Tady je výstup z RK.Nic jsem dál nemazal ani nedělal.
RogueKiller V12.9.2.0 [Jan 9 2017] (Free) by Adlice Software
mail :
http://www.adlice.com/contact/
Feedback :
http://forum.adlice.com
Webová stránka :
http://www.adlice.com/download/roguekiller/
Blog :
http://www.adlice.com
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spuštěno : Normální režim
Uživatel : milan [Práva správce]
Started from : C:\Users\milan\Downloads\RogueKiller.exe
Mód : Prohledat -- Datum : 01/16/2017 17:21:33 (Duration : 01:10:20)
¤¤¤ Procesy : 0 ¤¤¤
¤¤¤ Registry : 15 ¤¤¤
[PUP.Gen1] HKEY_CLASSES_ROOT\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98} (C:\Program Files\MyFree Codec\1.0b beta\XVID-CORE\xvid.ax) -> Nalezeno
[PUP.Gen1] HKEY_CLASSES_ROOT\CLSID\{64697678-0000-0010-8000-00AA00389B71} (C:\Program Files\MyFree Codec\1.0b beta\XVID-CORE\xvid.ax) -> Nalezeno
[PUP.Gen1] HKEY_CLASSES_ROOT\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2} (C:\Program Files\MyFree Codec\1.0b beta\MyFree.ax) -> Nalezeno
[Suspicious.Path] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | SNPMI03 : C:\Windows\vsnpmi03.exe [7] -> Nalezeno
[Suspicious.Path] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost | HPService : (C:\Users\milan\AppData\Local\Temp\7zS18C6\hpslpsvc32.dll) [x] -> Nalezeno
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CFcatchme (\??\C:\Users\milan\AppData\Local\Temp\CFcatchme.sys) -> Nalezeno
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ECTUKUHGCAEC (C:\Users\milan\AppData\Local\Temp\ECTUKUHGCAEC.exe) -> Nalezeno
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HPSLPSVC (C:\Users\milan\AppData\Local\Temp\7zS18C6\hpslpsvc32.dll) -> Nalezeno
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\JMLVQPVMACCI (C:\Users\milan\AppData\Local\Temp\JMLVQPVMACCI.exe) -> Nalezeno
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RBAAE (C:\Users\milan\AppData\Local\Temp\RBAAE.exe) -> Nalezeno
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\CFcatchme (\??\C:\Users\milan\AppData\Local\Temp\CFcatchme.sys) -> Nalezeno
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ECTUKUHGCAEC (C:\Users\milan\AppData\Local\Temp\ECTUKUHGCAEC.exe) -> Nalezeno
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\HPSLPSVC (C:\Users\milan\AppData\Local\Temp\7zS18C6\hpslpsvc32.dll) -> Nalezeno
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\JMLVQPVMACCI (C:\Users\milan\AppData\Local\Temp\JMLVQPVMACCI.exe) -> Nalezeno
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RBAAE (C:\Users\milan\AppData\Local\Temp\RBAAE.exe) -> Nalezeno
¤¤¤ Úlohy : 0 ¤¤¤
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ WMI : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤
¤¤¤ Webové prohlížeče : 1 ¤¤¤
[PUM.HomePage][Chrome:Config] Default [SecurePrefs] : session.startup_urls [
http://www.centrum.cz/] -> Nalezeno
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: ST3160812A ATA Device +++++
--- User ---
[MBR] 7913e8a8aecad2310d85514331edd9c6
[BSP] 6d4420669008a4363831bd2987892e2d : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 152617 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive1: Maxtor 6B200P0 ATA Device +++++
--- User ---
[MBR] b9680e8321d210c162356bc061d38c7a
[BSP] c4040624f82ea83ffe3f986e36c8ff34 : Windows XP|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 194466 MB [Windows XP Bootstrap | Windows XP Bootloader]
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive2: TOSHIBA MK5075GSX USB Device +++++
--- User ---
[MBR] a10dd43547ad437e18d343c9bf40638f
[BSP] 9c5d54a1108fe94feed7664943749264 : Empty MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 476935 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
Error reading LL2 MBR! ([32] Po?adavek není podporován. )