Prosím o kontrolu logu z HJT - infikovaný notebook Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod jaro3 » 07 bře 2017 19:18

Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
FF - prefs.js..extensions.enabledAddons: %7BE6C1199F-E687-42da-8C24-E7770CC3AE66%7D:2.1.2
FF - prefs.js..extensions.enabledAddons: %7Bf13b157f-b174-47e7-a34d-4815ddfdfeb8%7D:0.9.89.1-signed.1-signed
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:47.0.2
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF64_23_0_0_162.dll File not found
[2015.11.06 18:56:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lenovo\AppData\Roaming\mozilla\Extensions
[2017.03.02 17:55:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lenovo\AppData\Roaming\mozilla\Firefox\Profiles\1xy2o2g4.default-1446832914166\extensions
[2017.03.02 17:55:32 | 000,023,373 | ---- | M] () (No name found) -- C:\Users\Lenovo\AppData\Roaming\mozilla\firefox\profiles\1xy2o2g4.default-1446832914166\extensions\firefox-hotfix@mozilla.org.xpi
[2016.11.19 16:27:41 | 000,046,440 | ---- | M] () (No name found) -- C:\Users\Lenovo\AppData\Roaming\mozilla\firefox\profiles\1xy2o2g4.default-1446832914166\extensions\tinyjsdebugger@enigmail.net.xpi
[2016.11.19 16:29:15 | 000,032,504 | ---- | M] () (No name found) -- C:\Users\Lenovo\AppData\Roaming\mozilla\firefox\profiles\1xy2o2g4.default-1446832914166\extensions\{E6C1199F-E687-42da-8C24-E7770CC3AE66}.xpi
[2016.11.19 16:30:43 | 000,214,132 | ---- | M] () (No name found) -- C:\Users\Lenovo\AppData\Roaming\mozilla\firefox\profiles\1xy2o2g4.default-1446832914166\extensions\{f13b157f-b174-47e7-a34d-4815ddfdfeb8}.xpi
[2017.03.03 23:19:28 | 000,006,253 | ---- | M] () (No name found) -- C:\Users\Lenovo\AppData\Roaming\mozilla\firefox\profiles\1xy2o2g4.default-1446832914166\features\{d56f0c80-859f-4034-b31c-adf9c5bad21b}\e10srollout@mozilla.org.xpi
[2017.03.03 23:19:28 | 000,838,245 | ---- | M] () (No name found) -- C:\Users\Lenovo\AppData\Roaming\mozilla\firefox\profiles\1xy2o2g4.default-1446832914166\features\{d56f0c80-859f-4034-b31c-adf9c5bad21b}\firefox@getpocket.com.xpi
[2017.03.03 23:19:28 | 000,005,391 | ---- | M] () (No name found) -- C:\Users\Lenovo\AppData\Roaming\mozilla\firefox\profiles\1xy2o2g4.default-1446832914166\features\{d56f0c80-859f-4034-b31c-adf9c5bad21b}\loop@mozilla.org.xpi
[2017.03.03 23:19:28 | 000,006,446 | ---- | M] () (No name found) -- C:\Users\Lenovo\AppData\Roaming\mozilla\firefox\profiles\1xy2o2g4.default-1446832914166\features\{d56f0c80-859f-4034-b31c-adf9c5bad21b}\websensehelper@mozilla.org.xpi
[2017.03.02 19:38:03 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
[2017.01.21 21:46:27 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\windows.storage.dll -- [2016.11.11 11:01:16 | 007,219,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\windows.storage.dll -- [2016.11.11 08:47:14 | 005,722,832 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2016.07.16 12:42:31 | 000,977,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2016.07.16 12:42:56 | 000,779,776 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2016.07.16 12:42:31 | 000,518,656 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

:Files
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\System32\dllcache\*.tmp
C:\WINDOWS\system32\SET*.tmp
C:\WINDOWS\system32\DUMP*.tmp
c:\windows\Tasks\*.job /s
C:\*.tmp
C:\WINDOWS\System32\drivers\*.tmp
C:\Program Files\*.tmp
C:\Documents and Settings\All Users\Data aplikací\*.tmp
C:\Windows\SysNative\drivers\*.tmp
C:\Windows\SysWow64\drivers\*.tmp
C:\Program Files (x86)\*.tmp
C:\Windows\SysWow64\*.tmp
C:\Windows\SysNative\*.tmp
C:\Program Files (x86)\*.tmp
C:\ProgramData\DP45977C.lfl
ipconfig /flushdns /c

:Reg
:Commands
[resethosts]
[purity]
[emptytemp]
[start explorer]
[Reboot]


Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Reklama
GoodByeMomo
Level 1
Level 1
Příspěvky: 50
Registrován: únor 17
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod GoodByeMomo » 07 bře 2017 19:59

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named firefox.exe was found!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Prefs.js: %7BE6C1199F-E687-42da-8C24-E7770CC3AE66%7D:2.1.2 removed from extensions.enabledAddons
Prefs.js: %7Bf13b157f-b174-47e7-a34d-4815ddfdfeb8%7D:0.9.89.1-signed.1-signed removed from extensions.enabledAddons
Prefs.js: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:47.0.2 removed from extensions.enabledAddons
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully.
C:\Users\Lenovo\AppData\Roaming\mozilla\Extensions folder moved successfully.
C:\Users\Lenovo\AppData\Roaming\mozilla\Firefox\Profiles\1xy2o2g4.default-1446832914166\extensions folder moved successfully.
File C:\Users\Lenovo\AppData\Roaming\mozilla\firefox\profiles\1xy2o2g4.default-1446832914166\extensions\firefox-hotfix@mozilla.org.xpi not found.
File C:\Users\Lenovo\AppData\Roaming\mozilla\firefox\profiles\1xy2o2g4.default-1446832914166\extensions\tinyjsdebugger@enigmail.net.xpi not found.
File C:\Users\Lenovo\AppData\Roaming\mozilla\firefox\profiles\1xy2o2g4.default-1446832914166\extensions\{E6C1199F-E687-42da-8C24-E7770CC3AE66}.xpi not found.
File C:\Users\Lenovo\AppData\Roaming\mozilla\firefox\profiles\1xy2o2g4.default-1446832914166\extensions\{f13b157f-b174-47e7-a34d-4815ddfdfeb8}.xpi not found.
C:\Users\Lenovo\AppData\Roaming\mozilla\firefox\profiles\1xy2o2g4.default-1446832914166\features\{d56f0c80-859f-4034-b31c-adf9c5bad21b}\e10srollout@mozilla.org.xpi moved successfully.
C:\Users\Lenovo\AppData\Roaming\mozilla\firefox\profiles\1xy2o2g4.default-1446832914166\features\{d56f0c80-859f-4034-b31c-adf9c5bad21b}\firefox@getpocket.com.xpi moved successfully.
C:\Users\Lenovo\AppData\Roaming\mozilla\firefox\profiles\1xy2o2g4.default-1446832914166\features\{d56f0c80-859f-4034-b31c-adf9c5bad21b}\loop@mozilla.org.xpi moved successfully.
C:\Users\Lenovo\AppData\Roaming\mozilla\firefox\profiles\1xy2o2g4.default-1446832914166\features\{d56f0c80-859f-4034-b31c-adf9c5bad21b}\websensehelper@mozilla.org.xpi moved successfully.
C:\Program Files (x86)\Mozilla Firefox\browser\extensions folder moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
C:\WINDOWS\assembly\Desktop.ini moved successfully.
File EY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 not found.
File EY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] not found.
File EY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 not found.
File EY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] not found.
File EY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 not found.
File EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] not found.
Folder EY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64\ not found.
Folder EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]\ not found.
Folder EY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64\ not found.
Folder EY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]\ not found.
========== FILES ==========
File\Folder C:\WINDOWS\System32\*.tmp not found.
C:\WINDOWS\LastGood.Tmp\SysWOW64 folder moved successfully.
C:\WINDOWS\LastGood.Tmp\system32\DRIVERS folder moved successfully.
C:\WINDOWS\LastGood.Tmp\system32 folder moved successfully.
C:\WINDOWS\LastGood.Tmp folder moved successfully.
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\System32\dllcache\*.tmp not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
File\Folder C:\WINDOWS\system32\DUMP*.tmp not found.
c:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-104870834-3866067964-3722874268-1000Core1d236e7f7f2f40.job moved successfully.
c:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-104870834-3866067964-3722874268-1000UA1d236e7101a6a00.job moved successfully.
File\Folder C:\*.tmp not found.
File\Folder C:\WINDOWS\System32\drivers\*.tmp not found.
File\Folder C:\Program Files\*.tmp not found.
File\Folder C:\Documents and Settings\All Users\Data aplikací\*.tmp not found.
File\Folder C:\Windows\SysNative\drivers\*.tmp not found.
File\Folder C:\Windows\SysWow64\drivers\*.tmp not found.
File\Folder C:\Program Files (x86)\*.tmp not found.
File\Folder C:\Windows\SysWow64\*.tmp not found.
File\Folder C:\Windows\SysNative\*.tmp not found.
File\Folder C:\Program Files (x86)\*.tmp not found.
C:\ProgramData\DP45977C.lfl moved successfully.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Lenovo\Desktop\cmd.bat deleted successfully.
C:\Users\Lenovo\Desktop\cmd.txt deleted successfully.
========== REGISTRY ==========
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes

User: Default.migrated

User: Lenovo
->Temp folder emptied: 23886 bytes
->Temporary Internet Files folder emptied: 128 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 144119216 bytes
->Flash cache emptied: 0 bytes

User: Public

User: čo ja viem

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3673550 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 105300 bytes

Total Files Cleaned = 141,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 03072017_194752

Files\Folders moved on Reboot...
C:\Users\Lenovo\AppData\Local\Microsoft\Windows\INetCache\counters.dat moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod jaro3 » 07 bře 2017 22:20

Co problémy , internet?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

GoodByeMomo
Level 1
Level 1
Příspěvky: 50
Registrován: únor 17
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod GoodByeMomo » 10 bře 2017 17:19

Odhlásenie a opätovné prihlásenie do Windows robí problémy stále, takisto aj štart z vypnutého stavu. Pripojenie na internet cez wifi je v poriadku. Systém samozrejme beží rýchlejšie ako pred vyčistením.
Ďakujem za pomoc.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod jaro3 » 10 bře 2017 18:14

Stáhni si MiniToolBox
a spusť ho.
V okně zaškrtni čtverečky:
Report IE Proxy Settings
Report FF Proxy Settings
List content of Hosts
List IP configuration
List Winsock Entries
List last 10 Event Viewer log
List Installed Programs
List Users, Partitions and Memory size

Potom klikni na GO , po chvíli skenu se objeví log s názvem „Result“ , zkopíruj sem celý jeho obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

GoodByeMomo
Level 1
Level 1
Příspěvky: 50
Registrován: únor 17
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod GoodByeMomo » 10 bře 2017 18:37

MiniToolBox by Farbar Version: 17-06-2016
Ran by Lenovo (administrator) on 10-03-2017 at 18:36:35
Running from "C:\Users\Lenovo\Desktop"
Microsoft Windows 10 Pro (X64)
Model: 20150 Manufacturer: LENOVO
Boot Mode: Normal
***************************************************************************

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

========================= FF Proxy Settings: ==============================

========================= Hosts content: =================================
127.0.0.1 localhost
========================= IP Configuration: ================================

Qualcomm Atheros AR9485WB-EG Wireless Network Adapter = Wi-Fi (Connected)
Qualcomm Atheros AR8162/8166/8168 PCI-E Fast Ethernet Controller (NDIS 6.30) = Ethernet (Media disconnected)


# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset


popd
# End of IPv4 configuration



Windows IP Configuration

Host Name . . . . . . . . . . . . : Lenovo-PC
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Ethernet:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Qualcomm Atheros AR8162/8166/8168 PCI-E Fast Ethernet Controller (NDIS 6.30)
Physical Address. . . . . . . . . : 20-89-84-9C-22-2B
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes

Wireless LAN adapter Lok lne pripojenie* 14:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft Hosted Network Virtual Adapter #2
Physical Address. . . . . . . . . : 56-FD-52-25-68-86
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes

Wireless LAN adapter Lok lne pripojenie* 15:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft Wi-Fi Direct Virtual Adapter #2
Physical Address. . . . . . . . . : 16-FD-52-25-68-86
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes

Wireless LAN adapter Wi-Fi:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Qualcomm Atheros AR9485WB-EG Wireless Network Adapter
Physical Address. . . . . . . . . : 24-FD-52-25-68-86
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::145c:53b7:bc88:18b6%3(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.1.13(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : piatok, 10. marca 2017 17:10:30
Lease Expires . . . . . . . . . . : sobota, 11. marca 2017 17:10:25
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DHCPv6 IAID . . . . . . . . . . . : 52755794
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-19-D3-59-5B-20-89-84-9C-22-2B
DNS Servers . . . . . . . . . . . : 192.168.1.1
NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter isatap.{0C32F422-8665-4B76-9DDF-37F6F188800B}:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft ISATAP Adapter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Lok lne pripojenie* 12:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft Teredo Tunneling Adapter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv6 Address. . . . . . . . . . . : 2001:0:5ef5:79fd:c7e:9ba:3f57:fef2(Preferred)
Link-local IPv6 Address . . . . . : fe80::c7e:9ba:3f57:fef2%10(Preferred)
Default Gateway . . . . . . . . . : ::
DHCPv6 IAID . . . . . . . . . . . : 117440512
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-19-D3-59-5B-20-89-84-9C-22-2B
NetBIOS over Tcpip. . . . . . . . : Disabled
Server: csp1.zte.com.cn
Address: 192.168.1.1

Name: google.com
Addresses: 2a00:1450:4014:80c::200e
172.217.23.206


Pinging google.com [172.217.23.206] with 32 bytes of data:
Reply from 172.217.23.206: bytes=32 time=34ms TTL=57
Reply from 172.217.23.206: bytes=32 time=32ms TTL=57

Ping statistics for 172.217.23.206:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 32ms, Maximum = 34ms, Average = 33ms
Server: csp3.zte.com.cn
Address: 192.168.1.1

Name: yahoo.com
Addresses: 2001:4998:c:a06::2:4008
2001:4998:58:c02::a9
2001:4998:44:204::a7
98.139.183.24
206.190.36.45
98.138.253.109


Pinging yahoo.com [98.139.183.24] with 32 bytes of data:
Reply from 98.139.183.24: bytes=32 time=154ms TTL=47
Reply from 98.139.183.24: bytes=32 time=252ms TTL=47

Ping statistics for 98.139.183.24:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 154ms, Maximum = 252ms, Average = 203ms

Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
17...20 89 84 9c 22 2b ......Qualcomm Atheros AR8162/8166/8168 PCI-E Fast Ethernet Controller (NDIS 6.30)
7...56 fd 52 25 68 86 ......Microsoft Hosted Network Virtual Adapter #2
16...16 fd 52 25 68 86 ......Microsoft Wi-Fi Direct Virtual Adapter #2
3...24 fd 52 25 68 86 ......Qualcomm Atheros AR9485WB-EG Wireless Network Adapter
1...........................Software Loopback Interface 1
24...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
10...00 00 00 00 00 00 00 e0 Microsoft Teredo Tunneling Adapter
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.13 55
127.0.0.0 255.0.0.0 On-link 127.0.0.1 331
127.0.0.1 255.255.255.255 On-link 127.0.0.1 331
127.255.255.255 255.255.255.255 On-link 127.0.0.1 331
192.168.1.0 255.255.255.0 On-link 192.168.1.13 311
192.168.1.13 255.255.255.255 On-link 192.168.1.13 311
192.168.1.255 255.255.255.255 On-link 192.168.1.13 311
224.0.0.0 240.0.0.0 On-link 127.0.0.1 331
224.0.0.0 240.0.0.0 On-link 192.168.1.13 311
255.255.255.255 255.255.255.255 On-link 127.0.0.1 331
255.255.255.255 255.255.255.255 On-link 192.168.1.13 311
===========================================================================
Persistent Routes:
None

IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
10 331 ::/0 On-link
1 331 ::1/128 On-link
10 331 2001::/32 On-link
10 331 2001:0:5ef5:79fd:c7e:9ba:3f57:fef2/128
On-link
3 311 fe80::/64 On-link
10 331 fe80::/64 On-link
10 331 fe80::c7e:9ba:3f57:fef2/128
On-link
3 311 fe80::145c:53b7:bc88:18b6/128
On-link
1 331 ff00::/8 On-link
3 311 ff00::/8 On-link
10 331 ff00::/8 On-link
===========================================================================
Persistent Routes:
If Metric Network Destination Gateway
0 9000 ::/0 2620:9b::1900:1
0 4294967295 2620:9b::/96 On-link
===========================================================================
========================= Winsock entries =====================================

Catalog5 01 C:\WINDOWS\SysWoW64\NLAapi.dll [65024] (Microsoft Corporation)
Catalog5 02 C:\WINDOWS\SysWoW64\mswsock.dll [306016] (Microsoft Corporation)
Catalog5 03 C:\WINDOWS\SysWoW64\winrnr.dll [24064] (Microsoft Corporation)
Catalog5 04 C:\WINDOWS\SysWoW64\napinsp.dll [55808] (Microsoft Corporation)
Catalog5 05 C:\WINDOWS\SysWoW64\pnrpnsp.dll [70656] (Microsoft Corporation)
Catalog5 06 C:\WINDOWS\SysWoW64\pnrpnsp.dll [70656] (Microsoft Corporation)
Catalog5 07 C:\WINDOWS\SysWoW64\wshbth.dll [51712] (Microsoft Corporation)
Catalog9 01 C:\WINDOWS\SysWoW64\mswsock.dll [306016] (Microsoft Corporation)
Catalog9 02 C:\WINDOWS\SysWoW64\mswsock.dll [306016] (Microsoft Corporation)
Catalog9 03 C:\WINDOWS\SysWoW64\mswsock.dll [306016] (Microsoft Corporation)
Catalog9 04 C:\WINDOWS\SysWoW64\mswsock.dll [306016] (Microsoft Corporation)
Catalog9 05 C:\WINDOWS\SysWoW64\mswsock.dll [306016] (Microsoft Corporation)
Catalog9 06 C:\WINDOWS\SysWoW64\mswsock.dll [306016] (Microsoft Corporation)
Catalog9 07 C:\WINDOWS\SysWoW64\mswsock.dll [306016] (Microsoft Corporation)
Catalog9 08 C:\WINDOWS\SysWoW64\mswsock.dll [306016] (Microsoft Corporation)
Catalog9 09 C:\WINDOWS\SysWoW64\mswsock.dll [306016] (Microsoft Corporation)
Catalog9 10 C:\WINDOWS\SysWoW64\mswsock.dll [306016] (Microsoft Corporation)
Catalog9 11 C:\WINDOWS\SysWoW64\mswsock.dll [306016] (Microsoft Corporation)
Catalog9 12 C:\WINDOWS\SysWoW64\mswsock.dll [306016] (Microsoft Corporation)
Catalog9 13 C:\WINDOWS\SysWoW64\mswsock.dll [306016] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [80896] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\winrnr.dll [31744] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\napinsp.dll [67584] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 07 C:\Windows\System32\wshbth.dll [62976] (Microsoft Corporation)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 11 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 12 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 13 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (03/10/2017 06:34:03 PM) (Source: Application Error) (User: )
Description: Názov chybujúcej aplikácie: svchost.exe, verzia: 10.0.14393.0, časová značka: 0x57899b1c
Názov chybujúceho modulu: LicenseManager.dll, verzia: 10.0.14393.576, časová značka: 0x584a7b1f
Kód výnimky: 0xc0000005
Odstup chyby: 0x0000000000023b8b
Identifikácia chybujúceho procesu: 0x22ec
Čas spustenia chybujúcej aplikácie: 0xsvchost.exe0
Cesta chybujúcej aplikácie: svchost.exe1
Cesta chybujúceho modulu: svchost.exe2
Identifikácia hlásenia: svchost.exe3
Celé meno chybujúceho balíka: svchost.exe4
Identifikácia chybujúcej aplikácie vzhľadom na balík: svchost.exe5

Error: (03/10/2017 06:34:02 PM) (Source: Application Error) (User: )
Description: Názov chybujúcej aplikácie: svchost.exe, verzia: 10.0.14393.0, časová značka: 0x57899b1c
Názov chybujúceho modulu: LicenseManager.dll, verzia: 10.0.14393.576, časová značka: 0x584a7b1f
Kód výnimky: 0xc0000005
Odstup chyby: 0x0000000000023b8b
Identifikácia chybujúceho procesu: 0x2270
Čas spustenia chybujúcej aplikácie: 0xsvchost.exe0
Cesta chybujúcej aplikácie: svchost.exe1
Cesta chybujúceho modulu: svchost.exe2
Identifikácia hlásenia: svchost.exe3
Celé meno chybujúceho balíka: svchost.exe4
Identifikácia chybujúcej aplikácie vzhľadom na balík: svchost.exe5

Error: (03/10/2017 06:25:21 PM) (Source: Application Error) (User: )
Description: Názov chybujúcej aplikácie: svchost.exe, verzia: 10.0.14393.0, časová značka: 0x57899b1c
Názov chybujúceho modulu: LicenseManager.dll, verzia: 10.0.14393.576, časová značka: 0x584a7b1f
Kód výnimky: 0xc0000005
Odstup chyby: 0x0000000000023b8b
Identifikácia chybujúceho procesu: 0xdb8
Čas spustenia chybujúcej aplikácie: 0xsvchost.exe0
Cesta chybujúcej aplikácie: svchost.exe1
Cesta chybujúceho modulu: svchost.exe2
Identifikácia hlásenia: svchost.exe3
Celé meno chybujúceho balíka: svchost.exe4
Identifikácia chybujúcej aplikácie vzhľadom na balík: svchost.exe5

Error: (03/10/2017 06:10:20 PM) (Source: Application Error) (User: )
Description: Názov chybujúcej aplikácie: svchost.exe, verzia: 10.0.14393.0, časová značka: 0x57899b1c
Názov chybujúceho modulu: LicenseManager.dll, verzia: 10.0.14393.576, časová značka: 0x584a7b1f
Kód výnimky: 0xc0000005
Odstup chyby: 0x0000000000023b8b
Identifikácia chybujúceho procesu: 0xdd0
Čas spustenia chybujúcej aplikácie: 0xsvchost.exe0
Cesta chybujúcej aplikácie: svchost.exe1
Cesta chybujúceho modulu: svchost.exe2
Identifikácia hlásenia: svchost.exe3
Celé meno chybujúceho balíka: svchost.exe4
Identifikácia chybujúcej aplikácie vzhľadom na balík: svchost.exe5

Error: (03/10/2017 06:02:25 PM) (Source: Application Error) (User: )
Description: Názov chybujúcej aplikácie: svchost.exe, verzia: 10.0.14393.0, časová značka: 0x57899b1c
Názov chybujúceho modulu: LicenseManager.dll, verzia: 10.0.14393.576, časová značka: 0x584a7b1f
Kód výnimky: 0xc0000005
Odstup chyby: 0x0000000000023b8b
Identifikácia chybujúceho procesu: 0x1fbc
Čas spustenia chybujúcej aplikácie: 0xsvchost.exe0
Cesta chybujúcej aplikácie: svchost.exe1
Cesta chybujúceho modulu: svchost.exe2
Identifikácia hlásenia: svchost.exe3
Celé meno chybujúceho balíka: svchost.exe4
Identifikácia chybujúcej aplikácie vzhľadom na balík: svchost.exe5

Error: (03/10/2017 06:01:55 PM) (Source: Application Error) (User: )
Description: Názov chybujúcej aplikácie: svchost.exe, verzia: 10.0.14393.0, časová značka: 0x57899b1c
Názov chybujúceho modulu: LicenseManager.dll, verzia: 10.0.14393.576, časová značka: 0x584a7b1f
Kód výnimky: 0xc0000005
Odstup chyby: 0x0000000000023b8b
Identifikácia chybujúceho procesu: 0x1998
Čas spustenia chybujúcej aplikácie: 0xsvchost.exe0
Cesta chybujúcej aplikácie: svchost.exe1
Cesta chybujúceho modulu: svchost.exe2
Identifikácia hlásenia: svchost.exe3
Celé meno chybujúceho balíka: svchost.exe4
Identifikácia chybujúcej aplikácie vzhľadom na balík: svchost.exe5

Error: (03/10/2017 05:55:23 PM) (Source: Application Error) (User: )
Description: Názov chybujúcej aplikácie: svchost.exe, verzia: 10.0.14393.0, časová značka: 0x57899b1c
Názov chybujúceho modulu: LicenseManager.dll, verzia: 10.0.14393.576, časová značka: 0x584a7b1f
Kód výnimky: 0xc0000005
Odstup chyby: 0x0000000000023b8b
Identifikácia chybujúceho procesu: 0x2214
Čas spustenia chybujúcej aplikácie: 0xsvchost.exe0
Cesta chybujúcej aplikácie: svchost.exe1
Cesta chybujúceho modulu: svchost.exe2
Identifikácia hlásenia: svchost.exe3
Celé meno chybujúceho balíka: svchost.exe4
Identifikácia chybujúcej aplikácie vzhľadom na balík: svchost.exe5

Error: (03/10/2017 05:55:20 PM) (Source: Application Error) (User: )
Description: Názov chybujúcej aplikácie: svchost.exe, verzia: 10.0.14393.0, časová značka: 0x57899b1c
Názov chybujúceho modulu: LicenseManager.dll, verzia: 10.0.14393.576, časová značka: 0x584a7b1f
Kód výnimky: 0xc0000005
Odstup chyby: 0x0000000000023b8b
Identifikácia chybujúceho procesu: 0x1f88
Čas spustenia chybujúcej aplikácie: 0xsvchost.exe0
Cesta chybujúcej aplikácie: svchost.exe1
Cesta chybujúceho modulu: svchost.exe2
Identifikácia hlásenia: svchost.exe3
Celé meno chybujúceho balíka: svchost.exe4
Identifikácia chybujúcej aplikácie vzhľadom na balík: svchost.exe5

Error: (03/10/2017 05:46:36 PM) (Source: Application Error) (User: )
Description: Názov chybujúcej aplikácie: svchost.exe, verzia: 10.0.14393.0, časová značka: 0x57899b1c
Názov chybujúceho modulu: LicenseManager.dll, verzia: 10.0.14393.576, časová značka: 0x584a7b1f
Kód výnimky: 0xc0000005
Odstup chyby: 0x0000000000023b8b
Identifikácia chybujúceho procesu: 0x1758
Čas spustenia chybujúcej aplikácie: 0xsvchost.exe0
Cesta chybujúcej aplikácie: svchost.exe1
Cesta chybujúceho modulu: svchost.exe2
Identifikácia hlásenia: svchost.exe3
Celé meno chybujúceho balíka: svchost.exe4
Identifikácia chybujúcej aplikácie vzhľadom na balík: svchost.exe5

Error: (03/10/2017 05:40:23 PM) (Source: Application Error) (User: )
Description: Názov chybujúcej aplikácie: svchost.exe, verzia: 10.0.14393.0, časová značka: 0x57899b1c
Názov chybujúceho modulu: LicenseManager.dll, verzia: 10.0.14393.576, časová značka: 0x584a7b1f
Kód výnimky: 0xc0000005
Odstup chyby: 0x0000000000023b8b
Identifikácia chybujúceho procesu: 0x1d18
Čas spustenia chybujúcej aplikácie: 0xsvchost.exe0
Cesta chybujúcej aplikácie: svchost.exe1
Cesta chybujúceho modulu: svchost.exe2
Identifikácia hlásenia: svchost.exe3
Celé meno chybujúceho balíka: svchost.exe4
Identifikácia chybujúcej aplikácie vzhľadom na balík: svchost.exe5


System errors:
=============
Error: (03/10/2017 06:36:03 PM) (Source: DCOM) (User: Lenovo-PC)
Description: {21F282D1-A881-49E1-9A3A-26E44E39B86C}

Error: (03/10/2017 06:34:04 PM) (Source: Service Control Manager) (User: )
Description: Volanie LoadUserProfile zlyhalo s nasledujúcou chybou:
%%1009 = The configuration registry database is corrupt.


Error: (03/10/2017 06:34:04 PM) (Source: Service Control Manager) (User: )
Description: Služba Windows License Manager Service bola ukončená s nasledujúcou chybou služby:
%%2147942405 = Access is denied.


Error: (03/10/2017 06:34:04 PM) (Source: Service Control Manager) (User: )
Description: Volanie LoadUserProfile zlyhalo s nasledujúcou chybou:
%%1009 = The configuration registry database is corrupt.


Error: (03/10/2017 06:34:03 PM) (Source: Service Control Manager) (User: )
Description: Služba WinHTTP Web Proxy Auto-Discovery Service sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 27-krát.

Error: (03/10/2017 06:34:03 PM) (Source: Service Control Manager) (User: )
Description: Služba Diagnostic Service Host sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 26-krát.

Error: (03/10/2017 06:34:03 PM) (Source: Service Control Manager) (User: )
Description: Služba Network Store Interface Service sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 28-krát.

Error: (03/10/2017 06:34:03 PM) (Source: Service Control Manager) (User: )
Description: Služba Služba zoznamu sietí sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 28-krát.

Error: (03/10/2017 06:34:03 PM) (Source: Service Control Manager) (User: )
Description: Služba Connected Devices Platform Service bola ukončená s nasledujúcou chybou:
%%2147500037 = Unspecified error


Error: (03/10/2017 06:34:03 PM) (Source: Service Control Manager) (User: )
Description: Služba Windows License Manager Service bola ukončená s nasledujúcou chybou služby:
%%2147942405 = Access is denied.



Microsoft Office Sessions:
=========================
Error: (03/10/2017 06:34:03 PM) (Source: Application Error)(User: )
Description: svchost.exe10.0.14393.057899b1cLicenseManager.dll10.0.14393.576584a7b1fc00000050000000000023b8b22ec01d299c482378bd2C:\WINDOWS\system32\svchost.exec:\windows\system32\LicenseManager.dll68108f63-479d-414e-a231-a8f5ce21d262

Error: (03/10/2017 06:34:02 PM) (Source: Application Error)(User: )
Description: svchost.exe10.0.14393.057899b1cLicenseManager.dll10.0.14393.576584a7b1fc00000050000000000023b8b227001d299c34b9b2a1eC:\WINDOWS\system32\svchost.exec:\windows\system32\LicenseManager.dlled9690f2-6ad1-47f0-bae0-42e602933f70

Error: (03/10/2017 06:25:21 PM) (Source: Application Error)(User: )
Description: svchost.exe10.0.14393.057899b1cLicenseManager.dll10.0.14393.576584a7b1fc00000050000000000023b8bdb801d299c1334fea01C:\WINDOWS\system32\svchost.exec:\windows\system32\LicenseManager.dllacc91e4a-2ed0-43c0-adf3-5ce991e7f2a4

Error: (03/10/2017 06:10:20 PM) (Source: Application Error)(User: )
Description: svchost.exe10.0.14393.057899b1cLicenseManager.dll10.0.14393.576584a7b1fc00000050000000000023b8bdd001d299c017d0e0c5C:\WINDOWS\system32\svchost.exec:\windows\system32\LicenseManager.dllc75a169e-6455-4f20-b0d5-bedb2e881230

Error: (03/10/2017 06:02:25 PM) (Source: Application Error)(User: )
Description: svchost.exe10.0.14393.057899b1cLicenseManager.dll10.0.14393.576584a7b1fc00000050000000000023b8b1fbc01d299c0060c4910C:\WINDOWS\system32\svchost.exec:\windows\system32\LicenseManager.dll75218c58-0d6f-48fc-a3aa-7d8ba6e736cb

Error: (03/10/2017 06:01:55 PM) (Source: Application Error)(User: )
Description: svchost.exe10.0.14393.057899b1cLicenseManager.dll10.0.14393.576584a7b1fc00000050000000000023b8b199801d299bf1c798247C:\WINDOWS\System32\svchost.exec:\windows\system32\LicenseManager.dll7571b83c-9f69-4be0-b4fc-8a4ee6799c3a

Error: (03/10/2017 05:55:23 PM) (Source: Application Error)(User: )
Description: svchost.exe10.0.14393.057899b1cLicenseManager.dll10.0.14393.576584a7b1fc00000050000000000023b8b221401d299bf1a969a16C:\WINDOWS\system32\svchost.exec:\windows\system32\LicenseManager.dlld0620179-40a3-43e3-a901-15bf7b1e4630

Error: (03/10/2017 05:55:20 PM) (Source: Application Error)(User: )
Description: svchost.exe10.0.14393.057899b1cLicenseManager.dll10.0.14393.576584a7b1fc00000050000000000023b8b1f8801d299bde1f03ea9C:\WINDOWS\system32\svchost.exec:\windows\system32\LicenseManager.dllb6de7b2d-f28a-43ba-9531-e906191d58c1

Error: (03/10/2017 05:46:36 PM) (Source: Application Error)(User: )
Description: svchost.exe10.0.14393.057899b1cLicenseManager.dll10.0.14393.576584a7b1fc00000050000000000023b8b175801d299bd0408f24cC:\WINDOWS\System32\svchost.exec:\windows\system32\LicenseManager.dll9f522093-dbd5-4c3e-91bd-4bb04bd9bae0

Error: (03/10/2017 05:40:23 PM) (Source: Application Error)(User: )
Description: svchost.exe10.0.14393.057899b1cLicenseManager.dll10.0.14393.576584a7b1fc00000050000000000023b8b1d1801d299bd02205c8eC:\WINDOWS\system32\svchost.exec:\windows\system32\LicenseManager.dllbeeab2af-5694-43f8-ae90-0b81bf5c198b


CodeIntegrity Errors:
===================================
Date: 2017-03-04 21:04:51.297
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\eelam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2017-02-26 13:48:41.680
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

Date: 2017-02-26 13:48:41.629
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

Date: 2017-02-26 13:48:41.599
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

Date: 2017-02-26 13:48:41.526
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

Date: 2017-02-26 13:48:41.506
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

Date: 2017-02-26 13:48:41.487
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

Date: 2017-02-26 13:48:40.341
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

Date: 2017-02-26 13:48:40.024
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

Date: 2017-02-26 13:43:32.250
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.


=========================== Installed Programs ============================

Adobe Flash Player 23 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 23.0.0.162 - Adobe Systems Incorporated)
Adobe Photoshop CC 2015 (HKLM-x32\...\{793C2BF7-A4FE-4608-91C9-9282C5801C21}) (Version: 16.0 - Adobe Systems Incorporated)
Adobe Reader XI - Slovak (HKLM-x32\...\{AC76BA86-7AD7-1051-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.1.171 - Adobe Systems, Inc.)
Aktualizácie NVIDIA 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation)
Angry Birds Breakfast 1 (HKLM-x32\...\{85B535D9-F249-49CB-9D75-011F420A40D7}) (Version: 1.0.16 - Rovio Entertainment Ltd.)
Atheros Bluetooth Suite (64) (HKLM\...\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.4.0.135 - Atheros)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.0.14.15 - Atheros Communications Inc.)
Autodesk MapGuide(R) Viewer ActiveX Control Release 6.5 (HKLM-x32\...\{E031338C-839D-4EDD-9537-99B653C39D81}) (Version: 6.5.5.24 - Autodesk, Inc.)
Brawlhalla (HKLM-x32\...\Steam App 291550) (Version: - Blue Mammoth Games)
Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: - )
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: - )
Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version: - )
Canon MP280 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP280_series) (Version: - )
Canon MP280 series User Registration (HKLM-x32\...\Canon MP280 series User Registration) (Version: - )
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: - )
Canon Solution Menu EX (HKLM-x32\...\CanonSolutionMenuEX) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 5.27 - Piriform)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.66.16.50 - Conexant)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve)
CPUID HWMonitor 1.30 (HKLM\...\CPUID HWMonitor_is1) (Version: - )
CrystalDiskInfo 7.0.5 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 7.0.5 - Crystal Dew World)
Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.6.5.1 - Dolby Laboratories Inc)
Driver Booster 4.2 (HKLM-x32\...\Driver Booster_is1) (Version: 4.2.0 - IObit)
Dropbox (HKCU\...\Dropbox) (Version: 19.4.13 - Dropbox, Inc.)
Energy Management (HKLM-x32\...\{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 7.0.3.3 - Lenovo) Hidden
Energy Management (HKLM-x32\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 7.0.3.3 - Lenovo)
ESET NOD32 Antivirus (HKLM\...\{2C4A3E47-2A55-4AE1-969C-67B3F9F836EF}) (Version: 10.0.390.0 - ESET, spol. s r.o.)
Euro Truck Simulator 2 (HKLM-x32\...\{1B705E8F-9893-4486-B5D7-4F7FEB9C871E}_is1) (Version: 1.2.5 - SCS Software)
Goat Simulator (HKLM-x32\...\Steam App 265930) (Version: - Coffee Stain Studios)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Spoločnosť Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.32.7 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
HD Tune 2.55 (HKLM-x32\...\HD Tune_is1) (Version: - EFD Software)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.3.1427 - Intel Corporation)
Intel(R) OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4358 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.5.235 - Intel Corporation)
Intel® PROSet/Wireless WiFi Software (HKLM\...\{DF7756DD-656A-45C3-BA71-74673E8259A9}) (Version: 15.00.0000.0642 - Intel Corporation)
Intel® Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation)
Java 8 Update 121 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation)
Lenovo EasyCamera (HKLM-x32\...\{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0333}) (Version: 1.12.204.1 - Lenovo EasyCamera)
Lenovo Service Bridge (HKCU\...\dda9ca0b023f4c56) (Version: 1.6.6.0 - Lenovo)
Lenovo System Interface Foundation (HKLM\...\{C2E5CA37-C862-4A69-AC6D-24F450A20C16}) (Version: 1.0.070.04 - Lenovo)
Lenovo System Update (HKLM-x32\...\{25C64847-B900-48AD-A164-1B4F9B774650}) (Version: 5.07.0045 - Lenovo)
Mafia II (HKLM-x32\...\Steam App 50130) (Version: - 2K Czech)
Medal of Honor™ Warfighter (HKLM-x32\...\{13AD2A08-C3B8-49F2-B374-7C1D790626BC}) (Version: 1.0.0.0 - Electronic Arts)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Minecraft1.7.2 (HKLM-x32\...\Minecraft1.7.2) (Version: - )
Moj CEWE FOTOSVET (HKLM-x32\...\Moj CEWE FOTOSVET) (Version: 6.0.5 - CEWE Stiftung u Co. KGaA)
MouseServer version 1.5.2.0 (HKLM-x32\...\{E13018F5-FFC7-4729-9C1B-1A85807D03E6}_is1) (Version: 1.5.2.0 - Necta Co.)
Mozilla Firefox 47.0.2 (x86 sk) (HKLM-x32\...\Mozilla Firefox 47.0.2 (x86 sk)) (Version: 47.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 47.0.2.6148 - Mozilla)
NVIDIA Grafický ovládač 376.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.54 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.0.13.2135 - Electronic Arts, Inc.)
osu! (HKLM-x32\...\{845c2eda-ec26-4ef5-988a-787b716d99f1}) (Version: latest - ppy Pty Ltd)
Ovládací panel NVIDIA 376.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 376.54 - NVIDIA Corporation) Hidden
Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.)
PC Translator 2004 Komplet (HKLM-x32\...\PC Translator 2004 Komplet) (Version: - JANOSiK TEAM)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
QuickTime (HKLM-x32\...\QuickTime) (Version: - )
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.14393.31228 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Reader Driver (HKLM-x32\...\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7601.39016 - Realtek Semiconductor Corp.)
Remote Mouse version 3.002 (HKLM-x32\...\{01E4BC6D-3ACC-45E1-8928-C2FF626F63F3}_is1) (Version: 3.002 - Remote Mouse)
Saints Row: The Third (HKLM-x32\...\Steam App 55230) (Version: - Volition)
Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation)
Skype™ 7.24 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.24.104 - Skype Technologies S.A.)
Sophos Virus Removal Tool (HKLM-x32\...\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.5.6 - Sophos Limited)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version: - Valve)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH)
TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.72365 - TeamViewer)
The Escapists (HKLM-x32\...\Steam App 298630) (Version: - Mouldy Toof Studios)
Tomb Raider (HKLM-x32\...\Steam App 203160) (Version: - Crystal Dynamics)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 9.0a - Ghisler Software GmbH)
Unturned (HKLM-x32\...\Steam App 304930) (Version: - Nelson Sexton)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.)
Windows Driver Package - Lenovo (ACPIVPC) System (12/15/2011 7.1.0.1) (HKLM\...\99841829BE839365AA67B2AD0E50D371F59F8A1E) (Version: 12/15/2011 7.1.0.1 - Lenovo)
WinRAR 5.00 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH)

========================= Memory info: ===================================

Percentage of memory in use: 35%
Total physical RAM: 3998.35 MB
Available physical RAM: 2587.23 MB
Total Virtual: 5726.35 MB
Available Virtual: 4040.79 MB

========================= Partitions: =====================================

1 Drive c: () (Fixed) (Total:237.81 GB) (Free:102.31 GB) NTFS
2 Drive d: (Nový zväzok) (Fixed) (Total:226.77 GB) (Free:178.61 GB) NTFS

========================= Users: ========================================

User accounts for \\LENOVO-PC

Administrator DefaultAccount Guest
Lenovo


**** End of log ****

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod jaro3 » 10 bře 2017 18:56

Odezva je dlouhá.

Spusť znovu MiniToolBox.
Zaškrtni čtverečky:
Flush DNS
Reset IE Proxy Settings
Reset FF Proxy Settings
List Device * Only problem * No Driver *All
List Minidump Files
Potom klikni na GO , po chvíli skenu se objeví log s názvem „Result“ , zkopíruj sem celý jeho obsah.


Stáhni si Emsisoft Emergency Kit
http://dl.emsisoft.com/EmsisoftEmergencyKit.exe
na svojí plochu. Poklepej na soubor EmsisoftEmergencyKit.exe . Ponech všechna nastavení tak, jak jsou a klikni na tlačítko „Extract“ v dolní části. Složka s názvem EEK bude vytvořena v kořenovém adresáři jednotky (obvykle c: \).

1) Po extrakci poklikej na novou ikonu Emsisoft Emergency Kit na Tvé ploše.
2) Při prvním spuštění Emsisoft Emergency Kit doporučujeme povolit stahování aktualizací. Prosím, klepni na tlačítko „Yes“ (Ano), potom se stáhne nejnovější aktualizace databáze.
3) Po dokončení procesu aktualizace se zobrazí nové tlačítko v levém dolním rohu, s názvem „ Back“. Klikni na toto tlačítko pro návrat na předešlou obrazovku .
4) Klikni na „Scan“ , ukáží se volby skenování. Pokud budeš dotázán, zda chceš, aby se vyhledávaly potenciálně nežádoucí programy, klepni na tlačítko „Yes“(Ano).
5) Klikni na tlačítko „Full Scan“ pro zahájení skenování.
6) Když je skenování dokončeno klikni na tlačítko „Quarantine“ (karanténa vybraných objektů). Poznámka: Tato možnost je k dispozici pouze v případě, že během kontroly byly zjištěny škodlivé objekty.
7) Když budou v karanténě hrozby, klepni na tlačítko „View report“ (Zobrazit zprávy) v pravém dolním rohu, a protokol skenu se otevře v poznámkovém bloku.
8) Prosím ulož si protokol v poznámkovém bloku na plochu, a vlož sem celý jeho obsah.
9) Když zavřeš Emsisoft Emergency Kit, bude Ti nabídnuta možnost přihlásit se k odběru novinek. Toto je volitelné a není to nezbytné odstraňování malware.

Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků



zkoušel si reset routeru?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

GoodByeMomo
Level 1
Level 1
Příspěvky: 50
Registrován: únor 17
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod GoodByeMomo » 10 bře 2017 21:13

Myslíte tým údaj 154ms?
Pinging yahoo.com [98.139.183.24] with 32 bytes of data:
Reply from 98.139.183.24: bytes=32 time=154ms TTL=47
Reply from 98.139.183.24: bytes=32 time=252ms TTL=47

Môžem to skúsiť z PC, ktorý je pripojený cez kábel.

GoodByeMomo
Level 1
Level 1
Příspěvky: 50
Registrován: únor 17
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod GoodByeMomo » 10 bře 2017 21:14

MiniToolBox by Farbar Version: 17-06-2016
Ran by Lenovo (administrator) on 10-03-2017 at 21:07:14
Running from "C:\Users\Lenovo\Desktop"
Microsoft Windows 10 Pro (X64)
Model: 20150 Manufacturer: LENOVO
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

"Reset IE Proxy Settings": IE Proxy Settings were reset.

"Reset FF Proxy Settings": Firefox Proxy settings were reset.


========================= Devices: ================================

Name: Intel(R) HD Graphics 4000
Description: Intel(R) HD Graphics 4000
Class Guid: {4d36e968-e325-11ce-bfc1-08002be10318}
Manufacturer: Intel Corporation
Service: igfx
Device ID: PCI\VEN_8086&DEV_0166&SUBSYS_390117AA&REV_09\3&11583659&0&10

Name: System board
Description: System board
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service:
Device ID: ACPI\PNP0C01\2

Name: Motherboard resources
Description: Motherboard resources
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service:
Device ID: ACPI\PNP0C02\1

Name: Motherboard resources
Description: Motherboard resources
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service:
Device ID: ACPI\PNP0C02\2

Name: Microsoft AC Adapter
Description: Microsoft AC Adapter
Class Guid: {72631e54-78a4-11d0-bcf7-00aa00b7b32a}
Manufacturer: Microsoft
Service: CmBatt
Device ID: ACPI\ACPI0003\4&1BC423EF&0

Name: Intel(R) HM76 Express Chipset LPC Controller - 1E59
Description: Intel(R) HM76 Express Chipset LPC Controller - 1E59
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: INTEL
Service: msisadrv
Device ID: PCI\VEN_8086&DEV_1E59&SUBSYS_397717AA&REV_04\3&11583659&0&F8

Name: Microsoft ACPI-Compliant Control Method Battery
Description: Microsoft ACPI-Compliant Control Method Battery
Class Guid: {72631e54-78a4-11d0-bcf7-00aa00b7b32a}
Manufacturer: Microsoft
Service: CmBatt
Device ID: ACPI\PNP0C0A\1

Name: Tlačový front koreňa
Description: Local Print Queue
Class Guid: {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
Manufacturer: Microsoft
Service:
Device ID: SWD\PRINTENUM\PRINTQUEUES

Name: Microsoft Wi-Fi Direct Virtual Adapter #2
Description: Microsoft Wi-Fi Direct Virtual Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vwifimp
Device ID: {5D624F94-8850-40C3-A3FA-A4FD2080BAF3}\VWIFIMP_WFD\5&39D39B29&6&24

Name: HID-compliant consumer control device
Description: HID-compliant consumer control device
Class Guid: {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
Manufacturer: Microsoft
Service:
Device ID: HID\VID_045E&PID_0095&COL03\6&8BB2D2B&0&0002

Name: Microsoft Hosted Network Virtual Adapter #2
Description: Microsoft Hosted Network Virtual Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vwifimp
Device ID: {5D624F94-8850-40C3-A3FA-A4FD2080BAF3}\VWIFIMP_SAP\5&39D39B29&6&23

Name: Volume Manager
Description: Volume Manager
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: volmgr
Device ID: ROOT\VOLMGR\0000

Name: HID-compliant consumer control device
Description: HID-compliant consumer control device
Class Guid: {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
Manufacturer: Microsoft
Service:
Device ID: HID\VID_045E&PID_0095&COL02\6&8BB2D2B&0&0001

Name: Numeric data processor
Description: Numeric data processor
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service:
Device ID: ACPI\PNP0C04\4&1BC423EF&0

Name: HID-compliant mouse
Description: HID-compliant mouse
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: mouhid
Device ID: HID\VID_045E&PID_0095&COL01\6&8BB2D2B&0&0000

Name: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz
Description: Intel Processor
Class Guid: {50127dc3-0f36-415e-a6cc-4cb3be910b65}
Manufacturer: Intel
Service: intelppm
Device ID: ACPI\GENUINEINTEL_-_INTEL64_FAMILY_6_MODEL_58_-________INTEL(R)_CORE(TM)_I5-3230M_CPU_@_2.60GHZ\_1

Name: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz
Description: Intel Processor
Class Guid: {50127dc3-0f36-415e-a6cc-4cb3be910b65}
Manufacturer: Intel
Service: intelppm
Device ID: ACPI\GENUINEINTEL_-_INTEL64_FAMILY_6_MODEL_58_-________INTEL(R)_CORE(TM)_I5-3230M_CPU_@_2.60GHZ\_2

Name: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz
Description: Intel Processor
Class Guid: {50127dc3-0f36-415e-a6cc-4cb3be910b65}
Manufacturer: Intel
Service: intelppm
Device ID: ACPI\GENUINEINTEL_-_INTEL64_FAMILY_6_MODEL_58_-________INTEL(R)_CORE(TM)_I5-3230M_CPU_@_2.60GHZ\_3

Name: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz
Description: Intel Processor
Class Guid: {50127dc3-0f36-415e-a6cc-4cb3be910b65}
Manufacturer: Intel
Service: intelppm
Device ID: ACPI\GENUINEINTEL_-_INTEL64_FAMILY_6_MODEL_58_-________INTEL(R)_CORE(TM)_I5-3230M_CPU_@_2.60GHZ\_4

Name: High Definition Audio Controller
Description: High Definition Audio Controller
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: HDAudBus
Device ID: PCI\VEN_8086&DEV_1E20&SUBSYS_397717AA&REV_04\3&11583659&0&D8

Name: Microsoft Basic Display Driver
Description: Microsoft Basic Display Driver
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard display types)
Service: BasicDisplay
Device ID: ROOT\BASICDISPLAY\0000

Name: Microsoft IPv4 IPv6 Transition Adapter Bus
Description: Všeobecné softvérové zariadenie
Class Guid: {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
Manufacturer: Microsoft
Service:
Device ID: SWD\IP_TUNNEL_VBUS\IP_TUNNEL_DEVICE_ROOT

Name: Volume
Description: Volume
Class Guid: {71a27cdd-812a-11d0-bec7-08002be2092f}
Manufacturer: Microsoft
Service: volume
Device ID: STORAGE\VOLUME\{4A8095B2-2527-11E3-9B56-806E6F6E6963}#0000003B7A200000

Name: Intel(R) USB 3.0 eXtensible Host Controller - 1.0 (Microsoft)
Description: USB xHCI Compliant Host Controller
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: Generic USB xHCI Host Controller
Service: USBXHCI
Device ID: PCI\VEN_8086&DEV_1E31&SUBSYS_397717AA&REV_04\3&11583659&0&A0

Name: Microsoft Teredo Tunneling Adapter
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Device ID: SWD\IP_TUNNEL_VBUS\TEREDO_TUNNEL_DEVICE

Name: ACPI Thermal Zone
Description: ACPI Thermal Zone
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service:
Device ID: ACPI\THERMALZONE\TZ00

Name: UMBus Enumerator
Description: UMBus Enumerator
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: umbus
Device ID: UMB\UMB\1&841921D&0&TERMINPUT_BUS

Name: Intel(R) 7 Series Chipset Family SATA AHCI Controller
Description: Intel(R) 7 Series Chipset Family SATA AHCI Controller
Class Guid: {4d36e96a-e325-11ce-bfc1-08002be10318}
Manufacturer: Intel
Service: iaStor
Device ID: PCI\VEN_8086&DEV_1E03&SUBSYS_397717AA&REV_04\3&11583659&0&FA

Name: Legacy device
Description: Legacy device
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Intel
Service:
Device ID: ACPI\INT0800\4&1BC423EF&0

Name: USB Root Hub (xHCI)
Description: USB Root Hub (xHCI)
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: (Standard USB HUBs)
Service: USBHUB3
Device ID: USB\ROOT_HUB30\4&D858888&0&0

Name: High precision event timer
Description: High precision event timer
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service:
Device ID: ACPI\PNP0103\0

Name: Wi-Fi
Description: Všeobecné softvérové zariadenie
Class Guid: {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
Manufacturer: Microsoft
Service:
Device ID: SWD\RADIO\{0C32F422-8665-4B76-9DDF-37F6F188800B}

Name: Intel(R) Management Engine Interface
Description: Intel(R) Management Engine Interface
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Intel
Service: MEIx64
Device ID: PCI\VEN_8086&DEV_1E3A&SUBSYS_397717AA&REV_04\3&11583659&0&B0

Name: Composite Bus Enumerator
Description: Composite Bus Enumerator
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: CompositeBus
Device ID: ROOT\COMPOSITEBUS\0000

Name: Internal Microphone (Conexant SmartAudio HD)
Description: Audio Endpoint
Class Guid: {c166523c-fe0c-4a94-a586-f1a80cfbbf3e}
Manufacturer: Microsoft
Service:
Device ID: SWD\MMDEVAPI\{0.0.1.00000000}.{91C19D5C-781C-4C89-BF5B-266459E50460}

Name: Microsoft Virtual Drive Enumerator
Description: Microsoft Virtual Drive Enumerator
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vdrvroot
Device ID: ROOT\VDRVROOT\0000

Name: Generic PnP Monitor
Description: Generic PnP Monitor
Class Guid: {4d36e96e-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard monitor types)
Service: monitor
Device ID: DISPLAY\SEC4252\4&377CCE6E&0&UID67568640

Name: Volume
Description: Volume
Class Guid: {71a27cdd-812a-11d0-bec7-08002be2092f}
Manufacturer: Microsoft
Service: volume
Device ID: STORAGE\VOLUME\{4A8095B2-2527-11E3-9B56-806E6F6E6963}#000000742B730000

Name: Microsoft ISATAP Adapter
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Device ID: SWD\IP_TUNNEL_VBUS\ISATAP_0

Name: Microsoft Storage Spaces Controller
Description: Microsoft Storage Spaces Controller
Class Guid: {4d36e97b-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: spaceport
Device ID: ROOT\SPACEPORT\0000

Name: USB Composite Device
Description: USB Composite Device
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: (Standard USB Host Controller)
Service: usbccgp
Device ID: USB\VID_5986&PID_0295\6&14154DBE&0&6

Name: Microsoft Kernel Debug Network Adapter
Description: Microsoft Kernel Debug Network Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: kdnic
Device ID: ROOT\KDNIC\0000

Name: Generic volume shadow copy
Description: Generic volume shadow copy
Class Guid: {533c5b84-ec70-11d2-9505-00c04f79deaf}
Manufacturer: Microsoft
Service:
Device ID: STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1

Name: Generic volume shadow copy
Description: Generic volume shadow copy
Class Guid: {533c5b84-ec70-11d2-9505-00c04f79deaf}
Manufacturer: Microsoft
Service:
Device ID: STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2

Name: Generic volume shadow copy
Description: Generic volume shadow copy
Class Guid: {533c5b84-ec70-11d2-9505-00c04f79deaf}
Manufacturer: Microsoft
Service:
Device ID: STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3

Name: Generic volume shadow copy
Description: Generic volume shadow copy
Class Guid: {533c5b84-ec70-11d2-9505-00c04f79deaf}
Manufacturer: Microsoft
Service:
Device ID: STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4

Name: Generic volume shadow copy
Description: Generic volume shadow copy
Class Guid: {533c5b84-ec70-11d2-9505-00c04f79deaf}
Manufacturer: Microsoft
Service:
Device ID: STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5

Name: Generic volume shadow copy
Description: Generic volume shadow copy
Class Guid: {533c5b84-ec70-11d2-9505-00c04f79deaf}
Manufacturer: Microsoft
Service:
Device ID: STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6

Name: Generic volume shadow copy
Description: Generic volume shadow copy
Class Guid: {533c5b84-ec70-11d2-9505-00c04f79deaf}
Manufacturer: Microsoft
Service:
Device ID: STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7

Name: Intel(R) 7 Series/C216 Chipset Family PCI Express Root Port 1 - 1E10
Description: Intel(R) 7 Series/C216 Chipset Family PCI Express Root Port 1 - 1E10
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: INTEL
Service: pci
Device ID: PCI\VEN_8086&DEV_1E10&SUBSYS_397717AA&REV_C4\3&11583659&0&E0

Name: Microsoft ACPI-Compliant Embedded Controller
Description: Microsoft ACPI-Compliant Embedded Controller
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service:
Device ID: ACPI\PNP0C09\4&1BC423EF&0

Name: System timer
Description: System timer
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service:
Device ID: ACPI\PNP0100\4&1BC423EF&0

Name: ACPI Lid
Description: ACPI Lid
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service:
Device ID: ACPI\PNP0C0D\2&DABA3FF&1

Name: UMBus Enumerator
Description: UMBus Enumerator
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: umbus
Device ID: UMB\UMB\1&841921D&0&TS_USB_HUB_ENUMERATOR

Name: Qualcomm Atheros AR9485WB-EG Wireless Network Adapter
Description: Qualcomm Atheros AR9485WB-EG Wireless Network Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Qualcomm Atheros Communications Inc.
Service: athr
Device ID: PCI\VEN_168C&DEV_0032&SUBSYS_321817AA&REV_01\4&18901DAC&0&00E1

Name: Intel(R) Zvuk pre obrazovky
Description: Intel(R) Zvuk pre obrazovky
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: Intel(R) Corporation
Service: IntcDAud
Device ID: HDAUDIO\FUNC_01&VEN_8086&DEV_2806&SUBSYS_80860101&REV_1000\4&3A3FC0BE&0&0301

Name: Intel(R) 7 Series/C216 Chipset Family SMBus Host Controller - 1E22
Description: Intel(R) 7 Series/C216 Chipset Family SMBus Host Controller - 1E22
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: INTEL
Service:
Device ID: PCI\VEN_8086&DEV_1E22&SUBSYS_397717AA&REV_04\3&11583659&0&FB

Name: Fax
Description: Local Print Queue
Class Guid: {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
Manufacturer: Microsoft
Service:
Device ID: SWD\PRINTENUM\{893B4776-289D-4501-AD99-0C436C181E3E}

Name: UMBus Root Bus Enumerator
Description: UMBus Root Bus Enumerator
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: umbus
Device ID: ROOT\UMBUS\0000

Name: Integrated Camera
Description: Integrated Camera
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Vimicro
Service: vm331avs
Device ID: USB\VID_5986&PID_0295&MI_00\7&3A5155EF&0&0000

Name: Generic USB Hub
Description: Generic USB Hub
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: (Generic USB Hub)
Service: usbhub
Device ID: USB\VID_8087&PID_0024\5&1A59D89A&1&1

Name: Odeslat do aplikace OneNote 2010
Description: Local Print Queue
Class Guid: {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
Manufacturer:
Service:
Device ID: SWD\PRINTENUM\{75CE07ED-251D-46F0-BA9C-6A61917177E5}

Name: Microsoft Radio Device Enumeration Bus
Description: Všeobecné softvérové zariadenie
Class Guid: {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
Manufacturer: Microsoft
Service:
Device ID: SWD\RADIO\{3DB5895D-CC28-44B3-AD3D-6F01A782B8D2}

Name: Xeon(R) processor E3 - 1200 v2/3rd Gen Core processor DRAM Controller - 0154
Description: Xeon(R) processor E3 - 1200 v2/3rd Gen Core processor DRAM Controller - 0154
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: INTEL
Service:
Device ID: PCI\VEN_8086&DEV_0154&SUBSYS_397717AA&REV_09\3&11583659&0&00

Name: NVIDIA GeForce GT 635M
Description: NVIDIA GeForce GT 635M
Class Guid: {4d36e968-e325-11ce-bfc1-08002be10318}
Manufacturer: NVIDIA
Service: nvlddmkm
Device ID: PCI\VEN_10DE&DEV_0DE3&SUBSYS_390117AA&REV_A1\4&23704A70&0&0008

Name: Microsoft Device Association Root Enumerator
Description: Všeobecné softvérové zariadenie
Class Guid: {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
Manufacturer: Microsoft
Service:
Device ID: SWD\MSDAS\{CE958E9A-424F-4C88-86F4-11314821E75A}

Name: Volume
Description: Volume
Class Guid: {71a27cdd-812a-11d0-bec7-08002be2092f}
Manufacturer: Microsoft
Service: volume
Device ID: STORAGE\VOLUME\{4A8095B2-2527-11E3-9B56-806E6F6E6963}#0000000000100000

Name: ACPI x64-based PC
Description: ACPI x64-based PC
Class Guid: {4d36e966-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard computers)
Service: \Driver\ACPI_HAL
Device ID: ROOT\ACPI_HAL\0000

Name: PCI Express Root Complex
Description: PCI Express Root Complex
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service: pci
Device ID: ACPI\PNP0A08\0

Name: Lenovo ACPI-Compliant Virtual Power Controller
Description: Lenovo ACPI-Compliant Virtual Power Controller
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Lenovo
Service: ACPIVPC
Device ID: ACPI\VPC2004\0

Name: Qualcomm Atheros QCA61x4 Bluetooth 4.1
Description: Qualcomm Atheros QCA61x4 Bluetooth 4.1
Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Manufacturer: Qualcomm Atheros Communications
Service: BTHUSB
Device ID: USB\VID_0CF3&PID_3004\ALASKA_DAY_2006

Name: Speakers (Conexant SmartAudio HD)
Description: Audio Endpoint
Class Guid: {c166523c-fe0c-4a94-a586-f1a80cfbbf3e}
Manufacturer: Microsoft
Service:
Device ID: SWD\MMDEVAPI\{0.0.0.00000000}.{A266DA92-B8A2-4E61-84AF-818962733E93}

Name: Microsoft ACPI-Compliant System
Description: Microsoft ACPI-Compliant System
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: ACPI
Device ID: ACPI_HAL\PNP0C08\0

Name:
Description:
Class Guid:
Manufacturer:
Service:
Device ID: HTREE\ROOT\0

Name: Microsoft Basic Render Driver
Description: Microsoft Basic Render Driver
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: BasicRender
Device ID: ROOT\BASICRENDER\0000

Name: UMBus Enumerator
Description: UMBus Enumerator
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: umbus
Device ID: UMB\UMB\1&841921D&0&TSBUS

Name: Xeon(R) processor E3 - 1200 v2/3rd Gen Core processor PCI Express Root Port - 0151
Description: Xeon(R) processor E3 - 1200 v2/3rd Gen Core processor PCI Express Root Port - 0151
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: INTEL
Service: pci
Device ID: PCI\VEN_8086&DEV_0151&SUBSYS_397717AA&REV_09\3&11583659&0&08

Name: Intel(R) 7 Series/C216 Chipset Family PCI Express Root Port 2 - 1E12
Description: Intel(R) 7 Series/C216 Chipset Family PCI Express Root Port 2 - 1E12
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: INTEL
Service: pci
Device ID: PCI\VEN_8086&DEV_1E12&SUBSYS_397717AA&REV_C4\3&11583659&0&E1

Name: Microsoft Print to PDF
Description: Local Print Queue
Class Guid: {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
Manufacturer: Microsoft
Service:
Device ID: SWD\PRINTENUM\{31C266AF-3592-41E1-93B9-E8361FFD9CD9}

Name: ACPI Fixed Feature Button
Description: ACPI Fixed Feature Button
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service:
Device ID: ACPI\FIXEDBUTTON\2&DABA3FF&1

Name: USB Root Hub
Description: USB Root Hub
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: (Standard USB Host Controller)
Service: usbhub
Device ID: USB\ROOT_HUB20\4&2BE5801C&0

Name: ST500LT012-9WS142
Description: Disk drive
Class Guid: {4d36e967-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard disk drives)
Service: disk
Device ID: IDE\DISKST500LT012-9WS142_______________________0001LVM1\4&3359EDDD&0&0.0.0

Name: ACPI Sleep Button
Description: ACPI Sleep Button
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service:
Device ID: ACPI\PNP0C0E\4&1BC423EF&0

Name: Intel(R) 7 Series/C216 Chipset Family USB Enhanced Host Controller - 1E2D
Description: Intel(R) 7 Series/C216 Chipset Family USB Enhanced Host Controller - 1E2D
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: Intel
Service: usbehci
Device ID: PCI\VEN_8086&DEV_1E2D&SUBSYS_397717AA&REV_04\3&11583659&0&D0

Name: Microsoft GS Wavetable Synth
Description: Všeobecné softvérové zariadenie
Class Guid: {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
Manufacturer: Microsoft
Service:
Device ID: SWD\MMDEVAPI\MICROSOFTGSWAVETABLESYNTH

Name: Synaptics Pointing Device
Description: Synaptics Pointing Device
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Synaptics
Service: i8042prt
Device ID: ACPI\SYN073B\4&1BC423EF&0

Name: HL-DT-ST DVDRAM GT80N
Description: CD-ROM Drive
Class Guid: {4d36e965-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard CD-ROM drives)
Service: cdrom
Device ID: IDE\CDROMHL-DT-ST_DVDRAM_GT80N___________________LN80____\4&3359EDDD&0&0.1.0

Name: System CMOS/real time clock
Description: System CMOS/real time clock
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service:
Device ID: ACPI\PNP0B00\4&1BC423EF&0

Name: Remote Desktop USB Hub
Description: Remote Desktop USB Hub
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service: tsusbhub
Device ID: TS_USB_HUB_ENUMERATOR\UMB\2&30D3618&0&TS_USB_HUB

Name: Conexant SmartAudio HD
Description: Conexant SmartAudio HD
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: Conexant
Service: CnxtHdAudService
Device ID: HDAUDIO\FUNC_01&VEN_14F1&DEV_506E&SUBSYS_17AAC023&REV_1000\4&3A3FC0BE&0&0001

Name: NDIS Virtual Network Adapter Enumerator
Description: NDIS Virtual Network Adapter Enumerator
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: NdisVirtualBus
Device ID: ROOT\NDISVIRTUALBUS\0000

Name: Qualcomm Atheros AR8162/8166/8168 PCI-E Fast Ethernet Controller (NDIS 6.30)
Description: Qualcomm Atheros AR8162/8166/8168 PCI-E Fast Ethernet Controller (NDIS 6.30)
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Qualcomm Atheros
Service: L1C
Device ID: PCI\VEN_1969&DEV_1090&SUBSYS_397917AA&REV_10\4&8F8BD4C&0&00E0

Name: Programmable interrupt controller
Description: Programmable interrupt controller
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service:
Device ID: ACPI\PNP0000\4&1BC423EF&0

Name: Standard PS/2 Keyboard
Description: Standard PS/2 Keyboard
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard keyboards)
Service: i8042prt
Device ID: ACPI\PNP0303\4&1BC423EF&0

Name: Generic USB Hub
Description: Generic USB Hub
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: (Generic USB Hub)
Service: usbhub
Device ID: USB\VID_8087&PID_0024\5&294335C8&1&1

Name: ACPI Power Button
Description: ACPI Power Button
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service:
Device ID: ACPI\PNP0C0C\4&1BC423EF&0

Name: Microsoft XPS Document Writer
Description: Local Print Queue
Class Guid: {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
Manufacturer: Microsoft
Service:
Device ID: SWD\PRINTENUM\{4210B376-897E-4957-A710-BB9401D588ED}

Name: Volume
Description: Volume
Class Guid: {71a27cdd-812a-11d0-bec7-08002be2092f}
Manufacturer: Microsoft
Service: volume
Device ID: STORAGE\VOLUME\{4A8095B2-2527-11E3-9B56-806E6F6E6963}#0000000006500000

Name: Motherboard resources
Description: Motherboard resources
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service:
Device ID: ACPI\INT3F0D\4&1BC423EF&0

Name: Microsoft System Management BIOS Driver
Description: Microsoft System Management BIOS Driver
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service: mssmbios
Device ID: ROOT\MSSMBIOS\0000

Name: Motherboard resources
Description: Motherboard resources
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service:
Device ID: ACPI\INT340E\2&DABA3FF&1

Name: Direct memory access controller
Description: Direct memory access controller
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service:
Device ID: ACPI\PNP0200\4&1BC423EF&0

Name: Intel(R) 7 Series/C216 Chipset Family USB Enhanced Host Controller - 1E26
Description: Intel(R) 7 Series/C216 Chipset Family USB Enhanced Host Controller - 1E26
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: Intel
Service: usbehci
Device ID: PCI\VEN_8086&DEV_1E26&SUBSYS_397717AA&REV_04\3&11583659&0&E8

Name: USB Root Hub
Description: USB Root Hub
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: (Standard USB Host Controller)
Service: usbhub
Device ID: USB\ROOT_HUB20\4&14C1C731&0

Name: Plug and Play Software Device Enumerator
Description: Plug and Play Software Device Enumerator
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service: swenum
Device ID: ROOT\SYSTEM\0000

Name: Atheros Bluetooth Bus
Description: Atheros Bluetooth Bus
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Atheros Communications
Service: BTATH_BUS
Device ID: ROOT\SYSTEM\0001

Name: IWD Bus Enumerator
Description: IWD Bus Enumerator
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service: iwdbus
Device ID: ROOT\SYSTEM\0002

Name: System Interface Foundation Device
Description: System Interface Foundation Device
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Lenovo
Service: WUDFRd
Device ID: ROOT\SYSTEM\0003

Name: USB Input Device
Description: USB Input Device
Class Guid: {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
Manufacturer: (Standard system devices)
Service: HidUsb
Device ID: USB\VID_045E&PID_0095\5&262ED807&0&4

Name: Remote Desktop Device Redirector Bus
Description: Remote Desktop Device Redirector Bus
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: rdpbus
Device ID: ROOT\RDPBUS\0000

Name: Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter
Description: Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter
Class Guid: {dad27e18-2598-4484-98b0-5dba8e007f6a}
Manufacturer: Intel Corporation
Service: AMPPAL
Device ID: ROOT\AMPPAL\0000

========================= Minidump Files ==================================

No minidump file found


**** End of log ****

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod jaro3 » 10 bře 2017 21:29

Určitě vyzkoušej kabel , pokud to bude stejné udělej reset routeru , nebo lépe dej tam nejnovější firmware ( bude pak třeba znovu nastavit wifi!).

+ to ostatní , co jsem psal.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

GoodByeMomo
Level 1
Level 1
Příspěvky: 50
Registrován: únor 17
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod GoodByeMomo » 10 bře 2017 21:40

Na kábli je ping google.com 30ms a yahoo.com 152ms, takže plus-mínus podobne. Vyskúšam reset, alebo novší firmware, ako píšete.

GoodByeMomo
Level 1
Level 1
Příspěvky: 50
Registrován: únor 17
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu z HJT - infikovaný notebook

Příspěvekod GoodByeMomo » 10 bře 2017 21:42

Emsisoft Emergency Kit - Version 2017.2
Last update: 10.3.2017 21:23:22
User account: Lenovo-PC\Lenovo
Computer name: LENOVO-PC
OS version: Windows 10x64

Scan settings:

Scan type: Malware Scan
Objects: Rootkits, Memory, Traces, Files

Detect PUPs: On
Scan archives: Off
ADS Scan: On
File extension filter: Off
Direct disk access: Off

Scan start: 10.3.2017 21:24:24

Zkontrolováno 140556
Nalezeno 0

Konec kontroly: 10.3.2017 21:33:45
Čas kontroly: 0:09:21


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 8 hostů