Stránka 1 z 6

policie vir velky problem

Napsal: 19 bře 2013 09:17
od Lokhys
Dobry den prosim vas mam potize s timhle Policie vir vubec nic uz nemuzu delat ani v nouzovem rezimu tam me to taky hazi prosim o radu děkuji předem. :)

Re: policie vir velky problem

Napsal: 19 bře 2013 09:19
od vyosek
Zdravim, pekne dopoledne preji a vitam Vas u nas na foru :welcome:

:arrow: Mate instalacni CD\DVD od windows?

:arrow: Na zdravem PC stahnete Farbar Recovery Scan Tool http://www.bleepingcomputer.com/downloa ... scan-tool/
  • Ulozte na nejaky flash disk, primo na jeho koren
:arrow: Na poskozenem PC nabootujte Nouzovy rezim s prikazovym radkem MS-DOS

:arrow: Nyni si zjisteme pismeno flash disku
  • Zadejte prikaz notepad a odenterujte
  • Otebre se poznamkovy blok (notepad)
  • Dejte Soubor --> Otevrit --> najdete tento pocitac a otevrete USB klic je FRST ulozeny
  • Podivejte se, jake pismeno ma USB klic (F:\, G:\ apod)
  • Zavrete notepad krizkem
:arrow: Ted si ziskame log
  • Pokud mate stazeny FRST pro 64 bit OS, tak se jmenuje FRST64.exe a je nutne jej tak zadat
  • Zadejte prikaz "pismeno disku":\FRST.exe a odenterujte (napr. F:\FRST.exe)
  • Spusti se FRST
  • Spuste prohledavani kliknutim na Scan
  • Po chvili se vytvori na flash disku log FRST.exe
  • Ten mi sem vlozte pres zdravy PC

Re: policie vir velky problem

Napsal: 19 bře 2013 09:22
od Lokhys
když nemám falsh disk mužu ten program vypálit na disk ? EDIT: Flashku sem našeůl omlouvam se jdu nato :)

Re: policie vir velky problem

Napsal: 19 bře 2013 09:53
od Lokhys
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2013 (ATTENTION: FRST version is 6 days old)
Ran by Administrator at 19-03-2013 09:47:29
Running from F:\
Service Pack 3 (X86) OS Language: Czech
Attention: Could not load system hive.

Error: Proces nemá přístup k souboru, neboť jej právě využívá jiný proces.
ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNCTION PROPERLY.


==================== One Month Created Files and Folders ========

2013-03-18 12:49 - 2013-03-18 12:49 - 00000000 __SHD C:\Documents and Settings\Administrator.LUKASEK-31FF2A8\PrivacIE
2013-03-18 12:43 - 2013-03-18 12:43 - 00113152 ____A C:\Documents and Settings\Lukasek\4447798.dll
2013-03-16 08:10 - 2013-03-16 08:10 - 00021520 ____A C:\ComboFix.txt
2013-03-16 07:55 - 2013-03-16 07:55 - 00000000 RASHD C:\cmdcons
2013-03-16 07:55 - 2013-03-15 10:12 - 00000324 ____A C:\Boot.bak
2013-03-16 07:55 - 2004-08-03 23:00 - 00261312 _RASH C:\cmldr
2013-03-16 07:53 - 2011-06-26 07:45 - 00256000 ____A C:\Windows\PEV.exe
2013-03-16 07:53 - 2010-11-07 18:20 - 00208896 ____A C:\Windows\MBR.exe
2013-03-16 07:53 - 2009-04-20 05:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2013-03-16 07:53 - 2000-08-31 01:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2013-03-16 07:53 - 2000-08-31 01:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2013-03-16 07:53 - 2000-08-31 01:00 - 00212480 ____A (SteelWerX) C:\Windows\SWXCACLS.exe
2013-03-16 07:53 - 2000-08-31 01:00 - 00098816 ____A C:\Windows\sed.exe
2013-03-16 07:53 - 2000-08-31 01:00 - 00080412 ____A C:\Windows\grep.exe
2013-03-16 07:53 - 2000-08-31 01:00 - 00068096 ____A C:\Windows\zip.exe
2013-03-16 07:49 - 2013-03-16 08:10 - 00000000 ____D C:\Qoobox
2013-03-16 07:48 - 2013-03-16 08:09 - 00000000 ____D C:\Windows\erdnt
2013-03-15 10:49 - 2013-03-15 10:49 - 00000000 __SHD C:\Documents and Settings\Administrator.LUKASEK-31FF2A8\IETldCache
2013-03-15 10:48 - 2013-03-19 09:42 - 00000062 __ASH C:\Documents and Settings\Administrator.LUKASEK-31FF2A8\Local Settings\desktop.ini
2013-03-15 10:48 - 2013-03-19 07:33 - 00000098 ___SH C:\Documents and Settings\Administrator.LUKASEK-31FF2A8\ntuser.ini
2013-03-15 10:48 - 2013-03-18 12:49 - 00000000 ____D C:\Documents and Settings\Administrator.LUKASEK-31FF2A8\Oblíbené položky
2013-03-15 10:48 - 2012-02-23 18:11 - 00000000 __RHD C:\Documents and Settings\Administrator.LUKASEK-31FF2A8\Data aplikací
2013-03-15 10:48 - 2012-02-23 18:11 - 00000000 ___RD C:\Documents and Settings\Administrator.LUKASEK-31FF2A8\Nabídka Start
2013-03-15 10:48 - 2012-02-23 18:11 - 00000000 ___HD C:\Documents and Settings\Administrator.LUKASEK-31FF2A8\Okolní tiskárny
2013-03-15 10:48 - 2012-02-23 18:11 - 00000000 ___HD C:\Documents and Settings\Administrator.LUKASEK-31FF2A8\Okolní síť
2013-03-15 10:48 - 2012-02-23 18:11 - 00000000 ____D C:\Documents and Settings\Administrator.LUKASEK-31FF2A8\Plocha
2013-03-15 10:48 - 2012-02-23 18:11 - 00000000 ____D C:\Documents and Settings\Administrator.LUKASEK-31FF2A8\Dokumenty
2013-03-15 10:48 - 2012-02-23 17:25 - 00000000 ___HD C:\Documents and Settings\Administrator.LUKASEK-31FF2A8\Local Settings\Data aplikací
2013-03-15 10:48 - 2012-02-23 17:20 - 00000000 ___HD C:\Documents and Settings\Administrator.LUKASEK-31FF2A8\Šablony
2013-03-15 10:23 - 2013-03-15 10:23 - 00000000 ____D C:\Windows\CTQNKHQJG9IF81UN
2013-03-15 10:05 - 2013-03-15 11:12 - 00000000 ____D C:\WINDOWS.0
2013-03-15 10:01 - 2013-03-15 10:01 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-03-15 10:01 - 2013-03-15 10:01 - 00000000 ____D C:\Program Files\Adobe
2013-03-15 09:21 - 2013-03-15 09:21 - 00000000 ____D C:\Documents and Settings\Administrator\PrivacIE
2013-03-15 09:21 - 2013-03-15 09:21 - 00000000 ____D C:\Documents and Settings\Administrator\IETldCache
2013-03-15 09:19 - 2013-03-15 09:57 - 00000000 ____D C:\Documents and Settings\Administrator\Šablony
2013-03-15 09:19 - 2013-03-15 09:57 - 00000000 ____D C:\Documents and Settings\Administrator\Data aplikací
2013-03-15 09:19 - 2012-02-23 17:25 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Data aplikací
2013-03-15 06:55 - 2013-03-16 09:02 - 00005742 ____A C:\Windows\updspapi.log
2013-03-15 06:54 - 2013-03-18 12:37 - 00006307 ____A C:\Windows\setupapi.log
2013-03-15 06:54 - 2013-03-18 12:37 - 00000075 ____A C:\Windows\setupact.log
2013-03-15 06:54 - 2013-03-16 09:02 - 00035070 ____A C:\Windows\KB2809289-IE8.log
2013-03-15 06:54 - 2013-03-16 09:02 - 00018550 ____A C:\Windows\FaxSetup.log
2013-03-15 06:54 - 2013-03-16 09:02 - 00008868 ____A C:\Windows\ocgen.log
2013-03-15 06:54 - 2013-03-16 09:02 - 00007078 ____A C:\Windows\tsoc.log
2013-03-15 06:54 - 2013-03-16 09:02 - 00006136 ____A C:\Windows\comsetup.log
2013-03-15 06:54 - 2013-03-16 09:02 - 00003723 ____A C:\Windows\ntdtcsetup.log
2013-03-15 06:54 - 2013-03-16 09:02 - 00002926 ____A C:\Windows\iis6.log
2013-03-15 06:54 - 2013-03-16 09:02 - 00001374 ____A C:\Windows\imsins.log
2013-03-15 06:54 - 2013-03-16 09:02 - 00001158 ____A C:\Windows\ocmsn.log
2013-03-15 06:54 - 2013-03-16 09:02 - 00000927 ____A C:\Windows\msgsocm.log
2013-03-15 06:54 - 2013-03-15 09:58 - 00000000 ___DC C:\Windows\$NtUninstallKB2807986$
2013-03-15 06:54 - 2013-03-15 06:55 - 00001374 ____A C:\Windows\imsins.BAK
2013-03-15 06:54 - 2013-03-15 06:54 - 00000000 ____A C:\Windows\setuperr.log
2013-03-15 06:53 - 2013-03-15 06:54 - 00009693 ____A C:\Windows\KB2807986.log
2013-03-14 11:17 - 2013-03-15 10:00 - 00000000 ____D C:\Program Files\Common Files\Adobe(2)
2013-03-14 11:17 - 2013-03-14 11:17 - 00000000 ____D C:\Program Files\Adobe(2)
2013-03-11 15:45 - 2013-03-11 15:45 - 00003588 ____A C:\Windows\System32\ealregsnapshot1.reg
2013-03-11 13:11 - 2013-03-11 13:11 - 00000000 ____D C:\Program Files\GameSpy
2013-03-09 16:00 - 2013-03-09 16:11 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-02-27 08:29 - 2013-03-01 09:41 - 00000000 ____D C:\Program Files\McAfee Security Scan
2013-02-26 11:20 - 2013-03-09 15:52 - 28631040 ____A C:\Windows\System32\config\software.iobit
2013-02-26 11:20 - 2013-03-09 15:52 - 04689920 ____A C:\Windows\System32\config\system.iobit
2013-02-26 11:20 - 2013-03-09 15:52 - 00249856 ____A C:\Windows\System32\config\default.iobit
2013-02-26 11:20 - 2013-03-09 15:52 - 00053248 ____A C:\Windows\System32\config\SECURITY.iobit
2013-02-26 11:20 - 2013-03-09 15:52 - 00024576 ____A C:\Windows\System32\config\SAM.iobit
2013-02-21 12:47 - 2013-02-21 12:47 - 00000000 ____D C:\Program Files\EA Sports
2013-02-18 09:32 - 2013-02-18 09:32 - 00000000 ____D C:\Program Files\Shadow Era
2013-02-17 14:25 - 2013-02-17 14:25 - 00000000 __HDC C:\Windows\$NtUninstallKB2780091$
2013-02-17 14:22 - 2013-02-17 14:22 - 00000000 __HDC C:\Windows\$NtUninstallKB2802968$
2013-02-17 14:11 - 2013-02-17 14:11 - 00000000 __HDC C:\Windows\$NtUninstallKB2799494$
2013-02-17 14:05 - 2013-02-17 14:05 - 00000000 __HDC C:\Windows\$NtUninstallKB2778344$


==================== One Month Modified Files and Folders ========

2013-03-19 09:47 - 2013-03-19 09:47 - 00000000 ____D C:\FRST
2013-03-19 09:42 - 2013-03-15 10:48 - 00000062 __ASH C:\Documents and Settings\Administrator.LUKASEK-31FF2A8\Local Settings\desktop.ini
2013-03-19 09:42 - 2012-02-23 17:29 - 00000062 __ASH C:\Documents and Settings\NetworkService\Local Settings\desktop.ini
2013-03-19 08:53 - 2012-07-09 07:43 - 00000364 ___AH C:\Windows\Tasks\avast! Emergency Update.job
2013-03-19 08:53 - 2012-07-02 07:56 - 00000282 ____A C:\Windows\Tasks\Game_Booster_AutoUpdate.job
2013-03-19 08:53 - 2012-05-27 19:43 - 00000049 ____A C:\Windows\wiaservc.log
2013-03-19 08:53 - 2012-04-02 17:51 - 00000238 ____A C:\Windows\Tasks\Scheduled Update for Ask Toolbar.job
2013-03-19 08:53 - 2012-02-23 18:09 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2013-03-19 08:53 - 2012-02-23 17:31 - 00000062 __ASH C:\Documents and Settings\Lukasek\Local Settings\desktop.ini
2013-03-19 08:53 - 2012-02-23 17:29 - 00000062 __ASH C:\Documents and Settings\LocalService\Local Settings\desktop.ini
2013-03-19 08:53 - 2012-02-23 17:29 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-03-19 07:33 - 2013-03-15 10:48 - 00000098 ___SH C:\Documents and Settings\Administrator.LUKASEK-31FF2A8\ntuser.ini
2013-03-19 07:33 - 2012-02-23 17:23 - 02027013 ____A C:\Windows\WindowsUpdate.log
2013-03-19 06:50 - 2012-05-27 19:43 - 00000159 ____A C:\Windows\wiadebug.log
2013-03-18 14:28 - 2012-02-23 17:31 - 00000178 ___SH C:\Documents and Settings\Lukasek\ntuser.ini
2013-03-18 13:14 - 2012-05-29 22:21 - 00000914 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-03-18 12:49 - 2013-03-18 12:49 - 00000000 __SHD C:\Documents and Settings\Administrator.LUKASEK-31FF2A8\PrivacIE
2013-03-18 12:49 - 2013-03-15 10:48 - 00000000 ____D C:\Documents and Settings\Administrator.LUKASEK-31FF2A8\Oblíbené položky
2013-03-18 12:45 - 2012-09-22 13:16 - 00000000 ____D C:\Program Files\BitTorrentControl_v12
2013-03-18 12:45 - 2012-02-23 17:31 - 00000000 __RHD C:\Documents and Settings\Lukasek\Data aplikací
2013-03-18 12:43 - 2013-03-18 12:43 - 00113152 ____A C:\Documents and Settings\Lukasek\4447798.dll
2013-03-18 12:37 - 2013-03-15 06:54 - 00006307 ____A C:\Windows\setupapi.log
2013-03-18 12:37 - 2013-03-15 06:54 - 00000075 ____A C:\Windows\setupact.log
2013-03-18 12:36 - 2004-08-18 15:00 - 00013646 ____A C:\Windows\System32\wpa.dbl
2013-03-16 09:23 - 2012-02-23 17:31 - 00000000 ____D C:\Documents and Settings\Lukasek\Plocha
2013-03-16 09:07 - 2012-02-23 17:29 - 00032720 ____A C:\Windows\SchedLgU.Txt
2013-03-16 09:03 - 2012-02-24 11:58 - 69796088 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-03-16 09:02 - 2013-03-15 06:55 - 00005742 ____A C:\Windows\updspapi.log
2013-03-16 09:02 - 2013-03-15 06:54 - 00035070 ____A C:\Windows\KB2809289-IE8.log
2013-03-16 09:02 - 2013-03-15 06:54 - 00018550 ____A C:\Windows\FaxSetup.log
2013-03-16 09:02 - 2013-03-15 06:54 - 00008868 ____A C:\Windows\ocgen.log
2013-03-16 09:02 - 2013-03-15 06:54 - 00007078 ____A C:\Windows\tsoc.log
2013-03-16 09:02 - 2013-03-15 06:54 - 00006136 ____A C:\Windows\comsetup.log
2013-03-16 09:02 - 2013-03-15 06:54 - 00003723 ____A C:\Windows\ntdtcsetup.log
2013-03-16 09:02 - 2013-03-15 06:54 - 00002926 ____A C:\Windows\iis6.log
2013-03-16 09:02 - 2013-03-15 06:54 - 00001374 ____A C:\Windows\imsins.log
2013-03-16 09:02 - 2013-03-15 06:54 - 00001158 ____A C:\Windows\ocmsn.log
2013-03-16 09:02 - 2013-03-15 06:54 - 00000927 ____A C:\Windows\msgsocm.log
2013-03-16 08:25 - 2012-02-23 18:11 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2013-03-16 08:14 - 2012-05-29 22:21 - 00693976 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-03-16 08:14 - 2012-05-29 22:21 - 00073432 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-03-16 08:10 - 2013-03-16 08:10 - 00021520 ____A C:\ComboFix.txt
2013-03-16 08:10 - 2013-03-16 07:49 - 00000000 ____D C:\Qoobox
2013-03-16 08:09 - 2013-03-16 07:48 - 00000000 ____D C:\Windows\erdnt
2013-03-16 08:08 - 2004-08-18 15:00 - 00000227 ____A C:\Windows\system.ini
2013-03-16 07:55 - 2013-03-16 07:55 - 00000000 RASHD C:\cmdcons
2013-03-16 07:55 - 2012-02-23 18:08 - 00000441 _RASH C:\boot.ini
2013-03-16 07:49 - 2012-02-23 18:11 - 00000000 ___RD C:\Documents and Settings\All Users\Dokumenty
2013-03-15 11:12 - 2013-03-15 10:05 - 00000000 ____D C:\WINDOWS.0
2013-03-15 10:49 - 2013-03-15 10:49 - 00000000 __SHD C:\Documents and Settings\Administrator.LUKASEK-31FF2A8\IETldCache
2013-03-15 10:23 - 2013-03-15 10:23 - 00000000 ____D C:\Windows\CTQNKHQJG9IF81UN
2013-03-15 10:21 - 2012-02-23 17:23 - 00000000 ____D C:\Windows\System32\DirectX
2013-03-15 10:20 - 2012-12-11 07:41 - 00000000 ____D C:\Games
2013-03-15 10:14 - 2012-02-23 18:08 - 00270984 ____A C:\Windows\System32\FNTCACHE.DAT
2013-03-15 10:12 - 2013-03-16 07:55 - 00000324 ____A C:\Boot.bak
2013-03-15 10:07 - 2012-02-23 17:21 - 00000000 ____D C:\Windows\Registration
2013-03-15 10:04 - 2012-02-23 17:31 - 00000000 ___HD C:\Documents and Settings\Lukasek\Local Settings\Data aplikací
2013-03-15 10:01 - 2013-03-15 10:01 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-03-15 10:01 - 2013-03-15 10:01 - 00000000 ____D C:\Program Files\Adobe
2013-03-15 10:00 - 2013-03-14 11:17 - 00000000 ____D C:\Program Files\Common Files\Adobe(2)
2013-03-15 09:58 - 2013-03-15 06:54 - 00000000 ___DC C:\Windows\$NtUninstallKB2807986$
2013-03-15 09:57 - 2013-03-15 09:19 - 00000000 ____D C:\Documents and Settings\Administrator\Šablony
2013-03-15 09:57 - 2013-03-15 09:19 - 00000000 ____D C:\Documents and Settings\Administrator\Data aplikací
2013-03-15 09:21 - 2013-03-15 09:21 - 00000000 ____D C:\Documents and Settings\Administrator\PrivacIE
2013-03-15 09:21 - 2013-03-15 09:21 - 00000000 ____D C:\Documents and Settings\Administrator\IETldCache
2013-03-15 08:00 - 2012-03-01 13:45 - 00000410 ___AH C:\Windows\Tasks\Norton Security Scan for Lukasek.job
2013-03-15 06:55 - 2013-03-15 06:54 - 00001374 ____A C:\Windows\imsins.BAK
2013-03-15 06:54 - 2013-03-15 06:54 - 00000000 ____A C:\Windows\setuperr.log
2013-03-15 06:54 - 2013-03-15 06:53 - 00009693 ____A C:\Windows\KB2807986.log
2013-03-15 06:54 - 2012-02-26 23:03 - 00000000 ____D C:\Windows\ie8updates
2013-03-15 06:54 - 2012-02-23 17:37 - 00000000 ___HD C:\Windows\$hf_mig$
2013-03-14 11:17 - 2013-03-14 11:17 - 00000000 ____D C:\Program Files\Adobe(2)
2013-03-11 15:45 - 2013-03-11 15:45 - 00003588 ____A C:\Windows\System32\ealregsnapshot1.reg
2013-03-11 15:45 - 2012-02-23 17:58 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-03-11 13:11 - 2013-03-11 13:11 - 00000000 ____D C:\Program Files\GameSpy
2013-03-11 13:05 - 2012-12-06 19:31 - 00669184 ____A C:\Windows\System32\pbsvc.exe
2013-03-11 13:05 - 2012-09-05 15:39 - 00022328 ____A C:\Windows\System32\Drivers\PnkBstrK.sys
2013-03-11 13:05 - 2012-09-05 15:38 - 00103736 ____A C:\Windows\System32\PnkBstrB.exe
2013-03-11 13:05 - 2012-09-05 15:38 - 00066872 ____A C:\Windows\System32\PnkBstrA.exe
2013-03-11 12:40 - 2012-08-20 20:48 - 00000000 ____D C:\Program Files\Electronic Arts
2013-03-10 11:32 - 2012-05-29 22:07 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-03-09 16:11 - 2013-03-09 16:00 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-03-09 15:52 - 2013-02-26 11:20 - 28631040 ____A C:\Windows\System32\config\software.iobit
2013-03-09 15:52 - 2013-02-26 11:20 - 04689920 ____A C:\Windows\System32\config\system.iobit
2013-03-09 15:52 - 2013-02-26 11:20 - 00249856 ____A C:\Windows\System32\config\default.iobit
2013-03-09 15:52 - 2013-02-26 11:20 - 00053248 ____A C:\Windows\System32\config\SECURITY.iobit
2013-03-09 15:52 - 2013-02-26 11:20 - 00024576 ____A C:\Windows\System32\config\SAM.iobit
2013-03-04 15:15 - 2012-08-07 07:24 - 00163539 ____A C:\Documents and Settings\Lukasek\debug.log
2013-03-01 09:41 - 2013-02-27 08:29 - 00000000 ____D C:\Program Files\McAfee Security Scan
2013-03-01 03:27 - 2010-04-16 17:08 - 06011392 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\mshtml.dll
2013-03-01 03:27 - 2004-08-18 15:00 - 06011392 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-02-28 07:20 - 2012-03-01 13:45 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2013-02-26 11:50 - 2012-04-23 13:56 - 00000000 ____D C:\Windows\Minidump
2013-02-22 11:19 - 2012-10-01 12:47 - 00000000 ___HD C:\Windows\msdownld.tmp
2013-02-22 11:09 - 2012-08-14 09:29 - 00000000 ____D C:\Program Files\Paradox Interactive
2013-02-22 10:56 - 2012-02-23 17:31 - 00000000 ___RD C:\Documents and Settings\Lukasek\Dokumenty
2013-02-21 12:47 - 2013-02-21 12:47 - 00000000 ____D C:\Program Files\EA Sports
2013-02-18 14:16 - 2012-12-08 15:09 - 00000000 ____D C:\Program Files\Steam
2013-02-18 09:32 - 2013-02-18 09:32 - 00000000 ____D C:\Program Files\Shadow Era
2013-02-17 14:46 - 2012-02-23 18:23 - 00000000 ____D C:\Windows\Microsoft.NET
2013-02-17 14:25 - 2013-02-17 14:25 - 00000000 __HDC C:\Windows\$NtUninstallKB2780091$
2013-02-17 14:22 - 2013-02-17 14:22 - 00000000 __HDC C:\Windows\$NtUninstallKB2802968$
2013-02-17 14:20 - 2012-02-23 18:11 - 00986890 ____A C:\Windows\System32\PerfStringBackup.INI
2013-02-17 14:11 - 2013-02-17 14:11 - 00000000 __HDC C:\Windows\$NtUninstallKB2799494$
2013-02-17 14:05 - 2013-02-17 14:05 - 00000000 __HDC C:\Windows\$NtUninstallKB2778344$


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe
[2004-08-18 15:00] - [2008-04-14 04:22] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1

C:\Windows\System32\winlogon.exe
[2004-08-18 15:00] - [2008-04-14 04:22] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea

C:\Windows\System32\svchost.exe
[2004-08-18 15:00] - [2008-04-14 04:22] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93

C:\Windows\System32\services.exe
[2004-08-18 15:00] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7

C:\Windows\System32\User32.dll
[2004-08-18 15:00] - [2008-04-14 04:22] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53

C:\Windows\System32\userinit.exe
[2004-08-18 15:00] - [2008-04-14 04:22] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239

C:\Windows\System32\Drivers\volsnap.sys
[2004-08-18 15:00] - [2008-04-14 03:12] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1

c:\Windows\system32\codeintegrity\Bootcat.cache IS MISSING <==== ATTENTION!.

==================== Restore Points (XP) =====================

RP: -> 2013-03-16 09:00 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP336

RP: -> 2013-03-15 10:50 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP335

RP: -> 2013-03-15 10:18 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP334

RP: -> 2013-03-15 09:56 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP333

RP: -> 2013-03-15 06:50 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP332

RP: -> 2013-03-14 18:26 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP331

RP: -> 2013-03-13 17:25 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP330

RP: -> 2013-03-12 17:19 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP329

RP: -> 2013-03-11 15:45 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP328

RP: -> 2013-03-11 13:10 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP327

RP: -> 2013-03-11 13:04 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP326

RP: -> 2013-03-11 12:40 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP325

RP: -> 2013-03-10 17:31 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP324

RP: -> 2013-03-04 10:41 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP323

RP: -> 2013-02-28 20:43 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP322

RP: -> 2013-02-27 19:28 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP321

RP: -> 2013-02-26 18:52 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP320

RP: -> 2013-02-22 10:39 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP319

RP: -> 2013-02-22 09:52 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP318

RP: -> 2013-02-21 12:47 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP317

RP: -> 2013-02-21 12:45 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP316

RP: -> 2013-02-21 12:15 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP315

RP: -> 2013-02-21 10:21 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP314

RP: -> 2013-02-20 11:58 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP313

RP: -> 2013-02-19 19:20 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP312

RP: -> 2013-02-18 09:00 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP311

RP: -> 2013-02-17 23:25 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP310

RP: -> 2013-02-17 14:25 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP309

RP: -> 2013-02-17 14:24 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP308

RP: -> 2013-02-17 14:22 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP307

RP: -> 2013-02-17 14:12 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP306

RP: -> 2013-02-17 14:08 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP305

RP: -> 2013-02-17 14:05 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP304

RP: -> 2013-02-03 20:57 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP303

RP: -> 2013-02-02 15:13 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP302

RP: -> 2013-01-31 22:53 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP301

RP: -> 2013-01-30 16:26 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP300

RP: -> 2013-01-29 16:35 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP299

RP: -> 2013-01-23 22:27 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP298

RP: -> 2013-01-22 18:31 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP297

RP: -> 2013-01-21 17:48 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP296

RP: -> 2013-01-20 17:38 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP295

RP: -> 2013-01-17 10:03 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP294

RP: -> 2013-01-10 17:25 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP293

RP: -> 2013-01-09 13:21 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP292

RP: -> 2013-01-09 13:12 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP291

RP: -> 2013-01-09 13:10 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP290

RP: -> 2013-01-09 13:08 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP289

RP: -> 2013-01-09 12:07 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP288

RP: -> 2013-01-09 11:37 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP287

RP: -> 2013-01-09 11:23 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP286

RP: -> 2013-01-09 11:02 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP285

RP: -> 2013-01-08 04:51 - 024576 _restore{B3651207-5D99-4E1B-A63B-A50F3C335A8A}\RP284


==================== Memory info ===========================

Percentage of memory in use: 8%
Total physical RAM: 2559.36 MB
Available physical RAM: 2332.57 MB
Total Pagefile: 6499 MB
Available Pagefile: 6448.91 MB
Total Virtual: 2047.88 MB
Available Virtual: 1996.69 MB

==================== Partitions =============================

2 Drive c: () (Fixed) (Total:108.81 GB) (Free:18.57 GB) NTFS ==>[Drive with boot components (Windows XP)]
3 Drive d: (csko) (CDROM) (Total:0.01 GB) (Free:0 GB) CDFS
5 Drive f: () (Removable) (Total:0.48 GB) (Free:0.45 GB) FAT

V poźˇtaźi: LUKASEK-31FF2A8
Disk ### Stav Velikost Voln‚ Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 109 GB 0 B
Probˇh  ukonźenˇ programu DiskPart...

Partitions of Disk 0:
===============

V poźˇtaźi: LUKASEK-31FF2A8
Nynˇ je vybr n disk 0.
Oddˇl ### Typ Velikost Posunutˇ
------------- ---------------- ------- -------
Oddˇl 1 Prim rnˇ 109 GB 32 KB
Probˇh  ukonźenˇ programu DiskPart...

=========================================================
============================== MBR Partition Table ==================

==============================
Partitions of Disk 0:
===============
Disk ID: E304E304

Partition 1:
=========
Hex: 8001010007FEFFFF3F0000003DDC990D
Active: YES
Type: 07 (NTFS)
Size: 109 GB

==================== End Of Log ============================

Re: policie vir velky problem

Napsal: 19 bře 2013 13:08
od Lokhys
co ted pls ???

Re: policie vir velky problem

Napsal: 19 bře 2013 13:29
od vyosek
:arrow: Podivejte, my jste tu ZDARMA a ve svem VOLNEM case :!:

:arrow: Pokud se Vam nelibi doba a rychlos s jakou odpovidame, nikdo Vas tu nenuti byt, tlacitko Odhlasit je vlevo nahore a muzete si jit hledat placeny servis, kde si muzete na ne stezovat, ze delaji pomalu a ne hned. tady si bud pockate nebo nashledanou...

:arrow: Neodpovedel jste mi, jestli mate instalacni CD od windows

:arrow: Co se tyce ComboFixu, ktery jste pouzil, tak na zaklade licence a pravidel fora ptam, umite s nim pracovat (spusteni, rozlusteni logu, napsani skriptu)?

:arrow: licencni podminky hovori jasne "Nikdy by nemel byt pouzit v prostredi bez dozoru zkusene osoby"
Obrázek

:arrow: Nebezpeci CFka
  • Je urcen primarne pro radce - jeho svevolnym pouzitim ztracite narok na podporu
  • Maze stopy po haveti, takze v logu z RSIT neni nic videt
  • Jeho log je treba dolustit, jelikoz neumi smazat vse - to ovsem tezko zvladnete pokud k tomu nejste vyskolen
  • CF muze mit bug = sunda Vam system, pokud nevite kam co uklada, jak co obnovit, mate system v kytkam a ceka Vas reinstal
  • CF taky bohuzel prozatim nekontroluje nektere dulezite knihovny (napr. hal.dll) - ty treba mazou nektere typy haveti (napr. angela) - smaze Vam po restartu hal.dll = nenajede Vam system a jste o radek vyse = reinstal

Re: policie vir velky problem

Napsal: 19 bře 2013 13:33
od Lokhys
Ja si nestezuji nani tak se omlouvam jeslti to tak vyznelo jen sem tam projistotu dopsal co dal pac nvm jestli ste online nebo jak to mate na forech sem prvne kamarad mi to poradil :)

Ano instalacni CD windowsu mam

Re: policie vir velky problem

Napsal: 19 bře 2013 13:34
od Lokhys
a s combofixem sem zkousel jen podle navodu a mozna i blbě nejsu si 100pro jisty

Re: policie vir velky problem

Napsal: 19 bře 2013 13:38
od vyosek
:arrow: Jestli jsem online vidite napr zde http://forum.viry.cz/viewonline.php

:arrow: Proto se u ComboFixu pise, ze se ma pouzivat jen pokud s nim umite

:arrow: Dle kolegy
1. vlozit do mechaniky instalacni CD Windows XP --> v BIOSu nastavit boot z mechaniky --> spustit instalaci z CD --> v prvnim okne "Vita vas instalacni program" stisknutim klavesy "R" spustit Konzolu pro zotaveni --> vybrat instalaci, ke ktere se chcete prihlasit (zpravidla "1:") --> 1 --> Enter --> zadat pripadne heslo
:arrow: Pripojte flash disk s FRST

:arrow: Nyni zadejte do toho prikazoveho radku F:\FRST.exe

:arrow: Opet nechte udelat log pres FRST a dejte mi jej sem

Re: policie vir velky problem

Napsal: 19 bře 2013 13:43
od Lokhys
jak dam to cd do mechaniky mam to spustit hned jak se spousti pc nebo nejak v nouzovem rezimu ???

Re: policie vir velky problem

Napsal: 19 bře 2013 13:46
od vyosek
Musite nastavit na prvni misto botovani CD mechaniku http://www.tipypropc.cz/jak-zmenit-poradi-bootovani/

System nabehne z CD a ne z disku = to potrebujeme

Re: policie vir velky problem

Napsal: 19 bře 2013 13:50
od Lokhys
ano napsalo mito jak sem spoustel pc jestli chuc spustit cd at stisknu libovolnou klavesu ma to tak byt ? :)

Re: policie vir velky problem

Napsal: 19 bře 2013 13:51
od vyosek
Ano, tu stisknete a tim spustite instalacni CD

Re: policie vir velky problem

Napsal: 19 bře 2013 13:53
od Lokhys
Jj přesně a teď tam mam oddíl tak mam instalaci pokračovat na tom starem oddilu nebo ho mam smazat a vytvořit nějaky nový ?

Re: policie vir velky problem

Napsal: 19 bře 2013 14:03
od vyosek
Jak mate tuto obrazovku, tak na ni dejte R
Obrázek