Stránka 1 z 1

Zhroucení počítače

Napsal: 21 dub 2013 09:14
od Marxxx
Zdravím Vás.
Asi hodně laický dotaz, tak mě prosím za to nekamenujte :)
V počítači přestalo běžet spoustu věcí a úplně zmizeli. Dokonce píše že procesor není k dispozici, nainstalovaná paměť RAM není k dispozici. Našel jsem nějaký sajrajt Win32:PUP-GEN.
Vůbec netuším, zda se s tím dá něco dělat, či jestli se musí přeinstalovat celý OS.
Děkuji za každou radu

Re: Zhroucení počítače

Napsal: 21 dub 2013 09:38
od vyosek
Zdravim :)

:arrow: Zkuste se dostat do nouzoveho rezimu (restart PC, mackat F8, zvolit Stav nouze s praci v siti)

:arrow: Zkuste udelat log z RSIT http://forum.viry.cz/viewtopic.php?f=24&t=81939

:arrow: Pripadne problemove hlasky vyfotte a dejte je sem

Re: Zhroucení počítače

Napsal: 21 dub 2013 13:45
od Marxxx
Už jsem tady...

Logfile of random's system information tool 1.09 (written by random/random)
Run by acer at 2013-04-21 14:40:04
WIN_7 Service Pack 1
System drive C: has 543 GB (58%) free of 935 GB
Total RAM: 3948 MB (88% free)

HijackThis download failed

======Listing Processes======


======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1191941196-2314733267-3189003766-1001Core.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1191941196-2314733267-3189003766-1001UA.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1191941196-2314733267-3189003766-1001Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1191941196-2314733267-3189003766-1001UA.job
C:\Windows\tasks\PC Performer_DEFAULT.job
C:\Windows\tasks\PC Performer_UPDATES.job

=========Mozilla firefox=========

ProfilePath - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\tkf9ui3n.default

prefs.js - "browser.search.useDBForOrder" - "false"
prefs.js - "browser.startup.homepage" - "http://search.softonic.com/INF00176/tb_ ... rce=13&cc="
prefs.js - "keyword.URL" - "http://search.softonic.com/INF00176/tb_ ... e=2&cc=&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.6.602.180 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.17.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@mcafee.com/McAfeeMssPlugin]
"Description"=McAfee Mss Plugin
"Path"=C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0]
"Description"=WildTangent Games App V2 Presence Detector Plugin
"Path"=C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.6.602.180 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.17.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll

C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files (x86)\Mozilla Firefox\plugins\
nppdf32.DEU
nppdf32.dll
nppdf32.FRA
nppdf32.JPN

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
babylon.xml
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\tkf9ui3n.default\extensions\
ffxtlbra@softonic.com
SpecialSavings@SpecialSavings.com
toolbar@ask.com
{800b5000-a755-47e1-992b-48a1c1357f07}
{97A78363-B868-4B48-AC91-A783A31215AF}
{ea614400-e918-4741-9a97-7a972ff7c30b}
{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}

C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\tkf9ui3n.default\searchplugins\
askcom.xml
icqplugin-1.xml
icqplugin-2.xml
icqplugin-3.xml
icqplugin-4.xml
icqplugin-5.xml
icqplugin-6.xml
icqplugin.gif
icqplugin.src
icqplugin.xml
softonic.xml
sweetim.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}]
MSS+ Identifier - C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{856E12B5-22D7-4E22-9ACA-EA9A008DD65B}]
MrFroggy Class - C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{938958E8-355C-49FF-92B0-53C1B87ACEA9}]
SpecialSavings - C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{944FEDFD-C4FD-441D-8275-9C651A9FFBDE}]
Smiley Bar for Facebook - C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA74D58F-ACD0-450D-A85E-6C04B171C044}]
MinibarBHO - C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E87806B5-E908-45FD-AF5E-957D83E58E68}]
Softonic Helper Object - C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
SweetPacks Browser Helper - C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program File [2012-10-31 6527128]
{EEE6C35B-6118-11DC-9C72-001320C79847} - SweetPacks Toolbar for Internet Explorer - C:\Program File [2012-10-31 6527128]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program File [2012-10-31 6527128]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program File [2012-10-31 6527128]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program File [2012-10-31 6527128]
{5018CFD2-804D-4C99-9F81-25EAEA2769DE} - Softonic Toolbar - C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-06-21 167704]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-06-21 392472]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-06-21 416024]
"AtherosBtStack"=C:\Program File [2012-10-31 6527128]
"AthBtTray"=C:\Program File [2012-10-31 6527128]
"ETDCtrl"=C:\Program File [2012-10-31 6527128]
"RtHDVCpl"=C:\Program File [2012-10-31 6527128]
"RtHDVBg_Dolby"=C:\Program File [2012-10-31 6527128]
"Power Management"=C:\Program File [2012-10-31 6527128]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program File [2012-10-31 6527128]
"Pando Media Booster"=C:\Program File [2012-10-31 6527128]
"cz.seznam.software.autoupdate"=C:\Users\acer\AppData\Roaming\Seznam.cz\szninstall.exe [2012-09-13 1009288]
"cz.seznam.software.szndesktop"=C:\Users\acer\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2012-12-19 92296]
"SDP"=C:\Program File [2012-10-31 6527128]
"Google Update"=C:\Users\acer\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-08 116648]
"PC Speed Maximizer"=C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Clownfish]
C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Comrade.exe]
C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
C:\Users\acer\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-10-17 138096]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\acer\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-08 116648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
~C:\Program Files (x86)\ICQ7M\ICQ.exe silent loginmode=4 []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileBroadband]
C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Speed Maximizer]
C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YouCam Service]
C:\Program File [2012-10-31 6527128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GamePark klient 2.lnk]
C:\PROGRA~1\GAMEPA~1\gpcl.exe [2011-07-29 442880]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^acer^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^DesktopVideoPlayer.lnk]
C:\Users\acer\AppData\Local\vghd\bin\vghd.exe -fromStartup []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SuiteTray"=C:\Program File [2012-10-31 6527128]
"BackupManagerTray"=C:\Program File [2012-10-31 6527128]
"LManager"=C:\Program File [2012-10-31 6527128]
"Dolby Advanced Audio v2"=C:\Dolby PCEE4\pcee4.exe [2011-06-01 506712]
"ArcadeMovieService"=C:\Program File [2012-10-31 6527128]
""= []
"ApnUpdater"=C:\Program File [2012-10-31 6527128]
"SweetIM"=C:\Program File [2012-10-31 6527128]
"Sweetpacks Communicator"=C:\Program File [2012-10-31 6527128]
"avast"=C:\Program File [2012-10-31 6527128]
"speedvid"=C:\Program File [2012-10-31 6527128]
"Guard.Mail.ru.gui"=C:\Program File [2012-10-31 6527128]
"seznam-listicka-distribuce"=C:\Program File [2012-10-31 6527128]
"Adobe ARM"=C:\Program File [2012-10-31 6527128]
"SunJavaUpdateSched"=C:\Program File [2012-10-31 6527128]
"LogMeIn Hamachi Ui"=C:\Program File [2012-10-31 6527128]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
McAfee Security Scan Plus.lnk - C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe

C:\Users\acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
GamersFirst LIVE!.lnk - C:\Users\acer\AppData\Local\GamersFirst\LIVE!\Live.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-06-10 389632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-04-21 14:40:04 ----D---- C:\rsit
2013-04-21 14:40:04 ----D---- C:\Program Files\trend micro
2013-04-20 21:19:08 ----A---- C:\Windows\ntbtlog.txt
2013-04-18 18:59:14 ----D---- C:\ProgramData\REVOLT
2013-04-18 18:55:03 ----D---- C:\Program Files (x86)\The Walking Dead CZ
2013-04-17 18:37:09 ----D---- C:\Users\acer\AppData\Roaming\PerformerSoft
2013-04-17 18:37:08 ----A---- C:\Windows\system32\roboot64.exe
2013-04-17 18:37:06 ----D---- C:\Program Files (x86)\PC Performer
2013-04-17 18:36:59 ----D---- C:\Users\acer\AppData\Roaming\SpecialSavings
2013-04-17 18:36:58 ----D---- C:\Program Files (x86)\SpecialSavings
2013-04-17 18:36:55 ----D---- C:\Users\acer\AppData\Roaming\StatusWinks
2013-04-17 18:36:54 ----D---- C:\Program Files (x86)\Smiley Bar for Facebook
2013-04-17 18:36:49 ----D---- C:\Users\acer\AppData\Roaming\File Scout
2013-04-17 18:36:49 ----D---- C:\ProgramData\IBUpdaterService
2013-04-17 18:35:07 ----D---- C:\Users\acer\AppData\Roaming\uTorrent
2013-04-12 22:54:27 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-04-11 06:39:46 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-04-11 06:39:46 ----A---- C:\Windows\system32\mshtmled.dll
2013-04-11 06:39:45 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-04-11 06:39:43 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-04-11 06:39:42 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-04-11 06:39:42 ----A---- C:\Windows\system32\ieUnatt.exe
2013-04-11 06:39:42 ----A---- C:\Windows\system32\ieui.dll
2013-04-11 06:39:41 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-04-11 06:39:41 ----A---- C:\Windows\SYSWOW64\url.dll
2013-04-11 06:39:41 ----A---- C:\Windows\system32\url.dll
2013-04-11 06:39:40 ----A---- C:\Windows\system32\urlmon.dll
2013-04-11 06:39:40 ----A---- C:\Windows\system32\jscript9.dll
2013-04-11 06:39:39 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-04-11 06:39:39 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-04-11 06:39:39 ----A---- C:\Windows\system32\wininet.dll
2013-04-11 06:39:39 ----A---- C:\Windows\system32\msfeeds.dll
2013-04-11 06:39:38 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-04-11 06:39:38 ----A---- C:\Windows\system32\jsproxy.dll
2013-04-11 06:39:37 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-04-11 06:39:37 ----A---- C:\Windows\system32\vbscript.dll
2013-04-11 06:39:37 ----A---- C:\Windows\system32\jscript.dll
2013-04-11 06:39:36 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-04-11 06:39:36 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-04-11 06:39:36 ----A---- C:\Windows\system32\iertutil.dll
2013-04-11 06:39:34 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-04-11 06:39:33 ----A---- C:\Windows\system32\mshtml.dll
2013-04-11 06:39:31 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-04-11 06:39:31 ----A---- C:\Windows\system32\ieframe.dll
2013-04-10 13:00:02 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2013-04-10 13:00:02 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2013-04-10 13:00:02 ----A---- C:\Windows\system32\mstscax.dll
2013-04-10 13:00:01 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2013-04-10 13:00:01 ----A---- C:\Windows\system32\tsgqec.dll
2013-04-10 13:00:01 ----A---- C:\Windows\system32\aaclient.dll
2013-04-10 12:59:55 ----A---- C:\Windows\system32\win32k.sys
2013-04-10 12:59:53 ----A---- C:\Windows\system32\drivers\ntfs.sys
2013-04-10 12:59:53 ----A---- C:\Windows\system32\drivers\fvevol.sys
2013-04-10 12:59:51 ----A---- C:\Windows\system32\ntoskrnl.exe
2013-04-10 12:59:49 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2013-04-10 12:59:48 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2013-04-10 12:59:48 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2013-04-10 12:59:48 ----A---- C:\Windows\system32\smss.exe
2013-04-10 12:59:48 ----A---- C:\Windows\system32\csrsrv.dll
2013-04-02 09:09:37 ----D---- C:\Program Files (x86)\Microsoft XNA
2013-04-01 19:52:00 ----D---- C:\Program Files (x86)\Paradox Interactive
2013-03-31 19:55:23 ----SHD---- C:\Windows\ftpcache
2013-03-31 19:55:10 ----A---- C:\Windows\game.ini
2013-03-31 18:34:16 ----D---- C:\Program Files (x86)\Cossacks
2013-03-31 17:16:29 ----D---- C:\Program Files (x86)\Smokin' Guns
2013-03-29 13:05:07 ----A---- C:\Windows\SYSWOW64\unrar.dll
2013-03-29 13:05:06 ----A---- C:\Windows\uncsetup.exe

======List of files/folders modified in the last 1 month======

2013-04-21 14:40:04 ----RD---- C:\Program Files
2013-04-21 10:22:39 ----D---- C:\Users\acer\AppData\Roaming\Seznam.cz
2013-04-21 09:45:18 ----D---- C:\Windows\Temp
2013-04-21 09:33:22 ----D---- C:\Users\acer\AppData\Roaming\vlc
2013-04-20 21:19:08 ----D---- C:\Windows
2013-04-20 19:58:42 ----D---- C:\Program Files (x86)\Optimizer Pro
2013-04-20 19:42:23 ----D---- C:\Windows\system32\catroot
2013-04-20 19:42:18 ----D---- C:\Windows\system32\DriverStore
2013-04-20 19:42:18 ----D---- C:\Windows\system32\drivers
2013-04-20 19:42:18 ----D---- C:\Windows\inf
2013-04-20 15:10:18 ----D---- C:\Windows\pss
2013-04-20 14:40:10 ----AD---- C:\ProgramData\Temp
2013-04-20 14:18:47 ----SHD---- C:\Recovery
2013-04-20 14:18:38 ----D---- C:\Windows\Logs
2013-04-20 12:54:22 ----SD---- C:\ProgramData\Microsoft
2013-04-20 03:05:30 ----A---- C:\Windows\SYSWOW64\log.txt
2013-04-20 02:59:19 ----D---- C:\Users\acer\AppData\Roaming\Skype
2013-04-19 19:05:55 ----D---- C:\Windows\System32
2013-04-19 19:05:55 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-04-19 15:47:06 ----D---- C:\ProgramData\boost_interprocess
2013-04-19 15:46:50 ----D---- C:\Users\acer\AppData\Roaming\ICQ
2013-04-19 15:45:35 ----D---- C:\ProgramData\clear.fi
2013-04-19 15:04:49 ----D---- C:\Windows\system32\config
2013-04-19 15:01:12 ----D---- C:\Windows\system32\Tasks
2013-04-19 12:35:09 ----D---- C:\Windows\system32\catroot2
2013-04-18 18:59:14 ----HD---- C:\ProgramData
2013-04-18 18:55:03 ----RD---- C:\Program Files (x86)
2013-04-17 20:29:56 ----D---- C:\Program Files (x86)\Electronic Arts
2013-04-17 18:37:16 ----D---- C:\Windows\Tasks
2013-04-17 18:05:02 ----D---- C:\Users\acer\AppData\Roaming\SoftGrid Client
2013-04-17 10:47:38 ----D---- C:\Windows\Prefetch
2013-04-16 11:44:10 ----SHD---- C:\System Volume Information
2013-04-14 10:06:01 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2013-04-13 09:30:12 ----D---- C:\Windows\system32\NDF
2013-04-13 00:26:39 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-04-11 09:42:07 ----D---- C:\Windows\winsxs
2013-04-11 06:44:38 ----D---- C:\Windows\SysWOW64
2013-04-11 06:44:37 ----D---- C:\Windows\SYSWOW64\migration
2013-04-11 06:44:37 ----D---- C:\Windows\system32\migration
2013-04-11 06:44:37 ----D---- C:\Program Files\Internet Explorer
2013-04-11 06:44:37 ----D---- C:\Program Files (x86)\Internet Explorer
2013-04-11 06:41:06 ----A---- C:\Windows\system32\MRT.exe
2013-04-09 08:01:07 ----SHD---- C:\Windows\Installer
2013-04-09 08:01:07 ----D---- C:\ProgramData\Skype
2013-04-09 08:01:04 ----RD---- C:\Program Files (x86)\Skype
2013-04-09 08:01:03 ----D---- C:\Program Files (x86)\Common Files
2013-04-02 19:33:00 ----D---- C:\Users\acer\AppData\Roaming\.minecraft
2013-04-02 09:09:55 ----RSD---- C:\Windows\assembly
2013-04-01 17:34:19 ----D---- C:\ProgramData\HappyCloud
2013-03-31 19:55:14 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2013-03-22 14:47:15 ----D---- C:\Program Files (x86)\Google

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2013-02-28 65408]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iaStor.sys [2011-04-26 557848]
R0 nvpciflt;nvpciflt; C:\Windows\system32\DRIVERS\nvpciflt.sys [2011-03-31 25960]
R0 pe3agmlb;Armed Assault Environment Driver (pe3agmlb); C:\Windows\system32\drivers\pe3agmlb.sys [2007-06-04 73088]
R0 pe3aqn8b;XIII Century Environment Driver (pe3aqn8b); C:\Windows\system32\drivers\pe3aqn8b.sys [2008-02-11 72312]
R0 ps6agmlb;Armed Assault Synchronization Driver (ps6agmlb); C:\Windows\system32\drivers\ps6agmlb.sys [2007-06-04 77704]
R0 ps7aqn8b;XIII Century Synchronization Driver (ps7aqn8b); C:\Windows\system32\drivers\ps7aqn8b.sys [2008-02-11 103552]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2012-10-31 21136]
R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [2013-02-28 71064]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-12-01 283200]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2011-07-20 2755584]
R3 b57xdbd;Broadcom xD Picture Bus Driver Service; C:\Windows\system32\DRIVERS\b57xdbd.sys [2011-01-21 67624]
R3 b57xdmp;Broadcom xD Picture vstorp client drv; C:\Windows\system32\DRIVERS\b57xdmp.sys [2011-01-21 19496]
R3 bScsiMSa;bScsiMSa; C:\Windows\system32\DRIVERS\bScsiMSa.sys [2011-05-16 51240]
R3 BTATH_BUS;Atheros Bluetooth Bus; C:\Windows\system32\DRIVERS\btath_bus.sys [2011-09-17 30368]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2011-04-05 142632]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
R3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys [2011-07-12 86016]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60a.sys [2011-05-10 425000]
R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys [2011-03-10 18432]
R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys [2011-03-10 17408]
S1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2013-02-28 1025880]
S1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2013-02-28 377992]
S1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2013-02-28 68992]
S1 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2011-08-12 22648]
S1 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2011-08-12 20520]
S1 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2011-08-12 62776]
S2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2013-02-28 33472]
S2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2013-02-28 80888]
S3 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2013-02-28 177672]
S3 AthBTPort;Atheros Virtual Bluetooth Class; C:\Windows\system32\DRIVERS\btath_flt.sys [2011-09-17 36000]
S3 bScsiSDa;bScsiSDa; C:\Windows\system32\DRIVERS\bScsiSDa.sys [2011-05-06 86056]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver; C:\Windows\system32\drivers\btath_a2dp.sys [2011-09-17 330912]
S3 btath_avdt;Atheros Bluetooth AVDT Service; C:\Windows\system32\drivers\btath_avdt.sys [2011-09-17 110240]
S3 BTATH_HCRP;Bluetooth HCRP Server driver; C:\Windows\system32\DRIVERS\btath_hcrp.sys [2011-09-17 167584]
S3 BTATH_LWFLT;Bluetooth LWFLT Device; C:\Windows\system32\DRIVERS\btath_lwflt.sys [2011-09-17 68256]
S3 BTATH_RCP;Bluetooth AVRCP Device; C:\Windows\system32\DRIVERS\btath_rcp.sys [2011-09-17 280992]
S3 BtFilter;BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys [2011-09-17 517280]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 clwvd;CyberLink WebCam Virtual Driver; C:\Windows\system32\DRIVERS\clwvd.sys []
S3 cpuz135;cpuz135; \??\C:\Users\acer\AppData\Local\Temp\cpuz135\cpuz135_x64.sys []
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [2011-07-12 117248]
S3 ew_usbenumfilter;huawei_CompositeFilter; C:\Windows\system32\DRIVERS\ew_usbenumfilter.sys [2011-07-12 13952]
S3 huawei_cdcacm;huawei_cdcacm; C:\Windows\system32\DRIVERS\ew_jucdcacm.sys [2011-07-12 98816]
S3 huawei_ext_ctrl;huawei_ext_ctrl; C:\Windows\system32\DRIVERS\ew_juextctrl.sys [2011-07-12 28672]
S3 huawei_wwanecm;huawei_wwanecm; C:\Windows\system32\DRIVERS\ew_juwwanecm.sys [2011-07-12 213504]
S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2011-06-10 12230912]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-08-16 3056360]
S3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 Sftfs;Sftfs; C:\Windows\system32\DRIVERS\Sftfslh.sys [2009-12-03 721768]
S3 Sftplay;Sftplay; C:\Windows\system32\DRIVERS\Sftplaylh.sys [2009-12-03 269672]
S3 Sftredir;Sftredir; C:\Windows\system32\DRIVERS\Sftredirlh.sys [2009-12-03 25960]
S3 Sftvol;Sftvol; C:\Windows\system32\DRIVERS\Sftvollh.sys [2009-12-03 22376]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\Windows\system32\DRIVERS\ss_bbus.sys [2009-09-19 127488]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

S2 avast! Antivirus;avast! Antivirus; C:\Program File [2012-10-31 6527128]
S2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2012-12-26 76888]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe []
S4 AdobeARMservice;Adobe Acrobat Update Service; C:\Program File [2012-10-31 6527128]
S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-04-13 256904]
S4 AtherosSvc;AtherosSvc; C:\Program File [2012-10-31 6527128]
S4 BBSvc;BingBar Service; C:\Program File [2012-10-31 6527128]
S4 BBUpdate;BBUpdate; C:\Program File [2012-10-31 6527128]
S4 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S4 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S4 cvhsvc;Client Virtualization Handler; C:\Program File [2012-10-31 6527128]
S4 DsiWMIService;Dritek WMI Service; C:\Program File [2012-10-31 6527128]
S4 EgisTec Ticket Service;EgisTec Ticket Service; C:\Program File [2012-10-31 6527128]
S4 ePowerSvc;ePower Service; C:\Program File [2012-10-31 6527128]
S4 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program File [2012-10-31 6527128]
S4 GamesAppService;GamesAppService; C:\Program File [2012-10-31 6527128]
S4 GREGService;GREGService; C:\Program File [2012-10-31 6527128]
S4 Guard.Mail.ru;Guard.Mail.ru; C:\Program File [2012-10-31 6527128]
S4 gupdate;Služba Google Update (gupdate); C:\Program File [2012-10-31 6527128]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program File [2012-10-31 6527128]
S4 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program File [2012-10-31 6527128]
S4 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program File [2012-10-31 6527128]
S4 ICQ Service;ICQ Service; C:\PROGRA~2\ICQ6TO~1\ICQSER~1.EXE [2012-03-20 247872]
S4 IDriverT;InstallDriver Table Manager; C:\Program File [2012-10-31 6527128]
S4 Live Updater Service;Live Updater Service; C:\Program File [2012-10-31 6527128]
S4 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program File [2012-10-31 6527128]
S4 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program File [2012-10-31 6527128]
S4 MozillaMaintenance;Mozilla Maintenance Service; C:\Program File [2012-10-31 6527128]
S4 NOBU;Norton Online Backup; C:\Program File [2012-10-31 6527128]
S4 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program File [2012-10-31 6527128]
S4 NVSvc;NVIDIA Driver Helper Service; C:\Windows\system32\nvvsvc.exe [2011-03-31 993896]
S4 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program File [2012-10-31 6527128]
S4 ose;Office Source Engine; C:\Program File [2012-10-31 6527128]
S4 osppsvc;Office Software Protection Platform; C:\Program File [2012-10-31 6527128]
S4 pr2agmlb;Armed Assault Drivers Auto Removal (pr2agmlb); C:\Windows\system32\pr2agmlb.exe [2007-06-04 754304]
S4 pr2aqn8b;XIII Century Drivers Auto Removal (pr2aqn8b); C:\Windows\system32\pr2aqn8b.exe [2008-02-11 781176]
S4 sftlist;Application Virtualization Client; C:\Program File [2012-10-31 6527128]
S4 sftvsa;Application Virtualization Service Agent; C:\Program File [2012-10-31 6527128]
S4 SkypeUpdate;Skype Updater; C:\Program File [2012-10-31 6527128]
S4 Steam Client Service;Steam Client Service; C:\Program File [2012-10-31 6527128]
S4 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program File [2012-10-31 6527128]
S4 VmbService;Vodafone Mobile Connect Service; C:\Program File [2012-10-31 6527128]
S4 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-09-05 1255736]

-----------------EOF-----------------

Re: Zhroucení počítače

Napsal: 21 dub 2013 15:43
od vyosek
:arrow: Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix

Re: Zhroucení počítače

Napsal: 21 dub 2013 16:01
od Marxxx
Rkill 2.4.7 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 04/21/2013 04:56:47 PM in x64 mode.
Windows Version: Windows 7 Home Premium Service Pack 1

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* No malware processes found to kill.

Active Proxy Server Detected

* Proxy Disabled.
* ProxyOverride value deleted.
* ProxyServer value deleted.
* AutoConfigURL value deleted.
* Proxy settings were backed up to Registry file.

Checking Registry for malware related settings:

* Explorer Policy Removed: NoActiveDesktopChanges [HKLM]

Backup Registry file created at:
C:\Users\acer\Desktop\rkill\rkill-04-21-2013-04-58-17.reg

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* No issues found.

Checking Windows Service Integrity:

* Služba BFE (Base Filtering Engine) (BFE) is not Running.
Startup Type set to: Disabled

* Klient DHCP (Dhcp) is not Running.
Startup Type set to: Disabled

* Klient DNS (Dnscache) is not Running.
Startup Type set to: Disabled

* Systém událostí COM+ (EventSystem) is not Running.
Startup Type set to: Disabled

* Brána Windows Firewall (MpsSvc) is not Running.
Startup Type set to: Disabled

* Síťová připojení (Netman) is not Running.
Startup Type set to: Manual

* Služba rozhraní síťového úložiště (nsi) is not Running.
Startup Type set to: Disabled

* Windows Defender (WinDefend) is not Running.
Startup Type set to: Disabled

* Služba WMI (Winmgmt) is not Running.
Startup Type set to: Disabled

* Centrum zabezpečení (wscsvc) is not Running.
Startup Type set to: Disabled

* Windows Update (wuauserv) is not Running.
Startup Type set to: Disabled

* Ovladač ověření brány Windows Firewall (mpsdrv) is not Running.
Startup Type set to: Manual

* FontCache => %SystemRoot%\system32\svchost.exe -k LocalService [Incorrect ImagePath]

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* No issues found.

Program finished at: 04/21/2013 04:58:27 PM
Execution time: 0 hours(s), 1 minute(s), and 40 seconds(s)

Re: Zhroucení počítače

Napsal: 21 dub 2013 22:52
od vyosek
:arrow: System je hodne naboren, nevim, jestli se nam jej podari dat do kupy...

:arrow: CF jste spoustel :???:

Re: Zhroucení počítače

Napsal: 26 dub 2013 19:43
od Marxxx
Děkuji za odpovědi, byl jsem několik dní mimo, tak reaguji až teď.
Na mě musíte méně profesionálněji :D Co myslíte tím CF?

Re: Zhroucení počítače

Napsal: 26 dub 2013 21:41
od vyosek
:arrow: CF=ComboFix jak jsem psal v navodu - dal jste jen log z RKillu ale pak z CF uz nikoli...