Stránka 1 z 1

PC po zapnutí zatuhne, pouze nouzový režim

Napsal: 06 led 2011 20:49
od pdulik
Zdravím, :(
Potřeboval by jsem pomoc/poradit, dnes při normálním používání mi PC z niečhoš nic zathulo, tka jsem čekal chvíly, nic se nedělo, tak jsem ho restartoval a od té doby se vždy po naběhnutí do účtů zasekne, a jde pouze reset :( .... když mám počítač v nouzovém režimu, všechno je v pořádku,..Když jsems e zkoušel připojit na jiný účet(máme tu v PC dva můjj-správce a potom má přítelkyně - normální uživatel) tak u ní to šlo normálně (tedy) vypadalo to že to jde,.. tak jsem si řekl že tedy vytvořív v nouzáku nový účet správce, potom se tma zalogoju přetáhnu si důležité a tamten účet smažu... avšak do nového účtu už jsem se nedokázal ani přihlásit :(

Re: PC po zapnutí zatuhne, pouze nouzový režim

Napsal: 06 led 2011 21:26
od Roli
Zdravím, když už jsi v tom nouzáku, jde se přes bod obnovy vrátit k datu kdy PC normálně fungoval ?

Také použij Rsit z mého podpisu a dej mi sem z něj log.txt podívám se zda to nedělá nějaký šmejd.

Re: PC po zapnutí zatuhne, pouze nouzový režim

Napsal: 07 led 2011 16:00
od pdulik
Bohužel nejde :(
tady je ten LOG ;)

Logfile of random's system information tool 1.08 (written by random/random)
Run by Dulaj at 2011-01-07 15:59:13
Microsoft Windows 7 Professional
System drive C: has 4 GB (8%) free of 55 GB
Total RAM: 2047 MB (70% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:59:19, on 7.1.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Safe mode with network support

Running processes:
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\Dulaj.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.zaparit.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Dulaj\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: LinkAirBrowserHelper HistoryTriggerBHO - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Program Files (x86)\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll
O2 - BHO: QipLI - {6B5863A0-C43F-4C0A-982B-CC0E9125783F} - C:\Users\Dulaj\AppData\Roaming\Microsoft\Internet Explorer\qstatsrv.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Dulaj\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [PWRISOVM.EXE] D:\Programy\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [avast5] "D:\Programy\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [365dni] D:\Program Files (x86)\365dni\365dniNET.exe
O4 - HKLM\..\Run: [WheelMouse] C:\ADVANC~1\wh_exec.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [QIP Internet Guardian] C:\Users\Dulaj\AppData\Roaming\QipGuard\QipGuard.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [System] C:\Users\Dulaj\Music\lst.exe
O4 - HKCU\..\Run: [EA Core] "D:\Programy\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [Steam] "d:\programy\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Seznam Postak] "C:\Users\Dulaj\AppData\Local\Seznam.cz\postak.exe" -s
O4 - HKCU\..\Run: [Infium] "C:\Program Files (x86)\QIP Infium\infium.exe" /autorun
O4 - HKCU\..\Run: [Google Update] "C:\Users\Dulaj\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [ICQ] "D:\Programy\ICQ7.0\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [LG LinkAir] C:\Program Files (x86)\LG Electronics\LG PC Suite IV\LinkAir\LinkAir.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: hamachi.lnk = C:\Program Files (x86)\Hamachi\hamachi.exe
O4 - Startup: Trillian.lnk = D:\Programy\Trillian\trillian.exe
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\Programy\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Image - res://C:\Program Files (x86)\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/206
O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Memo - res://C:\Program Files (x86)\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/208
O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Text file - res://C:\Program Files (x86)\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/210
O8 - Extra context menu item: LG Air Sync (R-Click) - Set as Mobile Wallpaper - res://C:\Program Files (x86)\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/205
O8 - Extra context menu item: LG Air Sync Option - res://C:\Program Files (x86)\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/209
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - D:\Programy\ICQ7.0\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - D:\Programy\ICQ7.0\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Stavová služba ASP.NET (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! Antivirus - ALWIL Software - D:\Programy\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Programy\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\Programy\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: TunngleService - Tunngle.net GmbH - D:\Programy\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13030 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Explorer.EXE
ctfmon.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k swprv
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=1692.7d7ef60.1252142165 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" 1692 plugin \\.\pipe\gecko-crash-server-pipe.1692
"C:\Users\Dulaj\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2007022874-1101423518-1516767573-1001Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2007022874-1101423518-1516767573-1001UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{21A88CB9-84D2-4020-A2D1-B25A21034884}]
HistoryTriggerBHO Class - C:\Program Files (x86)\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll [2010-09-09 35688]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6B5863A0-C43F-4C0A-982B-CC0E9125783F}]
QipLI Class - C:\Users\Dulaj\AppData\Roaming\Microsoft\Internet Explorer\qstatsrv.dll [2010-04-21 48080]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - D:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Users\Dulaj\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2010-02-18 149968]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-09-15 41760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"PCSpeedUp"=C:\Program Files\Zrychleni Pocitace\PCSpeedUp.exe [2010-09-21 856312]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"QIP Internet Guardian"=C:\Users\Dulaj\AppData\Roaming\QipGuard\QipGuard.exe [2010-02-18 181712]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2010-02-22 26101032]
"System"=C:\Users\Dulaj\Music\lst.exe [2010-03-05 10752]
"EA Core"=D:\Programy\Electronic Arts\EADM\Core.exe -silent []
"Steam"=d:\programy\steam\steam.exe [2011-01-02 1242448]
"zASRockInstantBoot"= []
"ASRockIES"= []
"ASRockOCTuner"= []
"Seznam Postak"=C:\Users\Dulaj\AppData\Local\Seznam.cz\postak.exe [2010-05-19 462104]
"Infium"=C:\Program Files (x86)\QIP Infium\infium.exe [2010-06-10 5809616]
"Google Update"=C:\Users\Dulaj\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-21 136176]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"ICQ"=D:\Programy\ICQ7.0\ICQ.exe [2010-10-27 133432]
"LG LinkAir"=C:\Program Files (x86)\LG Electronics\LG PC Suite IV\LinkAir\LinkAir.exe [2010-09-09 2440552]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"PWRISOVM.EXE"=D:\Programy\PowerISO\PWRISOVM.EXE [2009-07-27 180224]
"avast5"=D:\Programy\Alwil Software\Avast5\avastUI.exe [2010-05-06 2815192]
"AdobeCS4ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]
"amd_dc_opt"=C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [2008-07-22 77824]
"GrooveMonitor"=D:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"365dni"=D:\Program Files (x86)\365dni\365dniNET.exe []
"WheelMouse"=C:\ADVANC~1\wh_exec.exe [2007-11-10 98304]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2010-03-17 421888]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-10-19 98304]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
McAfee Security Scan Plus.lnk - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe

C:\Users\Dulaj\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
hamachi.lnk - C:\Program Files (x86)\Hamachi\hamachi.exe
Trillian.lnk - D:\Programy\Trillian\trillian.exe
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - D:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=D:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - "D:\Programy\Macromedia\Dreamweaver 8\dreamweaver.exe" "%1"
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 2 months======

2011-01-07 15:59:13 ----D---- C:\rsit
2011-01-07 15:59:13 ----D---- C:\Program Files\trend micro
2011-01-05 17:46:57 ----AT---- C:\Windows\SYSWOW64\SIntfNT.dll
2011-01-05 17:46:57 ----AT---- C:\Windows\SYSWOW64\SIntf32.dll
2011-01-05 17:46:57 ----AT---- C:\Windows\SYSWOW64\SIntf16.dll
2011-01-05 17:35:36 ----A---- C:\Windows\DIIUnin.pif
2011-01-05 17:35:35 ----A---- C:\Windows\DIIUnin.exe
2011-01-05 02:41:51 ----D---- C:\Windows\Minidump
2011-01-03 19:22:55 ----D---- C:\Program Files (x86)\OpenOffice.org 3
2010-12-26 17:41:01 ----D---- C:\android
2010-12-25 00:21:44 ----D---- C:\videooutput
2010-12-25 00:21:27 ----A---- C:\Windows\SYSWOW64\NCMedia2.dll
2010-12-25 00:21:26 ----D---- C:\Program Files (x86)\Smallvideosoft
2010-12-24 21:04:27 ----D---- C:\Program Files (x86)\Convert DVD to AVI
2010-12-24 20:56:05 ----D---- C:\Users\Dulaj\AppData\Roaming\DVDVideoSoft
2010-12-24 20:43:18 ----A---- C:\Windows\SYSWOW64\Wnaspi32.dll
2010-12-24 20:43:18 ----A---- C:\Windows\SYSWOW64\drivers\Aspi32.sys
2010-12-24 20:43:14 ----D---- C:\Program Files (x86)\Xvid
2010-12-24 20:43:14 ----A---- C:\Windows\SYSWOW64\xvidvfw.dll
2010-12-24 20:43:14 ----A---- C:\Windows\SYSWOW64\xvidcore.dll
2010-12-24 20:43:13 ----D---- C:\Program Files (x86)\AoA DVD Ripper
2010-12-24 20:37:22 ----D---- C:\divx
2010-12-24 19:25:01 ----D---- C:\Program Files (x86)\LG Electronics
2010-12-19 20:00:14 ----D---- C:\Users\Dulaj\AppData\Roaming\The Witch and The Warrior
2010-12-19 18:57:08 ----D---- C:\Users\Dulaj\AppData\Roaming\OnLive App
2010-12-19 18:56:45 ----D---- C:\Program Files (x86)\OnLive
2010-12-17 21:09:57 ----D---- C:\Users\Dulaj\AppData\Roaming\world
2010-12-17 21:09:57 ----A---- C:\Users\Dulaj\AppData\Roaming\ops.txt
2010-12-17 21:09:57 ----A---- C:\Users\Dulaj\AppData\Roaming\Návod.TXT
2010-12-17 21:09:57 ----A---- C:\Users\Dulaj\AppData\Roaming\Minecraft_Server.exe
2010-12-17 21:09:57 ----A---- C:\Users\Dulaj\AppData\Roaming\Minecraft.exe
2010-12-17 21:09:57 ----A---- C:\Users\Dulaj\AppData\Roaming\banned-players.txt
2010-12-17 21:09:57 ----A---- C:\Users\Dulaj\AppData\Roaming\banned-ips.txt
2010-12-17 21:03:34 ----D---- C:\Users\Dulaj\AppData\Roaming\.minecraft
2010-12-17 21:02:01 ----A---- C:\Windows\The Witch and The Warrior Uninstaller.exe
2010-12-14 23:30:34 ----A---- C:\Windows\system32\mshtml.dll
2010-12-14 23:30:33 ----A---- C:\Windows\system32\iertutil.dll
2010-12-14 23:30:32 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2010-12-14 23:30:32 ----A---- C:\Windows\system32\ieframe.dll
2010-12-14 23:30:30 ----A---- C:\Windows\system32\mstime.dll
2010-12-14 23:30:29 ----A---- C:\Windows\SYSWOW64\mstime.dll
2010-12-14 23:30:28 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2010-12-14 23:30:27 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2010-12-14 23:30:25 ----A---- C:\Windows\system32\wininet.dll
2010-12-14 23:30:24 ----A---- C:\Windows\SYSWOW64\wininet.dll
2010-12-14 23:30:24 ----A---- C:\Windows\system32\msfeeds.dll
2010-12-14 23:30:23 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2010-12-14 23:30:23 ----A---- C:\Windows\system32\urlmon.dll
2010-12-14 23:30:21 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2010-12-14 23:30:21 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2010-12-14 23:30:21 ----A---- C:\Windows\system32\iedkcs32.dll
2010-12-14 23:30:20 ----A---- C:\Windows\SYSWOW64\ieui.dll
2010-12-14 23:30:20 ----A---- C:\Windows\system32\ieui.dll
2010-12-14 23:30:20 ----A---- C:\Windows\system32\iepeers.dll
2010-12-14 23:30:19 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2010-12-14 23:30:19 ----A---- C:\Windows\system32\mshtmled.dll
2010-12-14 23:30:18 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2010-12-14 23:30:18 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2010-12-14 23:30:17 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-12-14 23:30:16 ----A---- C:\Windows\system32\licmgr10.dll
2010-12-14 23:30:15 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2010-12-14 23:30:15 ----A---- C:\Windows\system32\msfeedssync.exe
2010-12-14 23:30:14 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2010-12-14 23:30:14 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2010-12-14 23:30:14 ----A---- C:\Windows\system32\jsproxy.dll
2010-12-14 23:29:56 ----A---- C:\Windows\SYSWOW64\tzres.dll
2010-12-14 23:29:56 ----A---- C:\Windows\system32\tzres.dll
2010-12-14 23:29:19 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2010-12-14 23:29:19 ----A---- C:\Windows\system32\atmlib.dll
2010-12-14 23:29:19 ----A---- C:\Windows\system32\atmfd.dll
2010-12-14 23:29:18 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2010-12-14 23:29:13 ----A---- C:\Windows\system32\schedsvc.dll
2010-12-14 23:29:12 ----A---- C:\Windows\system32\taskschd.dll
2010-12-14 23:29:12 ----A---- C:\Windows\system32\taskeng.exe
2010-12-14 23:29:11 ----A---- C:\Windows\system32\wmicmiplugin.dll
2010-12-14 23:29:10 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2010-12-14 23:29:10 ----A---- C:\Windows\system32\taskcomp.dll
2010-12-14 23:29:07 ----A---- C:\Windows\system32\schtasks.exe
2010-12-14 23:29:06 ----A---- C:\Windows\SYSWOW64\taskeng.exe
2010-12-14 23:29:06 ----A---- C:\Windows\SYSWOW64\taskcomp.dll
2010-12-14 23:29:06 ----A---- C:\Windows\SYSWOW64\schtasks.exe
2010-12-14 23:28:53 ----A---- C:\Windows\system32\webio.dll
2010-12-14 23:28:52 ----A---- C:\Windows\SYSWOW64\webio.dll
2010-12-14 23:28:42 ----A---- C:\Windows\system32\win32k.sys
2010-12-14 23:28:33 ----A---- C:\Windows\system32\consent.exe
2010-12-12 16:36:59 ----A---- C:\Windows\system32\pdfcmnnt.dll
2010-12-12 16:36:57 ----D---- C:\Program Files (x86)\PDFCreator
2010-12-12 16:36:57 ----A---- C:\Windows\SYSWOW64\MSMPIDE.DLL
2010-12-02 17:05:32 ----A---- C:\Windows\game.ini
2010-11-30 13:06:46 ----D---- C:\Program Files (x86)\Activision
2010-11-25 20:13:19 ----D---- C:\Program Files (x86)\Terrafarmers
2010-11-24 21:46:53 ----A---- C:\Windows\msvcr100.dll
2010-11-24 21:45:05 ----A---- C:\Windows\system32\msvcr100.dll
2010-11-24 21:41:47 ----A---- C:\Windows\msvcp100.dll
2010-11-24 21:38:32 ----A---- C:\Windows\system32\msvcp100.dll
2010-11-17 22:15:17 ----D---- C:\ProgramData\EA Core
2010-11-17 20:14:16 ----D---- C:\ProgramData\Solidshield
2010-11-17 11:09:34 ----D---- C:\Program Files (x86)\4G Client

======List of files/folders modified in the last 2 months======

2011-01-07 15:59:16 ----D---- C:\Windows\Temp
2011-01-07 15:59:13 ----RD---- C:\Program Files
2011-01-07 15:52:16 ----A---- C:\Windows\ntbtlog.txt
2011-01-07 14:07:37 ----D---- C:\Windows\Prefetch
2011-01-07 13:56:03 ----D---- C:\ProgramData\NVIDIA
2011-01-07 13:39:30 ----D---- C:\Users\Dulaj\AppData\Roaming\skypePM
2011-01-07 13:39:17 ----D---- C:\Users\Dulaj\AppData\Roaming\Skype
2011-01-07 13:37:41 ----D---- C:\Users\Dulaj\AppData\Roaming\Hamachi
2011-01-06 21:59:42 ----D---- C:\Windows\System32
2011-01-06 21:59:42 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-01-06 20:04:34 ----D---- C:\Windows\system32\LogFiles
2011-01-06 19:47:06 ----SHD---- C:\$Recycle.Bin
2011-01-06 19:45:47 ----RD---- C:\Users
2011-01-06 15:06:50 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2011-01-06 14:32:55 ----SHD---- C:\System Volume Information
2011-01-06 08:31:21 ----D---- C:\Windows\system32\config
2011-01-05 17:46:57 ----D---- C:\Windows\SysWOW64
2011-01-05 17:35:38 ----D---- C:\Windows
2011-01-05 15:27:05 ----SD---- C:\Users\Dulaj\AppData\Roaming\Microsoft
2011-01-04 15:34:21 ----HD---- C:\Config.Msi
2011-01-03 19:24:51 ----SHD---- C:\Windows\Installer
2011-01-03 19:24:14 ----RSD---- C:\Windows\assembly
2011-01-03 19:23:28 ----RSD---- C:\Windows\Fonts
2011-01-03 19:22:55 ----RD---- C:\Program Files (x86)
2011-01-02 11:22:24 ----D---- C:\Users\Dulaj\AppData\Roaming\ICQ
2010-12-26 17:48:30 ----D---- C:\Windows\system32\drivers
2010-12-25 00:20:22 ----D---- C:\Users\Dulaj\AppData\Roaming\dvdcss
2010-12-24 20:56:03 ----D---- C:\Program Files (x86)\DVDVideoSoft
2010-12-24 20:43:18 ----D---- C:\Windows\SYSWOW64\drivers
2010-12-24 20:43:18 ----D---- C:\Windows\system
2010-12-24 20:35:59 ----D---- C:\Program Files (x86)\DivX
2010-12-24 19:26:36 ----D---- C:\Windows\inf
2010-12-24 19:26:16 ----D---- C:\Windows\system32\DriverStore
2010-12-24 19:26:16 ----D---- C:\Windows\system32\catroot
2010-12-16 03:01:32 ----A---- C:\Windows\system32\MRT.exe
2010-12-16 03:01:20 ----D---- C:\ProgramData\Microsoft Help
2010-12-15 04:05:17 ----D---- C:\Windows\rescache
2010-12-15 03:25:51 ----D---- C:\Windows\winsxs
2010-12-15 03:21:42 ----D---- C:\Windows\SYSWOW64\cs-CZ
2010-12-15 03:21:42 ----D---- C:\Windows\system32\cs-CZ
2010-12-15 03:21:41 ----D---- C:\Windows\SYSWOW64\migration
2010-12-15 03:21:41 ----D---- C:\Program Files\Windows Mail
2010-12-15 03:21:41 ----D---- C:\Program Files\Internet Explorer
2010-12-15 03:21:41 ----D---- C:\Program Files (x86)\Windows Mail
2010-12-15 03:21:41 ----D---- C:\Program Files (x86)\Internet Explorer
2010-12-15 03:21:40 ----D---- C:\Windows\system32\migration
2010-12-15 03:03:53 ----D---- C:\Windows\system32\catroot2
2010-12-12 14:28:04 ----D---- C:\Users\Dulaj\AppData\Roaming\gtk-2.0
2010-12-11 20:19:57 ----D---- C:\Program Files (x86)\Mozilla Firefox
2010-12-10 15:49:54 ----D---- C:\Program Files (x86)\TeamViewer
2010-12-10 15:49:22 ----D---- C:\Users\Dulaj\AppData\Roaming\TeamViewer
2010-12-02 17:06:14 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2010-12-01 14:39:21 ----D---- C:\Users\Dulaj\AppData\Roaming\uTorrent
2010-11-30 16:41:46 ----D---- C:\Users\Dulaj\AppData\Roaming\HLSW
2010-11-30 16:01:39 ----D---- C:\Program Files (x86)\GamePark
2010-11-17 22:15:17 ----HD---- C:\ProgramData
2010-11-16 15:42:44 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-11-13 17:56:17 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2010-11-10 14:39:31 ----D---- C:\Windows\system32\appmgmt

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2010-05-06 28752]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R3 lgbusenum;LG Bluetooth Bus Enumerator; C:\Windows\system32\DRIVERS\lgbtbs64.sys [2009-09-29 14848]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\Windows\system32\DRIVERS\VMNetSrv.sys [2007-01-29 79760]
S0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-13 834544]
S1 ASPI32;ASPI32; C:\Windows\system32\drivers\ASPI32.sys []
S1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2010-05-06 121936]
S1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2010-05-06 51280]
S1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2009-07-27 90544]
S1 vmm;Virtual Machine Monitor; \??\C:\Windows\system32\Drivers\vmm.sys [2010-09-07 294232]
S2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys [2008-06-27 88632]
S2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2010-05-06 22096]
S2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2010-05-06 63568]
S2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2010-03-02 314016]
S2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2009-07-14 120320]
S2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2010-03-02 43680]
S2 npf;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2009-11-16 47632]
S3 Andbus;LGE Android Platform Composite USB Device; C:\Windows\system32\DRIVERS\lgandbus64.sys [2010-08-02 19456]
S3 AndDiag;LGE Android Platform USB Serial Port; C:\Windows\system32\DRIVERS\lganddiag64.sys [2010-08-02 27648]
S3 AndGps;LGE Android Platform USB GPS NMEA Port; C:\Windows\system32\DRIVERS\lgandgps64.sys [2010-08-02 27136]
S3 ANDModem;LGE Android Platform USB Modem; C:\Windows\system32\DRIVERS\lgandmodem64.sys [2010-08-02 33792]
S3 androidusb;ADB Interface Driver; C:\Windows\System32\Drivers\lgandadb.sys [2010-08-02 31744]
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2009-09-30 121872]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-10-20 6098432]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 551936]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 79360]
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 145920]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2009-07-14 19968]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 43008]
S3 dump_wmimmc;dump_wmimmc; \??\D:\Games\PlayPark\RayCitySEA\GameGuard\dump_wmimmc.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2010-05-08 33344]
S3 irsir;Microsoft Serial Infrared Driver; C:\Windows\system32\DRIVERS\irsir.sys [2008-01-19 27648]
S3 LgBttPort;LGE Bluetooth TransPort; C:\Windows\system32\DRIVERS\lgbtpt64.sys [2009-09-29 16384]
S3 LGVMODEM;LGE Virtual Modem; C:\Windows\system32\DRIVERS\lgvmdm64.sys [2009-09-29 17408]
S3 NPPTNT2;NPPTNT2; \??\C:\Windows\syswow64\npptNT2.sys [2004-12-31 4682]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\Windows\system32\DRIVERS\tap0901t.sys [2009-09-16 31232]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 whfltr2k;WheelMouse USB Lower Filter Driver; C:\Windows\system32\DRIVERS\whfltr2k.sys [2007-01-26 9600]
S4 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\Windows\System32\drivers\sfdrv01.sys [2005-08-10 68608]
S4 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\Windows\System32\drivers\sfhlp02.sys [2005-05-16 7168]
S4 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\Windows\System32\drivers\sfvfs02.sys [2005-11-03 89600]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

S2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-10-20 202752]
S2 avast! Antivirus;avast! Antivirus; D:\Programy\Alwil Software\Avast5\AvastSvc.exe [2010-05-06 40384]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-05-21 136176]
S2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2009-05-27 29262680]
S2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-30 935208]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2010-11-13 75136]
S2 PnkBstrB;PnkBstrB; C:\Windows\syswow64\PnkBstrB.exe [2011-01-06 214520]
S2 SQLBrowser;SQL Server Browser; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-11-24 239968]
S2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-25 153952]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-04-03 240232]
S2 TeamViewer5;TeamViewer 5; C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2010-10-06 2002728]
S2 TeamViewer6;TeamViewer 6; C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008]
S2 TunngleService;TunngleService; D:\Programy\Tunngle\TnglCtrl.exe [2010-03-23 704760]
S2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe []
S3 avast! Mail Scanner;avast! Mail Scanner; D:\Programy\Alwil Software\Avast5\AvastSvc.exe [2010-05-06 40384]
S3 avast! Web Scanner;avast! Web Scanner; D:\Programy\Alwil Software\Avast5\AvastSvc.exe [2010-05-06 40384]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-03-03 1038088]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-03-03 655624]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; D:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\syswow64\GameMon.des [2010-02-24 3432444]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-01-03 403240]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-20 1255736]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-11-24 45408]
S4 msvsmon90;Visual Studio 2008 Remote Debugger; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [2007-11-07 4466688]

-----------------EOF-----------------

Re: PC po zapnutí zatuhne, pouze nouzový režim

Napsal: 07 led 2011 17:45
od pdulik
Tka jsem zpuštěl různé opravy windowsu a diagnostiky paměti,.. nic se mi nikdy nenašlo až jsem narazil na chybu: Startup Repair Offline
problem 1 - 6.1.7600.16385
problem 2 - 6.1.7600.16385
problem 3 - unknow
problem 4 - 104
problem 5 - AutoFailover
problem 6 - 1
problem 7 - NoRootCause


na jednom zahraničním foru jsem se dočetl že někomu pomohl odinstalovat eset ... já ho nemám tak jsem zkusil avas, a ejhle :) všechno funguje,.. ale řekl bych teda že nějaká mrška v tom bude,.. nechtěl bych mít za týden ten samý problém,.. takže pokud mi naleznete v PC nějaký malware,rootkidy atd..budu velice vděčný, že se problém 100% vyřeší ;)

Re: PC po zapnutí zatuhne, pouze nouzový režim

Napsal: 07 led 2011 22:30
od Roli
Tohle fixni v HJT :

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Dulaj\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Dulaj\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [System] C:\Users\Dulaj\Music\lst.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Dulaj\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?


HJT najdeš zde :

C:\Program Files\trend micro\Dulaj.exe

Fix znamená že spustíš HJT Obrázek jako admin

v okně které se ti otevře klikneš na Do a system scan only

v dalším okně najdeš řádky které jsem ti vypsal,

vedle nich je čtvereček do kterého uděláš zatržítko,

pak klikneš na Fix checked které je vlevo dole,

program se ti zeptá zda opravdu ANO s tím samozřejmě souhlasíš a je hotovo.


Přes Start >> Všechny programy >> Příslušenství >> Spustit >> napiš - services.msc >> Enter. Najdi službu :

Služba Google Update

McAfee Security Scan Component Host Service

Nero BackItUp Scheduler 4.0


klikni na ni pravým myšítkem, zvol vlastnosti, na další kartě nejprve službu zastav tlačítkem Zastavit a u položky Typ spouštění zvol Zakázáno.


Stáhni a ulož na plochu ComboFix,

spusť aplikaci jako Administrátor a povol instalaci Konzole pro zotavení - Recovery Console.

Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,

pak ještě jednou klik na ANO a už to jede.

Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.

Při skenovaní může být PC i restartováno nelekat se.

Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,

protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.

Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt

(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.

Re: PC po zapnutí zatuhne, pouze nouzový režim

Napsal: 08 led 2011 19:19
od pdulik
ComboFix 11-01-07.02 - Dulaj 08.01.2011 18:42:25.1.2 - x64
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.2047.1114 [GMT 1:00]
Spuštěný z: c:\users\Dulaj\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Dulaj\AppData\Roaming\Desktopicon
c:\users\Dulaj\AppData\Roaming\Desktopicon\eBay.ico
c:\users\Dulaj\AppData\Roaming\Desktopicon\uninst.exe
c:\users\Dulaj\AppData\Roaming\Microsoft\Internet Explorer\qsTAtsrv.dll
c:\users\Dulaj\AppData\Roaming\Minecraft.exe
c:\users\Dulaj\AppData\Roaming\Minecraft_Server.exe
c:\windows\SysWow64\Packet.dll
c:\windows\SysWow64\pthreadVC.dll
c:\windows\SysWow64\wpcap.dll
D:\install.exe

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NPF
-------\Service_npf


((((((((((((((((((((((((( Soubory vytvořené od 2010-12-08 do 2011-01-08 )))))))))))))))))))))))))))))))
.

2011-01-07 16:37 . 2010-11-10 05:35 8199504 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7E43260E-1470-41DC-A33F-851C59CE718D}\mpengine.dll
2011-01-07 15:08 . 2011-01-07 15:08 -------- d-----w- c:\users\Dulaj\AppData\Roaming\Rovio
2011-01-07 14:59 . 2011-01-08 17:34 -------- d-----w- c:\program files\trend micro
2011-01-07 14:59 . 2011-01-07 14:59 -------- d-----w- C:\rsit
2011-01-05 16:46 . 2011-01-05 16:47 21840 ----atw- c:\windows\SysWow64\SIntfNT.dll
2011-01-05 16:46 . 2011-01-05 16:47 17212 ----atw- c:\windows\SysWow64\SIntf32.dll
2011-01-05 16:46 . 2011-01-05 16:47 12067 ----atw- c:\windows\SysWow64\SIntf16.dll
2011-01-05 16:35 . 2011-01-05 16:35 2829 ----a-w- c:\windows\DIIUnin.pif
2011-01-05 16:35 . 2011-01-05 16:35 94208 ----a-w- c:\windows\DIIUnin.exe
2011-01-03 18:22 . 2011-01-03 18:22 -------- d-----w- c:\program files (x86)\OpenOffice.org 3
2010-12-26 17:01 . 2010-12-26 18:09 -------- d-----w- c:\users\Dulaj\.android
2010-12-26 16:41 . 2010-11-30 18:34 -------- d-----w- C:\android
2010-12-24 23:21 . 2010-12-24 23:22 -------- d-----w- C:\videooutput
2010-12-24 23:21 . 2009-06-04 12:17 8676883 ----a-w- c:\windows\SysWow64\NCMedia2.dll
2010-12-24 23:21 . 2010-12-24 23:21 -------- d-----w- c:\program files (x86)\Smallvideosoft
2010-12-24 20:04 . 2010-12-24 20:04 -------- d-----w- c:\program files (x86)\Convert DVD to AVI
2010-12-24 19:56 . 2010-12-24 19:56 -------- d-----w- c:\users\Dulaj\AppData\Roaming\DVDVideoSoft
2010-12-24 19:43 . 2002-07-17 15:22 3535 ----a-w- c:\windows\system\Wowpost.exe
2010-12-24 19:43 . 2002-07-17 15:22 4455 ----a-w- c:\windows\system\Winaspi.dll
2010-12-24 19:43 . 2002-07-17 08:20 45056 ----a-w- c:\windows\SysWow64\Wnaspi32.dll
2010-12-24 19:43 . 2002-07-17 07:53 16877 ----a-w- c:\windows\SysWow64\drivers\Aspi32.sys
2010-12-24 19:43 . 2010-12-24 19:43 -------- d-----w- c:\program files (x86)\Xvid
2010-12-24 19:43 . 2007-06-28 17:55 77824 ----a-w- c:\windows\SysWow64\xvid.ax
2010-12-24 19:43 . 2007-06-28 17:54 180224 ----a-w- c:\windows\SysWow64\xvidvfw.dll
2010-12-24 19:43 . 2007-06-28 17:52 765952 ----a-w- c:\windows\SysWow64\xvidcore.dll
2010-12-24 19:43 . 2011-01-05 23:32 -------- d-----w- c:\program files (x86)\AoA DVD Ripper
2010-12-24 19:37 . 2011-01-07 20:43 -------- d-----w- C:\divx
2010-12-24 18:26 . 2010-12-24 18:26 -------- d-----w- c:\users\Dulaj\AppData\Local\LG Electronics
2010-12-24 18:25 . 2010-12-24 18:26 -------- d-----w- c:\program files (x86)\LG Electronics
2010-12-19 19:00 . 2010-12-19 19:00 -------- d-----w- c:\users\Dulaj\AppData\Roaming\The Witch and The Warrior
2010-12-19 17:57 . 2010-12-19 17:57 -------- d-----w- c:\users\Dulaj\AppData\Local\OnLive App
2010-12-19 17:57 . 2010-12-19 17:57 -------- d-----w- c:\users\Dulaj\AppData\Roaming\OnLive App
2010-12-19 17:56 . 2010-12-19 17:57 -------- d-----w- c:\program files (x86)\OnLive
2010-12-17 20:09 . 2010-12-17 20:09 -------- d-----w- c:\users\Dulaj\AppData\Roaming\world
2010-12-17 20:03 . 2010-12-17 20:09 -------- d-----w- c:\users\Dulaj\AppData\Roaming\.minecraft
2010-12-17 20:02 . 2010-12-17 20:02 175979 ----a-w- c:\windows\The Witch and The Warrior Uninstaller.exe
2010-12-14 22:29 . 2010-10-27 04:32 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2010-12-14 22:29 . 2010-10-12 05:05 35328 ----a-w- c:\program files\Windows Mail\wabfind.dll
2010-12-14 22:29 . 2010-10-12 05:00 516096 ----a-w- c:\program files\Windows Mail\wab.exe
2010-12-14 22:29 . 2010-10-12 04:25 516096 ----a-w- c:\program files (x86)\Windows Mail\wab.exe
2010-12-14 22:29 . 2010-10-20 02:58 294400 ----a-w- c:\windows\SysWow64\atmfd.dll
2010-12-14 22:29 . 2010-10-20 04:54 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2010-12-14 22:29 . 2010-11-02 04:40 496128 ----a-w- c:\windows\SysWow64\taskschd.dll
2010-12-14 22:29 . 2010-11-02 04:40 305152 ----a-w- c:\windows\SysWow64\taskcomp.dll
2010-12-14 22:29 . 2010-11-02 04:34 192000 ----a-w- c:\windows\SysWow64\taskeng.exe
2010-12-14 22:29 . 2010-11-02 04:34 179712 ----a-w- c:\windows\SysWow64\schtasks.exe
2010-12-14 22:28 . 2010-10-16 04:36 314368 ----a-w- c:\windows\SysWow64\webio.dll
2010-12-12 15:36 . 1998-06-23 23:00 137000 ----a-w- c:\windows\SysWow64\MSMAPI32.OCX
2010-12-12 15:36 . 2010-12-12 15:37 -------- d-----w- c:\program files (x86)\PDFCreator
2010-12-12 15:36 . 1998-07-05 23:00 23552 ----a-w- c:\windows\SysWow64\MSMPIDE.DLL

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-08 15:33 . 2010-02-27 16:26 214520 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2011-01-08 15:33 . 2010-02-27 16:21 214520 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2010-11-13 16:56 . 2010-02-27 16:21 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2010-10-28 20:02 . 2010-08-18 12:40 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2010-10-14 00:36 . 2010-10-14 00:36 15451288 ----a-w- c:\windows\SysWow64\xlive.dll
2010-10-14 00:36 . 2010-10-14 00:36 13642904 ----a-w- c:\windows\SysWow64\xlivefnt.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QIP Internet Guardian"="c:\users\Dulaj\AppData\Roaming\QipGuard\QipGuard.exe" [2010-02-18 181712]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2010-02-22 26101032]
"Steam"="d:\programy\steam\steam.exe" [2011-01-02 1242448]
"Infium"="c:\program files (x86)\QIP Infium\infium.exe" [2010-06-10 5809616]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"ICQ"="d:\programy\ICQ7.0\ICQ.exe" [2010-10-27 133432]
"LG LinkAir"="c:\program files (x86)\LG Electronics\LG PC Suite IV\LinkAir\LinkAir.exe" [2010-09-09 2440552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"PWRISOVM.EXE"="d:\programy\PowerISO\PWRISOVM.EXE" [2009-07-27 180224]
"amd_dc_opt"="c:\program files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"WheelMouse"="c:\advanc~1\wh_exec.exe" [2007-11-10 98304]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\lgandadb.sys [2010-08-02 31744]
R3 dump_wmimmc;dump_wmimmc;d:\games\PlayPark\RayCitySEA\GameGuard\dump_wmimmc.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-03-03 1038088]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [x]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [2009-09-16 31232]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-20 1255736]
R3 whfltr2k;WheelMouse USB Lower Filter Driver;c:\windows\system32\DRIVERS\whfltr2k.sys [2007-01-26 9600]
R4 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-21 136176]
R4 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-10-13 834544]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-10-20 202752]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-04-03 240232]
S2 TeamViewer5;TeamViewer 5;c:\program files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2010-10-06 2002728]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-07 2228008]
S2 TunngleService;TunngleService;d:\programy\Tunngle\TnglCtrl.exe [2010-03-23 704760]
S3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\DRIVERS\lgandbus64.sys [2010-08-02 19456]
S3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\DRIVERS\lganddiag64.sys [2010-08-02 27648]
S3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\DRIVERS\lgandgps64.sys [2010-08-02 27136]
S3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\DRIVERS\lgandmodem64.sys [2010-08-02 33792]
S3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\DRIVERS\lgbtpt64.sys [2009-09-29 16384]
S3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\DRIVERS\lgbtbs64.sys [2009-09-29 14848]
S3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\DRIVERS\lgvmdm64.sys [2009-09-29 17408]
S3 RTL8167;Ovladač Realtek 8167 NT;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]

.
Obsah adresáře 'Naplánované úlohy'

2011-01-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-21 18:03]

2011-01-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-21 18:03]

2011-01-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2007022874-1101423518-1516767573-1001Core.job
- c:\users\Dulaj\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-29 18:03]

2011-01-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2007022874-1101423518-1516767573-1001UA.job
- c:\users\Dulaj\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-29 18:03]
.

--------- x86-64 -----------


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF18098.cfxxe" [X]
"PCSpeedUp"="c:\program files\Zrychleni Pocitace\PCSpeedUp.exe" [2010-09-21 856312]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.zaparit.cz/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - d:\programy\MICROS~1\Office12\EXCEL.EXE/3000
IE: LG Air Sync (R-Click) - Save as Mobile Image - c:\program files (x86)\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/206
IE: LG Air Sync (R-Click) - Save as Mobile Memo - c:\program files (x86)\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/208
IE: LG Air Sync (R-Click) - Save as Mobile Text file - c:\program files (x86)\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/210
IE: LG Air Sync (R-Click) - Set as Mobile Wallpaper - c:\program files (x86)\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/205
IE: LG Air Sync Option - c:\program files (x86)\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/209
FF - ProfilePath - c:\users\Dulaj\AppData\Roaming\Mozilla\Firefox\Profiles\9okmts5c.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/ig?hl=cs&source=iglk
FF - prefs.js: keyword.URL - hxxp://search.seznam.cz/?sourceid=FFlisticka_13&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Skype extension for Firefox: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Battlefield Heroes Updater: battlefieldheroespatcher@ea.com - %profile%\extensions\battlefieldheroespatcher@ea.com
FF - Ext: Media Converter: {6e764c17-863a-450f-bdd0-6772bd5aaa18} - %profile%\extensions\{6e764c17-863a-450f-bdd0-6772bd5aaa18}
FF - Ext: FaceMod Dislike Button: {64e8cc5b-20db-4212-8320-178fc5ae71f7} - %profile%\extensions\{64e8cc5b-20db-4212-8320-178fc5ae71f7}
FF - Ext: QipCounter: QipCounter@qip.ru - %profile%\extensions\QipCounter@qip.ru
FF - Ext: Stylish: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8} - %profile%\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
FF - Ext: LG Air Sync: {00ADD29A-66F4-4f22-BCC0-4C1D29DA647B} - c:\program files (x86)\LG Electronics\LG PC Suite IV\LinkAir\{00ADD29A-66F4-4f22-BCC0-4C1D29DA647B}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

Wow6432Node-HKCU-Run-EA Core - d:\programy\Electronic Arts\EADM\Core.exe
Wow6432Node-HKCU-Run-zASRockInstantBoot - (no file)
Wow6432Node-HKCU-Run-ASRockIES - (no file)
Wow6432Node-HKCU-Run-ASRockOCTuner - (no file)
Wow6432Node-HKLM-Run-365dni - d:\program files (x86)\365dni\365dniNET.exe
AddRemove-4578-0181-0549-1546 - d:\games\Altitude\uninstall.exe
AddRemove-Abe's Oddysee - d:\games\Abe's Oddysee\Uninst.isu
AddRemove-Adobe Shockwave Player - c:\windows\system32\adobe\SHOCKW~1\UNWISE.EXE
AddRemove-Aliens Vs Predator MultiPlayer 1.1 - d:\games\Aliens Vs Predator\Uninstall.exe
AddRemove-ASSP_is1 - d:\games\Digital Red\All Star Strip Poker Girls at Work\unins000.exe
AddRemove-Bejeweled Blitz - d:\games\PopCap Games\Bejeweled Blitz\PopUninstall.exe
AddRemove-Blip Blop - d:\games\Blip Blop\uninstall.exe
AddRemove-Call of Duty: Black Ops_is1 - d:\games\Call of Duty - Black Ops\unins000.exe
AddRemove-Counter-Strike: Source - d:\games\Counter-Strike Source\Uninst.exe
AddRemove-DAEMON Tools Toolbar - c:\program files (x86)\DAEMON Tools Toolbar\uninst.exe
AddRemove-eBay Icon - c:\users\Dulaj\AppData\Roaming\Desktopicon\uninst.exe
AddRemove-FlatOut Ultimate Carnage - d:\games\Empire Interactive\FlatOut Ultimate Carnage\Uninstall.exe
AddRemove-Gold Miner Vegas - d:\games\Gold Miner Vegas\Uninstal.exe
AddRemove-Heroes of Might and Magic III Complete CZ - d:\games\HOMAM3\Uninstal.exe
AddRemove-Lara Croft and the Guardian of Light_is1 - d:\games\Lara Croft and the Guardian of Light\unins000.exe
AddRemove-Mafia Game - c:\windows\system32\MafiaSetup.exe
AddRemove-Magic The Gathering - Duels of the Planeswalkers_is1 - d:\games\Wizards of the Coast LLC\Magic The Gathering - Duels of the Planeswalkers\unins000.exe
AddRemove-NFS: Most Wanted - d:\games\EAGAME~1\NEEDFO~2\odinstalovat_cz.exe
AddRemove-NVIDIAStereo - c:\program files (x86)\NVIDIA Corporation\3D Vision\nvStInst.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_moh.exe
AddRemove-QIP Infium JadrisPack 3.1.1 - c:\qip infium jadrispack\Uninstall.exe
AddRemove-Shank_is1 - d:\games\Shank\unins000.exe
AddRemove-Shockwave - c:\windows\System32\Macromed\SHOCKW~1\UNWISE.EXE
AddRemove-Sniper Ghost Warrior_is1 - d:\games\City Interactive\Sniper Ghost Warrior\unins000.exe
AddRemove-Star Wars: The Force Unleashed_is1 - d:\games\Aspyr\Star Wars The Force Unleashed\unins000.exe
AddRemove-Super Mario 3 : Mario Forever - d:\games\softendo.com\Mario Forever\Uninstal.exe
AddRemove-{A9DCC49B-E188-4A4D-8125-5E66121CBA53} - c:\program files (x86)\Mesa Dynamics
AddRemove-{7353BAE6-5E49-46C4-A9B5-8A269A313789} - c:\users\Dulaj\AppData\Local\{0691F710-1ECA-4B5A-9727-25554F1BFDC6}\setup.exe



[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-2007022874-1101423518-1516767573-1001\Software\SecuROM\License information*]
"datasecu"=hex:46,ed,3f,f0,2a,32,6c,b1,14,9c,fc,1b,e1,27,f7,f9,e7,fe,f4,00,cc,
da,5a,ea,6a,1d,52,62,47,0a,b5,ae,71,81,98,d0,2d,60,fc,ae,13,ad,a3,3f,36,82,\
"rkeysecu"=hex:9f,ca,16,75,83,0a,d6,fd,d2,a5,ab,cb,c1,0d,12,f7

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\windows\SysWOW64\PnkBstrB.exe
c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
.
**************************************************************************
.
Celkový čas: 2011-01-08 19:12:52 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-01-08 18:12

Před spuštěním: 1 676 771 328
Po spuštění: Volných bajtů: 11 338 485 760

- - End Of File - - FD72795CF46065873E6A45A75A745989

Re: PC po zapnutí zatuhne, pouze nouzový režim

Napsal: 08 led 2011 21:45
od Roli
Pokud jsi tak ještě neučinil, přesuň Combofix na plochu

otevři si Poznámkový blok

do něj zkopíruj skript z následujícího okna:

Kód: Vybrat vše

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
ulož Tebou vytvořený TXT soubor jako CFScript.txt na plochu,

po uložení uchop vytvořený skript levým myšítkem a přesuň ho nad ikonu Combofixu, kde ho upustíš:

Obrázek

Po aplikaci na Tebe vypadne další log, zkopíruj ho sem

Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou,

v tom případě znovu restartuj a přitom mačkej F8 poté zvol Poslední známou funkční konfiguraci

Re: PC po zapnutí zatuhne, pouze nouzový režim

Napsal: 09 led 2011 12:36
od pdulik
Ten sken je opravdu strašně dlouhý, takže by jsem ho musel rozdělit do moc psotu, takže raději přiložím přímo log.txt http://www.edisk.cz/stahni/65518/log.txt_560.83KB.html

Re: PC po zapnutí zatuhne, pouze nouzový režim

Napsal: 09 led 2011 21:23
od Roli
Přes Start >> Spustit zkopíruj do okna:

ComboFix /Uninstall

a stiskni Enter

To odinstaluje ComboFix a smaže s ním související soubory a složky.


Pak dej vědět jaký je stav PC.