Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:
Kód: Vybrat vše
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\_elementtree.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\_socket.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\pysqlite2._sqlite.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\win32com.shell.shell.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\win32api.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\wx._html2.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\_multiprocessing.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\win32ts.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\wx._gdi_.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\windows._cacheinvalidation.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\_ctypes.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\win32profile.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\win32crypt.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\pythoncom27.dll ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\wx._core_.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\_ssl.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\wx._misc_.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\PyWinTypes27.dll ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\win32security.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\win32process.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\win32pdh.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\wx._windows_.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\_hashlib.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\wx._wizard.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\win32file.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\win32inet.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\wx._controls_.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\pyexpat.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\win32event.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\unicodedata.pyd ()
MOD - C:\Users\hellhound71\AppData\Local\Temp\_MEI50282\select.pyd ()
DRV:64bit: - (01420742) -- C:\Windows\SysNative\drivers\01420742.sys (Kaspersky Lab ZAO)
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes,DefaultScope = {BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
FF - prefs.js..extensions.enabledAddons: %7B35106bca-6c78-48c7-ac28-56df30b51d2a%7D:1.3.8
FF - prefs.js..extensions.enabledAddons: foxmarks%40kei.com:4.2.1
FF - prefs.js..extensions.enabledAddons: mozilla_cc%40internetdownloadmanager.com:7.3.55
FF - prefs.js..extensions.enabledAddons: toolbarbutton%40browseradditions.com:1.0
FF - prefs.js..extensions.enabledAddons: %7B740B3FD5-4483-469D-BE7F-8555B153BD04%7D:1.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll File not found
[2012.11.28 01:10:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\hellhound71\AppData\Roaming\Mozilla\Extensions
[2013.09.01 13:05:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions
[2013.07.22 23:17:14 | 000,000,000 | ---D | M] (saFe syave) -- C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\coafy3@pieu.edu
[2013.04.20 18:52:47 | 000,301,821 | ---- | M] () (No name found) -- C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\compatibility@addons.mozilla.org.xpi
[2012.12.28 17:39:19 | 000,067,812 | ---- | M] () (No name found) -- C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}.xpi
[2013.08.12 20:06:32 | 000,824,302 | ---- | M] () (No name found) -- C:\Users\hellhound71\AppData\Roaming\Mozilla\Firefox\Profiles\sr2pnxv0.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.08.31 03:38:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013.08.31 03:38:19 | 000,000,000 | ---D | M] (BasicServe) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{740B3FD5-4483-469D-BE7F-8555B153BD04}
O4 - HKLM..\RunOnce: [GrpConv] C:\Windows\SysWow64\grpconv.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
[2013.09.01 15:48:03 | 000,634,530 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2013.09.01 15:48:03 | 000,618,936 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.09.01 15:48:03 | 000,123,120 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2013.09.01 15:48:03 | 000,107,256 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:1CE11B51
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:B797EE03
:Files
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\System32\dllcache\*.tmp
C:\WINDOWS\system32\SET*.tmp
C:\WINDOWS\system32\DUMP*.tmp
c:\windows\Tasks\*.job /s
C:\*.tmp
C:\WINDOWS\System32\drivers\*.tmp
C:\Documents and Settings\All Users\Data aplikací\*.tmp
C:\Windows\SysNative\drivers\*.tmp
C:\Windows\SysWow64\drivers\*.tmp
C:\Program Files (x86)\*.tmp
C:\Windows\SysWow64\*.tmp
C:\Windows\SysNative\*.tmp
C:\ProgramData\Kaspersky Lab
C:\Windows\SysNative\drivers\01420742.sys
C:\Users\hellhound71\Desktop\Kaspersky-Virus-Removal-Tool_11.0.0.1245_[07.07.2013].exe
C:\Windows\MusiccityDownload.exe
C:\Windows\SysWow64\cis-2.4.dll
C:\Windows\SysWow64\issacapi_bs-2.3.dll
C:\Windows\SysWow64\issacapi_pe-2.3.dll
C:\Windows\SysWow64\issacapi_se-2.3.dll
C:\Windows\ativpsrm.bin
C:\Users\hellhound71\AppData\Local\Temp\_MEI50282
:Reg
:Commands
[purity]
[emptytemp]
[CLEARALLRESTOREPOINTS]
[CREATERESTOREPOINT]
[start explorer]
[Reboot]
Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.
Drive C: | 97,66 Gb Total Space | 7,73 Gb Free Space | 7,92% Space Free | Partition Type: NTFS
Málo místa na syst. disku!! Něco musíš odinstalovat , smazat. Je třeba mít alespoň 15% volného místa pro správný chod windows.