Re: Preventivka - zpomalené PC
Napsal: 02 pro 2013 22:27
Zde je log:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 01-12-2013
Ran by Ivan at 2013-12-02 22:23:53 Run:1
Running from C:\Documents and Settings\Ivan\Plocha
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKCU\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [153136 2007-05-16] (Nero AG)
HKCU\...\Run: [MSMSGS] - C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)
MountPoints2: {5c4830c1-a02e-11e1-8a0d-0025225c5197} - G:\VW100_Modem_Installation.exe
MountPoints2: {f2ce0c40-3d4a-11e2-bfa4-0025225c5197} - G:\LaunchU3.exe -a
HKU\Lubinak\...\Run: [swg] - "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
HKU\Lubinak\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [ 2007-05-16] (Nero AG)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
S2 ekrn; "C:\Program Files\ESET\ESET Smart Security\ekrn.exe" [x]
S3 AmdLLD; system32\DRIVERS\AmdLLD.sys [x]
S1 ehdrv; system32\DRIVERS\ehdrv.sys [x]
U5 Epfwndis; C:\Windows\System32\Drivers\Epfwndis.sys [33096 2009-02-06] (ESET)
S4 IntelIde; No ImagePath
S3 massfilter; system32\drivers\massfilter.sys [x]
S3 RTL8192su; system32\DRIVERS\RTL8192su.sys [x]
U1 WS2IFSL;
S3 ZTEusbnet; system32\DRIVERS\ZTEusbnet.sys [x]
S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [x]
S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [x]
2013-12-02 20:57 - 2013-12-02 20:57 - 00029696 _____ C:\Documents and Settings\Ivan\Local Settings\Data aplikací\MSGBOX.EXE
2013-12-02 20:57 - 2013-12-02 20:57 - 00015327 _____ C:\Documents and Settings\Ivan\Plocha\LM.bat
2013-12-02 20:55 - 2013-12-02 20:55 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Ivan\Plocha\FRSTLauncher.exe
2013-12-02 20:55 - 2013-03-09 14:19 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Avira
C:\Documents and Settings\Ivan\Local Settings\Temp\avgnt.exe
C:\Documents and Settings\Ivan\Local Settings\Temp\Quarantine.exe
C:\Documents and Settings\Ivan\Local Settings\Temp\tbBit0.dll
C:\Documents and Settings\Ivan\Local Settings\Temp\uninst1.exe
C:\Documents and Settings\Lubinak\Local Settings\Temp\avgnt.exe
C:\Documents and Settings\Lubinak\Local Settings\Temp\setup.exe
2013-12-02 22:01 - 2013-12-02 22:01 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Ivan\Plocha\FRSTLauncher (1).exe
2013-12-02 22:01 - 2013-12-02 22:01 - 00112107 _____ (forum.viry.cz) C:\Documents and Settings\Ivan\Plocha\VerzeOS.exe
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
AlternateDataStreams: C:\Documents and Settings\All Users\Data aplikací\TEMP:D0757AAB
Hosts:
CMD: shutdown /r /f /t 2
End
*****************
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\MSMSGS => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5c4830c1-a02e-11e1-8a0d-0025225c5197} => Key deleted successfully.
HKCR\CLSID\{5c4830c1-a02e-11e1-8a0d-0025225c5197} => Key not found.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f2ce0c40-3d4a-11e2-bfa4-0025225c5197} => Key deleted successfully.
HKCR\CLSID\{f2ce0c40-3d4a-11e2-bfa4-0025225c5197} => Key not found.
HKU\Lubinak\Software\Microsoft\Windows\CurrentVersion\Run\\swg => Value deleted successfully.
HKU\Lubinak\Software\Microsoft\Windows\CurrentVersion\Run\\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value deleted successfully.
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found.
HKLM\SOFTWARE\Policies\Google => Key deleted successfully.
ekrn => Service deleted successfully.
AmdLLD => Service deleted successfully.
ehdrv => Service deleted successfully.
Epfwndis => Service deleted successfully.
IntelIde => Service deleted successfully.
massfilter => Service deleted successfully.
RTL8192su => Service deleted successfully.
WS2IFSL => Service deleted successfully.
ZTEusbnet => Service deleted successfully.
ZTEusbnmea => Service deleted successfully.
ZTEusbser6k => Service deleted successfully.
"C:\Documents and Settings\Ivan\Local Settings\Data aplikací\MSGBOX.EXE" => File/Directory not found.
"C:\Documents and Settings\Ivan\Plocha\LM.bat" => File/Directory not found.
C:\Documents and Settings\Ivan\Plocha\FRSTLauncher.exe => Moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Avira => Moved successfully.
"C:\Documents and Settings\Ivan\Local Settings\Temp\avgnt.exe" => File/Directory not found.
C:\Documents and Settings\Ivan\Local Settings\Temp\Quarantine.exe => Moved successfully.
C:\Documents and Settings\Ivan\Local Settings\Temp\tbBit0.dll => Moved successfully.
C:\Documents and Settings\Ivan\Local Settings\Temp\uninst1.exe => Moved successfully.
C:\Documents and Settings\Lubinak\Local Settings\Temp\avgnt.exe => Moved successfully.
C:\Documents and Settings\Lubinak\Local Settings\Temp\setup.exe => Moved successfully.
"C:\Documents and Settings\Ivan\Plocha\FRSTLauncher (1).exe" => File/Directory not found.
"C:\Documents and Settings\Ivan\Plocha\VerzeOS.exe" => File/Directory not found.
C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\WINDOWS\Tasks\avast! Emergency Update.job => Moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Documents and Settings\All Users\Data aplikací\TEMP => ":D0757AAB" ADS removed successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
========= shutdown /r /f /t 2 =========
========= End of CMD: =========
==== End of Fixlog ====
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 01-12-2013
Ran by Ivan at 2013-12-02 22:23:53 Run:1
Running from C:\Documents and Settings\Ivan\Plocha
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKCU\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [153136 2007-05-16] (Nero AG)
HKCU\...\Run: [MSMSGS] - C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)
MountPoints2: {5c4830c1-a02e-11e1-8a0d-0025225c5197} - G:\VW100_Modem_Installation.exe
MountPoints2: {f2ce0c40-3d4a-11e2-bfa4-0025225c5197} - G:\LaunchU3.exe -a
HKU\Lubinak\...\Run: [swg] - "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
HKU\Lubinak\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [ 2007-05-16] (Nero AG)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
S2 ekrn; "C:\Program Files\ESET\ESET Smart Security\ekrn.exe" [x]
S3 AmdLLD; system32\DRIVERS\AmdLLD.sys [x]
S1 ehdrv; system32\DRIVERS\ehdrv.sys [x]
U5 Epfwndis; C:\Windows\System32\Drivers\Epfwndis.sys [33096 2009-02-06] (ESET)
S4 IntelIde; No ImagePath
S3 massfilter; system32\drivers\massfilter.sys [x]
S3 RTL8192su; system32\DRIVERS\RTL8192su.sys [x]
U1 WS2IFSL;
S3 ZTEusbnet; system32\DRIVERS\ZTEusbnet.sys [x]
S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [x]
S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [x]
2013-12-02 20:57 - 2013-12-02 20:57 - 00029696 _____ C:\Documents and Settings\Ivan\Local Settings\Data aplikací\MSGBOX.EXE
2013-12-02 20:57 - 2013-12-02 20:57 - 00015327 _____ C:\Documents and Settings\Ivan\Plocha\LM.bat
2013-12-02 20:55 - 2013-12-02 20:55 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Ivan\Plocha\FRSTLauncher.exe
2013-12-02 20:55 - 2013-03-09 14:19 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Avira
C:\Documents and Settings\Ivan\Local Settings\Temp\avgnt.exe
C:\Documents and Settings\Ivan\Local Settings\Temp\Quarantine.exe
C:\Documents and Settings\Ivan\Local Settings\Temp\tbBit0.dll
C:\Documents and Settings\Ivan\Local Settings\Temp\uninst1.exe
C:\Documents and Settings\Lubinak\Local Settings\Temp\avgnt.exe
C:\Documents and Settings\Lubinak\Local Settings\Temp\setup.exe
2013-12-02 22:01 - 2013-12-02 22:01 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Ivan\Plocha\FRSTLauncher (1).exe
2013-12-02 22:01 - 2013-12-02 22:01 - 00112107 _____ (forum.viry.cz) C:\Documents and Settings\Ivan\Plocha\VerzeOS.exe
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
AlternateDataStreams: C:\Documents and Settings\All Users\Data aplikací\TEMP:D0757AAB
Hosts:
CMD: shutdown /r /f /t 2
End
*****************
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\MSMSGS => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5c4830c1-a02e-11e1-8a0d-0025225c5197} => Key deleted successfully.
HKCR\CLSID\{5c4830c1-a02e-11e1-8a0d-0025225c5197} => Key not found.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f2ce0c40-3d4a-11e2-bfa4-0025225c5197} => Key deleted successfully.
HKCR\CLSID\{f2ce0c40-3d4a-11e2-bfa4-0025225c5197} => Key not found.
HKU\Lubinak\Software\Microsoft\Windows\CurrentVersion\Run\\swg => Value deleted successfully.
HKU\Lubinak\Software\Microsoft\Windows\CurrentVersion\Run\\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value deleted successfully.
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found.
HKLM\SOFTWARE\Policies\Google => Key deleted successfully.
ekrn => Service deleted successfully.
AmdLLD => Service deleted successfully.
ehdrv => Service deleted successfully.
Epfwndis => Service deleted successfully.
IntelIde => Service deleted successfully.
massfilter => Service deleted successfully.
RTL8192su => Service deleted successfully.
WS2IFSL => Service deleted successfully.
ZTEusbnet => Service deleted successfully.
ZTEusbnmea => Service deleted successfully.
ZTEusbser6k => Service deleted successfully.
"C:\Documents and Settings\Ivan\Local Settings\Data aplikací\MSGBOX.EXE" => File/Directory not found.
"C:\Documents and Settings\Ivan\Plocha\LM.bat" => File/Directory not found.
C:\Documents and Settings\Ivan\Plocha\FRSTLauncher.exe => Moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Avira => Moved successfully.
"C:\Documents and Settings\Ivan\Local Settings\Temp\avgnt.exe" => File/Directory not found.
C:\Documents and Settings\Ivan\Local Settings\Temp\Quarantine.exe => Moved successfully.
C:\Documents and Settings\Ivan\Local Settings\Temp\tbBit0.dll => Moved successfully.
C:\Documents and Settings\Ivan\Local Settings\Temp\uninst1.exe => Moved successfully.
C:\Documents and Settings\Lubinak\Local Settings\Temp\avgnt.exe => Moved successfully.
C:\Documents and Settings\Lubinak\Local Settings\Temp\setup.exe => Moved successfully.
"C:\Documents and Settings\Ivan\Plocha\FRSTLauncher (1).exe" => File/Directory not found.
"C:\Documents and Settings\Ivan\Plocha\VerzeOS.exe" => File/Directory not found.
C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\WINDOWS\Tasks\avast! Emergency Update.job => Moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Documents and Settings\All Users\Data aplikací\TEMP => ":D0757AAB" ADS removed successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
========= shutdown /r /f /t 2 =========
========= End of CMD: =========
==== End of Fixlog ====