UPDATE: Po zobrazení loga windows se zobrazí modrá smrt a tato chybová hláška:
STOP: C0000135 The program can't start because %hs is missing. Try resintalling the program
Plus dokládám FRST log z jednoho z napadených počítačů - je to provedeno pomocí příkazového řádku a instalačního CD, takže bohužel bez addition. Kdyby bylo potřeba, zkusim dodat.
Díky
Zde log:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06.06.2018 01
Ran by SYSTEM on MININT-KCOUFN7 (15-06-2018 09:18:21)
Running from e:\
Platform: Windows 7 Professional Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Recovery
Default: ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AVGUI.exe] => C:\Program Files\AVG\Antivirus\AvLaunch.exe [291568 2018-06-13] (AVG Technologies CZ, s.r.o.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\Default\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\Default User\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
Lsa: [Notification Packages] scecli C:\Program Files\ThinkPad\Bluetooth Software\BtwProximityCP.dll
BootExecute: autocheck autochk * autopart.exe
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Dell Wireless\Ath_CoexAgent.exe [135168 2011-02-16] (Atheros)
S2 AVG Antivirus; C:\Program Files\AVG\Antivirus\AVGSvc.exe [318328 2018-06-13] (AVG Technologies CZ, s.r.o.)
S2 AVG Firewall; C:\Program Files\AVG\Antivirus\afwServ.exe [430032 2018-06-13] (AVG Technologies CZ, s.r.o.)
S2 avgAdminClient; C:\Program Files\AVG\Antivirus\avgAdminClientServicex.exe [79632 2018-06-13] (AVG Technologies CZ, s.r.o.)
S3 avgbIDSAgent; C:\Program Files\AVG\Antivirus\x64\aswidsagenta.exe [7670672 2018-06-13] (AVG Technologies CZ, s.r.o.)
S4 LPlatSvc; C:\Windows\system32\LPlatSvc.exe [774736 2017-09-05] (Lenovo.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S4 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe /launchService [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S1 avgArPot; C:\Windows\System32\drivers\avgArPot.sys [189032 2018-06-13] (AVG Technologies CZ, s.r.o.)
S1 avgbdisk; C:\Windows\System32\drivers\avgbdiska.sys [166064 2018-06-13] (AVG Technologies CZ, s.r.o.)
S1 avgbidsdriver; C:\Windows\System32\drivers\avgbidsdrivera.sys [220600 2018-06-13] (AVG Technologies CZ, s.r.o.)
S0 avgbidsh; C:\Windows\System32\drivers\avgbidsha.sys [192536 2018-06-13] (AVG Technologies CZ, s.r.o.)
S0 avgblog; C:\Windows\System32\drivers\avgbloga.sys [336848 2018-06-13] (AVG Technologies CZ, s.r.o.)
S0 avgbuniv; C:\Windows\System32\drivers\avgbuniva.sys [50776 2018-06-13] (AVG Technologies CZ, s.r.o.)
S3 avgHwid; C:\Windows\System32\drivers\avgHwid.sys [39352 2018-06-13] (AVG Technologies CZ, s.r.o.)
S2 avgMonFlt; C:\Windows\System32\drivers\avgMonFlt.sys [151504 2018-06-13] (AVG Technologies CZ, s.r.o.)
S3 avgNetNd6; C:\Windows\System32\DRIVERS\avgNetNd6.sys [29944 2018-06-13] (AVG Technologies CZ, s.r.o.)
S1 avgNetSec; C:\Windows\System32\drivers\avgNetSec.sys [632640 2018-06-13] (AVG Technologies CZ, s.r.o.)
S1 avgRdr; C:\Windows\System32\drivers\avgRdr2.sys [103744 2018-06-13] (AVG Technologies CZ, s.r.o.)
S0 avgRvrt; C:\Windows\System32\drivers\avgRvrt.sys [78352 2018-06-13] (AVG Technologies CZ, s.r.o.)
S1 avgSnx; C:\Windows\System32\drivers\avgSnx.sys [1020112 2018-06-13] (AVG Technologies CZ, s.r.o.)
S1 avgSP; C:\Windows\System32\drivers\avgSP.sys [452904 2018-06-13] (AVG Technologies CZ, s.r.o.)
S2 avgStm; C:\Windows\System32\drivers\avgStm.sys [198368 2018-06-13] (AVG Technologies CZ, s.r.o.)
S0 avgVmm; C:\Windows\System32\drivers\avgVmm.sys [373944 2018-06-13] (AVG Technologies CZ, s.r.o.)
S2 AODDriver4.2; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [X]
S4 Avgfwfd; system32\DRIVERS\avgfwd6a.sys [X]
S4 Avgmfx64; system32\DRIVERS\avgmfx64.sys [X]
S4 Avgrkx64; system32\DRIVERS\avgrkx64.sys [X]
S4 Avgtdia; system32\DRIVERS\avgtdia.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-06-15 09:18 - 2018-06-15 09:18 - 000000000 ____D C:\FRST
2018-06-13 12:15 - 2018-06-13 12:10 - 000166064 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgbdiska.sys
2018-06-13 12:12 - 2018-06-13 12:12 - 000001836 _____ C:\Users\Public\Desktop\AVG Business Security.lnk
2018-06-13 12:11 - 2018-06-13 12:11 - 000003904 _____ C:\Windows\System32\Tasks\Antivirus Emergency Update
2018-06-13 12:11 - 2018-06-13 12:11 - 000000000 ____D C:\Windows\System32\Tasks\AVG
2018-06-13 12:11 - 2018-06-13 12:10 - 000452904 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgSP.sys
2018-06-13 12:11 - 2018-06-13 12:10 - 000373944 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgVmm.sys
2018-06-13 12:11 - 2018-06-13 12:10 - 000198368 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgStm.sys
2018-06-13 12:11 - 2018-06-13 12:10 - 000151504 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgMonFlt.sys
2018-06-13 12:11 - 2018-06-13 12:10 - 000078352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgRvrt.sys
2018-06-13 12:11 - 2018-06-13 12:10 - 000039352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgHwid.sys
2018-06-13 12:10 - 2018-06-13 12:10 - 001020112 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgSnx.sys
2018-06-13 12:10 - 2018-06-13 12:10 - 000632640 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgNetSec.sys
2018-06-13 12:10 - 2018-06-13 12:10 - 000377584 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\System32\avgBoot.exe
2018-06-13 12:10 - 2018-06-13 12:10 - 000336848 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgbloga.sys
2018-06-13 12:10 - 2018-06-13 12:10 - 000220600 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgbidsdrivera.sys
2018-06-13 12:10 - 2018-06-13 12:10 - 000192536 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgbidsha.sys
2018-06-13 12:10 - 2018-06-13 12:10 - 000189032 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgArPot.sys
2018-06-13 12:10 - 2018-06-13 12:10 - 000166064 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\aswaa871ddcfe3da598.tmp
2018-06-13 12:10 - 2018-06-13 12:10 - 000103744 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgRdr2.sys
2018-06-13 12:10 - 2018-06-13 12:10 - 000050776 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgbuniva.sys
2018-06-13 12:10 - 2018-06-13 12:10 - 000029944 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\System32\Drivers\avgNetNd6.sys
2018-06-13 12:10 - 2018-06-13 12:10 - 000000000 ____D C:\Program Files\Common Files\AVG
2018-06-13 12:09 - 2018-06-13 12:09 - 000000000 ____D C:\Program Files\AVG
2018-06-13 12:08 - 2018-06-13 12:13 - 000000000 ____D C:\Users\mudrc\AppData\Roaming\AVG
2018-06-13 11:19 - 2018-06-13 11:19 - 000000000 ____D C:\Users\mudrc\AppData\Roaming\Macromedia
2018-06-13 11:18 - 2018-06-13 11:18 - 000000000 ____D C:\Users\mudrc\AppData\LocalLow\Mozilla
2018-06-13 11:18 - 2018-06-13 11:18 - 000000000 ____D C:\Users\mudrc\AppData\Local\Mozilla
2018-06-13 11:09 - 2018-06-13 11:09 - 000000000 ____D C:\Users\mudrc\AppData\Local\CEF
2018-06-13 11:09 - 2018-06-13 11:09 - 000000000 ____D C:\Users\mudrc\AppData\Local\Avg
2018-06-13 11:08 - 2018-06-14 08:53 - 000000000 ____D C:\Users\mudrc\AppData\Local\Google
2018-05-18 10:11 - 2018-05-18 10:11 - 000003386 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2018-05-18 10:11 - 2018-05-18 10:11 - 000003258 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-06-14 08:53 - 2016-09-13 09:56 - 000786432 ____H C:\Users\mudrc\NTUSER.MAN
2018-06-14 07:34 - 2016-08-24 08:44 - 000002186 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-06-14 07:25 - 2011-04-12 09:34 - 000671742 _____ C:\Windows\System32\perfh005.dat
2018-06-14 07:25 - 2011-04-12 09:34 - 000142306 _____ C:\Windows\System32\perfc005.dat
2018-06-14 07:25 - 2009-07-14 06:13 - 001590850 _____ C:\Windows\System32\PerfStringBackup.INI
2018-06-14 07:25 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf
2018-06-14 07:22 - 2016-08-24 13:34 - 000000104 _____ C:\Windows\System32\config\netlogon.ftl
2018-06-13 12:14 - 2016-08-24 09:40 - 000000000 ____D C:\Program Files (x86)\AVG
2018-06-13 12:14 - 2016-08-24 08:23 - 000000000 ____D C:\ProgramData\Avg
2018-06-13 12:13 - 2016-08-24 09:41 - 000000000 ___HD C:\$AVG
2018-06-13 12:13 - 2016-08-24 08:24 - 000000000 ____D C:\ProgramData\MFAData
2018-06-13 12:07 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\rescache
2018-06-13 11:19 - 2009-07-14 05:45 - 000058288 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-06-13 11:19 - 2009-07-14 05:45 - 000058288 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-06-13 11:18 - 2016-10-11 08:17 - 000000000 ____D C:\Users\mudrc\AppData\Roaming\Mozilla
2018-06-13 11:07 - 2016-09-13 09:56 - 000000000 ____D C:\users\mudrc
2018-06-13 11:06 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-05-17 13:55 - 2016-08-24 09:28 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
==================== Known DLLs (Whitelisted) =========================
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe
[2018-03-07 16:22] - [2018-01-01 02:50] - 000455680 _____ (Microsoft Corporation) 11D6A262B617130F7C16E308C12E0D41
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll
[2018-03-07 16:22] - [2018-01-01 03:18] - 000512000 _____ (Microsoft Corporation) BA6C9EE518A11DA4AD061B223EBED3D3
C:\Windows\System32\dnsapi.dll => MD5 is legit
C:\Windows\SysWOW64\dnsapi.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== Association (Whitelisted) =============
==================== Restore Points =========================
==================== Memory info ===========================
Percentage of memory in use: 19%
Total physical RAM: 3979.23 MB
Available physical RAM: 3220.45 MB
Total Virtual: 3977.43 MB
Available Virtual: 3263.75 MB
==================== Drives ================================
Drive c: (WIN) (Fixed) (Total:149.05 GB) (Free:98.92 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (GSP1RMCPRXFREO_CS_DVD) (CDROM) (Total:2.97 GB) (Free:0 GB) UDF
Drive e: (Zákravský) (Fixed) (Total:931.51 GB) (Free:639.95 GB) NTFS
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 298.1 GB) (Disk ID: E2BC0A16)
Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 93080E91)
Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)
LastRegBack: 2018-06-07 07:35
==================== End of FRST.txt ============================