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile CSY Language Pack" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"WinRAR archiver" = WinRAR 4.01 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{13557DA4-3AB0-DB9B-B746-1BE901DEC60D}" = Catalyst Control Center
"{19A492A0-888F-44A0-9B21-D91700763F62}" = Catalyst Control Center - Branding
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java(TM) 6 Update 29
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{34962E5E-FAC1-D8DF-7070-AA2B58971E31}" = Catalyst Control Center Graphics Previews Common
"{35CB6715-41F8-4F99-8881-6FC75BF054B0}" = Oblivion
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7627A1A6-437E-43D1-A5D5-D4B1AFD2A3EB}" = Yandex.Bar v barvách Seznamu 5.4 pro Internet Explorer
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{AC76BA86-7AD7-1029-7B44-AA1000000001}" = Adobe Reader X (10.1.2) - Czech
"{BE4BA698-8533-4F77-9559-C7F3F78C0B05}" = Assassin's Creed Brotherhood
"{DAABB60F-D2CB-ADC0-6FA7-8B2BB0A78CDA}" = Catalyst Control Center InstallProxy
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E737A098-F161-4B6F-AF22-86AAE34F6FBD}" = Pro Evolution Soccer 2012
"{EFABB945-0D32-C208-897A-F611F63A19D4}" = CCC Help English
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Advanced SystemCare 5_is1" = Advanced SystemCare 5
"Ashampoo Burning Studio 6 FREE_is1" = Ashampoo Burning Studio 6 FREE v.6.80
"AVG9Uninstall" = AVG 9.0
"conduitEngine" = Conduit Engine
"DAEMON Tools Lite" = DAEMON Tools Lite
"DivX Setup" = DivX Setup
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 7.9.0
"MyAshampoo Toolbar" = MyAshampoo Toolbar
"Opera 11.60.1185" = Opera 11.60
"PotPlayer" = Daum PotPlayer 1.5.28025
"PunkBusterSvc" = PunkBuster Services
"StartNow Toolbar" = StartNow Toolbar
"uTorrent" = µTorrent
"uTorrentBar Toolbar" = uTorrentBar Toolbar
"Vypínač na dobrou noc_is1" = Vypínač na dobrou noc verze 2.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 29.12.2011 13:04:01 | Computer Name = Minikobzol-PC | Source = Application Hang | ID = 1002
Description = Program cod2.exe verze 2.1.12.0 přestal spolupracovat se systémem
Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto
problému, vyhledejte historii problému v ovládacím panelu Centrum akcí. ID procesu:
d9c Čas spuštění: 01ccc64bc0d7afff Čas ukončení: 12 Cesta k aplikaci: F:\Setup\rsrc\cod2.exe

ID
hlášení:

Error - 13.1.2012 7:14:10 | Computer Name = Minikobzol-PC | Source = Application Error | ID = 1000
Description = Název chybující aplikace: pes2012.exe, verze: 1.3.0.0, časové razítko:
0x4ecd86d9 Název chybujícího modulu: pes2012.exe, verze: 1.3.0.0, časové razítko:
0x4ecd86d9 Kód výjimky: 0xc0000005 Posun chyby: 0x0038b834 ID chybujícího procesu:
0x1100 Čas spuštění chybující aplikace: 0x01ccd1de72623a3e Cesta k chybující aplikaci:
C:\Program Files (x86)\KONAMI\Pro Evolution Soccer 2012\pes2012.exe Cesta k chybujícímu
modulu: C:\Program Files (x86)\KONAMI\Pro Evolution Soccer 2012\pes2012.exe ID zprávy:
b6fd37ce-3dd7-11e1-b620-0013d4c29d67

Error - 13.1.2012 7:15:50 | Computer Name = Minikobzol-PC | Source = Application Error | ID = 1000
Description = Název chybující aplikace: pes2012.exe, verze: 1.3.0.0, časové razítko:
0x4ecd86d9 Název chybujícího modulu: pes2012.exe, verze: 1.3.0.0, časové razítko:
0x4ecd86d9 Kód výjimky: 0xc0000005 Posun chyby: 0x0038b834 ID chybujícího procesu:
0x13a0 Čas spuštění chybující aplikace: 0x01ccd1e48478ed20 Cesta k chybující aplikaci:
C:\Program Files (x86)\KONAMI\Pro Evolution Soccer 2012\pes2012.exe Cesta k chybujícímu
modulu: C:\Program Files (x86)\KONAMI\Pro Evolution Soccer 2012\pes2012.exe ID zprávy:
f2ab60ea-3dd7-11e1-b620-0013d4c29d67

Error - 15.1.2012 7:27:53 | Computer Name = Minikobzol-PC | Source = Application Error | ID = 1000
Description = Název chybující aplikace: avgupd.exe, verze: 9.0.0.910, časové razítko:
0x4e4ba13b Název chybujícího modulu: winspamcatcher.dll_unloaded, verze: 0.0.0.0,
časové razítko: 0x4c515b49 Kód výjimky: 0xc0000005 Posun chyby: 0x70b95050 ID chybujícího
procesu: 0x15a4 Čas spuštění chybující aplikace: 0x01ccd378a9b3eb30 Cesta k chybující
aplikaci: C:\Program Files (x86)\AVG\AVG9\avgupd.exe Cesta k chybujícímu modulu:
winspamcatcher.dll ID zprávy: f6951868-3f6b-11e1-8e5c-0013d4c29d67

Error - 17.1.2012 14:19:46 | Computer Name = Minikobzol-PC | Source = Application Hang | ID = 1002
Description = Program TS3.exe verze 0.0.0.11190 přestal spolupracovat se systémem
Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto
problému, vyhledejte historii problému v ovládacím panelu Centrum akcí. ID procesu:
500 Čas spuštění: 01ccd54454862910 Čas ukončení: 109 Cesta k aplikaci: C:\Program
Files (x86)\Electronic Arts\The Sims 3\Game\Bin\TS3.exe ID hlášení:

Error - 18.1.2012 10:00:17 | Computer Name = Minikobzol-PC | Source = Application Hang | ID = 1002
Description = Program iexplore.exe verze 9.0.8112.16421 přestal spolupracovat se
systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací
o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID
procesu: 8b8 Čas spuštění: 01ccd5e978a46a56 Čas ukončení: 23 Cesta k aplikaci: C:\Program
Files (x86)\Internet Explorer\iexplore.exe ID hlášení:

Error - 18.1.2012 13:19:04 | Computer Name = Minikobzol-PC | Source = Application Error | ID = 1000
Description = Název chybující aplikace: PotPlayerMini.exe, verze: 0.0.0.0, časové
razítko: 0x4d252720 Název chybujícího modulu: ntdll.dll, verze: 6.1.7601.17725,
časové razítko: 0x4ec49b8f Kód výjimky: 0xc0000005 Posun chyby: 0x00033ab3 ID chybujícího
procesu: 0x1684 Čas spuštění chybující aplikace: 0x01ccd60544d73dd6 Cesta k chybující
aplikaci: C:\Program Files (x86)\Daum\PotPlayer\PotPlayerMini.exe Cesta k chybujícímu
modulu: C:\Windows\SysWOW64\ntdll.dll ID zprávy: 8527b45b-41f8-11e1-bd47-0013d4c29d67

Error - 18.1.2012 13:19:12 | Computer Name = Minikobzol-PC | Source = Application Error | ID = 1000
Description = Název chybující aplikace: PotPlayerMini.exe, verze: 0.0.0.0, časové
razítko: 0x4d252720 Název chybujícího modulu: ntdll.dll, verze: 6.1.7601.17725,
časové razítko: 0x4ec49b8f Kód výjimky: 0xc0000005 Posun chyby: 0x00033ab3 ID chybujícího
procesu: 0x5d0 Čas spuštění chybující aplikace: 0x01ccd6054af1c6fe Cesta k chybující
aplikaci: C:\Program Files (x86)\Daum\PotPlayer\PotPlayerMini.exe Cesta k chybujícímu
modulu: C:\Windows\SysWOW64\ntdll.dll ID zprávy: 89ec1c10-41f8-11e1-bd47-0013d4c29d67

Error - 19.1.2012 7:40:17 | Computer Name = Minikobzol-PC | Source = System Restore | ID = 8193
Description =

Error - 19.1.2012 8:30:04 | Computer Name = Minikobzol-PC | Source = System Restore | ID = 8193
Description =

[ System Events ]
Error - 17.1.2012 16:46:12 | Computer Name = Minikobzol-PC | Source = ACPI | ID = 327686
Description = IRQARB: Systém ACPI BIOS neobsahuje přerušení IRQ pro zařízení v patici
PCI 0 s funkcí 1. Obraťte se na prodejce systému s žádostí o odbornou pomoc.

Error - 17.1.2012 16:46:12 | Computer Name = Minikobzol-PC | Source = ACPI | ID = 327686
Description = IRQARB: Systém ACPI BIOS neobsahuje přerušení IRQ pro zařízení v patici
PCI 0 s funkcí 1. Obraťte se na prodejce systému s žádostí o odbornou pomoc.

Error - 17.1.2012 16:46:12 | Computer Name = Minikobzol-PC | Source = ACPI | ID = 327686
Description = IRQARB: Systém ACPI BIOS neobsahuje přerušení IRQ pro zařízení v patici
PCI 0 s funkcí 1. Obraťte se na prodejce systému s žádostí o odbornou pomoc.

Error - 17.1.2012 16:46:12 | Computer Name = Minikobzol-PC | Source = ACPI | ID = 327686
Description = IRQARB: Systém ACPI BIOS neobsahuje přerušení IRQ pro zařízení v patici
PCI 0 s funkcí 1. Obraťte se na prodejce systému s žádostí o odbornou pomoc.

Error - 17.1.2012 16:46:12 | Computer Name = Minikobzol-PC | Source = ACPI | ID = 327686
Description = IRQARB: Systém ACPI BIOS neobsahuje přerušení IRQ pro zařízení v patici
PCI 0 s funkcí 1. Obraťte se na prodejce systému s žádostí o odbornou pomoc.

Error - 17.1.2012 16:46:12 | Computer Name = Minikobzol-PC | Source = ACPI | ID = 327686
Description = IRQARB: Systém ACPI BIOS neobsahuje přerušení IRQ pro zařízení v patici
PCI 0 s funkcí 1. Obraťte se na prodejce systému s žádostí o odbornou pomoc.

Error - 17.1.2012 16:46:12 | Computer Name = Minikobzol-PC | Source = ACPI | ID = 327686
Description = IRQARB: Systém ACPI BIOS neobsahuje přerušení IRQ pro zařízení v patici
PCI 0 s funkcí 1. Obraťte se na prodejce systému s žádostí o odbornou pomoc.

Error - 17.1.2012 16:46:12 | Computer Name = Minikobzol-PC | Source = ACPI | ID = 327686
Description = IRQARB: Systém ACPI BIOS neobsahuje přerušení IRQ pro zařízení v patici
PCI 0 s funkcí 1. Obraťte se na prodejce systému s žádostí o odbornou pomoc.

Error - 17.1.2012 16:46:12 | Computer Name = Minikobzol-PC | Source = ACPI | ID = 327686
Description = IRQARB: Systém ACPI BIOS neobsahuje přerušení IRQ pro zařízení v patici
PCI 0 s funkcí 1. Obraťte se na prodejce systému s žádostí o odbornou pomoc.

Error - 17.1.2012 16:46:12 | Computer Name = Minikobzol-PC | Source = ACPI | ID = 327686
Description = IRQARB: Systém ACPI BIOS neobsahuje přerušení IRQ pro zařízení v patici
PCI 0 s funkcí 1. Obraťte se na prodejce systému s žádostí o odbornou pomoc.


< End of report >

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: System Windows se vypne za necelou minutu

#12 Příspěvek od motji »

fousek
Založte si prosím vlastní topic, takto by to bylo nepřehledné. děkuji :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: System Windows se vypne za necelou minutu

#13 Příspěvek od motji »

Dobrý večer,
založte si prosím vlastní topic a vložte do něj log ze rsitu http://forum.viry.cz/viewtopic.php?f=13&t=105895
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět