RUNDLL Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
BigJimmy
Level 2
Level 2
Příspěvky: 184
Registrován: červenec 11
Pohlaví: Muž
Stav:
Offline

Re: RUNDLL

Příspěvekod BigJimmy » 30 črc 2011 20:03

btw... jak Conduit Engine odinstalovat?

Reklama
Uživatelský avatar
BigJimmy
Level 2
Level 2
Příspěvky: 184
Registrován: červenec 11
Pohlaví: Muž
Stav:
Offline

Re: RUNDLL

Příspěvekod BigJimmy » 30 črc 2011 20:27

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named firefox.exe was found!
Service HidServ stopped successfully!
Service HidServ deleted successfully!
File File not found not found.
Service AppMgmt stopped successfully!
Service AppMgmt deleted successfully!
File File not found not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\CustomizeSearch| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully!
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\zh-TW\ffjcext folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\zh-TW folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\zh-CN\ffjcext folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\zh-CN folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\sv-SE\ffjcext folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\sv-SE folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\ko-KR\ffjcext folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\ko-KR folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\ja-JP\ffjcext folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\ja-JP folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\it-IT\ffjcext folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\it-IT folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\fr-FR\ffjcext folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\fr-FR folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\es-ES\ffjcext folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\es-ES folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\en-US\ffjcext folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\en-US folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\de-DE\ffjcext folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\de-DE folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\content\ffjcext folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\content folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\components folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions folder moved successfully.
Folder C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\ not found.
127.0.0.1 localhost removed from HOSTS file successfully
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
Starting removal of ActiveX control {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
C:\WINDOWS\Downloaded Program Files\QTPlugin.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}\ not found.
Starting removal of ActiveX control {166B1BCA-3F9C-11CF-8075-444553540000}
C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{166B1BCA-3F9C-11CF-8075-444553540000}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{166B1BCA-3F9C-11CF-8075-444553540000}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{166B1BCA-3F9C-11CF-8075-444553540000}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{166B1BCA-3F9C-11CF-8075-444553540000}\ not found.
Starting removal of ActiveX control {41564D57-9980-0010-8000-00AA00389B71}
C:\WINDOWS\Downloaded Program Files\wmvadvd.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{41564D57-9980-0010-8000-00AA00389B71}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41564D57-9980-0010-8000-00AA00389B71}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{41564D57-9980-0010-8000-00AA00389B71}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41564D57-9980-0010-8000-00AA00389B71}\ not found.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
C:\WINDOWS\Downloaded Program Files\erma.inf not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Starting removal of ActiveX control {D27CDB6E-AE6D-11CF-96B8-444553540000}
C:\WINDOWS\Downloaded Program Files\swflash.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D27CDB6E-AE6D-11CF-96B8-444553540000}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{D27CDB6E-AE6D-11CF-96B8-444553540000}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ipp\ deleted successfully.
File Protocol\Handler\ipp - No CLSID value found not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\ deleted successfully.
File Protocol\Handler\msdaipp - No CLSID value found not found.
File not found.
File move failed. F:\AutoRun.exe scheduled to be moved on reboot.
File move failed. F:\AutoRunGUI.dll scheduled to be moved on reboot.
File move failed. F:\autorun.inf scheduled to be moved on reboot.
File not found.
File move failed. G:\AutoRun.exe scheduled to be moved on reboot.
File move failed. G:\AutoRunGUI.dll scheduled to be moved on reboot.
File move failed. G:\autorun.inf scheduled to be moved on reboot.
C:\WINDOWS\system32\perfh009.dat moved successfully.
C:\WINDOWS\system32\perfh005.dat moved successfully.
C:\WINDOWS\system32\perfc005.dat moved successfully.
C:\WINDOWS\system32\perfc009.dat moved successfully.
File C:\WINDOWS\System32\perfh009.dat not found.
File C:\WINDOWS\System32\perfh005.dat not found.
C:\WINDOWS\system32\perfi009.dat moved successfully.
C:\WINDOWS\system32\perfi005.dat moved successfully.
File C:\WINDOWS\System32\perfc005.dat not found.
File C:\WINDOWS\System32\perfc009.dat not found.
C:\WINDOWS\system32\perfd005.dat moved successfully.
C:\WINDOWS\system32\perfd009.dat moved successfully.
========== FILES ==========
File\Folder C:\WINDOWS\System32\*.tmp not found.
File\Folder C:\WINDOWS\*.tmp not found.
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\System32\dllcache\*.tmp not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully.
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully.
File\Folder C:\*.tmp not found.
File\Folder C:\Documents and Settings\All Users\Data aplikací\*.tmp not found.
C:\found.000 folder moved successfully.
C:\Program Files\COMODO\COMODO Internet Security\translations folder moved successfully.
C:\Program Files\COMODO\COMODO Internet Security\themes folder moved successfully.
C:\Program Files\COMODO\COMODO Internet Security\scanners folder moved successfully.
C:\Program Files\COMODO\COMODO Internet Security\repair folder moved successfully.
C:\Program Files\COMODO\COMODO Internet Security\database folder moved successfully.
C:\Program Files\COMODO\COMODO Internet Security folder moved successfully.
C:\Program Files\COMODO folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Comodo\Installer folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Comodo folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Comodo Downloader folder moved successfully.
C:\Documents and Settings\Minařík\Plocha\cfw_installer.exe moved successfully.
C:\WINDOWS\SWREG.exe moved successfully.
C:\WINDOWS\SWSC.exe moved successfully.
C:\WINDOWS\SWXCACLS.exe moved successfully.
C:\WINDOWS\NIRCMD.exe moved successfully.
C:\Qoobox\Quarantine\Registry_backups folder moved successfully.
C:\Qoobox\Quarantine\C\WINDOWS\Tasks folder moved successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32 folder moved successfully.
C:\Qoobox\Quarantine\C\WINDOWS\Downloaded Program Files folder moved successfully.
C:\Qoobox\Quarantine\C\WINDOWS folder moved successfully.
C:\Qoobox\Quarantine\C\PROGRA~1\MYWEBS~1\bar\1.bin folder moved successfully.
C:\Qoobox\Quarantine\C\PROGRA~1\MYWEBS~1\bar folder moved successfully.
C:\Qoobox\Quarantine\C\PROGRA~1\MYWEBS~1 folder moved successfully.
C:\Qoobox\Quarantine\C\PROGRA~1 folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\video activex object folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\SystemDoctor 2006 Free folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\SrchAstt\1.bin folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\SrchAstt folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Settings folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Notifier folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Message folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\icons folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\History folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Game folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Cache folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Avatar folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\MyWebSearch folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\Internet Explorer folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\HTV folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\FunWebProducts\Shared\Cache folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\FunWebProducts\Shared folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\FunWebProducts\ScreenSaver\Images folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\FunWebProducts\ScreenSaver folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\FunWebProducts folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files\DaemonTools_WhenUSave_Installer folder moved successfully.
C:\Qoobox\Quarantine\C\Program Files folder moved successfully.
C:\Qoobox\Quarantine\C folder moved successfully.
C:\Qoobox\Quarantine folder moved successfully.
Folder move failed. C:\Qoobox\BackEnv scheduled to be moved on reboot.
C:\Qoobox folder moved successfully.
C:\Documents and Settings\Minařík\Plocha\ComboFix.exe moved successfully.
File\Folder C:\Documents and Settings\Minařík\Plocha\cfw_installer.exe not found.
C:\WINDOWS\System32\drivers\fwdrv.err moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts moved successfully.
C:\WINDOWS\PEV.exe moved successfully.
C:\WINDOWS\MBR.exe moved successfully.
C:\WINDOWS\sed.exe moved successfully.
C:\WINDOWS\grep.exe moved successfully.
C:\WINDOWS\zip.exe moved successfully.
C:\WINDOWS\System32\exp16sys.dll moved successfully.
C:\WINDOWS\System32\syscl.exe moved successfully.
C:\WINDOWS\dsez5867.dat moved successfully.
C:\WINDOWS\SETUP32.INI moved successfully.
C:\WINDOWS\setup_rangers.exe moved successfully.
C:\WINDOWS\LEBALKS5.INI moved successfully.
C:\WINDOWS\System32\5581115F18.dll moved successfully.
C:\WINDOWS\unins001.exe moved successfully.
C:\WINDOWS\unins001.dat moved successfully.
C:\WINDOWS\System32\unrar.dll moved successfully.
C:\WINDOWS\unins000.dat moved successfully.
C:\Documents and Settings\Minařík\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini moved successfully.
C:\Documents and Settings\All Users\Data aplikací\AVG10\scanlogs folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\AVG10\log\IDP\log folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\AVG10\log\IDP folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\AVG10\log folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\AVG10\Dumps folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\AVG10 folder moved successfully.
C:\Documents and Settings\Minařík\Data aplikací\AVG10\cfgall folder moved successfully.
C:\Documents and Settings\Minařík\Data aplikací\AVG10 folder moved successfully.
C:\WINDOWS\System32\搀ģ moved successfully.
File\Folder C:\WINDOWS\System32\搀ģ not found.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirstRunDisabled deleted successfully.
========== COMMANDS ==========
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: fanda

User: LocalService
->Temp folder emptied: 65748 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->FireFox cache emptied: 0 bytes

User: Minak
->Temp folder emptied: 0 bytes

User: Minařík

User: Minařík
->Temp folder emptied: 151628593 bytes
->Temporary Internet Files folder emptied: 26302389 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 21494592 bytes
->Flash cache emptied: 1054 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 7396464 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 21456486 bytes

Total Files Cleaned = 218.00 mb


[EMPTYFLASH]

User: All Users

User: Default User

User: fanda

User: LocalService

User: Minak

User: Minařík

User: Minařík
->Flash cache emptied: 0 bytes

User: NetworkService

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.26.1 log created on 07302011_201919

Files\Folders moved on Reboot...
File move failed. F:\AutoRun.exe scheduled to be moved on reboot.
File move failed. F:\AutoRunGUI.dll scheduled to be moved on reboot.
File move failed. F:\autorun.inf scheduled to be moved on reboot.
File move failed. G:\AutoRun.exe scheduled to be moved on reboot.
File move failed. G:\AutoRunGUI.dll scheduled to be moved on reboot.
File move failed. G:\autorun.inf scheduled to be moved on reboot.
File\Folder C:\Qoobox\BackEnv not found!
C:\Documents and Settings\Minařík\Local Settings\Temp\WCESLog.log moved successfully.
File move failed. C:\WINDOWS\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...


Uživatelský avatar
BigJimmy
Level 2
Level 2
Příspěvky: 184
Registrován: červenec 11
Pohlaví: Muž
Stav:
Offline

Re: RUNDLL

Příspěvekod BigJimmy » 30 črc 2011 21:03

TA KONTROLA CHKDSK NETRVALA ANI PUL MINUTY... NAPSALO TO MYSLIM, ZE NEJSOU ZADNE CHYBY.. NEBO NECO V TOM SMYSLU , PROTOZE SE SPUSTILA AUTOMATICKY ODPOLEDNE, KDYZ JSEM RESTARTOVAL POCITAC.... TO SMAZALO A OBNOVILO DOST SOUBORŮ ..... TED JDU ZKUSIT TY RAMKY.. ANO MAM TAM 2 RAMKY PO 1 GB ... JINAK ZITRA TU NEBUDU, BUDU TU AZ V PONDELI....

Uživatelský avatar
BigJimmy
Level 2
Level 2
Příspěvky: 184
Registrován: červenec 11
Pohlaví: Muž
Stav:
Offline

Re: RUNDLL

Příspěvekod BigJimmy » 31 črc 2011 12:29

Tak memtest ukazal 0 erorů (ja jsem to nevidel, rikala to babicka, ale ja ji verim :D ) , jinak ted u ni nejsem, jsem doma, tak budem pokracovat zitra....

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: RUNDLL

Příspěvekod jaro3 » 31 črc 2011 19:16

Půl minuty??

Tu kontrolu disku udělej s opravou. V příkazovém řádku stačí napsat :
chkdsk /f
a povolit test při dalším spuštění počítače.

Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

:Files
C:\WINDOWS\System32\ppt2exe_uninstall.exe

:Reg
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]


Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
BigJimmy
Level 2
Level 2
Příspěvky: 184
Registrován: červenec 11
Pohlaví: Muž
Stav:
Offline

Re: RUNDLL

Příspěvekod BigJimmy » 31 črc 2011 19:58

btw ten test jsem zkousel u sebe doma, a je tam 10 vterin na zruseni :/ ... ja jsem to asi omylem zrusil .. nejsem si jistej, ale vzhledem k timu, jak dlouho to trvalo u me, tak si myslim ze sem to musel nejak zrusit :/ ... zkusim to znova zitra ....

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: RUNDLL

Příspěvekod jaro3 » 31 črc 2011 20:16

asi jo , dej vědět.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
BigJimmy
Level 2
Level 2
Příspěvky: 184
Registrován: červenec 11
Pohlaví: Muž
Stav:
Offline

Re: RUNDLL

Příspěvekod BigJimmy » 01 srp 2011 15:25

tak ted probehl test chkdsk v porádku .... asi to teda nic neopravilo (vetsinou to pise treba. smazano to a to, atd... ted to jenom bezely procenta....) ted jdu na to otl

Uživatelský avatar
BigJimmy
Level 2
Level 2
Příspěvky: 184
Registrován: červenec 11
Pohlaví: Muž
Stav:
Offline

Re: RUNDLL

Příspěvekod BigJimmy » 01 srp 2011 15:32

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named firefox.exe was found!
========== FILES ==========
C:\WINDOWS\System32\ppt2exe_uninstall.exe moved successfully.
========== REGISTRY ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: fanda

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->FireFox cache emptied: 0 bytes

User: Minak
->Temp folder emptied: 0 bytes

User: Minařík

User: Minařík
->Temp folder emptied: 47729 bytes
->Temporary Internet Files folder emptied: 3351949 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 16384 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 3.00 mb


OTL by OldTimer - Version 3.2.26.1 log created on 08012011_152700

Files\Folders moved on Reboot...
C:\Documents and Settings\Minařík\Local Settings\Temp\WCESLog.log moved successfully.
File move failed. C:\WINDOWS\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Uživatelský avatar
BigJimmy
Level 2
Level 2
Příspěvky: 184
Registrován: červenec 11
Pohlaví: Muž
Stav:
Offline

Re: RUNDLL

Příspěvekod BigJimmy » 01 srp 2011 19:03

btw .. koukal jsem na video na youtube a najednou se mi v pulce videa vypnul pc .... :/

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: RUNDLL

Příspěvekod jaro3 » 01 srp 2011 19:13

Tak to už mě napadá jen zdroj..
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 90 hostů