Prosím o kontrolu, pomalý boot, nelze nahrávat na flash +

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
MaxDamageCZ
Level 2.5
Level 2.5
Příspěvky: 355
Registrován: červenec 09
Bydliště: Ostrava
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu, pomalý boot, nelze nahrávat na flash

Příspěvekod MaxDamageCZ » 26 lis 2012 16:28

Ještě dodám, že dnes jsem si všiml, že na flashku už lze nahrávat, což je skvělá zpráva, bohužel však stále nelze nahrávat na paměťové karty, které jsou připojeny přes čtečku karet. Možná některé registry ještě zůstaly poškozeny? Nevím. Každopádně prozatím díky alespoň za ty flashky :)
AMD Athlon II X4 640 3.00Ghz Ram 4 GB, Win 7 64 bit, Grafika ATI Radeon HD 4600 series 1GB, HDD 600GB


Iphone 3g 16gb černý

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43293
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu, pomalý boot, nelze nahrávat na flash

Příspěvekod jaro3 » 27 lis 2012 10:37

Aktualizuj javu:
Java SE Runtime Environment 7

Klikni na Accept License Agreement
Vyber si OS (Windows nebo Windows x64, Offline Installation)
jre-7-windows-i586-p.exe nebo
jre-7-windows-x64.exe
Stáhni ( download) a nainstaluj.
Ostatní javy odeber v přidat/odebrat programy.



Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=111304&tt=3512_8&babsrc=SP_ss&mntrId=1ce788610000000000008ca9827a85a0
IE - HKCU\..\SearchScopes\{4D3EC364-8453-4230-9F16-9AEA44F8576F}: "URL" = http://search.yahoo.com/search?fr=chr-g ... =867034&p={searchTerms}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searcerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{71CF1FB3-3D54-4A20-AC9A-84D34A47953E}: "URL" = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKCU\..\SearchScopes\firmy.cz-150429: "URL" = http://www.firmy.cz/phr/{searchTerms}
IE - HKCU\..\SearchScopes\mapy.cz-150429: "URL" = http://www.mapy.cz/?sourceid=quicksearch_6826&query={searchTerms}
IE - HKCU\..\SearchScopes\seznam.cz-150429: "URL" = http://isearch.avg.com/search?cid={7C350596-3C7E-4C3F-A155-0A390B2F05D0}&mid=bbc1cfdbe07047d0b612389458f7bc68-4461002d0cef9fb5d426a782c09e557e3ec433f6&lang=cs&ds=st011&pr=sa&d=2012-06-04 20:17:44&v=11.1.0.7&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\videa.seznam.cz-150429: "URL" = http://videa.seznam.cz/?q={searchTerms}
IE - HKCU\..\SearchScopes\zbozi.cz-150429: "URL" = http://www.zbozi.cz/?sourceid=quicksearch_6826&q={searchTerms}
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"
FF - prefs.js..browser.startup.homepage: "http://search.babylon.com/?affID=111304&tt=3512_8&babsrc=HP_ss&mntrId=1ce788610000000000008ca9827a85a0"
FF - prefs.js..extensions.enabledAddons: yasearch@yandex.ru:6.5.0
FF - prefs.js..extensions.enabledAddons: {972ce4c6-7e08-4474-a285-3208198ce6fd}:13.0.1
FF - prefs.js..keyword.URL: "http://search.babylon.com/?affID=111304&tt=3512_8&babsrc=KW_ss&mntrId=1ce788610000000000008ca9827a85a0&q="
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_287.dll File not found
[2012.07.14 09:43:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Matěj\AppData\Roaming\Mozilla\Extensions
[2012.07.14 09:43:49 | 000,000,000 | ---D | M] (Yandex.Bar) -- C:\Users\Matěj\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\yasearch@yandex.ru
File not found (No name found) -- C:\USERS\MATěJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NAHD6HA2.DEFAULT\EXTENSIONS\YASEARCH@YANDEX.RU
[2012.08.31 18:08:13 | 000,002,349 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
CHR - homepage: http://search.babylon.com/?affID=111304 ... a9827a85a0
CHR - homepage: http://search.babylon.com/?affID=111304 ... a9827a85a0
O1 HOSTS File: ([2012.11.25 11:27:47 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2012.11.25 14:53:14 | 000,805,748 | ---- | M] () -- C:\Windows\SysNative\perfh00C.dat
[2012.11.25 14:53:14 | 000,805,604 | ---- | M] () -- C:\Windows\SysNative\perfh00A.dat
[2012.11.25 14:53:14 | 000,803,514 | ---- | M] () -- C:\Windows\SysNative\perfh013.dat
[2012.11.25 14:53:14 | 000,800,222 | ---- | M] () -- C:\Windows\SysNative\perfh010.dat
[2012.11.25 14:53:14 | 000,757,198 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.11.25 14:53:14 | 000,743,906 | ---- | M] () -- C:\Windows\SysNative\perfh00E.dat
[2012.11.25 14:53:14 | 000,723,782 | ---- | M] () -- C:\Windows\SysNative\perfh01D.dat
[2012.11.25 14:53:14 | 000,722,148 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.11.25 14:53:14 | 000,667,156 | ---- | M] () -- C:\Windows\SysNative\perfh008.dat
[2012.11.25 14:53:14 | 000,541,632 | ---- | M] () -- C:\Windows\SysNative\perfh00B.dat
[2012.11.25 14:53:14 | 000,538,974 | ---- | M] () -- C:\Windows\SysNative\perfh001.dat
[2012.11.25 14:53:14 | 000,487,498 | ---- | M] () -- C:\Windows\SysNative\perfh012.dat
[2012.11.25 14:53:14 | 000,452,086 | ---- | M] () -- C:\Windows\SysNative\perfh00D.dat
[2012.11.25 14:53:14 | 000,197,592 | ---- | M] () -- C:\Windows\SysNative\perfc00E.dat
[2012.11.25 14:53:14 | 000,185,006 | ---- | M] () -- C:\Windows\SysNative\perfc00A.dat
[2012.11.25 14:53:14 | 000,179,560 | ---- | M] () -- C:\Windows\SysNative\perfc013.dat
[2012.11.25 14:53:14 | 000,176,124 | ---- | M] () -- C:\Windows\SysNative\perfc00C.dat
[2012.11.25 14:53:14 | 000,175,468 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.11.25 14:53:14 | 000,173,266 | ---- | M] () -- C:\Windows\SysNative\perfc010.dat
[2012.11.25 14:53:14 | 000,168,990 | ---- | M] () -- C:\Windows\SysNative\perfc01D.dat
[2012.11.25 14:53:14 | 000,166,294 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2012.11.25 14:53:14 | 000,148,400 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.11.25 14:53:14 | 000,146,168 | ---- | M] () -- C:\Windows\SysNative\perfc012.dat
[2012.11.25 14:53:14 | 000,137,556 | ---- | M] () -- C:\Windows\SysNative\perfc008.dat
[2012.11.25 14:53:14 | 000,127,804 | ---- | M] () -- C:\Windows\SysNative\perfc00B.dat
[2012.11.25 14:53:14 | 000,121,012 | ---- | M] () -- C:\Windows\SysNative\perfc001.dat
[2012.11.25 14:53:14 | 000,111,060 | ---- | M] () -- C:\Windows\SysNative\perfc00D.dat
[2012.11.25 14:53:14 | 000,036,356 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
@Alternate Data Stream - 171 bytes -> C:\ProgramData\TEMP:ECF54A0E
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:B755D674

:Files
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\System32\dllcache\*.tmp
C:\WINDOWS\system32\SET*.tmp
C:\WINDOWS\system32\DUMP*.tmp
c:\windows\Tasks\*.job
C:\*.tmp
C:\WINDOWS\System32\drivers\*.tmp
C:\Documents and Settings\All Users\Data aplikací\*.tmp
C:\Windows\SysNative\drivers\*.tmp
C:\Windows\SysWow64\drivers\*.tmp
C:\Program Files (x86)\*.tmp
C:\Windows\SysWow64\*.tmp
C:\Windows\SysNative\*.tmp
C:\Autorun.inf
C:\Users\Matěj\Desktop\tdsskiller.zip
C:\Windows\ativpsrm.bin
C:\Users\Matěj\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
C:\Windows\AutoKMS.ini
C:\Users\Matěj\AppData\Roaming\1CE78861
C:\Users\Matěj\AppData\Roaming\Babylon
C:\Users\Matěj\AppData\Roaming\Yandex

:Reg
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
""=""%1" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
""=""%1" %*"

:Commands
[purity]
[emptytemp]
[start explorer]
[CLEARALLRESTOREPOINTS]
[CREATERESTOREPOINT]
[EMPTYJAVA]
[Reboot]

Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.

V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému

Toto otestuj na Virustotal
C:\Windows\SysWow64\avcodec_32-54.dll
C:\Windows\SysWow64\avformat_32-54.dll
C:\Windows\SysWow64\avutil_32-51.dll

Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.

Nebo na:
http://www.virscan.org/


Drive C: | 465,66 Gb Total Space | 8,17 Gb Free Space | 1,76% Space Free
Málo volného místa na disku C!!!!
Něco odinstaluj nebo smaž. Máš mít nejméně 15% volného místa na systémovém diku , to je možná důvod problémů!


Error - 16.9.2012 10:04:17 | Computer Name = Matěj-PC | Source = Disk | ID = 262151
Description = Zařízení \Device\Harddisk0\DR0 má chybný blok.
buď je něco se řadičem nebo s diskem..

Stáhni si CrystalDiskInfo
Spusť program a klikni na Úpravy-Kopírovat. Poté sem vlož pomocí Ctrl+V obsah logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
MaxDamageCZ
Level 2.5
Level 2.5
Příspěvky: 355
Registrován: červenec 09
Bydliště: Ostrava
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu, pomalý boot, nelze nahrávat na flash

Příspěvekod MaxDamageCZ » 27 lis 2012 16:06

U toho OTL mám problém. Všechno jde bleskově rychle až do doby, než se začne "věnovat" těm registrům, to dole píše jen "processing registry data" a nikam se to nehýbe (už několik hodin).
Virustotal:
https://www.virustotal.com/file/c93e9f8 ... 354028356/
https://www.virustotal.com/file/e575b8e ... 354028457/
https://www.virustotal.com/file/6523fb8 ... /analysis/



----------------------------------------------------------------------------
CrystalDiskInfo 5.0.5 Shizuku Edition (C) 2008-2012 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 7 Ultimate Edition SP1 [6.1 Build 7601] (x64)
Date : 2012/11/27 16:06:03

-- Controller Map ----------------------------------------------------------
- ATA Channel 1 (1) [ATA]
+ Intel(R) 6 Series/C200 Series Chipset Family 4 port Serial ATA Storage Controller - 1C01 [ATA]
- ATA Channel 0 (0)
- ATA Channel 1 (1)
+ Intel(R) 6 Series/C200 Series Chipset Family 2 port Serial ATA Storage Controller - 1C09 [ATA]
- ATA Channel 0 (0)
- ATA Channel 1 (1)
+ Ricoh PCIe SDXC/MMC Host Controller [ATA]
- Ricoh SD Disk Device
+ ATA Channel 0 (0) [ATA]
- HL-DT-ST DVDRAM GT33N ATA Device
- ATA Channel 1 (1) [ATA]
+ ATA Channel 0 (0) [ATA]
- ST9500420AS ATA Device
+ A0UITLTU IDE Controller [SCSI]
- IFC WH2VK52RWDI SCSI CdRom Device
- IFC WH2VK52RWDI SCSI CdRom Device

-- Disk List ---------------------------------------------------------------
(1) ST9500420AS : 500,1 GB [0/0/0, pd1] - st

----------------------------------------------------------------------------
(1) ST9500420AS
----------------------------------------------------------------------------
Model : ST9500420AS
Firmware : 0003LVM1
Serial Number : 5VJFKE4R
Disk Size : 500,1 GB (8,4/137,4/500,1)
Buffer Size : 16384 KB
Queue Depth : 32
# of Sectors : 976773168
Rotation Rate : 7200 RPM
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ATA8-ACS version 4
Transfer Mode : SATA/300
Power On Hours : 2529 hod.
Power On Count : 1617 krát
Temparature : 44 C (111 F)
Health Status : Pozor
Features : S.M.A.R.T., APM, 48bit LBA, NCQ
APM Level : 8080h [ON]
AAM Level : ----

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 112 _85 __6 00000296979B Počet chyb čtení
03 100 _99 _85 000000000000 Čas na roztočení ploten
04 _99 _99 _20 000000000668 Počet spuštění/zastavení
05 _74 _74 _36 000000000216 Počet přemapovaných sektorů
07 _68 _60 _30 000C05C3DC0E Počet chybných hledání
09 _98 _98 __0 5D12000009E1 Hodin v činnosti
0A 100 100 _97 000000000000 Počet opakovaných pokusů o roztočení ploten
0C _99 _99 _20 000000000651 Počet cyklů zapnutí zařízení
B8 100 100 _99 000000000000 Ukončovacích chyb
BB __1 __1 __0 000000000D69 Ohlášeno neopravitelných chyb
BC 100 _97 __0 00000000000C Časový limit příkazu
BD 100 100 __0 000000000000 Vysoká rychlost zápisu
BE _56 _44 _45 00022C1A002C Teplota toku vzduchu
BF 100 100 __0 0000000000AF Počet udalostí zaznamenaných otřesovým senzorem
C0 100 100 __0 0000000000B3 Počet vypnutí disku
C1 _95 _95 __0 00000000285C Počet cyklů načítání/vymazání
C2 _44 _56 __0 00120000002C Teplota
C3 _49 _46 __0 00000296979B Počet oprav chybného čtení
C5 _98 _98 __0 2307000009BB Počet podezřelých sektorů
C6 100 100 __0 00000000001C Počet neopravitelných sektorů
C7 100 100 __0 00000000001C Počet chyb v kontrolním součtu UltraDMA
F0 200 200 __0 B18C00000000 Čas nastavování hlaviček - v hodinách
F1 100 100 __0 000000000000 Total LBAs Written
F2 100 253 __0 000000000000 Total LBAs Read
FE 100 100 __0 000000000000 Ochrana proti pádu

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 0C5A 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 2020 2020 2020 2020 2020 2020 3556 4A46 4B45 3452
020: 0000 8000 0004 3030 3033 4C56 4D31 5354 3935 3030
030: 3432 3041 5320 2020 2020 2020 2020 2020 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 0000 2F00
050: 4000 0200 0200 0007 3FFF 0010 003F FC10 00FB 0110
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 001F 0506 0004 0048 0048
080: 01F0 0029 346B 7D09 6123 3469 BC09 6123 203F 0034
090: 0034 8080 FFFE 0000 FE00 0000 0000 0000 0000 0000
100: 6030 3A38 0000 0000 0000 0000 4000 0000 5000 C500
110: 4892 A0CF 0000 0000 0000 0000 0000 0000 0000 401E
120: 401E 0000 0000 0000 0000 0000 0000 0000 0029 6030
130: 3A38 6030 3A38 2020 0002 0140 0100 5000 3C06 3C0A
140: 0000 003C 0000 0008 0000 0000 001F 0280 0004 0000
150: 0008 0000 0000 0000 0000 0000 0000 0000 3E00 8000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 103B 0000 0000 0000
210: 0000 0000 0000 0000 0000 0000 0000 1C20 0000 0000
220: 0002 0000 1010 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 07A5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 0A 00 01 0F 00 70 55 9B 97 96 02 00 00 00 03 03
010: 00 64 63 00 00 00 00 00 00 00 04 32 00 63 63 68
020: 06 00 00 00 00 00 05 33 00 4A 4A 16 02 00 00 00
030: 00 00 07 0F 00 44 3C 0E DC C3 05 0C 00 00 09 32
040: 00 62 62 E1 09 00 00 12 5D 2E 0A 13 00 64 64 00
050: 00 00 00 00 00 00 0C 32 00 63 63 51 06 00 00 00
060: 00 00 B8 32 00 64 64 00 00 00 00 00 00 00 BB 32
070: 00 01 01 69 0D 00 00 00 00 00 BC 32 00 64 61 0C
080: 00 00 00 00 00 00 BD 3A 00 64 64 00 00 00 00 00
090: 00 00 BE 22 00 38 2C 2C 00 1A 2C 02 00 00 BF 32
0A0: 00 64 64 AF 00 00 00 00 00 00 C0 32 00 64 64 B3
0B0: 00 00 00 00 00 00 C1 32 00 5F 5F 5C 28 00 00 00
0C0: 00 00 C2 22 00 2C 38 2C 00 00 00 12 00 00 C3 1A
0D0: 00 31 2E 9B 97 96 02 00 00 00 C5 12 00 62 62 BB
0E0: 09 00 00 07 23 1A C6 10 00 64 64 1C 00 00 00 00
0F0: 00 00 C7 3E 00 64 64 1C 00 00 00 00 00 00 F0 00
100: 00 C8 C8 00 00 00 00 8C B1 00 F1 00 00 64 64 00
110: 00 00 00 00 00 00 F2 00 00 64 FD 00 00 00 00 00
120: 00 00 FE 32 00 64 64 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 73
170: 03 00 01 00 01 6D 02 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 05 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00
1A0: 00 00 00 00 AF 00 00 00 BA B2 A2 7D 48 08 00 00
1B0: 00 00 00 00 01 00 05 05 82 EB 94 D7 CF 0B 00 00
1C0: EE 3F CF DA 07 24 00 00 00 00 00 00 B9 BB 20 00
1D0: 00 00 00 00 00 00 00 00 DF 26 00 00 43 00 02 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1F
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 06

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 01 00 01 06 00 00 00 00 00 00 00 00 00 00 03 55
010: 00 00 00 00 00 00 00 00 00 00 04 14 00 00 00 00
020: 00 00 00 00 00 00 05 24 00 00 00 00 00 00 00 00
030: 00 00 07 1E 00 00 00 00 00 00 00 00 00 00 09 00
040: 00 00 00 00 00 00 00 00 00 00 0A 61 00 00 00 00
050: 00 00 00 00 00 00 0C 14 00 00 00 00 00 00 00 00
060: 00 00 B8 63 00 00 00 00 00 00 00 00 00 00 BB 00
070: 00 00 00 00 00 00 00 00 00 00 BC 00 00 00 00 00
080: 00 00 00 00 00 00 BD 00 00 00 00 00 00 00 00 00
090: 00 00 BE 2D 00 00 00 00 00 00 00 00 00 00 BF 00
0A0: 00 00 00 00 00 00 00 00 00 00 C0 00 00 00 00 00
0B0: 00 00 00 00 00 00 C1 00 00 00 00 00 00 00 00 00
0C0: 00 00 C2 00 00 00 00 00 00 00 00 00 00 00 C3 00
0D0: 00 00 00 00 00 00 00 00 00 00 C5 00 00 00 00 00
0E0: 00 00 00 00 00 00 C6 00 00 00 00 00 00 00 00 00
0F0: 00 00 C7 00 00 00 00 00 00 00 00 00 00 00 F0 00
100: 00 00 00 00 00 00 00 00 00 00 F1 00 00 00 00 00
110: 00 00 00 00 00 00 F2 00 00 00 00 00 00 00 00 00
120: 00 00 FE 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 84
AMD Athlon II X4 640 3.00Ghz Ram 4 GB, Win 7 64 bit, Grafika ATI Radeon HD 4600 series 1GB, HDD 600GB


Iphone 3g 16gb černý

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43293
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu, pomalý boot, nelze nahrávat na flash

Příspěvekod jaro3 » 27 lis 2012 16:20

Udělej s tímto:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=111304&tt=3512_8&babsrc=SP_ss&mntrId=1ce788610000000000008ca9827a85a0
IE - HKCU\..\SearchScopes\{4D3EC364-8453-4230-9F16-9AEA44F8576F}: "URL" = http://search.yahoo.com/search?fr=chr-g ... =867034&p={searchTerms}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searcerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{71CF1FB3-3D54-4A20-AC9A-84D34A47953E}: "URL" = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKCU\..\SearchScopes\firmy.cz-150429: "URL" = http://www.firmy.cz/phr/{searchTerms}
IE - HKCU\..\SearchScopes\mapy.cz-150429: "URL" = http://www.mapy.cz/?sourceid=quicksearch_6826&query={searchTerms}
IE - HKCU\..\SearchScopes\seznam.cz-150429: "URL" = http://isearch.avg.com/search?cid={7C350596-3C7E-4C3F-A155-0A390B2F05D0}&mid=bbc1cfdbe07047d0b612389458f7bc68-4461002d0cef9fb5d426a782c09e557e3ec433f6&lang=cs&ds=st011&pr=sa&d=2012-06-04 20:17:44&v=11.1.0.7&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\videa.seznam.cz-150429: "URL" = http://videa.seznam.cz/?q={searchTerms}
IE - HKCU\..\SearchScopes\zbozi.cz-150429: "URL" = http://www.zbozi.cz/?sourceid=quicksearch_6826&q={searchTerms}
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"
FF - prefs.js..browser.startup.homepage: "http://search.babylon.com/?affID=111304&tt=3512_8&babsrc=HP_ss&mntrId=1ce788610000000000008ca9827a85a0"
FF - prefs.js..extensions.enabledAddons: yasearch@yandex.ru:6.5.0
FF - prefs.js..extensions.enabledAddons: {972ce4c6-7e08-4474-a285-3208198ce6fd}:13.0.1
FF - prefs.js..keyword.URL: "http://search.babylon.com/?affID=111304&tt=3512_8&babsrc=KW_ss&mntrId=1ce788610000000000008ca9827a85a0&q="
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_287.dll File not found
[2012.07.14 09:43:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Matěj\AppData\Roaming\Mozilla\Extensions
[2012.07.14 09:43:49 | 000,000,000 | ---D | M] (Yandex.Bar) -- C:\Users\Matěj\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\yasearch@yandex.ru
File not found (No name found) -- C:\USERS\MATěJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NAHD6HA2.DEFAULT\EXTENSIONS\YASEARCH@YANDEX.RU
[2012.08.31 18:08:13 | 000,002,349 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
CHR - homepage: http://search.babylon.com/?affID=111304 ... a9827a85a0
CHR - homepage: http://search.babylon.com/?affID=111304 ... a9827a85a0
O1 HOSTS File: ([2012.11.25 11:27:47 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2012.11.25 14:53:14 | 000,805,748 | ---- | M] () -- C:\Windows\SysNative\perfh00C.dat
[2012.11.25 14:53:14 | 000,805,604 | ---- | M] () -- C:\Windows\SysNative\perfh00A.dat
[2012.11.25 14:53:14 | 000,803,514 | ---- | M] () -- C:\Windows\SysNative\perfh013.dat
[2012.11.25 14:53:14 | 000,800,222 | ---- | M] () -- C:\Windows\SysNative\perfh010.dat
[2012.11.25 14:53:14 | 000,757,198 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.11.25 14:53:14 | 000,743,906 | ---- | M] () -- C:\Windows\SysNative\perfh00E.dat
[2012.11.25 14:53:14 | 000,723,782 | ---- | M] () -- C:\Windows\SysNative\perfh01D.dat
[2012.11.25 14:53:14 | 000,722,148 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.11.25 14:53:14 | 000,667,156 | ---- | M] () -- C:\Windows\SysNative\perfh008.dat
[2012.11.25 14:53:14 | 000,541,632 | ---- | M] () -- C:\Windows\SysNative\perfh00B.dat
[2012.11.25 14:53:14 | 000,538,974 | ---- | M] () -- C:\Windows\SysNative\perfh001.dat
[2012.11.25 14:53:14 | 000,487,498 | ---- | M] () -- C:\Windows\SysNative\perfh012.dat
[2012.11.25 14:53:14 | 000,452,086 | ---- | M] () -- C:\Windows\SysNative\perfh00D.dat
[2012.11.25 14:53:14 | 000,197,592 | ---- | M] () -- C:\Windows\SysNative\perfc00E.dat
[2012.11.25 14:53:14 | 000,185,006 | ---- | M] () -- C:\Windows\SysNative\perfc00A.dat
[2012.11.25 14:53:14 | 000,179,560 | ---- | M] () -- C:\Windows\SysNative\perfc013.dat
[2012.11.25 14:53:14 | 000,176,124 | ---- | M] () -- C:\Windows\SysNative\perfc00C.dat
[2012.11.25 14:53:14 | 000,175,468 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.11.25 14:53:14 | 000,173,266 | ---- | M] () -- C:\Windows\SysNative\perfc010.dat
[2012.11.25 14:53:14 | 000,168,990 | ---- | M] () -- C:\Windows\SysNative\perfc01D.dat
[2012.11.25 14:53:14 | 000,166,294 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2012.11.25 14:53:14 | 000,148,400 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.11.25 14:53:14 | 000,146,168 | ---- | M] () -- C:\Windows\SysNative\perfc012.dat
[2012.11.25 14:53:14 | 000,137,556 | ---- | M] () -- C:\Windows\SysNative\perfc008.dat
[2012.11.25 14:53:14 | 000,127,804 | ---- | M] () -- C:\Windows\SysNative\perfc00B.dat
[2012.11.25 14:53:14 | 000,121,012 | ---- | M] () -- C:\Windows\SysNative\perfc001.dat
[2012.11.25 14:53:14 | 000,111,060 | ---- | M] () -- C:\Windows\SysNative\perfc00D.dat
[2012.11.25 14:53:14 | 000,036,356 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
@Alternate Data Stream - 171 bytes -> C:\ProgramData\TEMP:ECF54A0E
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:B755D674

:Files
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\System32\dllcache\*.tmp
C:\WINDOWS\system32\SET*.tmp
C:\WINDOWS\system32\DUMP*.tmp
c:\windows\Tasks\*.job
C:\*.tmp
C:\WINDOWS\System32\drivers\*.tmp
C:\Documents and Settings\All Users\Data aplikací\*.tmp
C:\Windows\SysNative\drivers\*.tmp
C:\Windows\SysWow64\drivers\*.tmp
C:\Program Files (x86)\*.tmp
C:\Windows\SysWow64\*.tmp
C:\Windows\SysNative\*.tmp
C:\Autorun.inf
C:\Users\Matěj\Desktop\tdsskiller.zip
C:\Windows\ativpsrm.bin
C:\Users\Matěj\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
C:\Windows\AutoKMS.ini
C:\Users\Matěj\AppData\Roaming\1CE78861
C:\Users\Matěj\AppData\Roaming\Babylon
C:\Users\Matěj\AppData\Roaming\Yandex

:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
""=""%1" %*"

:Commands
[purity]
[emptytemp]
[start explorer]
[CLEARALLRESTOREPOINTS]
[CREATERESTOREPOINT]
[EMPTYJAVA]
[Reboot]


05 _74 _74 _36 000000000216 Počet přemapovaných sektorů
BB __1 __1 __0 000000000D69 Ohlášeno neopravitelných chyb
BF 100 100 __0 0000000000AF Počet udalostí zaznamenaných otřesovým senzorem
C3 _49 _46 __0 00000296979B Počet oprav chybného čtení
C5 _98 _98 __0 2307000009BB Počet podezřelých sektorů
C6 100 100 __0 00000000001C Počet neopravitelných sektorů


Špatná zpráva , disk je KO!!!

Zazálohuj si vše a rejklamuj , či kup jiný!
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
MaxDamageCZ
Level 2.5
Level 2.5
Příspěvky: 355
Registrován: červenec 09
Bydliště: Ostrava
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu, pomalý boot, nelze nahrávat na flash

Příspěvekod MaxDamageCZ » 27 lis 2012 16:54

OK, takže disk je špatný, obával jsem se toho, měl jsem na něj podezření... každopádně děkuji mnohokrát za pomoc :bigups: zde přikládám ještě log z OTL.


All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named firefox.exe was found!
Error: No service named SkypeUpdate was found to stop!
Service\Driver key SkypeUpdate not found.
File C:\Program Files (x86)\Skype\Updater\Updater.exe not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{4D3EC364-8453-4230-9F16-9AEA44F8576F}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4D3EC364-8453-4230-9F16-9AEA44F8576F}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{71CF1FB3-3D54-4A20-AC9A-84D34A47953E}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71CF1FB3-3D54-4A20-AC9A-84D34A47953E}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{searchTerms}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{searchTerms}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{searchTerms}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{searchTerms}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7C350596-3C7E-4C3F-A155-0A390B2F05D0}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C350596-3C7E-4C3F-A155-0A390B2F05D0}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{searchTerms}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{searchTerms}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{searchTerms}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{searchTerms}\ not found.
Prefs.js: "Search the web (Babylon)" removed from browser.search.defaultenginename
Prefs.js: "Search the web (Babylon)" removed from browser.search.order.1
Prefs.js: "Search the web (Babylon)" removed from browser.search.selectedEngine
Prefs.js: "http://search.babylon.com/?affID=111304&tt=3512_8&babsrc=HP_ss&mntrId=1ce788610000000000008ca9827a85a0" removed from browser.startup.homepage
Prefs.js: yasearch@yandex.ru:6.5.0 removed from extensions.enabledAddons
Prefs.js: {972ce4c6-7e08-4474-a285-3208198ce6fd}:13.0.1 removed from extensions.enabledAddons
Prefs.js: "http://search.babylon.com/?affID=111304&tt=3512_8&babsrc=KW_ss&mntrId=1ce788610000000000008ca9827a85a0&q=" removed from keyword.URL
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ not found.
Folder C:\Users\Matěj\AppData\Roaming\Mozilla\Extensions\ not found.
Folder C:\Users\Matěj\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\yasearch@yandex.ru\ not found.
File C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml not found.
Use Chrome's Settings page to change the HomePage.
Use Chrome's Settings page to change the HomePage.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{977AE9CC-AF83-45E8-9E03-E2798216E2D5} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{977AE9CC-AF83-45E8-9E03-E2798216E2D5}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Low Rights\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ not found.
File Protocol\Handler\livecall - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ not found.
File Protocol\Handler\msnim - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype4com\ not found.
File Protocol\Handler\skype4com - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ not found.
File Protocol\Handler\wlmailhtml - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ not found.
File Protocol\Handler\wlpg - No CLSID value found not found.
File/Folder C:\Windows\SysNative\*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
File C:\Windows\SysNative\perfh00C.dat not found.
File C:\Windows\SysNative\perfh00A.dat not found.
File C:\Windows\SysNative\perfh013.dat not found.
File C:\Windows\SysNative\perfh010.dat not found.
File C:\Windows\SysNative\perfh007.dat not found.
File C:\Windows\SysNative\perfh00E.dat not found.
File C:\Windows\SysNative\perfh01D.dat not found.
File C:\Windows\SysNative\perfh009.dat not found.
File C:\Windows\SysNative\perfh008.dat not found.
File C:\Windows\SysNative\perfh00B.dat not found.
File C:\Windows\SysNative\perfh001.dat not found.
File C:\Windows\SysNative\perfh012.dat not found.
File C:\Windows\SysNative\perfh00D.dat not found.
File C:\Windows\SysNative\perfc00E.dat not found.
File C:\Windows\SysNative\perfc00A.dat not found.
File C:\Windows\SysNative\perfc013.dat not found.
File C:\Windows\SysNative\perfc00C.dat not found.
File C:\Windows\SysNative\perfc007.dat not found.
File C:\Windows\SysNative\perfc010.dat not found.
File C:\Windows\SysNative\perfc01D.dat not found.
File C:\Windows\SysNative\perfc005.dat not found.
File C:\Windows\SysNative\perfc009.dat not found.
File C:\Windows\SysNative\perfc012.dat not found.
File C:\Windows\SysNative\perfc008.dat not found.
File C:\Windows\SysNative\perfc00B.dat not found.
File C:\Windows\SysNative\perfc001.dat not found.
File C:\Windows\SysNative\perfc00D.dat not found.
File C:\Windows\SysNative\perfh005.dat not found.
Unable to delete ADS C:\ProgramData\TEMP:ECF54A0E .
Unable to delete ADS C:\ProgramData\TEMP:B755D674 .
========== FILES ==========
File\Folder C:\WINDOWS\System32\*.tmp not found.
File\Folder C:\WINDOWS\*.tmp not found.
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\System32\dllcache\*.tmp not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
File\Folder C:\WINDOWS\system32\DUMP*.tmp not found.
File\Folder c:\windows\Tasks\*.job not found.
File\Folder C:\*.tmp not found.
File\Folder C:\WINDOWS\System32\drivers\*.tmp not found.
File\Folder C:\Documents and Settings\All Users\Data aplikací\*.tmp not found.
File\Folder C:\Windows\SysNative\drivers\*.tmp not found.
File\Folder C:\Windows\SysWow64\drivers\*.tmp not found.
File\Folder C:\Program Files (x86)\*.tmp not found.
File\Folder C:\Windows\SysWow64\*.tmp not found.
File\Folder C:\Windows\SysNative\*.tmp not found.
File\Folder C:\Autorun.inf not found.
File\Folder C:\Users\Matěj\Desktop\tdsskiller.zip not found.
File\Folder C:\Windows\ativpsrm.bin not found.
File\Folder C:\Users\Matěj\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini not found.
File\Folder C:\Windows\AutoKMS.ini not found.
File\Folder C:\Users\Matěj\AppData\Roaming\1CE78861 not found.
File\Folder C:\Users\Matěj\AppData\Roaming\Babylon not found.
File\Folder C:\Users\Matěj\AppData\Roaming\Yandex not found.
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command\\""|""%1" %*" /E : value set successfully!
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56475 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Matěj
->Temp folder emptied: 2811191 bytes
->Temporary Internet Files folder emptied: 744940 bytes
->Java cache emptied: 325192 bytes
->FireFox cache emptied: 18298880 bytes
->Google Chrome cache emptied: 426903918 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 57171 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 13262 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 85315 bytes
RecycleBin emptied: 2630200 bytes

Total Files Cleaned = 431,00 mb

Restore point Set: OTL Restore Point
Restore point Set: OTL Restore Point

[EMPTYJAVA]

User: All Users

User: Default

User: Default User

User: Matěj
->Java cache emptied: 0 bytes

User: Public

Total Java Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 11272012_164232

Files\Folders moved on Reboot...
C:\Users\Matěj\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File\Folder C:\Users\Matěj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{76F1D306-9E44-4C64-A489-9AEA36B84A4A}.tmp not found!
File\Folder C:\Users\Matěj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{6E311020-F8E4-47CA-9A48-6AED261F584A}.tmp not found!
File\Folder C:\Users\Matěj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{757526E0-1367-4579-907C-2EFCDC5504C3}.tmp not found!
File\Folder C:\Users\Matěj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{A300B534-BFBB-4226-9EC8-A2B892F80C40}.tmp not found!
File\Folder C:\Users\Matěj\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{D93EC15D-C419-486F-9720-D7A7587147F0}.tmp not found!

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
AMD Athlon II X4 640 3.00Ghz Ram 4 GB, Win 7 64 bit, Grafika ATI Radeon HD 4600 series 1GB, HDD 600GB


Iphone 3g 16gb černý

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43293
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu, pomalý boot, nelze nahrávat na flash

Příspěvekod jaro3 » 28 lis 2012 09:57

Spusť OTL a klikni na Vyčisti.

Pokud nejsou jiné problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 91 hostů