Re: Matky notebook v ohrožení
Napsal: 02 zář 2015 21:42
Fix result of Farbar Recovery Scan Tool (x86) Version:31-08-2015
Ran by Milena (2015-09-02 22:24:56) Run:2
Running from C:\Users\Milena\Desktop
Loaded Profiles: Milena (Available Profiles: Milena)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
HKLM\...\Run: [] => [X]
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKU\S-1-5-21-2164688541-3591248526-3584394944-1003\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6490904 2015-08-20] (Piriform Ltd)
S3 btwaudio; system32\drivers\btwaudio.sys [X]
S3 btwavdt; system32\drivers\btwavdt.sys [X]
S3 btwl2cap; system32\DRIVERS\btwl2cap.sys [X]
S3 btwrchid; system32\DRIVERS\btwrchid.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 upperdev; system32\DRIVERS\usbser_lowerflt.sys [X]
S3 usbbus; system32\DRIVERS\lgusbbus.sys [X]
S3 UsbDiag; system32\DRIVERS\lgusbdiag.sys [X]
S3 USBModem; system32\DRIVERS\lgusbmodem.sys [X]
S3 WisINT15; \??\C:\Elements\1stboot\WisINT15.SYS [X]
2015-09-02 21:39 - 2015-09-02 21:42 - 00000000 ____D C:\AdwCleaner
2015-09-02 21:36 - 2015-09-02 21:36 - 01654272 _____ C:\Users\Milena\Desktop\adwcleaner_5.005.exe
2015-09-02 21:07 - 2015-09-02 21:10 - 00069980 _____ C:\Users\Milena\Desktop\Addition.txt
2015-09-02 21:06 - 2015-09-02 21:53 - 00018316 _____ C:\Users\Milena\Desktop\FRST.txt
2015-09-02 18:30 - 2015-09-02 18:31 - 06667640 _____ (Piriform Ltd) C:\Users\Milena\Desktop\ccsetup509.exe
2012-10-14 18:08 - 2012-10-14 18:09 - 31175144 _____ (Oracle Corporation) C:\Program Files\jre-7u7-windows-i586.exe
2012-11-26 23:02 - 2012-11-26 23:03 - 31160808 _____ (Oracle Corporation) C:\Program Files\jre-7u9-windows-i586.exe
2011-01-09 15:39 - 2014-09-14 22:23 - 0000680 _____ () C:\Users\Milena\AppData\Local\d3d9caps.dat
2008-12-26 12:27 - 2008-12-26 12:27 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
Task: {4532A4F4-939E-4E50-93D2-7860BEB2B226} - System32\Tasks\{17B69AE0-20F1-409E-8B72-FAC96599E847} => pcalua.exe -a C:\Users\Milena\Desktop\pfs-setup-en.exe -d C:\Users\Milena\Desktop
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
Error: (0) Failed to create a restore point.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value removed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value removed successfully.
HKU\S-1-5-21-2164688541-3591248526-3584394944-1003\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value removed successfully.
btwaudio => service removed successfully.
btwavdt => service removed successfully.
btwl2cap => service removed successfully.
btwrchid => service removed successfully.
NwlnkFlt => service removed successfully.
NwlnkFwd => service removed successfully.
upperdev => service removed successfully.
usbbus => service removed successfully.
UsbDiag => service removed successfully.
USBModem => service removed successfully.
WisINT15 => service removed successfully.
C:\AdwCleaner => moved successfully
C:\Users\Milena\Desktop\adwcleaner_5.005.exe => moved successfully
C:\Users\Milena\Desktop\Addition.txt => moved successfully
C:\Users\Milena\Desktop\FRST.txt => moved successfully
C:\Users\Milena\Desktop\ccsetup509.exe => moved successfully
C:\Program Files\jre-7u7-windows-i586.exe => moved successfully
C:\Program Files\jre-7u9-windows-i586.exe => moved successfully
C:\Users\Milena\AppData\Local\d3d9caps.dat => moved successfully
C:\ProgramData\ezsidmv.dat => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4532A4F4-939E-4E50-93D2-7860BEB2B226}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4532A4F4-939E-4E50-93D2-7860BEB2B226}" => key removed successfully.
C:\Windows\System32\Tasks\{17B69AE0-20F1-409E-8B72-FAC96599E847} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{17B69AE0-20F1-409E-8B72-FAC96599E847}" => key removed successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
EmptyTemp: => 207.7 MB temporary data Removed.
The system needed a reboot.
==== End of Fixlog 22:35:21 ====
Ran by Milena (2015-09-02 22:24:56) Run:2
Running from C:\Users\Milena\Desktop
Loaded Profiles: Milena (Available Profiles: Milena)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
HKLM\...\Run: [] => [X]
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKU\S-1-5-21-2164688541-3591248526-3584394944-1003\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6490904 2015-08-20] (Piriform Ltd)
S3 btwaudio; system32\drivers\btwaudio.sys [X]
S3 btwavdt; system32\drivers\btwavdt.sys [X]
S3 btwl2cap; system32\DRIVERS\btwl2cap.sys [X]
S3 btwrchid; system32\DRIVERS\btwrchid.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 upperdev; system32\DRIVERS\usbser_lowerflt.sys [X]
S3 usbbus; system32\DRIVERS\lgusbbus.sys [X]
S3 UsbDiag; system32\DRIVERS\lgusbdiag.sys [X]
S3 USBModem; system32\DRIVERS\lgusbmodem.sys [X]
S3 WisINT15; \??\C:\Elements\1stboot\WisINT15.SYS [X]
2015-09-02 21:39 - 2015-09-02 21:42 - 00000000 ____D C:\AdwCleaner
2015-09-02 21:36 - 2015-09-02 21:36 - 01654272 _____ C:\Users\Milena\Desktop\adwcleaner_5.005.exe
2015-09-02 21:07 - 2015-09-02 21:10 - 00069980 _____ C:\Users\Milena\Desktop\Addition.txt
2015-09-02 21:06 - 2015-09-02 21:53 - 00018316 _____ C:\Users\Milena\Desktop\FRST.txt
2015-09-02 18:30 - 2015-09-02 18:31 - 06667640 _____ (Piriform Ltd) C:\Users\Milena\Desktop\ccsetup509.exe
2012-10-14 18:08 - 2012-10-14 18:09 - 31175144 _____ (Oracle Corporation) C:\Program Files\jre-7u7-windows-i586.exe
2012-11-26 23:02 - 2012-11-26 23:03 - 31160808 _____ (Oracle Corporation) C:\Program Files\jre-7u9-windows-i586.exe
2011-01-09 15:39 - 2014-09-14 22:23 - 0000680 _____ () C:\Users\Milena\AppData\Local\d3d9caps.dat
2008-12-26 12:27 - 2008-12-26 12:27 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
Task: {4532A4F4-939E-4E50-93D2-7860BEB2B226} - System32\Tasks\{17B69AE0-20F1-409E-8B72-FAC96599E847} => pcalua.exe -a C:\Users\Milena\Desktop\pfs-setup-en.exe -d C:\Users\Milena\Desktop
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
Error: (0) Failed to create a restore point.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value removed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value removed successfully.
HKU\S-1-5-21-2164688541-3591248526-3584394944-1003\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value removed successfully.
btwaudio => service removed successfully.
btwavdt => service removed successfully.
btwl2cap => service removed successfully.
btwrchid => service removed successfully.
NwlnkFlt => service removed successfully.
NwlnkFwd => service removed successfully.
upperdev => service removed successfully.
usbbus => service removed successfully.
UsbDiag => service removed successfully.
USBModem => service removed successfully.
WisINT15 => service removed successfully.
C:\AdwCleaner => moved successfully
C:\Users\Milena\Desktop\adwcleaner_5.005.exe => moved successfully
C:\Users\Milena\Desktop\Addition.txt => moved successfully
C:\Users\Milena\Desktop\FRST.txt => moved successfully
C:\Users\Milena\Desktop\ccsetup509.exe => moved successfully
C:\Program Files\jre-7u7-windows-i586.exe => moved successfully
C:\Program Files\jre-7u9-windows-i586.exe => moved successfully
C:\Users\Milena\AppData\Local\d3d9caps.dat => moved successfully
C:\ProgramData\ezsidmv.dat => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4532A4F4-939E-4E50-93D2-7860BEB2B226}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4532A4F4-939E-4E50-93D2-7860BEB2B226}" => key removed successfully.
C:\Windows\System32\Tasks\{17B69AE0-20F1-409E-8B72-FAC96599E847} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{17B69AE0-20F1-409E-8B72-FAC96599E847}" => key removed successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
EmptyTemp: => 207.7 MB temporary data Removed.
The system needed a reboot.
==== End of Fixlog 22:35:21 ====