11:11:57.0644 2364 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
11:11:57.0660 2364 RemoteRegistry - ok
11:11:57.0676 2364 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
11:11:57.0676 2364 RpcEptMapper - ok
11:11:57.0691 2364 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
11:11:57.0691 2364 RpcLocator - ok
11:11:57.0722 2364 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll
11:11:57.0722 2364 RpcSs - ok
11:11:57.0738 2364 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
11:11:57.0738 2364 rspndr - ok
11:11:57.0754 2364 [ 05C2613F661584190C752F6184D1C8EF ] RTL8167 C:\Windows\system32\DRIVERS\Rt86win7.sys
11:11:57.0769 2364 RTL8167 - ok
11:11:57.0785 2364 [ 7FA7F2E249A5DCBB7970630E15E1F482 ] s3cap C:\Windows\system32\drivers\vms3cap.sys
11:11:57.0785 2364 s3cap - ok
11:11:57.0800 2364 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\Windows\system32\lsass.exe
11:11:57.0800 2364 SamSs - ok
11:11:57.0816 2364 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
11:11:57.0816 2364 sbp2port - ok
11:11:57.0832 2364 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
11:11:57.0847 2364 SCardSvr - ok
11:11:57.0863 2364 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
11:11:57.0863 2364 scfilter - ok
11:11:57.0894 2364 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
11:11:57.0894 2364 Schedule - ok
11:11:57.0910 2364 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
11:11:57.0910 2364 SCPolicySvc - ok
11:11:57.0941 2364 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
11:11:57.0941 2364 SDRSVC - ok
11:11:57.0956 2364 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
11:11:57.0956 2364 secdrv - ok
11:11:57.0972 2364 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
11:11:57.0972 2364 seclogon - ok
11:11:57.0988 2364 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\system32\sens.dll
11:11:57.0988 2364 SENS - ok
11:11:58.0003 2364 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
11:11:58.0003 2364 SensrSvc - ok
11:11:58.0019 2364 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
11:11:58.0019 2364 Serenum - ok
11:11:58.0050 2364 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
11:11:58.0050 2364 Serial - ok
11:11:58.0066 2364 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
11:11:58.0066 2364 sermouse - ok
11:11:58.0128 2364 [ 8C1F87F5FDD92229D1754B98F073913F ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
11:11:58.0144 2364 ServiceLayer - ok
11:11:58.0190 2364 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
11:11:58.0206 2364 SessionEnv - ok
11:11:58.0222 2364 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
11:11:58.0237 2364 sffdisk - ok
11:11:58.0253 2364 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
11:11:58.0253 2364 sffp_mmc - ok
11:11:58.0268 2364 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
11:11:58.0268 2364 sffp_sd - ok
11:11:58.0284 2364 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
11:11:58.0284 2364 sfloppy - ok
11:11:58.0315 2364 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
11:11:58.0315 2364 SharedAccess - ok
11:11:58.0346 2364 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
11:11:58.0346 2364 ShellHWDetection - ok
11:11:58.0378 2364 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
11:11:58.0378 2364 sisagp - ok
11:11:58.0393 2364 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
11:11:58.0393 2364 SiSRaid2 - ok
11:11:58.0409 2364 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
11:11:58.0409 2364 SiSRaid4 - ok
11:11:58.0440 2364 [ F5BBEDF602C310B00036EB2DBF4348A5 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
11:11:58.0440 2364 SkypeUpdate - ok
11:11:58.0456 2364 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
11:11:58.0456 2364 Smb - ok
11:11:58.0487 2364 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
11:11:58.0487 2364 SNMPTRAP - ok
11:11:58.0502 2364 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
11:11:58.0502 2364 spldr - ok
11:11:58.0518 2364 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe
11:11:58.0534 2364 Spooler - ok
11:11:58.0596 2364 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
11:11:58.0627 2364 sppsvc - ok
11:11:58.0643 2364 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
11:11:58.0643 2364 sppuinotify - ok
11:11:58.0674 2364 [ CDDDEC541BC3C96F91ECB48759673505 ] sptd C:\Windows\system32\Drivers\sptd.sys
11:11:58.0690 2364 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: CDDDEC541BC3C96F91ECB48759673505
11:11:58.0690 2364 sptd ( LockedFile.Multi.Generic ) - warning
11:11:58.0690 2364 sptd - detected LockedFile.Multi.Generic (1)
11:11:58.0705 2364 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys
11:11:58.0721 2364 srv - ok
11:11:58.0721 2364 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
11:11:58.0736 2364 srv2 - ok
11:11:58.0736 2364 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
11:11:58.0752 2364 srvnet - ok
11:11:58.0752 2364 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
11:11:58.0768 2364 SSDPSRV - ok
11:11:58.0783 2364 [ A36EE93698802CD899F98BFD553D8185 ] ssmdrv C:\Windows\system32\DRIVERS\ssmdrv.sys
11:11:58.0783 2364 ssmdrv - ok
11:11:58.0799 2364 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
11:11:58.0799 2364 SstpSvc - ok
11:11:58.0814 2364 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
11:11:58.0814 2364 stexstor - ok
11:11:58.0846 2364 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
11:11:58.0846 2364 StiSvc - ok
11:11:58.0861 2364 [ 472AF0311073DCECEAA8FA18BA2BDF89 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
11:11:58.0861 2364 storflt - ok
11:11:58.0877 2364 [ 0BF669F0A910BEDA4A32258D363AF2A5 ] StorSvc C:\Windows\system32\storsvc.dll
11:11:58.0877 2364 StorSvc - ok
11:11:58.0892 2364 [ DCAFFD62259E0BDB433DD67B5BB37619 ] storvsc C:\Windows\system32\drivers\storvsc.sys
11:11:58.0908 2364 storvsc - ok
11:11:58.0908 2364 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys
11:11:58.0908 2364 swenum - ok
11:11:58.0939 2364 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
11:11:58.0939 2364 swprv - ok
11:11:58.0970 2364 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
11:11:58.0986 2364 SysMain - ok
11:11:59.0002 2364 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
11:11:59.0002 2364 TabletInputService - ok
11:11:59.0033 2364 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
11:11:59.0033 2364 TapiSrv - ok
11:11:59.0048 2364 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
11:11:59.0048 2364 TBS - ok
11:11:59.0095 2364 [ CA59F7C570AF70BC174F477CFE2D9EE3 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
11:11:59.0111 2364 Tcpip - ok
11:11:59.0142 2364 [ CA59F7C570AF70BC174F477CFE2D9EE3 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
11:11:59.0142 2364 TCPIP6 - ok
11:11:59.0173 2364 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
11:11:59.0173 2364 tcpipreg - ok
11:11:59.0204 2364 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
11:11:59.0204 2364 TDPIPE - ok
11:11:59.0220 2364 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
11:11:59.0236 2364 TDTCP - ok
11:11:59.0251 2364 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
11:11:59.0251 2364 tdx - ok
11:11:59.0251 2364 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys
11:11:59.0251 2364 TermDD - ok
11:11:59.0282 2364 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
11:11:59.0282 2364 TermService - ok
11:11:59.0298 2364 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
11:11:59.0314 2364 Themes - ok
11:11:59.0314 2364 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
11:11:59.0314 2364 THREADORDER - ok
11:11:59.0329 2364 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
11:11:59.0329 2364 TrkWks - ok
11:11:59.0360 2364 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
11:11:59.0360 2364 TrustedInstaller - ok
11:11:59.0392 2364 [ B37B08F2E5EEB1A37E448E09BACE1101 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
11:11:59.0392 2364 tssecsrv - ok
11:11:59.0423 2364 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
11:11:59.0423 2364 TsUsbFlt - ok
11:11:59.0438 2364 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
11:11:59.0438 2364 tunnel - ok
11:11:59.0470 2364 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
11:11:59.0470 2364 uagp35 - ok
11:11:59.0485 2364 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
11:11:59.0485 2364 udfs - ok
11:11:59.0516 2364 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
11:11:59.0516 2364 UI0Detect - ok
11:11:59.0532 2364 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
11:11:59.0532 2364 uliagpkx - ok
11:11:59.0563 2364 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\drivers\umbus.sys
11:11:59.0563 2364 umbus - ok
11:11:59.0579 2364 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
11:11:59.0579 2364 UmPass - ok
11:11:59.0594 2364 [ 409994A8EACEEE4E328749C0353527A0 ] UmRdpService C:\Windows\System32\umrdp.dll
11:11:59.0594 2364 UmRdpService - ok
11:11:59.0626 2364 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
11:11:59.0626 2364 upnphost - ok
11:11:59.0641 2364 [ EC01DA44B090D2651FC032C8B9257232 ] upperdev C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
11:11:59.0641 2364 upperdev - ok
11:11:59.0672 2364 [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
11:11:59.0672 2364 usbccgp - ok
11:11:59.0688 2364 [ 2352AB5F9F8F097BF9D41D5A4718A041 ] usbcir C:\Windows\system32\drivers\usbcir.sys
11:11:59.0688 2364 usbcir - ok
11:11:59.0704 2364 [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
11:11:59.0704 2364 usbehci - ok
11:11:59.0735 2364 [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
11:11:59.0735 2364 usbhub - ok
11:11:59.0766 2364 [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
11:11:59.0766 2364 usbohci - ok
11:11:59.0782 2364 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
11:11:59.0782 2364 usbprint - ok
11:11:59.0813 2364 [ 007C0C8D5B01D82ACEB70431D15083F6 ] usbser C:\Windows\system32\drivers\usbser.sys
11:11:59.0813 2364 usbser - ok
11:11:59.0828 2364 [ 4ABD37CFBD710E64F01F9DA8710C73F7 ] UsbserFilt C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
11:11:59.0828 2364 UsbserFilt - ok
11:11:59.0860 2364 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
11:11:59.0860 2364 USBSTOR - ok
11:11:59.0860 2364 [ 78780C3EBCE17405B1CCD07A3A8A7D72 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
11:11:59.0860 2364 usbuhci - ok
11:11:59.0891 2364 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
11:11:59.0906 2364 UxSms - ok
11:11:59.0906 2364 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\Windows\system32\lsass.exe
11:11:59.0906 2364 VaultSvc - ok
11:11:59.0922 2364 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
11:11:59.0922 2364 vdrvroot - ok
11:11:59.0953 2364 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe
11:11:59.0953 2364 vds - ok
11:11:59.0969 2364 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
11:11:59.0969 2364 vga - ok
11:11:59.0984 2364 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
11:11:59.0984 2364 VgaSave - ok
11:12:00.0016 2364 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
11:12:00.0016 2364 vhdmp - ok
11:12:00.0031 2364 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys
11:12:00.0031 2364 viaagp - ok
11:12:00.0047 2364 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
11:12:00.0047 2364 ViaC7 - ok
11:12:00.0062 2364 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys
11:12:00.0062 2364 viaide - ok
11:12:00.0094 2364 [ C2F2911156FDC7817C52829C86DA494E ] vmbus C:\Windows\system32\drivers\vmbus.sys
11:12:00.0094 2364 vmbus - ok
11:12:00.0109 2364 [ D4D77455211E204F370D08F4963063CE ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
11:12:00.0109 2364 VMBusHID - ok
11:12:00.0125 2364 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys
11:12:00.0125 2364 volmgr - ok
11:12:00.0140 2364 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
11:12:00.0140 2364 volmgrx - ok
11:12:00.0156 2364 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
11:12:00.0156 2364 volsnap - ok
11:12:00.0156 2364 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
11:12:00.0156 2364 vsmraid - ok
11:12:00.0203 2364 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe
11:12:00.0203 2364 VSS - ok
11:12:00.0234 2364 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
11:12:00.0234 2364 vwifibus - ok
11:12:00.0250 2364 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
11:12:00.0250 2364 W32Time - ok
11:12:00.0265 2364 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
11:12:00.0265 2364 WacomPen - ok
11:12:00.0281 2364 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
11:12:00.0281 2364 WANARP - ok
11:12:00.0296 2364 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
11:12:00.0296 2364 Wanarpv6 - ok
11:12:00.0359 2364 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
11:12:00.0390 2364 WatAdminSvc - ok
11:12:00.0437 2364 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe
11:12:00.0468 2364 wbengine - ok
11:12:00.0484 2364 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
11:12:00.0499 2364 WbioSrvc - ok
11:12:00.0515 2364 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll
11:12:00.0515 2364 wcncsvc - ok
11:12:00.0530 2364 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
11:12:00.0546 2364 WcsPlugInService - ok
11:12:00.0546 2364 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
11:12:00.0546 2364 Wd - ok
11:12:00.0577 2364 [ 25944D2CC49E0A6C581D02A74B7D6645 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
11:12:00.0593 2364 Wdf01000 - ok
11:12:00.0608 2364 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
11:12:00.0608 2364 WdiServiceHost - ok
11:12:00.0608 2364 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
11:12:00.0608 2364 WdiSystemHost - ok
11:12:00.0640 2364 [ 75E8EBD7040CE238684333F97014762A ] WebClient C:\Windows\System32\webclnt.dll
11:12:00.0640 2364 WebClient - ok
11:12:00.0671 2364 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
11:12:00.0671 2364 Wecsvc - ok
11:12:00.0686 2364 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
11:12:00.0686 2364 wercplsupport - ok
11:12:00.0702 2364 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
11:12:00.0702 2364 WerSvc - ok
11:12:00.0733 2364 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
11:12:00.0733 2364 WfpLwf - ok
11:12:00.0749 2364 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
11:12:00.0749 2364 WIMMount - ok
11:12:00.0796 2364 [ 082CF481F659FAE0DE51AD060881EB47 ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
11:12:00.0796 2364 WinDefend - ok
11:12:00.0811 2364 WinHttpAutoProxySvc - ok
11:12:00.0842 2364 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
11:12:00.0842 2364 Winmgmt - ok
11:12:00.0889 2364 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll
11:12:00.0889 2364 WinRM - ok
11:12:00.0936 2364 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
11:12:00.0936 2364 Wlansvc - ok
11:12:00.0952 2364 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
11:12:00.0952 2364 WmiAcpi - ok
11:12:00.0983 2364 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
11:12:00.0983 2364 wmiApSrv - ok
11:12:01.0045 2364 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
11:12:01.0061 2364 WMPNetworkSvc - ok
11:12:01.0076 2364 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
11:12:01.0092 2364 WPCSvc - ok
11:12:01.0108 2364 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
11:12:01.0123 2364 WPDBusEnum - ok
11:12:01.0139 2364 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
11:12:01.0139 2364 ws2ifsl - ok
11:12:01.0170 2364 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\system32\wscsvc.dll
11:12:01.0170 2364 wscsvc - ok
11:12:01.0170 2364 WSearch - ok
11:12:01.0232 2364 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
11:12:01.0264 2364 wuauserv - ok
11:12:01.0279 2364 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
11:12:01.0279 2364 WudfPf - ok
11:12:01.0295 2364 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
11:12:01.0295 2364 WUDFRd - ok
11:12:01.0326 2364 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
11:12:01.0326 2364 wudfsvc - ok
11:12:01.0342 2364 [ 3C5E51C05BE9B56EAFF4E388C3AB25E4 ] WwanSvc C:\Windows\System32\wwansvc.dll
11:12:01.0357 2364 WwanSvc - ok
11:12:01.0357 2364 ================ Scan global ===============================
11:12:01.0373 2364 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
11:12:01.0388 2364 [ 51BB04243DF6196C06E125898127E397 ] C:\Windows\system32\winsrv.dll
11:12:01.0404 2364 [ 51BB04243DF6196C06E125898127E397 ] C:\Windows\system32\winsrv.dll
11:12:01.0420 2364 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
11:12:01.0451 2364 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
11:12:01.0451 2364 [Global] - ok
11:12:01.0451 2364 ================ Scan MBR ==================================
11:12:01.0451 2364 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR1
11:12:01.0451 2364 \Device\Harddisk1\DR1 - ok
11:12:01.0466 2364 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
11:12:01.0622 2364 \Device\Harddisk0\DR0 - ok
11:12:01.0622 2364 ================ Scan VBR ==================================
11:12:01.0638 2364 [ F4CC9A9A561C0CBC67B086229B319A9D ] \Device\Harddisk1\DR1\Partition1
11:12:01.0638 2364 \Device\Harddisk1\DR1\Partition1 - ok
11:12:01.0638 2364 [ 176D3A00F1B90042B0D2F98DFE1AF710 ] \Device\Harddisk0\DR0\Partition1
11:12:01.0638 2364 \Device\Harddisk0\DR0\Partition1 - ok
11:12:01.0654 2364 [ 7182D1A75C1A8200F8EEEE7FE91A8348 ] \Device\Harddisk0\DR0\Partition2
11:12:01.0654 2364 \Device\Harddisk0\DR0\Partition2 - ok
11:12:01.0654 2364 [ B4261526528456EAD2AC0BEBF2CAAEFF ] \Device\Harddisk0\DR0\Partition3
11:12:01.0669 2364 \Device\Harddisk0\DR0\Partition3 - ok
11:12:01.0669 2364 ============================================================
11:12:01.0669 2364 Scan finished
11:12:01.0669 2364 ============================================================
11:12:01.0669 5824 Detected object count: 1
11:12:01.0669 5824 Actual detected object count: 1
11:12:04.0867 5824 sptd ( LockedFile.Multi.Generic ) - skipped by user
11:12:04.0867 5824 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
11:12:06.0942 0412 Deinitialize success
Prosím o kontrolu - ubývající místo na disku Vyřešeno
- memphisto
- Guru Level 13
- Příspěvky: 21113
- Registrován: září 06
- Bydliště: Zlín - České Budějovice
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu - ubývající místo na disku
Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je oznaèen pro odstranění, stačí restartovat počítač.
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je oznaèen pro odstranění, stačí restartovat počítač.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji
Re: Prosím o kontrolu - ubývající místo na disku
ComboFix 13-10-21.01 - Radim 22.10.2013 20:33:39.4.2 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.2046.1208 [GMT 2:00]
Spuštěný z: c:\users\Radim\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Radim\AppData\Local\Temp\_MEI26562\_ctypes.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\_elementtree.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\_hashlib.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\_multiprocessing.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\_socket.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\_ssl.pyd
c:\users\Radim\AppData\Local\temp\_MEI26562\msvcp100.dll
c:\users\Radim\AppData\Local\Temp\_MEI26562\msvcr100.dll
c:\users\Radim\AppData\Local\Temp\_MEI26562\pyexpat.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\pysqlite2._sqlite.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\python27.dll
c:\users\Radim\AppData\Local\temp\_MEI26562\pythoncom27.dll
c:\users\Radim\AppData\Local\Temp\_MEI26562\PyWinTypes27.dll
c:\users\Radim\AppData\Local\Temp\_MEI26562\select.pyd
c:\users\Radim\AppData\Local\temp\_MEI26562\unicodedata.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\win32api.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\win32com.shell.shell.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\win32crypt.pyd
c:\users\Radim\AppData\Local\temp\_MEI26562\win32event.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\win32file.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\win32inet.pyd
c:\users\Radim\AppData\Local\temp\_MEI26562\win32pdh.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\win32process.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\win32profile.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\win32security.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\win32ts.pyd
c:\users\Radim\AppData\Local\temp\_MEI26562\windows._cacheinvalidation.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\wx._controls_.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\wx._core_.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\wx._gdi_.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\wx._html2.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\wx._misc_.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\wx._windows_.pyd
c:\users\Radim\AppData\Local\temp\_MEI26562\wx._wizard.pyd
c:\users\Radim\AppData\Local\temp\_MEI26562\wxbase294u_net_vc90.dll
c:\users\Radim\AppData\Local\temp\_MEI26562\wxbase294u_vc90.dll
c:\users\Radim\AppData\Local\Temp\_MEI26562\wxmsw294u_adv_vc90.dll
c:\users\Radim\AppData\Local\temp\_MEI26562\wxmsw294u_core_vc90.dll
c:\users\Radim\AppData\Local\temp\_MEI26562\wxmsw294u_html_vc90.dll
c:\users\Radim\AppData\Local\Temp\_MEI26562\wxmsw294u_webview_vc90.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-09-22 do 2013-10-22 )))))))))))))))))))))))))))))))
.
.
2013-10-22 18:41 . 2013-10-22 18:41 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-10-22 18:41 . 2013-10-22 18:41 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-10-22 18:41 . 2013-10-22 18:41 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7F69D9A0-372C-4929-82A9-3AB1BDFBACB3}\offreg.dll
2013-10-22 06:57 . 2013-10-14 06:39 7796464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7F69D9A0-372C-4929-82A9-3AB1BDFBACB3}\mpengine.dll
2013-10-21 09:02 . 2013-10-21 09:02 -------- d-----w- c:\programdata\Oracle
2013-10-21 09:02 . 2013-10-21 09:02 -------- d-----w- c:\program files\Common Files\Java
2013-10-21 09:02 . 2013-10-21 09:02 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-10-21 09:02 . 2013-10-21 09:02 -------- d-----w- c:\program files\Java
2013-10-21 08:31 . 2013-10-21 08:31 -------- d-----w- c:\windows\ERUNT
2013-10-21 08:27 . 2013-10-22 08:17 -------- d-----w- C:\AdwCleaner
2013-10-21 08:06 . 2013-10-21 08:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-10-21 08:06 . 2013-04-04 12:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-10-20 16:12 . 2013-10-20 16:12 388096 ----a-r- c:\users\Radim\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-10-20 16:12 . 2013-10-20 16:12 -------- d-----w- c:\program files\Trend Micro
2013-10-10 12:29 . 2013-09-08 02:07 1294272 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-10-10 12:29 . 2013-07-03 03:36 55808 ----a-w- c:\windows\system32\drivers\hidclass.sys
2013-10-10 12:29 . 2013-07-03 03:36 25728 ----a-w- c:\windows\system32\drivers\hidparse.sys
2013-10-10 12:29 . 2013-09-14 00:48 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2013-10-10 12:29 . 2013-09-08 02:03 231424 ----a-w- c:\windows\system32\mswsock.dll
2013-10-10 12:29 . 2013-07-20 10:33 102608 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 12:29 . 2013-08-28 00:57 434688 ----a-w- c:\windows\system32\scavengeui.dll
2013-10-10 12:29 . 2013-07-04 11:50 530432 ----a-w- c:\windows\system32\comctl32.dll
2013-10-10 12:29 . 2013-08-01 11:03 729024 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-10-10 12:28 . 2013-08-29 01:12 28160 ----a-w- c:\windows\system32\drivers\usbser.sys
2013-10-10 12:28 . 2013-08-29 01:51 3969472 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-10-10 12:28 . 2013-08-29 01:51 3914176 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-10-10 12:28 . 2013-08-29 01:50 1289096 ----a-w- c:\windows\system32\ntdll.dll
2013-10-10 12:28 . 2013-08-29 01:50 619520 ----a-w- c:\windows\system32\tdh.dll
2013-10-10 12:28 . 2013-08-29 01:48 640512 ----a-w- c:\windows\system32\advapi32.dll
2013-10-10 12:19 . 2013-08-28 01:04 2348544 ----a-w- c:\windows\system32\win32k.sys
2013-10-10 12:19 . 2013-06-06 04:52 26112 ----a-w- c:\windows\system32\lpk.dll
2013-10-10 12:19 . 2013-06-06 04:51 70656 ----a-w- c:\windows\system32\fontsub.dll
2013-10-10 12:19 . 2013-06-06 04:50 10240 ----a-w- c:\windows\system32\dciman32.dll
2013-10-10 12:19 . 2013-06-06 03:01 295424 ----a-w- c:\windows\system32\atmfd.dll
2013-10-10 12:19 . 2013-06-06 03:01 34304 ----a-w- c:\windows\system32\atmlib.dll
2013-10-10 12:19 . 2013-07-04 11:57 205824 ----a-w- c:\windows\system32\WebClnt.dll
2013-10-10 12:19 . 2013-07-04 11:51 81920 ----a-w- c:\windows\system32\davclnt.dll
2013-10-10 12:19 . 2013-07-04 09:48 115712 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2013-10-10 12:17 . 2013-07-12 10:07 86016 ----a-w- c:\windows\system32\drivers\usbcir.sys
2013-10-10 12:17 . 2013-06-25 22:56 527064 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2013-10-08 05:45 . 2013-10-08 05:45 -------- d-----w- c:\users\Default\AppData\Local\Google
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-10-10 12:51 . 2012-05-04 11:10 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-10-10 12:51 . 2011-05-24 06:33 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-04 12:58 . 2013-02-26 17:57 88840 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-09-03 12:35 . 2010-09-19 10:39 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-08-20 08:29 . 2013-05-07 12:27 66144 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2013-08-20 08:29 . 2013-02-26 17:57 136672 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-08-05 01:56 . 2013-09-12 06:54 133056 ----a-w- c:\windows\system32\drivers\ataport.sys
2013-08-02 01:50 . 2013-09-12 06:54 169984 ----a-w- c:\windows\system32\winsrv.dll
2013-08-02 01:49 . 2013-09-12 06:54 293376 ----a-w- c:\windows\system32\KernelBase.dll
2013-08-02 01:48 . 2013-09-12 06:54 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 4096 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-08-02 00:52 . 2013-09-12 06:54 271360 ----a-w- c:\windows\system32\conhost.exe
2013-08-02 00:43 . 2013-09-12 06:54 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-08-02 00:43 . 2013-09-12 06:54 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-08-02 00:43 . 2013-09-12 06:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-08-02 00:43 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-07-25 08:57 . 2013-08-14 06:54 1620992 ----a-w- c:\windows\system32\WMVDECOD.DLL
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-08-14 20:34 222832 ----a-w- c:\users\Radim\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-08-14 20:34 222832 ----a-w- c:\users\Radim\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-08-14 20:34 222832 ----a-w- c:\users\Radim\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 131248 ----a-w- c:\users\Radim\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 131248 ----a-w- c:\users\Radim\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 131248 ----a-w- c:\users\Radim\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-10-02 20472992]
"GoogleDriveSync"="c:\program files\Google\Drive\googledrivesync.exe" [2013-09-25 20133824]
"SkyDrive"="c:\users\Radim\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" [2013-08-14 257136]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-12-08 8120864]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-08-20 347192]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
.
c:\users\Radim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Radim\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-10-10 29768376]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKLM\~\startupfolder\C:^Users^Radim^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
path=c:\users\Radim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KeePass 2 PreLoad]
2010-09-05 08:30 1655296 ----a-w- c:\program files\KeePass Password Safe 2\KeePass.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
2011-09-01 12:39 966712 ----a-w- c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
.
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-09-05 171680]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-09-20 1343400]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-12-20 691696]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2013-04-02 37352]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\program files\HWiNFO32\HWiNFO32.SYS [2012-02-07 21752]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2013-08-20 84024]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-08-20 189440]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2013-10-22 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-04 12:51]
.
2013-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-08-26 17:38]
.
2013-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-08-26 17:38]
.
2013-10-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2916595278-2769544797-2451419562-1000Core.job
- c:\users\Radim\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-26 18:47]
.
2013-10-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2916595278-2769544797-2451419562-1000UA.job
- c:\users\Radim\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-26 18:47]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
TCP: Interfaces\{95E635F5-B84E-4D33-8076-47AB93A275F0}: NameServer = 62.129.50.20,85.135.32.100
FF - ProfilePath - c:\users\Radim\AppData\Roaming\Mozilla\Firefox\Profiles\traxidc3.radim\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/
FF - prefs.js: keyword.URL - hxxp://www.google.cz/search?q=
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-HyperCam Toolbar - c:\program files\HyperCam Toolbar\UninstallToolbar.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2916595278-2769544797-2451419562-1000\Software\SecuROM\License information*]
"datasecu"=hex:e1,79,69,2d,e5,82,81,46,a3,90,42,13,8c,01,f3,4e,1f,44,47,28,f1,
43,a9,05,c3,1e,78,e8,ec,a0,f9,8c,9c,b0,7f,1c,39,63,95,1c,60,2c,31,39,65,2d,\
"rkeysecu"=hex:29,96,1e,0c,de,07,64,b4,bf,19,4a,ea,a2,1e,6e,29
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\conhost.exe
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer.exe
c:\users\Radim\AppData\Roaming\Dropbox\bin\Dropbox.exe
c:\windows\system32\sppsvc.exe
c:\windows\system32\Ribbons.scr
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Celkový čas: 2013-10-22 20:48:01 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-10-22 18:48
ComboFix2.txt 2012-11-17 12:18
.
Před spuštěním: 4 904 529 920
Po spuštění: 7 321 763 840
.
- - End Of File - - 2E71B95EFB1E3B1625184B75E0C5731A
A36C5E4F47E84449FF07ED3517B43A31
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.2046.1208 [GMT 2:00]
Spuštěný z: c:\users\Radim\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Radim\AppData\Local\Temp\_MEI26562\_ctypes.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\_elementtree.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\_hashlib.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\_multiprocessing.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\_socket.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\_ssl.pyd
c:\users\Radim\AppData\Local\temp\_MEI26562\msvcp100.dll
c:\users\Radim\AppData\Local\Temp\_MEI26562\msvcr100.dll
c:\users\Radim\AppData\Local\Temp\_MEI26562\pyexpat.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\pysqlite2._sqlite.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\python27.dll
c:\users\Radim\AppData\Local\temp\_MEI26562\pythoncom27.dll
c:\users\Radim\AppData\Local\Temp\_MEI26562\PyWinTypes27.dll
c:\users\Radim\AppData\Local\Temp\_MEI26562\select.pyd
c:\users\Radim\AppData\Local\temp\_MEI26562\unicodedata.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\win32api.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\win32com.shell.shell.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\win32crypt.pyd
c:\users\Radim\AppData\Local\temp\_MEI26562\win32event.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\win32file.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\win32inet.pyd
c:\users\Radim\AppData\Local\temp\_MEI26562\win32pdh.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\win32process.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\win32profile.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\win32security.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\win32ts.pyd
c:\users\Radim\AppData\Local\temp\_MEI26562\windows._cacheinvalidation.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\wx._controls_.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\wx._core_.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\wx._gdi_.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\wx._html2.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\wx._misc_.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26562\wx._windows_.pyd
c:\users\Radim\AppData\Local\temp\_MEI26562\wx._wizard.pyd
c:\users\Radim\AppData\Local\temp\_MEI26562\wxbase294u_net_vc90.dll
c:\users\Radim\AppData\Local\temp\_MEI26562\wxbase294u_vc90.dll
c:\users\Radim\AppData\Local\Temp\_MEI26562\wxmsw294u_adv_vc90.dll
c:\users\Radim\AppData\Local\temp\_MEI26562\wxmsw294u_core_vc90.dll
c:\users\Radim\AppData\Local\temp\_MEI26562\wxmsw294u_html_vc90.dll
c:\users\Radim\AppData\Local\Temp\_MEI26562\wxmsw294u_webview_vc90.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-09-22 do 2013-10-22 )))))))))))))))))))))))))))))))
.
.
2013-10-22 18:41 . 2013-10-22 18:41 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-10-22 18:41 . 2013-10-22 18:41 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-10-22 18:41 . 2013-10-22 18:41 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7F69D9A0-372C-4929-82A9-3AB1BDFBACB3}\offreg.dll
2013-10-22 06:57 . 2013-10-14 06:39 7796464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7F69D9A0-372C-4929-82A9-3AB1BDFBACB3}\mpengine.dll
2013-10-21 09:02 . 2013-10-21 09:02 -------- d-----w- c:\programdata\Oracle
2013-10-21 09:02 . 2013-10-21 09:02 -------- d-----w- c:\program files\Common Files\Java
2013-10-21 09:02 . 2013-10-21 09:02 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-10-21 09:02 . 2013-10-21 09:02 -------- d-----w- c:\program files\Java
2013-10-21 08:31 . 2013-10-21 08:31 -------- d-----w- c:\windows\ERUNT
2013-10-21 08:27 . 2013-10-22 08:17 -------- d-----w- C:\AdwCleaner
2013-10-21 08:06 . 2013-10-21 08:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-10-21 08:06 . 2013-04-04 12:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-10-20 16:12 . 2013-10-20 16:12 388096 ----a-r- c:\users\Radim\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-10-20 16:12 . 2013-10-20 16:12 -------- d-----w- c:\program files\Trend Micro
2013-10-10 12:29 . 2013-09-08 02:07 1294272 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-10-10 12:29 . 2013-07-03 03:36 55808 ----a-w- c:\windows\system32\drivers\hidclass.sys
2013-10-10 12:29 . 2013-07-03 03:36 25728 ----a-w- c:\windows\system32\drivers\hidparse.sys
2013-10-10 12:29 . 2013-09-14 00:48 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2013-10-10 12:29 . 2013-09-08 02:03 231424 ----a-w- c:\windows\system32\mswsock.dll
2013-10-10 12:29 . 2013-07-20 10:33 102608 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 12:29 . 2013-08-28 00:57 434688 ----a-w- c:\windows\system32\scavengeui.dll
2013-10-10 12:29 . 2013-07-04 11:50 530432 ----a-w- c:\windows\system32\comctl32.dll
2013-10-10 12:29 . 2013-08-01 11:03 729024 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-10-10 12:28 . 2013-08-29 01:12 28160 ----a-w- c:\windows\system32\drivers\usbser.sys
2013-10-10 12:28 . 2013-08-29 01:51 3969472 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-10-10 12:28 . 2013-08-29 01:51 3914176 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-10-10 12:28 . 2013-08-29 01:50 1289096 ----a-w- c:\windows\system32\ntdll.dll
2013-10-10 12:28 . 2013-08-29 01:50 619520 ----a-w- c:\windows\system32\tdh.dll
2013-10-10 12:28 . 2013-08-29 01:48 640512 ----a-w- c:\windows\system32\advapi32.dll
2013-10-10 12:19 . 2013-08-28 01:04 2348544 ----a-w- c:\windows\system32\win32k.sys
2013-10-10 12:19 . 2013-06-06 04:52 26112 ----a-w- c:\windows\system32\lpk.dll
2013-10-10 12:19 . 2013-06-06 04:51 70656 ----a-w- c:\windows\system32\fontsub.dll
2013-10-10 12:19 . 2013-06-06 04:50 10240 ----a-w- c:\windows\system32\dciman32.dll
2013-10-10 12:19 . 2013-06-06 03:01 295424 ----a-w- c:\windows\system32\atmfd.dll
2013-10-10 12:19 . 2013-06-06 03:01 34304 ----a-w- c:\windows\system32\atmlib.dll
2013-10-10 12:19 . 2013-07-04 11:57 205824 ----a-w- c:\windows\system32\WebClnt.dll
2013-10-10 12:19 . 2013-07-04 11:51 81920 ----a-w- c:\windows\system32\davclnt.dll
2013-10-10 12:19 . 2013-07-04 09:48 115712 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2013-10-10 12:17 . 2013-07-12 10:07 86016 ----a-w- c:\windows\system32\drivers\usbcir.sys
2013-10-10 12:17 . 2013-06-25 22:56 527064 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2013-10-08 05:45 . 2013-10-08 05:45 -------- d-----w- c:\users\Default\AppData\Local\Google
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-10-10 12:51 . 2012-05-04 11:10 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-10-10 12:51 . 2011-05-24 06:33 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-04 12:58 . 2013-02-26 17:57 88840 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-09-03 12:35 . 2010-09-19 10:39 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-08-20 08:29 . 2013-05-07 12:27 66144 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2013-08-20 08:29 . 2013-02-26 17:57 136672 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-08-05 01:56 . 2013-09-12 06:54 133056 ----a-w- c:\windows\system32\drivers\ataport.sys
2013-08-02 01:50 . 2013-09-12 06:54 169984 ----a-w- c:\windows\system32\winsrv.dll
2013-08-02 01:49 . 2013-09-12 06:54 293376 ----a-w- c:\windows\system32\KernelBase.dll
2013-08-02 01:48 . 2013-09-12 06:54 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 4096 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-08-02 00:52 . 2013-09-12 06:54 271360 ----a-w- c:\windows\system32\conhost.exe
2013-08-02 00:43 . 2013-09-12 06:54 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-08-02 00:43 . 2013-09-12 06:54 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-08-02 00:43 . 2013-09-12 06:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-08-02 00:43 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-07-25 08:57 . 2013-08-14 06:54 1620992 ----a-w- c:\windows\system32\WMVDECOD.DLL
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-08-14 20:34 222832 ----a-w- c:\users\Radim\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-08-14 20:34 222832 ----a-w- c:\users\Radim\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-08-14 20:34 222832 ----a-w- c:\users\Radim\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 131248 ----a-w- c:\users\Radim\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 131248 ----a-w- c:\users\Radim\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 131248 ----a-w- c:\users\Radim\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-10-02 20472992]
"GoogleDriveSync"="c:\program files\Google\Drive\googledrivesync.exe" [2013-09-25 20133824]
"SkyDrive"="c:\users\Radim\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" [2013-08-14 257136]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-12-08 8120864]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-08-20 347192]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
.
c:\users\Radim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Radim\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-10-10 29768376]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKLM\~\startupfolder\C:^Users^Radim^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
path=c:\users\Radim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KeePass 2 PreLoad]
2010-09-05 08:30 1655296 ----a-w- c:\program files\KeePass Password Safe 2\KeePass.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
2011-09-01 12:39 966712 ----a-w- c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
.
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-09-05 171680]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-09-20 1343400]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-12-20 691696]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2013-04-02 37352]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\program files\HWiNFO32\HWiNFO32.SYS [2012-02-07 21752]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2013-08-20 84024]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-08-20 189440]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2013-10-22 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-04 12:51]
.
2013-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-08-26 17:38]
.
2013-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-08-26 17:38]
.
2013-10-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2916595278-2769544797-2451419562-1000Core.job
- c:\users\Radim\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-26 18:47]
.
2013-10-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2916595278-2769544797-2451419562-1000UA.job
- c:\users\Radim\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-26 18:47]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
TCP: Interfaces\{95E635F5-B84E-4D33-8076-47AB93A275F0}: NameServer = 62.129.50.20,85.135.32.100
FF - ProfilePath - c:\users\Radim\AppData\Roaming\Mozilla\Firefox\Profiles\traxidc3.radim\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/
FF - prefs.js: keyword.URL - hxxp://www.google.cz/search?q=
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-HyperCam Toolbar - c:\program files\HyperCam Toolbar\UninstallToolbar.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2916595278-2769544797-2451419562-1000\Software\SecuROM\License information*]
"datasecu"=hex:e1,79,69,2d,e5,82,81,46,a3,90,42,13,8c,01,f3,4e,1f,44,47,28,f1,
43,a9,05,c3,1e,78,e8,ec,a0,f9,8c,9c,b0,7f,1c,39,63,95,1c,60,2c,31,39,65,2d,\
"rkeysecu"=hex:29,96,1e,0c,de,07,64,b4,bf,19,4a,ea,a2,1e,6e,29
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\conhost.exe
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer.exe
c:\users\Radim\AppData\Roaming\Dropbox\bin\Dropbox.exe
c:\windows\system32\sppsvc.exe
c:\windows\system32\Ribbons.scr
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Celkový čas: 2013-10-22 20:48:01 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-10-22 18:48
ComboFix2.txt 2012-11-17 12:18
.
Před spuštěním: 4 904 529 920
Po spuštění: 7 321 763 840
.
- - End Of File - - 2E71B95EFB1E3B1625184B75E0C5731A
A36C5E4F47E84449FF07ED3517B43A31
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu - ubývající místo na disku
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Nemáš málo místa na disku?
Zkopíruj do něj následující celý text označený zeleně:
Kód: Vybrat vše
ClearJavaCache::
KillAll::
File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2916595278-2769544797-2451419562-1000Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2916595278-2769544797-2451419562-1000UA.job
Folder::
c:\program files\Skype\Updater
c:\program files\Google\Update
c:\users\Radim\AppData\Local\Google\Update
Driver::
SkypeUpdate
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Nemáš málo místa na disku?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu - ubývající místo na disku
jaro3 píše:Nemáš málo místa na disku?
Měl jsem celkem dost a pak začalo miznout.
Teď jsem smazal nějaké fotky a je tam 6,5GB a zatím nemizne.
ComboFix 13-10-21.01 - Radim 24.10.2013 14:10:25.5.2 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.2046.1265 [GMT 2:00]
Spuštěný z: c:\users\Radim\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Radim\Desktop\CFScript.txt
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2916595278-2769544797-2451419562-1000Core.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2916595278-2769544797-2451419562-1000UA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Google\Update
c:\program files\Google\Update\1.3.21.165\GoogleCrashHandler.exe
c:\program files\Google\Update\1.3.21.165\GoogleCrashHandler64.exe
c:\program files\Google\Update\1.3.21.165\GoogleUpdate.exe
c:\program files\Google\Update\1.3.21.165\GoogleUpdateBroker.exe
c:\program files\Google\Update\1.3.21.165\GoogleUpdateHelper.msi
c:\program files\Google\Update\1.3.21.165\GoogleUpdateOnDemand.exe
c:\program files\Google\Update\1.3.21.165\GoogleUpdateSetup.exe
c:\program files\Google\Update\1.3.21.165\goopdate.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_am.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ar.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_bg.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_bn.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ca.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_cs.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_da.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_de.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_el.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_en-GB.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_en.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_es-419.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_es.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_et.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_fa.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_fi.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_fil.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_fr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_gu.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_hi.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_hr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_hu.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_id.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_is.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_it.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_iw.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ja.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_kn.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ko.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_lt.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_lv.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ml.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_mr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ms.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_nl.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_no.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_pl.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_pt-BR.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_pt-PT.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ro.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ru.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sk.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sl.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sv.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_sw.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ta.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_te.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_th.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_tr.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_uk.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_ur.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_vi.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_zh-CN.dll
c:\program files\Google\Update\1.3.21.165\goopdateres_zh-TW.dll
c:\program files\Google\Update\1.3.21.165\npGoogleUpdate3.dll
c:\program files\Google\Update\1.3.21.165\psmachine.dll
c:\program files\Google\Update\1.3.21.165\psuser.dll
c:\program files\Google\Update\Download\{3C122445-AECE-4309-90B7-85A6AEF42AC0}\0.0.0.0\gsync.msi
c:\program files\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.165\GoogleUpdateSetup.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\program files\Skype\Updater
c:\program files\Skype\Updater\Updater.dll
c:\program files\Skype\Updater\Updater.exe
c:\users\Radim\AppData\Local\Google\Update
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\GoogleCrashHandler.exe
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\GoogleCrashHandler64.exe
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\GoogleUpdate.exe
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\GoogleUpdateBroker.exe
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\GoogleUpdateHelper.msi
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\GoogleUpdateOnDemand.exe
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\GoogleUpdateSetup.exe
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdate.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_am.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_ar.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_bg.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_bn.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_ca.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_cs.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_da.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_de.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_el.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_en-GB.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_en.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_es-419.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_es.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_et.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_fa.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_fi.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_fil.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_fr.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_gu.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_hi.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_hr.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_hu.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_id.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_is.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_it.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_iw.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_ja.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_kn.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_ko.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_lt.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_lv.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_ml.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_mr.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_ms.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_nl.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_no.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_pl.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_pt-BR.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_pt-PT.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_ro.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_ru.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_sk.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_sl.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_sr.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_sv.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_sw.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_ta.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_te.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_th.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_tr.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_uk.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_ur.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_vi.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_zh-CN.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\goopdateres_zh-TW.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\psmachine.dll
c:\users\Radim\AppData\Local\Google\Update\1.3.21.165\psuser.dll
c:\users\Radim\AppData\Local\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.165\GoogleUpdateSetup.exe
c:\users\Radim\AppData\Local\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\30.0.1599.101\30.0.1599.101_30.0.1599.69_chrome_updater.exe
c:\users\Radim\AppData\Local\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\30.0.1599.101\30.0.1599.101_chrome_installer.exe
c:\users\Radim\AppData\Local\Google\Update\GoogleUpdate.exe
c:\users\Radim\AppData\Local\Temp\_MEI26922\_ctypes.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26922\_elementtree.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26922\_hashlib.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26922\_multiprocessing.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26922\_socket.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26922\_ssl.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26922\msvcp100.dll
c:\users\Radim\AppData\Local\Temp\_MEI26922\msvcr100.dll
c:\users\Radim\AppData\Local\temp\_MEI26922\pyexpat.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26922\pysqlite2._sqlite.pyd
c:\users\Radim\AppData\Local\temp\_MEI26922\python27.dll
c:\users\Radim\AppData\Local\Temp\_MEI26922\pythoncom27.dll
c:\users\Radim\AppData\Local\Temp\_MEI26922\PyWinTypes27.dll
c:\users\Radim\AppData\Local\Temp\_MEI26922\select.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26922\unicodedata.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26922\win32api.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26922\win32com.shell.shell.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26922\win32crypt.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26922\win32event.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26922\win32file.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26922\win32inet.pyd
c:\users\Radim\AppData\Local\temp\_MEI26922\win32pdh.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26922\win32process.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26922\win32profile.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26922\win32security.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26922\win32ts.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26922\windows._cacheinvalidation.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26922\wx._controls_.pyd
c:\users\Radim\AppData\Local\temp\_MEI26922\wx._core_.pyd
c:\users\Radim\AppData\Local\temp\_MEI26922\wx._gdi_.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26922\wx._html2.pyd
c:\users\Radim\AppData\Local\Temp\_MEI26922\wx._misc_.pyd
c:\users\Radim\AppData\Local\temp\_MEI26922\wx._windows_.pyd
c:\users\Radim\AppData\Local\temp\_MEI26922\wx._wizard.pyd
c:\users\Radim\AppData\Local\temp\_MEI26922\wxbase294u_net_vc90.dll
c:\users\Radim\AppData\Local\temp\_MEI26922\wxbase294u_vc90.dll
c:\users\Radim\AppData\Local\temp\_MEI26922\wxmsw294u_adv_vc90.dll
c:\users\Radim\AppData\Local\Temp\_MEI26922\wxmsw294u_core_vc90.dll
c:\users\Radim\AppData\Local\Temp\_MEI26922\wxmsw294u_html_vc90.dll
c:\users\Radim\AppData\Local\Temp\_MEI26922\wxmsw294u_webview_vc90.dll
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2916595278-2769544797-2451419562-1000Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2916595278-2769544797-2451419562-1000UA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_SkypeUpdate
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_SkypeUpdate
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-09-24 do 2013-10-24 )))))))))))))))))))))))))))))))
.
.
2013-10-24 12:20 . 2013-10-24 12:20 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-10-24 12:20 . 2013-10-24 12:20 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-10-22 18:41 . 2013-10-24 12:20 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7F69D9A0-372C-4929-82A9-3AB1BDFBACB3}\offreg.dll
2013-10-22 06:57 . 2013-10-14 06:39 7796464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7F69D9A0-372C-4929-82A9-3AB1BDFBACB3}\mpengine.dll
2013-10-21 09:02 . 2013-10-21 09:02 -------- d-----w- c:\programdata\Oracle
2013-10-21 09:02 . 2013-10-21 09:02 -------- d-----w- c:\program files\Common Files\Java
2013-10-21 09:02 . 2013-10-21 09:02 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-10-21 09:02 . 2013-10-21 09:02 -------- d-----w- c:\program files\Java
2013-10-21 08:31 . 2013-10-21 08:31 -------- d-----w- c:\windows\ERUNT
2013-10-21 08:27 . 2013-10-22 08:17 -------- d-----w- C:\AdwCleaner
2013-10-21 08:06 . 2013-10-21 08:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-10-21 08:06 . 2013-04-04 12:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-10-20 16:12 . 2013-10-20 16:12 388096 ----a-r- c:\users\Radim\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-10-20 16:12 . 2013-10-20 16:12 -------- d-----w- c:\program files\Trend Micro
2013-10-10 12:29 . 2013-09-08 02:07 1294272 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-10-10 12:29 . 2013-07-03 03:36 55808 ----a-w- c:\windows\system32\drivers\hidclass.sys
2013-10-10 12:29 . 2013-07-03 03:36 25728 ----a-w- c:\windows\system32\drivers\hidparse.sys
2013-10-10 12:29 . 2013-09-14 00:48 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2013-10-10 12:29 . 2013-09-08 02:03 231424 ----a-w- c:\windows\system32\mswsock.dll
2013-10-10 12:29 . 2013-07-20 10:33 102608 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 12:29 . 2013-08-28 00:57 434688 ----a-w- c:\windows\system32\scavengeui.dll
2013-10-10 12:29 . 2013-07-04 11:50 530432 ----a-w- c:\windows\system32\comctl32.dll
2013-10-10 12:29 . 2013-08-01 11:03 729024 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-10-10 12:28 . 2013-08-29 01:12 28160 ----a-w- c:\windows\system32\drivers\usbser.sys
2013-10-10 12:28 . 2013-08-29 01:51 3969472 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-10-10 12:28 . 2013-08-29 01:51 3914176 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-10-10 12:28 . 2013-08-29 01:50 1289096 ----a-w- c:\windows\system32\ntdll.dll
2013-10-10 12:28 . 2013-08-29 01:50 619520 ----a-w- c:\windows\system32\tdh.dll
2013-10-10 12:28 . 2013-08-29 01:48 640512 ----a-w- c:\windows\system32\advapi32.dll
2013-10-10 12:19 . 2013-08-28 01:04 2348544 ----a-w- c:\windows\system32\win32k.sys
2013-10-10 12:19 . 2013-06-06 04:52 26112 ----a-w- c:\windows\system32\lpk.dll
2013-10-10 12:19 . 2013-06-06 04:51 70656 ----a-w- c:\windows\system32\fontsub.dll
2013-10-10 12:19 . 2013-06-06 04:50 10240 ----a-w- c:\windows\system32\dciman32.dll
2013-10-10 12:19 . 2013-06-06 03:01 295424 ----a-w- c:\windows\system32\atmfd.dll
2013-10-10 12:19 . 2013-06-06 03:01 34304 ----a-w- c:\windows\system32\atmlib.dll
2013-10-10 12:19 . 2013-07-04 11:57 205824 ----a-w- c:\windows\system32\WebClnt.dll
2013-10-10 12:19 . 2013-07-04 11:51 81920 ----a-w- c:\windows\system32\davclnt.dll
2013-10-10 12:19 . 2013-07-04 09:48 115712 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2013-10-10 12:17 . 2013-07-12 10:07 86016 ----a-w- c:\windows\system32\drivers\usbcir.sys
2013-10-10 12:17 . 2013-06-25 22:56 527064 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2013-10-08 05:45 . 2013-10-08 05:45 -------- d-----w- c:\users\Default\AppData\Local\Google
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-10-10 12:51 . 2012-05-04 11:10 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-10-10 12:51 . 2011-05-24 06:33 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-04 12:58 . 2013-02-26 17:57 88840 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-09-03 12:35 . 2010-09-19 10:39 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-08-20 08:29 . 2013-05-07 12:27 66144 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2013-08-20 08:29 . 2013-02-26 17:57 136672 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-08-05 01:56 . 2013-09-12 06:54 133056 ----a-w- c:\windows\system32\drivers\ataport.sys
2013-08-02 01:50 . 2013-09-12 06:54 169984 ----a-w- c:\windows\system32\winsrv.dll
2013-08-02 01:49 . 2013-09-12 06:54 293376 ----a-w- c:\windows\system32\KernelBase.dll
2013-08-02 01:48 . 2013-09-12 06:54 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 4096 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-08-02 01:48 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-08-02 00:52 . 2013-09-12 06:54 271360 ----a-w- c:\windows\system32\conhost.exe
2013-08-02 00:43 . 2013-09-12 06:54 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-08-02 00:43 . 2013-09-12 06:54 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-08-02 00:43 . 2013-09-12 06:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-08-02 00:43 . 2013-09-12 06:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-08-14 20:34 222832 ----a-w- c:\users\Radim\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-08-14 20:34 222832 ----a-w- c:\users\Radim\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-08-14 20:34 222832 ----a-w- c:\users\Radim\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 131248 ----a-w- c:\users\Radim\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 131248 ----a-w- c:\users\Radim\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 131248 ----a-w- c:\users\Radim\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2013-09-25 15:37 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-10-02 20472992]
"GoogleDriveSync"="c:\program files\Google\Drive\googledrivesync.exe" [2013-09-25 20133824]
"SkyDrive"="c:\users\Radim\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" [2013-08-14 257136]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-12-08 8120864]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-08-20 347192]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
.
c:\users\Radim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Radim\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-10-10 29768376]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKLM\~\startupfolder\C:^Users^Radim^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
path=c:\users\Radim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KeePass 2 PreLoad]
2010-09-05 08:30 1655296 ----a-w- c:\program files\KeePass Password Safe 2\KeePass.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
2011-09-01 12:39 966712 ----a-w- c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
.
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-09-20 1343400]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-12-20 691696]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2013-04-02 37352]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\program files\HWiNFO32\HWiNFO32.SYS [2012-02-07 21752]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2013-08-20 84024]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-08-20 189440]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2013-10-23 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-04 12:51]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
TCP: Interfaces\{95E635F5-B84E-4D33-8076-47AB93A275F0}: NameServer = 62.129.50.20,85.135.32.100
FF - ProfilePath - c:\users\Radim\AppData\Roaming\Mozilla\Firefox\Profiles\traxidc3.radim\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/
FF - prefs.js: keyword.URL - hxxp://www.google.cz/search?q=
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2916595278-2769544797-2451419562-1000\Software\SecuROM\License information*]
"datasecu"=hex:e1,79,69,2d,e5,82,81,46,a3,90,42,13,8c,01,f3,4e,1f,44,47,28,f1,
43,a9,05,c3,1e,78,e8,ec,a0,f9,8c,9c,b0,7f,1c,39,63,95,1c,60,2c,31,39,65,2d,\
"rkeysecu"=hex:29,96,1e,0c,de,07,64,b4,bf,19,4a,ea,a2,1e,6e,29
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\taskhost.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\conhost.exe
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer.exe
c:\users\Radim\AppData\Roaming\Dropbox\bin\Dropbox.exe
.
**************************************************************************
.
Celkový čas: 2013-10-24 14:30:57 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-10-24 12:30
ComboFix2.txt 2013-10-22 18:48
ComboFix3.txt 2012-11-17 12:18
.
Před spuštěním: 6 847 176 704
Po spuštění: 6 590 365 696
.
- - End Of File - - 8FF7772AA256F98676B4D3FA8FDD2D75
A36C5E4F47E84449FF07ED3517B43A31
-----------------------------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:33:07, on 24.10.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16514)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Google\Drive\googledrivesync.exe
C:\Users\Radim\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
C:\Users\Radim\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\Google\Drive\googledrivesync.exe
C:\Windows\system32\notepad.exe
C:\Windows\Explorer.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart
O4 - HKCU\..\Run: [SkyDrive] "C:\Users\Radim\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
O4 - Startup: Dropbox.lnk = C:\Users\Radim\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{95E635F5-B84E-4D33-8076-47AB93A275F0}: NameServer = 62.129.50.20,85.135.32.100
O17 - HKLM\System\CS1\Services\Tcpip\..\{95E635F5-B84E-4D33-8076-47AB93A275F0}: NameServer = 62.129.50.20,85.135.32.100
O17 - HKLM\System\CS2\Services\Tcpip\..\{95E635F5-B84E-4D33-8076-47AB93A275F0}: NameServer = 62.129.50.20,85.135.32.100
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 5533 bytes
-----------------------------------------------------------
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-10-24 14:40:53
-----------------------------
14:40:53.001 OS Version: Windows 6.1.7601 Service Pack 1
14:40:53.001 Number of processors: 2 586 0x6B02
14:40:53.003 ComputerName: RADIM-PC UserName: Radim
14:40:54.193 Initialize success
14:41:04.775 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
14:41:04.785 Disk 0 Vendor: WDC_WD5000AACS-00ZUB0 01.01B01 Size: 476940MB BusType: 3
14:41:04.785 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-2
14:41:04.795 Disk 1 Vendor: WDC_WD3200AAKS-00C9A0 12.01B02 Size: 305244MB BusType: 3
14:41:04.805 Disk 1 MBR read successfully
14:41:04.805 Disk 1 MBR scan
14:41:04.815 Disk 1 Windows 7 default MBR code
14:41:04.825 Disk 1 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
14:41:04.835 Disk 1 Partition 2 00 07 HPFS/NTFS NTFS 64897 MB offset 206848
14:41:04.845 Disk 1 Partition 3 00 07 HPFS/NTFS NTFS 240244 MB offset 133115904
14:41:04.855 Disk 1 scanning sectors +625135616
14:41:04.905 Disk 1 scanning C:\Windows\system32\drivers
14:41:22.483 Service scanning
14:41:30.433 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32
14:41:33.073 Modules scanning
14:41:43.983 Disk 1 trace - called modules:
14:41:43.993 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll >>UNKNOWN [0x84e7a1f8]<<
14:41:44.003 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0x85cdb030]
14:41:44.013 3 CLASSPNP.SYS[894a359e] -> nt!IofCallDriver -> [0x85b6e830]
14:41:44.013 5 ACPI.sys[88d5e3d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T1L0-2[0x85ba8908]
14:41:44.023 \Driver\atapi[0x85ba0a58] -> IRP_MJ_CREATE -> 0x84e7a1f8
14:41:44.023 Scan finished successfully
14:41:54.307 Disk 1 MBR has been saved successfully to "C:\Users\Radim\Desktop\MBR.dat"
14:41:54.323 The log file has been saved successfully to "C:\Users\Radim\Desktop\aswMBR.txt"
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosím o kontrolu - ubývající místo na disku
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall
Vyčisti systém CCleanerem
Stáhni si OTC
na plochu. Poklepej na něj. Potom klikni na Clean up!.
Restartuj PC , pokud Ti bude doporučeno.
Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod
Měl bys ještě něco odinstalovat , smazat , máš mít alespoň 15% volného místa pro windows.
Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Start-Spustit a zadej ComboFix /Uninstall
Vyčisti systém CCleanerem
Stáhni si OTC
na plochu. Poklepej na něj. Potom klikni na Clean up!.
Restartuj PC , pokud Ti bude doporučeno.
Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod
Kód: Vybrat vše
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
Měl bys ještě něco odinstalovat , smazat , máš mít alespoň 15% volného místa pro windows.
Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosím o kontrolu - ubývající místo na disku Vyřešeno
Tak jsem ještě něco odinstaloval a mám teď 10,5 GB volných. Snad už to nebude miznout tak rychle.
Díky všem za pomoc.
Díky všem za pomoc.
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 119 hostů