Stránka 1 z 3

Policie zablokovala...

Napsal: 11 led 2013 08:36
od X-sat
Omlouvám se o vpád do příspěvku. Mám tu napadený notebook tímto virem, ale nepustí mě ani do nouzového režimu :shock: Můžete poradit? Děkuji.

Re: Policie zablokovala vás nb, zaplaťte blabla

Napsal: 11 led 2013 08:44
od cernohous13
X-sat - příště si založ vlastní "nové téma"

Zkus spustit Správce úloh (Ctrl+Alt+Delete) - jak to vypadá?

Re: Policie zablokovala vás nb, zaplaťte blabla

Napsal: 11 led 2013 13:46
od X-sat
Správce úloh spustím a vidím spuštěný IE a lupu. To je jediné okno, které vidím.

Jinak jen prázdnou plochu, bez ikon a tlačítka start. Klávesovou zkratkou lze spouštět, ale spuštěné aplikace fyzicky na ploše nevidím.

Re: Policie zablokovala...

Napsal: 11 led 2013 20:52
od X-sat
Asi formát...

Re: Policie zablokovala...

Napsal: 11 led 2013 21:57
od vyosek
Zdravim :)

:arrow: Omlouvam se kolegovi za vstup, zkuste tento postup

:arrow: Na zdravem PC stahnete Farbar Recovery Scan Tool http://www.bleepingcomputer.com/downloa ... scan-tool/
  • Ulozte na nejaky flash disk, primo na jeho koren
:arrow: Na poskozenem PC nabootujte Nouzovy rezim s prikazovym radkem MS-DOS

:arrow: Nyni si zjisteme pismeno flash disku
  • Zadejte prikaz notepad a odenterujte
  • Otebre se poznamkovy blok (notepad)
  • Dejte Soubor --> Otevrit --> najdete tento pocitac a otevrete USB klic je FRST ulozeny
  • Podivejte se, jake pismeno ma USB klic (F:\, G:\ apod)
  • Zavrete notepad krizkem
:arrow: Ted si ziskame log
  • Pokud mate stazeny FRST pro 64 bit OS, tak se jmenuje FRST64.exe a je nutne jej tak zadat
  • Zadejte prikaz "pismeno disku":\FRST.exe a odenterujte (napr. F:\FRST.exe)
  • Spusti se FRST
  • Spuste prohledavani kliknutim na Scan
  • Po chvili se vytvori na flash disku log FRST.exe
  • Ten mi sem vlozte pres zdravy PC

Re: Policie zablokovala...

Napsal: 12 led 2013 11:39
od X-sat
Sice nouzový režim vir nedovolí, ale přes nějaké pokusy jsem nakonec napadený NTB spustil do normálního běhu... Relativně... Takže výsledek je níže. Díky za pomoc.

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-01-2013
Ran by uživatel at 12-01-2013 11:14:18
Running from E:\
(X86) OS Language: Czech
Attention: Could not load system hive.
Chyba: Proces nem  pýˇstup k souboru, neboś jej pr vŘ vyu§ˇv  jině proces.

ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNCTION PROPERLY.


==================== One Month Created Files and Folders ========

2013-01-12 11:03 - 2013-01-12 11:03 - 00003240 ____N C:\bootsqm.dat
2013-01-12 11:01 - 2013-01-12 11:01 - 00000000 __SHD C:\found.000
2013-01-11 20:55 - 2013-01-11 20:55 - 00000050 ____A C:\Program Files\.directory
2013-01-11 08:26 - 2013-01-11 08:26 - 95023320 ___AT C:\Users\All Users\dsgsdgdsgdsgw.pad
2013-01-11 08:26 - 2013-01-11 08:26 - 00000000 ____A C:\Users\All Users\dsgsdgdsgdsgw.js
2013-01-09 15:04 - 2013-01-11 07:15 - 95023320 ___AT C:\Users\All Users\xxxdsgsdgdsgdsgw.pad
2013-01-09 15:04 - 2013-01-09 15:04 - 00189192 ____A (?????????? ??????????) C:\Users\uživatel\wgsdgsdgdsgsd.exe
2013-01-09 08:42 - 2012-11-30 06:06 - 00169984 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2013-01-09 08:42 - 2012-11-30 06:00 - 00868352 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2013-01-09 08:42 - 2012-11-30 06:00 - 00293376 ____A (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00005120 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 04:07 - 00271360 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
2013-01-09 08:42 - 2012-11-30 03:51 - 00006144 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 03:51 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 03:51 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 03:51 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 00:21 - 00420032 ____A C:\Windows\System32\locale.nls
2013-01-09 08:42 - 2012-11-23 04:06 - 02344960 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-01-09 08:42 - 2012-11-22 10:33 - 00627712 ____A (Microsoft Corporation) C:\Windows\System32\usp10.dll
2013-01-09 08:42 - 2012-11-09 05:49 - 00492032 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-01-09 08:42 - 2012-11-02 05:50 - 01388544 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2013-01-09 08:41 - 2012-12-07 06:04 - 00308736 ____A (Microsoft Corporation) C:\Windows\System32\Wpc.dll
2013-01-09 08:41 - 2012-12-07 05:57 - 02576384 ____A (Microsoft Corporation) C:\Windows\System32\gameux.dll
2013-01-09 08:41 - 2012-12-07 04:21 - 00055296 ____A (Microsoft) C:\Windows\System32\cero.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00051712 ____A (Microsoft) C:\Windows\System32\esrb.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00046592 ____A (Microsoft) C:\Windows\System32\fpb.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00045568 ____A (Microsoft) C:\Windows\System32\oflc-nz.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00044544 ____A (Microsoft) C:\Windows\System32\pegibbfc.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00043520 ____A (Microsoft) C:\Windows\System32\csrr.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00040960 ____A (Microsoft) C:\Windows\System32\cob-au.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00030720 ____A (Microsoft) C:\Windows\System32\usk.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00023552 ____A (Microsoft) C:\Windows\System32\oflc.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00021504 ____A (Microsoft) C:\Windows\System32\grb.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi-pt.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi-fi.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00015360 ____A (Microsoft) C:\Windows\System32\djctq.rs
2013-01-09 08:41 - 2012-11-20 06:10 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-12-27 14:01 - 2012-12-27 14:01 - 05013989 ____A C:\Users\uživatel\Downloads\HulaHoop.wmv.zip
2012-12-27 14:01 - 2012-12-27 14:01 - 00000162 ___AH C:\Users\uživatel\Downloads\~$laHoop.wmv.zip
2012-12-27 12:26 - 2012-12-27 12:26 - 04661166 ____A C:\Users\uživatel\Downloads\BRITISH-2.WMV
2012-12-25 17:49 - 2012-12-25 17:49 - 00000000 ____A C:\Users\uživatel\Downloads\untitled-[3].zip.yqabjrc.partial
2012-12-25 17:43 - 2012-12-25 17:43 - 00000000 ____A C:\Users\uživatel\Downloads\untitled-[3].zrtqb7i.partial
2012-12-22 08:49 - 2012-12-16 15:25 - 00295424 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
2012-12-22 08:49 - 2012-12-16 15:25 - 00034304 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll
2012-12-18 14:41 - 2012-12-18 14:41 - 00000190 ____A C:\Users\uživatel\Desktop\Atlas mail.url
2012-12-16 18:13 - 2012-12-16 18:13 - 00000551 ____A C:\Users\uživatel\Desktop\2. KAZUISTIKA.lnk
2012-12-14 17:05 - 2012-12-14 17:05 - 00000162 ___AH C:\Users\uživatel\Downloads\~$T00150.txt.zip
2012-12-14 13:15 - 2012-11-14 03:48 - 12320256 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-12-14 13:15 - 2012-11-14 03:14 - 09738240 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-12-14 13:15 - 2012-11-14 03:09 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-12-14 13:15 - 2012-11-14 02:58 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-12-14 13:15 - 2012-11-14 02:57 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-12-14 13:15 - 2012-11-14 02:57 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-12-14 13:15 - 2012-11-14 02:55 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-12-14 13:15 - 2012-11-14 02:51 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-12-14 13:15 - 2012-11-14 02:49 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-12-14 13:15 - 2012-11-14 02:49 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-12-14 13:15 - 2012-11-14 02:48 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-12-14 13:15 - 2012-11-14 02:47 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-12-14 13:15 - 2012-11-14 02:46 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-12-14 13:15 - 2012-11-14 02:45 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-12-14 13:15 - 2012-11-14 02:44 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-12-14 13:15 - 2012-11-14 02:41 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-12-13 08:55 - 2012-11-09 05:49 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
2012-12-13 08:55 - 2012-11-02 05:48 - 00376832 ____A (Microsoft Corporation) C:\Windows\System32\dpnet.dll
2012-12-13 08:55 - 2012-09-06 17:48 - 00245616 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\volsnap.sys


==================== One Month Modified Files and Folders ========

2013-01-12 11:12 - 2009-07-14 05:39 - 00068080 ____A C:\Windows\setupact.log
2013-01-12 11:11 - 2009-07-14 05:34 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-01-12 11:11 - 2009-07-14 05:34 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-01-12 11:04 - 2010-07-26 17:48 - 00000940 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-01-12 11:04 - 2010-07-16 07:32 - 14274328 ____A C:\FaceProv.log
2013-01-12 11:04 - 2010-05-16 13:50 - 00000000 ____D C:\Users\All Users\VeriFace
2013-01-12 11:03 - 2013-01-12 11:03 - 00003240 ____N C:\bootsqm.dat
2013-01-12 11:03 - 2009-07-14 05:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-01-12 11:01 - 2013-01-12 11:01 - 00000000 __SHD C:\found.000
2013-01-11 20:55 - 2013-01-11 20:55 - 00000050 ____A C:\Program Files\.directory
2013-01-11 14:44 - 2010-05-16 13:16 - 02021682 ____A C:\Windows\WindowsUpdate.log
2013-01-11 14:43 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache
2013-01-11 14:25 - 2012-10-01 15:05 - 00000350 ____A C:\Windows\Tasks\PC SpeedUp Service Deactivator.job
2013-01-11 14:20 - 2010-07-26 17:48 - 00000944 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-01-11 08:33 - 2010-07-16 07:35 - 00000000 ____D C:\Users\uživatel\AppData\Local\VirtualStore
2013-01-11 08:26 - 2013-01-11 08:26 - 95023320 ___AT C:\Users\All Users\dsgsdgdsgdsgw.pad
2013-01-11 08:26 - 2013-01-11 08:26 - 00000000 ____A C:\Users\All Users\dsgsdgdsgdsgw.js
2013-01-11 07:15 - 2013-01-09 15:04 - 95023320 ___AT C:\Users\All Users\xxxdsgsdgdsgdsgw.pad
2013-01-10 12:44 - 2012-10-01 15:05 - 00000000 ____D C:\Program Files\Zrychleni Pocitace
2013-01-09 16:20 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-01-09 15:42 - 2009-07-14 05:33 - 00430064 ____A C:\Windows\System32\FNTCACHE.DAT
2013-01-09 15:39 - 2010-05-16 13:36 - 00000000 ____D C:\Users\All Users\Microsoft Help
2013-01-09 15:25 - 2010-05-16 13:23 - 00005388 ____A C:\Windows\System32\PerfStringBackup.INI
2013-01-09 15:04 - 2013-01-09 15:04 - 00189192 ____A (?????????? ??????????) C:\Users\uživatel\wgsdgsdgdsgsd.exe
2013-01-09 15:04 - 2010-07-16 07:35 - 00000000 ____D C:\users\uživatel
2013-01-05 19:46 - 2010-07-26 17:34 - 00000000 ____D C:\Users\uživatel\AppData\Roaming\Skype
2013-01-03 10:30 - 2010-10-11 18:36 - 00000000 ____D C:\Users\All Users\CanonIJPLM
2012-12-28 14:18 - 2012-09-16 19:45 - 00000000 ____D C:\Users\uživatel\Desktop\pojistka
2012-12-27 14:01 - 2012-12-27 14:01 - 05013989 ____A C:\Users\uživatel\Downloads\HulaHoop.wmv.zip
2012-12-27 14:01 - 2012-12-27 14:01 - 00000162 ___AH C:\Users\uživatel\Downloads\~$laHoop.wmv.zip
2012-12-27 12:26 - 2012-12-27 12:26 - 04661166 ____A C:\Users\uživatel\Downloads\BRITISH-2.WMV
2012-12-25 17:49 - 2012-12-25 17:49 - 00000000 ____A C:\Users\uživatel\Downloads\untitled-[3].zip.yqabjrc.partial
2012-12-25 17:43 - 2012-12-25 17:43 - 00000000 ____A C:\Users\uživatel\Downloads\untitled-[3].zrtqb7i.partial
2012-12-18 14:41 - 2012-12-18 14:41 - 00000190 ____A C:\Users\uživatel\Desktop\Atlas mail.url
2012-12-16 18:13 - 2012-12-16 18:13 - 00000551 ____A C:\Users\uživatel\Desktop\2. KAZUISTIKA.lnk
2012-12-16 15:25 - 2012-12-22 08:49 - 00295424 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
2012-12-16 15:25 - 2012-12-22 08:49 - 00034304 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll
2012-12-14 19:16 - 2010-12-16 16:33 - 00000000 ___HD C:\Users\uživatel\Desktop\.picasaoriginals
2012-12-14 17:18 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\DriverStore
2012-12-14 17:05 - 2012-12-14 17:05 - 00000162 ___AH C:\Users\uživatel\Downloads\~$T00150.txt.zip
2012-12-13 09:22 - 2012-10-28 07:30 - 00002324 ____A C:\Users\Public\Desktop\Google Chrome.lnk


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys
[2012-12-13 08:55] - [2012-09-06 17:48] - 0245616 ____A (Microsoft Corporation) 59F06B4968E58BC83DFC56CA4517960E


==================== Memory info ===========================

Percentage of memory in use: 30%
Total physical RAM: 2812.2 MB
Available physical RAM: 1943.84 MB
Total Pagefile: 5622.68 MB
Available Pagefile: 4590.57 MB
Total Virtual: 2047.88 MB
Available Virtual: 1920.19 MB

==================== Partitions =============================

1 Drive c: () (Fixed) (Total:254.14 GB) (Free:202.72 GB) NTFS
2 Drive d: (LENOVO) (Fixed) (Total:29 GB) (Free:27.32 GB) NTFS
3 Drive e: () (Removable) (Total:0.48 GB) (Free:0.42 GB) FAT32

Disk ### Stav Velikost Voln‚ Dyn Gpt
-------- ------------- -------- ------- --- ---
Disk 0 Online 298 GB 1024 KB
Disk 1 Online 490 MB 0 B

Probˇh  ukonźenˇ programu DiskPart...

Partitions of Disk 0:
===============

Nynˇ je vybr n disk 0.

Oddˇl ### Typ Velikost Posunutˇ
------------- ---------------- -------- --------
Oddˇl 1 Prim rnˇ 200 MB 1024 KB
Oddˇl 2 Prim rnˇ 254 GB 201 MB
Oddˇl 0 Rozçˇýeně 28 GB 254 GB
Oddˇl 4 Logickě 28 GB 254 GB
Oddˇl 3 OEM 14 GB 283 GB

Probˇh  ukonźenˇ programu DiskPart...

=========================================================

Partitions of Disk 1:
===============

Nynˇ je vybr n disk 1.

Oddˇl ### Typ Velikost Posunutˇ
------------- ---------------- -------- --------
Oddˇl 1 Prim rnˇ 489 MB 16 KB

Probˇh  ukonźenˇ programu DiskPart...

=========================================================

Last Boot: 2013-01-04 17:39

==================== End Of Log ============================

Re: Policie zablokovala...

Napsal: 12 led 2013 12:16
od X-sat
A přesně podle návodu - výsledek:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-01-2013
Ran by uživatel at 12-01-2013 12:12:42
Running from E:\
(X86) OS Language: Czech
Attention: Could not load system hive.
Chyba: Proces nem  pýˇstup k souboru, neboś jej pr vŘ vyu§ˇv  jině proces.

ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNCTION PROPERLY.


==================== One Month Created Files and Folders ========

2013-01-12 11:51 - 2013-01-12 11:51 - 00015616 ____A C:\Windows\System32\Drivers\TrueSight.sys
2013-01-12 11:51 - 2013-01-12 11:51 - 00001985 ____A C:\Users\uživatel\Desktop\RKreport[4]_S_01122013_02d1151.txt
2013-01-12 11:38 - 2013-01-12 11:38 - 00001884 ____A C:\Users\uživatel\Desktop\RKreport[3]_S_01122013_02d1138.txt
2013-01-12 11:35 - 2013-01-12 11:35 - 00002334 ____A C:\Users\uživatel\Desktop\RKreport[2]_D_01122013_02d1135.txt
2013-01-12 11:32 - 2013-01-12 11:32 - 00002205 ____A C:\Users\uživatel\Desktop\RKreport[1]_S_01122013_02d1132.txt
2013-01-12 11:25 - 2013-01-12 11:32 - 00000000 ____D C:\Users\uživatel\Desktop\RK_Quarantine
2013-01-12 11:13 - 2013-01-12 12:12 - 00000000 ____D C:\FRST
2013-01-12 11:03 - 2013-01-12 11:03 - 00003240 ____N C:\bootsqm.dat
2013-01-12 11:01 - 2013-01-12 11:01 - 00000000 __SHD C:\found.000
2013-01-11 20:55 - 2013-01-11 20:55 - 00000050 ____A C:\Program Files\.directory
2013-01-11 08:26 - 2013-01-11 08:26 - 95023320 ___AT C:\Users\All Users\dsgsdgdsgdsgw.pad
2013-01-11 08:26 - 2013-01-11 08:26 - 00000000 ____A C:\Users\All Users\dsgsdgdsgdsgw.js
2013-01-09 15:04 - 2013-01-11 07:15 - 95023320 ___AT C:\Users\All Users\xxxdsgsdgdsgdsgw.pad
2013-01-09 08:42 - 2012-11-30 06:06 - 00169984 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2013-01-09 08:42 - 2012-11-30 06:00 - 00868352 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2013-01-09 08:42 - 2012-11-30 06:00 - 00293376 ____A (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00005120 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 04:07 - 00271360 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
2013-01-09 08:42 - 2012-11-30 03:51 - 00006144 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 03:51 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 03:51 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 03:51 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 00:21 - 00420032 ____A C:\Windows\System32\locale.nls
2013-01-09 08:42 - 2012-11-23 04:06 - 02344960 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-01-09 08:42 - 2012-11-22 10:33 - 00627712 ____A (Microsoft Corporation) C:\Windows\System32\usp10.dll
2013-01-09 08:42 - 2012-11-09 05:49 - 00492032 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-01-09 08:42 - 2012-11-02 05:50 - 01388544 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2013-01-09 08:41 - 2012-12-07 06:04 - 00308736 ____A (Microsoft Corporation) C:\Windows\System32\Wpc.dll
2013-01-09 08:41 - 2012-12-07 05:57 - 02576384 ____A (Microsoft Corporation) C:\Windows\System32\gameux.dll
2013-01-09 08:41 - 2012-12-07 04:21 - 00055296 ____A (Microsoft) C:\Windows\System32\cero.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00051712 ____A (Microsoft) C:\Windows\System32\esrb.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00046592 ____A (Microsoft) C:\Windows\System32\fpb.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00045568 ____A (Microsoft) C:\Windows\System32\oflc-nz.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00044544 ____A (Microsoft) C:\Windows\System32\pegibbfc.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00043520 ____A (Microsoft) C:\Windows\System32\csrr.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00040960 ____A (Microsoft) C:\Windows\System32\cob-au.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00030720 ____A (Microsoft) C:\Windows\System32\usk.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00023552 ____A (Microsoft) C:\Windows\System32\oflc.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00021504 ____A (Microsoft) C:\Windows\System32\grb.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi-pt.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi-fi.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00015360 ____A (Microsoft) C:\Windows\System32\djctq.rs
2013-01-09 08:41 - 2012-11-20 06:10 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-12-27 14:01 - 2012-12-27 14:01 - 05013989 ____A C:\Users\uživatel\Downloads\HulaHoop.wmv.zip
2012-12-27 14:01 - 2012-12-27 14:01 - 00000162 ___AH C:\Users\uživatel\Downloads\~$laHoop.wmv.zip
2012-12-27 12:26 - 2012-12-27 12:26 - 04661166 ____A C:\Users\uživatel\Downloads\BRITISH-2.WMV
2012-12-25 17:49 - 2012-12-25 17:49 - 00000000 ____A C:\Users\uživatel\Downloads\untitled-[3].zip.yqabjrc.partial
2012-12-25 17:43 - 2012-12-25 17:43 - 00000000 ____A C:\Users\uživatel\Downloads\untitled-[3].zrtqb7i.partial
2012-12-22 08:49 - 2012-12-16 15:25 - 00295424 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
2012-12-22 08:49 - 2012-12-16 15:25 - 00034304 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll
2012-12-18 14:41 - 2012-12-18 14:41 - 00000190 ____A C:\Users\uživatel\Desktop\Atlas mail.url
2012-12-16 18:13 - 2012-12-16 18:13 - 00000551 ____A C:\Users\uživatel\Desktop\2. KAZUISTIKA.lnk
2012-12-14 17:05 - 2012-12-14 17:05 - 00000162 ___AH C:\Users\uživatel\Downloads\~$T00150.txt.zip
2012-12-14 13:15 - 2012-11-14 03:48 - 12320256 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-12-14 13:15 - 2012-11-14 03:14 - 09738240 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-12-14 13:15 - 2012-11-14 03:09 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-12-14 13:15 - 2012-11-14 02:58 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-12-14 13:15 - 2012-11-14 02:57 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-12-14 13:15 - 2012-11-14 02:57 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-12-14 13:15 - 2012-11-14 02:55 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-12-14 13:15 - 2012-11-14 02:51 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-12-14 13:15 - 2012-11-14 02:49 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-12-14 13:15 - 2012-11-14 02:49 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-12-14 13:15 - 2012-11-14 02:48 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-12-14 13:15 - 2012-11-14 02:47 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-12-14 13:15 - 2012-11-14 02:46 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-12-14 13:15 - 2012-11-14 02:45 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-12-14 13:15 - 2012-11-14 02:44 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-12-14 13:15 - 2012-11-14 02:41 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-12-13 08:55 - 2012-11-09 05:49 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
2012-12-13 08:55 - 2012-11-02 05:48 - 00376832 ____A (Microsoft Corporation) C:\Windows\System32\dpnet.dll
2012-12-13 08:55 - 2012-09-06 17:48 - 00245616 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\volsnap.sys


==================== One Month Modified Files and Folders ========

2013-01-12 12:07 - 2010-05-16 13:23 - 00005388 ____A C:\Windows\System32\PerfStringBackup.INI
2013-01-12 12:02 - 2010-07-16 07:32 - 14299332 ____A C:\FaceProv.log
2013-01-12 12:01 - 2010-05-16 13:50 - 00000000 ____D C:\Users\All Users\VeriFace
2013-01-12 12:00 - 2010-07-26 17:48 - 00000940 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-01-12 12:00 - 2009-07-14 05:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-01-12 12:00 - 2009-07-14 05:39 - 00068248 ____A C:\Windows\setupact.log
2013-01-12 12:00 - 2009-07-14 05:34 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-01-12 12:00 - 2009-07-14 05:34 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-01-12 11:59 - 2010-05-16 13:16 - 02028350 ____A C:\Windows\WindowsUpdate.log
2013-01-12 11:56 - 2010-07-16 07:35 - 00000000 ____D C:\users\uživatel
2013-01-12 11:51 - 2013-01-12 11:51 - 00015616 ____A C:\Windows\System32\Drivers\TrueSight.sys
2013-01-12 11:51 - 2013-01-12 11:51 - 00001985 ____A C:\Users\uživatel\Desktop\RKreport[4]_S_01122013_02d1151.txt
2013-01-12 11:38 - 2013-01-12 11:38 - 00001884 ____A C:\Users\uživatel\Desktop\RKreport[3]_S_01122013_02d1138.txt
2013-01-12 11:35 - 2013-01-12 11:35 - 00002334 ____A C:\Users\uživatel\Desktop\RKreport[2]_D_01122013_02d1135.txt
2013-01-12 11:32 - 2013-01-12 11:32 - 00002205 ____A C:\Users\uživatel\Desktop\RKreport[1]_S_01122013_02d1132.txt
2013-01-12 11:32 - 2013-01-12 11:25 - 00000000 ____D C:\Users\uživatel\Desktop\RK_Quarantine
2013-01-12 11:20 - 2010-07-26 17:48 - 00000944 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-01-12 11:03 - 2013-01-12 11:03 - 00003240 ____N C:\bootsqm.dat
2013-01-12 11:01 - 2013-01-12 11:01 - 00000000 __SHD C:\found.000
2013-01-11 20:55 - 2013-01-11 20:55 - 00000050 ____A C:\Program Files\.directory
2013-01-11 14:43 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache
2013-01-11 14:25 - 2012-10-01 15:05 - 00000350 ____A C:\Windows\Tasks\PC SpeedUp Service Deactivator.job
2013-01-11 08:33 - 2010-07-16 07:35 - 00000000 ____D C:\Users\uživatel\AppData\Local\VirtualStore
2013-01-11 08:26 - 2013-01-11 08:26 - 95023320 ___AT C:\Users\All Users\dsgsdgdsgdsgw.pad
2013-01-11 08:26 - 2013-01-11 08:26 - 00000000 ____A C:\Users\All Users\dsgsdgdsgdsgw.js
2013-01-11 07:15 - 2013-01-09 15:04 - 95023320 ___AT C:\Users\All Users\xxxdsgsdgdsgdsgw.pad
2013-01-10 12:44 - 2012-10-01 15:05 - 00000000 ____D C:\Program Files\Zrychleni Pocitace
2013-01-09 16:20 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-01-09 15:42 - 2009-07-14 05:33 - 00430064 ____A C:\Windows\System32\FNTCACHE.DAT
2013-01-09 15:39 - 2010-05-16 13:36 - 00000000 ____D C:\Users\All Users\Microsoft Help
2013-01-05 19:46 - 2010-07-26 17:34 - 00000000 ____D C:\Users\uživatel\AppData\Roaming\Skype
2013-01-03 10:30 - 2010-10-11 18:36 - 00000000 ____D C:\Users\All Users\CanonIJPLM
2012-12-28 14:18 - 2012-09-16 19:45 - 00000000 ____D C:\Users\uživatel\Desktop\pojistka
2012-12-27 14:01 - 2012-12-27 14:01 - 05013989 ____A C:\Users\uživatel\Downloads\HulaHoop.wmv.zip
2012-12-27 14:01 - 2012-12-27 14:01 - 00000162 ___AH C:\Users\uživatel\Downloads\~$laHoop.wmv.zip
2012-12-27 12:26 - 2012-12-27 12:26 - 04661166 ____A C:\Users\uživatel\Downloads\BRITISH-2.WMV
2012-12-25 17:49 - 2012-12-25 17:49 - 00000000 ____A C:\Users\uživatel\Downloads\untitled-[3].zip.yqabjrc.partial
2012-12-25 17:43 - 2012-12-25 17:43 - 00000000 ____A C:\Users\uživatel\Downloads\untitled-[3].zrtqb7i.partial
2012-12-18 14:41 - 2012-12-18 14:41 - 00000190 ____A C:\Users\uživatel\Desktop\Atlas mail.url
2012-12-16 18:13 - 2012-12-16 18:13 - 00000551 ____A C:\Users\uživatel\Desktop\2. KAZUISTIKA.lnk
2012-12-16 15:25 - 2012-12-22 08:49 - 00295424 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
2012-12-16 15:25 - 2012-12-22 08:49 - 00034304 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll
2012-12-14 19:16 - 2010-12-16 16:33 - 00000000 ___HD C:\Users\uživatel\Desktop\.picasaoriginals
2012-12-14 17:18 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\DriverStore
2012-12-14 17:05 - 2012-12-14 17:05 - 00000162 ___AH C:\Users\uživatel\Downloads\~$T00150.txt.zip
2012-12-13 09:22 - 2012-10-28 07:30 - 00002324 ____A C:\Users\Public\Desktop\Google Chrome.lnk


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys
[2012-12-13 08:55] - [2012-09-06 17:48] - 0245616 ____A (Microsoft Corporation) 59F06B4968E58BC83DFC56CA4517960E


==================== Memory info ===========================

Percentage of memory in use: 11%
Total physical RAM: 2812.2 MB
Available physical RAM: 2487.64 MB
Total Pagefile: 5622.68 MB
Available Pagefile: 5310.66 MB
Total Virtual: 2047.88 MB
Available Virtual: 1937.81 MB

==================== Partitions =============================

1 Drive c: () (Fixed) (Total:254.14 GB) (Free:202.96 GB) NTFS
2 Drive d: (LENOVO) (Fixed) (Total:29 GB) (Free:27.32 GB) NTFS
3 Drive e: () (Removable) (Total:0.48 GB) (Free:0.42 GB) FAT32

Disk ### Stav Velikost Voln‚ Dyn Gpt
-------- ------------- -------- ------- --- ---
Disk 0 Online 298 GB 1024 KB
Disk 1 Online 490 MB 0 B

Probˇh  ukonźenˇ programu DiskPart...

Partitions of Disk 0:
===============

Nynˇ je vybr n disk 0.

Oddˇl ### Typ Velikost Posunutˇ
------------- ---------------- -------- --------
Oddˇl 1 Prim rnˇ 200 MB 1024 KB
Oddˇl 2 Prim rnˇ 254 GB 201 MB
Oddˇl 0 Rozçˇýeně 28 GB 254 GB
Oddˇl 4 Logickě 28 GB 254 GB
Oddˇl 3 OEM 14 GB 283 GB

Probˇh  ukonźenˇ programu DiskPart...

=========================================================

Partitions of Disk 1:
===============

Nynˇ je vybr n disk 1.

Oddˇl ### Typ Velikost Posunutˇ
------------- ---------------- -------- --------
Oddˇl 1 Prim rnˇ 489 MB 16 KB

Probˇh  ukonźenˇ programu DiskPart...

=========================================================

Last Boot: 2013-01-04 17:39

==================== End Of Log ============================

Re: Policie zablokovala...

Napsal: 12 led 2013 14:53
od X-sat
pls, mrkněte někdo znalý na ten log

Děkuji

Re: Policie zablokovala...

Napsal: 12 led 2013 18:42
od vyosek
:arrow: Omlouvam se, byl jsem cely den v robote...uz makam na dalsim postupu

Re: Policie zablokovala...

Napsal: 12 led 2013 18:45
od X-sat
:wub: díííky

Re: Policie zablokovala...

Napsal: 12 led 2013 18:47
od vyosek
:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    2013-01-11 08:26 - 2013-01-11 08:26 - 95023320 ___AT C:\Users\All Users\dsgsdgdsgdsgw.pad
    2013-01-11 08:26 - 2013-01-11 08:26 - 00000000 ____A C:\Users\All Users\dsgsdgdsgdsgw.js
    2013-01-11 07:15 - 2013-01-09 15:04 - 95023320 ___AT C:\Users\All Users\xxxdsgsdgdsgdsgw.pad
    2013-01-09 15:04 - 2013-01-09 15:04 - 00189192 ____A (?????????? ??????????) C:\Users\uživatel\wgsdgsdgdsgsd.exe
    2013-01-10 12:44 - 2012-10-01 15:05 - 00000000 ____D C:\Program Files\Zrychleni Pocitace
    2013-01-11 14:25 - 2012-10-01 15:05 - 00000350 ____A C:\Windows\Tasks\PC SpeedUp Service Deactivator.job
    2013-01-12 11:01 - 2013-01-12 11:01 - 00000000 __SHD C:\found.000
    CMD: del "%AppData%\Local\Microsoft\Windows\runctf.lnk"
    CMD: del "%AppData%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\runctf.lnk"
    CMD: del "%AppData%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk"
    CMD: del "%AppData%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.lnk" 
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny log na flashku k FRST

:arrow: Spustte znovu FRST.exe na tom poskozenem PC
  • Kliknete na Fix
  • Probehne oprava a na flash disku se vytvori log Fixlog.txt
:arrow: Pokuste se nastartovat do bezneho rezimu

Re: Policie zablokovala...

Napsal: 12 led 2013 19:43
od X-sat
Provedeno. Co říkáte na log? NTB běží normálně. Děkuji.

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-01-2013
Ran by uživatel at 12-01-2013 19:37:26
Running from E:\
(X86) OS Language: Czech
Attention: Could not load system hive.
Chyba: Proces nem  pýˇstup k souboru, neboś jej pr vŘ vyu§ˇv  jině proces.

ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNCTION PROPERLY.


==================== One Month Created Files and Folders ========

2013-01-12 19:06 - 2012-10-30 23:51 - 00199320 ____A (AVAST Software) C:\Windows\System32\Drivers\aswNdis2.sys
2013-01-12 19:06 - 2012-10-30 23:51 - 00106560 ____A (AVAST Software) C:\Windows\System32\Drivers\aswFW.sys
2013-01-12 19:05 - 2012-10-30 23:51 - 00020624 ____A (AVAST Software) C:\Windows\System32\Drivers\aswKbd.sys
2013-01-12 19:05 - 2012-09-21 10:26 - 00012112 ____A (ALWIL Software) C:\Windows\System32\Drivers\aswNdis.sys
2013-01-12 19:03 - 2013-01-12 19:03 - 00002014 ____A C:\Users\Public\Desktop\avast! Internet Security.lnk
2013-01-12 11:51 - 2013-01-12 11:51 - 00015616 ____A C:\Windows\System32\Drivers\TrueSight.sys
2013-01-12 11:51 - 2013-01-12 11:51 - 00001985 ____A C:\Users\uživatel\Desktop\RKreport[4]_S_01122013_02d1151.txt
2013-01-12 11:38 - 2013-01-12 11:38 - 00001884 ____A C:\Users\uživatel\Desktop\RKreport[3]_S_01122013_02d1138.txt
2013-01-12 11:35 - 2013-01-12 11:35 - 00002334 ____A C:\Users\uživatel\Desktop\RKreport[2]_D_01122013_02d1135.txt
2013-01-12 11:32 - 2013-01-12 11:32 - 00002205 ____A C:\Users\uživatel\Desktop\RKreport[1]_S_01122013_02d1132.txt
2013-01-12 11:25 - 2013-01-12 11:32 - 00000000 ____D C:\Users\uživatel\Desktop\RK_Quarantine
2013-01-12 11:13 - 2013-01-12 19:37 - 00000000 ____D C:\FRST
2013-01-12 11:03 - 2013-01-12 11:03 - 00003240 ____N C:\bootsqm.dat
2013-01-11 20:55 - 2013-01-11 20:55 - 00000050 ____A C:\Program Files\.directory
2013-01-09 08:42 - 2012-11-30 06:06 - 00169984 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2013-01-09 08:42 - 2012-11-30 06:00 - 00868352 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2013-01-09 08:42 - 2012-11-30 06:00 - 00293376 ____A (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00005120 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 05:56 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 04:07 - 00271360 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
2013-01-09 08:42 - 2012-11-30 03:51 - 00006144 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 03:51 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 03:51 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 03:51 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
2013-01-09 08:42 - 2012-11-30 00:21 - 00420032 ____A C:\Windows\System32\locale.nls
2013-01-09 08:42 - 2012-11-23 04:06 - 02344960 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-01-09 08:42 - 2012-11-22 10:33 - 00627712 ____A (Microsoft Corporation) C:\Windows\System32\usp10.dll
2013-01-09 08:42 - 2012-11-09 05:49 - 00492032 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-01-09 08:42 - 2012-11-02 05:50 - 01388544 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2013-01-09 08:41 - 2012-12-07 06:04 - 00308736 ____A (Microsoft Corporation) C:\Windows\System32\Wpc.dll
2013-01-09 08:41 - 2012-12-07 05:57 - 02576384 ____A (Microsoft Corporation) C:\Windows\System32\gameux.dll
2013-01-09 08:41 - 2012-12-07 04:21 - 00055296 ____A (Microsoft) C:\Windows\System32\cero.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00051712 ____A (Microsoft) C:\Windows\System32\esrb.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00046592 ____A (Microsoft) C:\Windows\System32\fpb.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00045568 ____A (Microsoft) C:\Windows\System32\oflc-nz.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00044544 ____A (Microsoft) C:\Windows\System32\pegibbfc.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00043520 ____A (Microsoft) C:\Windows\System32\csrr.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00040960 ____A (Microsoft) C:\Windows\System32\cob-au.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00030720 ____A (Microsoft) C:\Windows\System32\usk.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00023552 ____A (Microsoft) C:\Windows\System32\oflc.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00021504 ____A (Microsoft) C:\Windows\System32\grb.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi-pt.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi-fi.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi.rs
2013-01-09 08:41 - 2012-12-07 04:21 - 00015360 ____A (Microsoft) C:\Windows\System32\djctq.rs
2013-01-09 08:41 - 2012-11-20 06:10 - 00219136 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-12-27 14:01 - 2012-12-27 14:01 - 05013989 ____A C:\Users\uživatel\Downloads\HulaHoop.wmv.zip
2012-12-27 14:01 - 2012-12-27 14:01 - 00000162 ___AH C:\Users\uživatel\Downloads\~$laHoop.wmv.zip
2012-12-27 12:26 - 2012-12-27 12:26 - 04661166 ____A C:\Users\uživatel\Downloads\BRITISH-2.WMV
2012-12-25 17:49 - 2012-12-25 17:49 - 00000000 ____A C:\Users\uživatel\Downloads\untitled-[3].zip.yqabjrc.partial
2012-12-25 17:43 - 2012-12-25 17:43 - 00000000 ____A C:\Users\uživatel\Downloads\untitled-[3].zrtqb7i.partial
2012-12-22 08:49 - 2012-12-16 15:25 - 00295424 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
2012-12-22 08:49 - 2012-12-16 15:25 - 00034304 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll
2012-12-18 14:41 - 2012-12-18 14:41 - 00000190 ____A C:\Users\uživatel\Desktop\Atlas mail.url
2012-12-16 18:13 - 2012-12-16 18:13 - 00000551 ____A C:\Users\uživatel\Desktop\2. KAZUISTIKA.lnk
2012-12-14 17:05 - 2012-12-14 17:05 - 00000162 ___AH C:\Users\uživatel\Downloads\~$T00150.txt.zip
2012-12-14 13:15 - 2012-11-14 03:48 - 12320256 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-12-14 13:15 - 2012-11-14 03:14 - 09738240 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-12-14 13:15 - 2012-11-14 03:09 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-12-14 13:15 - 2012-11-14 02:58 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-12-14 13:15 - 2012-11-14 02:57 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-12-14 13:15 - 2012-11-14 02:57 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-12-14 13:15 - 2012-11-14 02:55 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-12-14 13:15 - 2012-11-14 02:51 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-12-14 13:15 - 2012-11-14 02:49 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-12-14 13:15 - 2012-11-14 02:49 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-12-14 13:15 - 2012-11-14 02:48 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-12-14 13:15 - 2012-11-14 02:47 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-12-14 13:15 - 2012-11-14 02:46 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-12-14 13:15 - 2012-11-14 02:45 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-12-14 13:15 - 2012-11-14 02:44 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-12-14 13:15 - 2012-11-14 02:41 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-12-13 08:55 - 2012-11-09 05:49 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
2012-12-13 08:55 - 2012-11-02 05:48 - 00376832 ____A (Microsoft Corporation) C:\Windows\System32\dpnet.dll
2012-12-13 08:55 - 2012-09-06 17:48 - 00245616 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\volsnap.sys


==================== One Month Modified Files and Folders ========

2013-01-12 19:32 - 2010-05-16 13:23 - 00005388 ____A C:\Windows\System32\PerfStringBackup.INI
2013-01-12 19:24 - 2009-07-14 05:34 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-01-12 19:24 - 2009-07-14 05:34 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-01-12 19:20 - 2010-07-26 17:48 - 00000944 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-01-12 19:17 - 2010-07-26 17:48 - 00000940 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-01-12 19:17 - 2010-07-16 07:32 - 14312972 ____A C:\FaceProv.log
2013-01-12 19:17 - 2010-05-16 13:50 - 00000000 ____D C:\Users\All Users\VeriFace
2013-01-12 19:16 - 2009-07-14 05:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-01-12 19:16 - 2009-07-14 05:39 - 00068416 ____A C:\Windows\setupact.log
2013-01-12 19:15 - 2010-05-16 13:16 - 02067511 ____A C:\Windows\WindowsUpdate.log
2013-01-12 19:14 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\NDF
2013-01-12 19:07 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\LogFiles
2013-01-12 19:06 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\DriverStore
2013-01-12 19:05 - 2009-07-14 03:04 - 00002577 ____A C:\Windows\System32\config.nt
2013-01-12 19:03 - 2013-01-12 19:03 - 00002014 ____A C:\Users\Public\Desktop\avast! Internet Security.lnk
2013-01-12 11:56 - 2010-07-16 07:35 - 00000000 ____D C:\users\uživatel
2013-01-12 11:51 - 2013-01-12 11:51 - 00015616 ____A C:\Windows\System32\Drivers\TrueSight.sys
2013-01-12 11:51 - 2013-01-12 11:51 - 00001985 ____A C:\Users\uživatel\Desktop\RKreport[4]_S_01122013_02d1151.txt
2013-01-12 11:38 - 2013-01-12 11:38 - 00001884 ____A C:\Users\uživatel\Desktop\RKreport[3]_S_01122013_02d1138.txt
2013-01-12 11:35 - 2013-01-12 11:35 - 00002334 ____A C:\Users\uživatel\Desktop\RKreport[2]_D_01122013_02d1135.txt
2013-01-12 11:32 - 2013-01-12 11:32 - 00002205 ____A C:\Users\uživatel\Desktop\RKreport[1]_S_01122013_02d1132.txt
2013-01-12 11:32 - 2013-01-12 11:25 - 00000000 ____D C:\Users\uživatel\Desktop\RK_Quarantine
2013-01-12 11:03 - 2013-01-12 11:03 - 00003240 ____N C:\bootsqm.dat
2013-01-11 20:55 - 2013-01-11 20:55 - 00000050 ____A C:\Program Files\.directory
2013-01-11 14:43 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache
2013-01-11 08:33 - 2010-07-16 07:35 - 00000000 ____D C:\Users\uživatel\AppData\Local\VirtualStore
2013-01-09 16:20 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-01-09 15:42 - 2009-07-14 05:33 - 00430064 ____A C:\Windows\System32\FNTCACHE.DAT
2013-01-09 15:39 - 2010-05-16 13:36 - 00000000 ____D C:\Users\All Users\Microsoft Help
2013-01-05 19:46 - 2010-07-26 17:34 - 00000000 ____D C:\Users\uživatel\AppData\Roaming\Skype
2013-01-03 10:30 - 2010-10-11 18:36 - 00000000 ____D C:\Users\All Users\CanonIJPLM
2012-12-28 14:18 - 2012-09-16 19:45 - 00000000 ____D C:\Users\uživatel\Desktop\pojistka
2012-12-27 14:01 - 2012-12-27 14:01 - 05013989 ____A C:\Users\uživatel\Downloads\HulaHoop.wmv.zip
2012-12-27 14:01 - 2012-12-27 14:01 - 00000162 ___AH C:\Users\uživatel\Downloads\~$laHoop.wmv.zip
2012-12-27 12:26 - 2012-12-27 12:26 - 04661166 ____A C:\Users\uživatel\Downloads\BRITISH-2.WMV
2012-12-25 17:49 - 2012-12-25 17:49 - 00000000 ____A C:\Users\uživatel\Downloads\untitled-[3].zip.yqabjrc.partial
2012-12-25 17:43 - 2012-12-25 17:43 - 00000000 ____A C:\Users\uživatel\Downloads\untitled-[3].zrtqb7i.partial
2012-12-18 14:41 - 2012-12-18 14:41 - 00000190 ____A C:\Users\uživatel\Desktop\Atlas mail.url
2012-12-16 18:13 - 2012-12-16 18:13 - 00000551 ____A C:\Users\uživatel\Desktop\2. KAZUISTIKA.lnk
2012-12-16 15:25 - 2012-12-22 08:49 - 00295424 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
2012-12-16 15:25 - 2012-12-22 08:49 - 00034304 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll
2012-12-14 19:16 - 2010-12-16 16:33 - 00000000 ___HD C:\Users\uživatel\Desktop\.picasaoriginals
2012-12-14 17:05 - 2012-12-14 17:05 - 00000162 ___AH C:\Users\uživatel\Downloads\~$T00150.txt.zip
2012-12-13 09:22 - 2012-10-28 07:30 - 00002324 ____A C:\Users\Public\Desktop\Google Chrome.lnk


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys
[2012-12-13 08:55] - [2012-09-06 17:48] - 0245616 ____A (Microsoft Corporation) 59F06B4968E58BC83DFC56CA4517960E


==================== Memory info ===========================

Percentage of memory in use: 32%
Total physical RAM: 2812.2 MB
Available physical RAM: 1894.64 MB
Total Pagefile: 5622.68 MB
Available Pagefile: 4550.1 MB
Total Virtual: 2047.88 MB
Available Virtual: 1939.09 MB

==================== Partitions =============================

1 Drive c: () (Fixed) (Total:254.14 GB) (Free:203.8 GB) NTFS
2 Drive d: (LENOVO) (Fixed) (Total:29 GB) (Free:27.32 GB) NTFS
3 Drive e: () (Removable) (Total:0.48 GB) (Free:0.42 GB) FAT32

Disk ### Stav Velikost Voln‚ Dyn Gpt
-------- ------------- -------- ------- --- ---
Disk 0 Online 298 GB 1024 KB
Disk 1 Online 490 MB 0 B

Probˇh  ukonźenˇ programu DiskPart...

Partitions of Disk 0:
===============

Nynˇ je vybr n disk 0.

Oddˇl ### Typ Velikost Posunutˇ
------------- ---------------- -------- --------
Oddˇl 1 Prim rnˇ 200 MB 1024 KB
Oddˇl 2 Prim rnˇ 254 GB 201 MB
Oddˇl 0 Rozçˇýeně 28 GB 254 GB
Oddˇl 4 Logickě 28 GB 254 GB
Oddˇl 3 OEM 14 GB 283 GB

Probˇh  ukonźenˇ programu DiskPart...

=========================================================

Partitions of Disk 1:
===============

Nynˇ je vybr n disk 1.

Oddˇl ### Typ Velikost Posunutˇ
------------- ---------------- -------- --------
Oddˇl 1 Prim rnˇ 489 MB 16 KB

Probˇh  ukonźenˇ programu DiskPart...

=========================================================

Last Boot: 2013-01-04 17:39

==================== End Of Log ============================

Re: Policie zablokovala...

Napsal: 12 led 2013 22:13
od vyosek
:arrow: Dejte mi sem prosim ten Fixlog.txt

:arrow: A log z RSIT http://forum.viry.cz/viewtopic.php?f=13&t=105895

Re: Policie zablokovala...

Napsal: 13 led 2013 09:57
od X-sat
Kde najdu ten Fixlog.txt ? Díky

RSIT log:

Logfile of random's system information tool 1.09 (written by random/random)
Run by uživatel at 2013-01-13 09:36:48
Microsoft Windows 7 Home Premium
System drive C: has 208 GB (80%) free of 260 GB
Total RAM: 2812 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:37:19, on 13.1.2013
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal

Running processes:
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\windows\system32\taskhost.exe
C:\windows\System32\rundll32.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Lenovo\VeriFace\PManage.exe
C:\Program Files\Lenovo\YouCam\YouCamTray.exe
C:\Program Files\Lenovo\Energy Management\utility.exe
C:\Program Files\Lenovo\Energy Management\Energy Management.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\windows\system32\wuauclt.exe
C:\windows\system32\wuauclt.exe
C:\Users\uživatel\Downloads\RSIT.exe
C:\Program Files\trend micro\uživatel.exe
C:\windows\SoftwareDistribution\Download\Install\spclite.exe
C:\3b488daa89e5166c0d4e6902\spinstall.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.atlas.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Nero Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [VeriFaceManager] C:\Program Files\Lenovo\VeriFace\PManage.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\3.0"
O4 - HKLM\..\Run: [YouCam Mirror Tray icon] "C:\Program Files\Lenovo\YouCam\YouCamTray.exe" /s
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
O4 - HKLM\..\Run: [EnergyUtility] C:\Program Files\Lenovo\Energy Management\utility.exe
O4 - HKLM\..\Run: [Energy Management] C:\Program Files\Lenovo\Energy Management\Energy Management.exe
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [CanonSolutionMenuEx] C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
O4 - HKLM\..\Run: [avast] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AMD External Events Utility - AMD - C:\windows\system32\atiesrxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\Alwil Software\Avast5\afwServ.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IGRS - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: Lenovo ReadyComm AppSvc - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\AppSvc.exe
O23 - Service: Lenovo ReadyComm ConnSvc - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe
O23 - Service: PC Speed Up Service (PCSUService) - Unknown owner - C:\Program Files\Zrychleni Pocitace\PCSUService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 8135 bytes

======Scheduled tasks folder======

C:\windows\tasks\GoogleUpdateTaskMachineCore.job
C:\windows\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\66m8bccj.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://cs.start3.mozilla.com/firefox?cl ... s:official"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21, wrc@avast.com:7.0.1456, {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.20.8620, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.10"

"wrc@avast.com"=C:\Program Files\Alwil Software\Avast5\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon Easy-PhotoPrint EX
"Path"=C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsINIProcessor.js
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js

C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll
npdnu.dll
npdnu.xpt
npdnupdater2.dll
npdnupdater2.xpt
npnul32.dll
npwachk.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\66m8bccj.default\extensions\
{0b38152b-1b20-484d-a11f-5e04a9b0661f}

C:\Users\uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\66m8bccj.default\searchplugins\
aol-search.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - C:\Program Files\Winamp Toolbar\winamptb.dll [2012-08-09 2041736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2010-06-28 202144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2012-10-30 1227736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2013-01-12 192144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Nero Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-02-04 1197448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-07-16 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Nero Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-02-04 1197448]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2010-06-28 1615256]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2012-10-30 1227736]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - C:\Program Files\Winamp Toolbar\winamptb.dll [2012-08-09 2041736]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2013-01-12 192144]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-03-03 98304]
"VeriFaceManager"=C:\Program Files\Lenovo\VeriFace\PManage.exe [2010-05-16 3122528]
"UCam_Menu"=C:\Program Files\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe [2009-05-19 222504]
"YouCam Mirror Tray icon"=C:\Program Files\Lenovo\YouCam\YouCamTray.exe [2009-12-22 167008]
"UpdateP2GShortCut"=C:\Program Files\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [2008-12-03 218408]
"EnergyUtility"=C:\Program Files\Lenovo\Energy Management\utility.exe [2009-12-17 4114368]
"Energy Management"=C:\Program Files\Lenovo\Energy Management\Energy Management.exe [2009-12-17 6223808]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2010-03-25 2516296]
"CanonSolutionMenuEx"=C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE [2010-04-02 1185112]
"avast"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2012-10-30 4297136]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-07-26 39408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-12-03 35184]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cAudioFilterAgent]
C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe [2010-03-10 496184]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSpeedUp]
C:\Program Files\Zrychleni Pocitace\PCSUNotifier.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartAudio]
C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2009-11-19 307768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snp2uvc]
C:\windows\vsnp2uvc.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-07-26 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.clmp3enc"=C:\PROGRA~1\Lenovo\Power2Go\CLMP3Enc.ACM
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"VIDC.FFDS"=ff_vfw.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-01-13 09:37:02 ----D---- C:\windows\system32\EventProviders
2013-01-13 09:36:51 ----D---- C:\3b488daa89e5166c0d4e6902
2013-01-13 09:36:48 ----D---- C:\rsit
2013-01-13 09:36:48 ----D---- C:\Program Files\trend micro
2013-01-12 19:06:40 ----A---- C:\windows\system32\drivers\aswFW.sys
2013-01-12 19:06:00 ----A---- C:\windows\system32\drivers\aswNdis2.sys
2013-01-12 19:05:59 ----A---- C:\windows\system32\drivers\aswKbd.sys
2013-01-12 19:05:42 ----A---- C:\windows\system32\drivers\aswNdis.sys
2013-01-12 11:51:32 ----A---- C:\windows\system32\drivers\TrueSight.sys
2013-01-12 11:13:54 ----D---- C:\FRST
2013-01-10 08:47:42 ----A---- C:\windows\ntbtlog.txt
2013-01-09 08:42:36 ----A---- C:\windows\system32\win32k.sys
2013-01-09 08:42:35 ----A---- C:\windows\system32\usp10.dll
2013-01-09 08:42:33 ----A---- C:\windows\system32\win32spl.dll
2013-01-09 08:42:20 ----A---- C:\windows\system32\msxml6.dll
2013-01-09 08:42:11 ----A---- C:\windows\system32\KernelBase.dll
2013-01-09 08:42:09 ----AH---- C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-09 08:42:09 ----AH---- C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-01-09 08:42:09 ----AH---- C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-01-09 08:42:09 ----AH---- C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-09 08:42:09 ----AH---- C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-01-09 08:42:09 ----AH---- C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-09 08:42:09 ----AH---- C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-09 08:42:09 ----A---- C:\windows\system32\winsrv.dll
2013-01-09 08:42:09 ----A---- C:\windows\system32\kernel32.dll
2013-01-09 08:42:09 ----A---- C:\windows\system32\conhost.exe
2013-01-09 08:42:08 ----AH---- C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-09 08:42:08 ----AH---- C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-01-09 08:42:08 ----AH---- C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-01-09 08:42:08 ----AH---- C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-09 08:42:08 ----AH---- C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-01-09 08:42:08 ----AH---- C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-09 08:42:08 ----AH---- C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-01-09 08:42:08 ----AH---- C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-01-09 08:42:07 ----AH---- C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-01-09 08:42:07 ----AH---- C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-01-09 08:42:07 ----AH---- C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-09 08:42:07 ----AH---- C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-01-09 08:42:07 ----AH---- C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-01-09 08:42:07 ----AH---- C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-09 08:42:07 ----AH---- C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-01-09 08:42:07 ----AH---- C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-01-09 08:42:07 ----AH---- C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-01-09 08:42:06 ----AH---- C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-01-09 08:42:06 ----AH---- C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-09 08:42:05 ----AH---- C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-01-09 08:42:05 ----AH---- C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-01-09 08:41:41 ----A---- C:\windows\system32\Wpc.dll
2013-01-09 08:41:40 ----A---- C:\windows\system32\gameux.dll
2013-01-09 08:41:14 ----A---- C:\windows\system32\ncrypt.dll
2012-12-22 08:49:24 ----A---- C:\windows\system32\atmlib.dll
2012-12-22 08:49:24 ----A---- C:\windows\system32\atmfd.dll
2012-12-14 13:15:55 ----A---- C:\windows\system32\vbscript.dll
2012-12-14 13:15:55 ----A---- C:\windows\system32\mshtmled.dll
2012-12-14 13:15:55 ----A---- C:\windows\system32\jsproxy.dll
2012-12-14 13:15:54 ----A---- C:\windows\system32\msfeeds.dll
2012-12-14 13:15:54 ----A---- C:\windows\system32\ieUnatt.exe
2012-12-14 13:15:54 ----A---- C:\windows\system32\ieui.dll
2012-12-14 13:15:53 ----A---- C:\windows\system32\wininet.dll
2012-12-14 13:15:53 ----A---- C:\windows\system32\jscript.dll
2012-12-14 13:15:52 ----A---- C:\windows\system32\url.dll
2012-12-14 13:15:52 ----A---- C:\windows\system32\jscript9.dll
2012-12-14 13:15:51 ----A---- C:\windows\system32\iertutil.dll
2012-12-14 13:15:50 ----A---- C:\windows\system32\urlmon.dll
2012-12-14 13:15:49 ----A---- C:\windows\system32\ieframe.dll
2012-12-14 13:15:46 ----A---- C:\windows\system32\mshtml.dll

======List of files/folders modified in the last 1 month======

2013-01-13 09:37:02 ----D---- C:\windows\System32
2013-01-13 09:37:01 ----D---- C:\windows\Temp
2013-01-13 09:36:48 ----RD---- C:\Program Files
2013-01-13 09:35:56 ----D---- C:\windows\Prefetch
2013-01-13 09:35:47 ----D---- C:\windows\system32\catroot
2013-01-13 09:35:07 ----SHD---- C:\System Volume Information
2013-01-13 09:32:31 ----A---- C:\windows\system32\PerfStringBackup.INI
2013-01-13 09:28:59 ----D---- C:\ProgramData\VeriFace
2013-01-13 09:28:03 ----D---- C:\windows\system32\config
2013-01-12 20:23:07 ----SHD---- C:\windows\Installer
2013-01-12 19:22:50 ----SD---- C:\ProgramData\Microsoft
2013-01-12 19:14:58 ----D---- C:\windows\system32\NDF
2013-01-12 19:07:17 ----D---- C:\windows\system32\LogFiles
2013-01-12 19:06:40 ----D---- C:\windows\system32\drivers
2013-01-12 19:06:19 ----D---- C:\windows\inf
2013-01-12 19:06:06 ----D---- C:\windows\system32\DriverStore
2013-01-12 19:06:02 ----D---- C:\windows\system32\Tasks
2013-01-12 19:05:41 ----D---- C:\Windows
2013-01-12 18:56:49 ----HD---- C:\ProgramData
2013-01-12 18:56:49 ----D---- C:\windows\Tasks
2013-01-12 18:55:37 ----D---- C:\windows\system32\catroot2
2013-01-11 14:43:15 ----D---- C:\windows\rescache
2013-01-09 16:20:32 ----D---- C:\windows\Microsoft.NET
2013-01-09 16:20:31 ----RSD---- C:\windows\assembly
2013-01-09 15:41:57 ----D---- C:\windows\winsxs
2013-01-09 15:40:17 ----D---- C:\windows\system32\cs-CZ
2013-01-09 15:39:07 ----D---- C:\ProgramData\Microsoft Help
2013-01-05 19:46:59 ----D---- C:\Users\uživatel\AppData\Roaming\Skype
2013-01-03 10:30:02 ----D---- C:\ProgramData\CanonIJPLM
2012-12-14 17:18:44 ----D---- C:\windows\system32\migration
2012-12-14 17:18:44 ----D---- C:\Program Files\Internet Explorer

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswNdis;avast! Firewall NDIS Filter Service; C:\windows\system32\DRIVERS\aswNdis.sys [2012-09-21 12112]
R0 aswNdis2;avast! Firewall Core Firewall Service; C:\windows\system32\drivers\aswNdis2.sys [2012-10-30 199320]
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\windows\system32\DRIVERS\AtiPcie.sys [2009-08-23 14392]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 aswFW;avast! TDI Firewall driver; C:\windows\system32\drivers\aswFW.sys [2012-10-30 106560]
R1 aswKbd;aswKbd; C:\windows\system32\drivers\aswKbd.sys [2012-10-30 20624]
R1 aswRdr;aswRdr; C:\windows\System32\Drivers\aswrdr2.sys [2012-10-15 44784]
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys [2012-10-30 738504]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2012-10-30 361032]
R1 aswTdi;avast! Network Shield Support; C:\windows\system32\drivers\aswTdi.sys [2012-10-30 54232]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 aswFsBlk;aswFsBlk; C:\windows\system32\drivers\aswFsBlk.sys [2012-10-30 21256]
R2 aswMonFlt;aswMonFlt; \??\C:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 58680]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\windows\system32\DRIVERS\AcpiVpc.sys [2009-09-03 21256]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atipmdag.sys [2010-03-03 5340160]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2010-03-03 152064]
R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\windows\system32\DRIVERS\Apfiltr.sys [2010-04-22 218744]
R3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\windows\system32\DRIVERS\bcmwl6.sys [2010-02-02 2707448]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\CHDRT32.sys [2010-01-18 514104]
R3 JmUsbCcgp;JMicron USB Composite Device Lower Filter Driver; C:\windows\system32\DRIVERS\jmccgp.sys [2009-12-03 15216]
R3 JmUsbVideo;JMicron 31x Upper Filter Driver; C:\windows\System32\Drivers\jmcam.sys [2009-12-03 46320]
R3 JmUsbVideo2;JMicron 31x Lower Filter Driver; C:\windows\System32\Drivers\jmcam_lo.sys [2009-12-03 24048]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\windows\system32\DRIVERS\L1C62x86.sys [2009-11-13 58368]
R3 usbfilter;AMD USB Filter Driver; C:\windows\system32\DRIVERS\usbfilter.sys [2009-12-22 30392]
R3 wdmirror;wdmirror; C:\windows\system32\DRIVERS\WDMirror.sys [2009-07-16 11792]
S2 Parvdm;Parvdm; C:\windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 Bridge0;Bridge0; C:\windows\system32\drivers\WDBridge.sys [2009-07-28 63240]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 393216]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2009-06-10 4756480]
S3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\k57nd60x.sys [2009-07-13 229888]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
S3 pciide;pciide; C:\windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUStor.sys [2010-03-24 191008]
S3 sisagp;SIS AGP Bus Filter; C:\windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 TrueSight;TrueSight; \??\C:\windows\system32\drivers\TrueSight.sys [2013-01-12 15616]
S3 usbscan;Ovladač skeneru USB; C:\windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 viaagp;VIA AGP Bus Filter; C:\windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WimFltr;WimFltr; C:\windows\system32\DRIVERS\wimfltr.sys [2008-08-06 128104]
S3 wsvd;wsvd; C:\windows\system32\DRIVERS\wsvd.sys [2009-07-21 81704]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2010-03-03 172032]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2012-10-30 44808]
R2 avast! Firewall;avast! Firewall; C:\Program Files\Alwil Software\Avast5\afwServ.exe [2012-10-30 133912]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service; C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-11 30312]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2010-04-05 116104]
R2 ReadyComm.DirectRouter;ReadyComm.DirectRouter; C:\windows\System32\IgrsSvcs.exe [2009-07-14 20992]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-12-10 238944]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-12-10 86880]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-07-26 135664]
S2 PCSUService;PC Speed Up Service; C:\Program Files\Zrychleni Pocitace\PCSUService.exe []
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-11-09 160944]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-07-26 135664]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-08-31 194032]
S3 IGRS;IGRS; C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe [2009-07-15 38152]
S3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc; C:\Program Files\Lenovo\ReadyComm\AppSvc.exe [2009-08-14 509192]
S3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc; C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe [2009-11-17 575304]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PS_MDP;ReadyComm Presentation Space Helper Service; C:\windows\System32\IgrsSvcs.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2010-07-18 1343400]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2010-12-10 44384]

-----------------EOF-----------------

Re: Policie zablokovala...

Napsal: 13 led 2013 10:02
od cernohous13
vyosek píše: Probehne oprava a na flash disku se vytvori log Fixlog.txt