Dobrý den, už asi 14 dní řaším zavirovaný počítat, skoro nepoužitelný. prosím o pomoc s vyčištěním, pokud se to ještě dá. přikládám log. vir jsem chytl po stahování z torrentů, nejspíš ze souboru torntv.exe...
Logfile of random's system information tool 1.10 (written by random/random)
Run by Honza at 2014-10-31 23:11:19
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 268 GB (56%) free of 477 GB
Total RAM: 2047 MB (58% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:11:51, on 31. 10. 2014
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\WINDOWS\system32\regsvr32.exe
C:\WINDOWS\system32\regsvr32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Honza\Dokumenty\Downloads\photoshop-cs5-cz-portable-bez-instalace\Photoshop CS5\LogTransport2.exe
C:\Documents and Settings\Honza\Plocha\RSIT.exe
C:\Program Files\trend micro\Honza.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [Ivdksoft] C:\Documents and Settings\Honza\Local Settings\Data aplikací\Ivdksoft\tmp5.exe
O4 - HKCU\..\Run: [Ufzmedia] regsvr32.exe "C:\Documents and Settings\Honza\Local Settings\Data aplikací\Ufzmedia\ITunestst.dll"
O4 - HKCU\..\Run: [UZGmedia] C:\WINDOWS\system32\regsvr32.exe "C:\Documents and Settings\Honza\Local Settings\Data aplikací\Ivdksoft\NormalSnap54.dll"
O4 - HKCU\..\RunOnce: [WiseStubReboot] MSIEXEC /quiet SKIP_PPU_DRIVER_INSTALL=1 /I "C:\Program Files\Common Files\Wise Installation Wizard\WISB83FC356B7C0441F8A4DD71E088E7974_9_09_0428.MSI" TRANSFORMS="C:\Program Files\Common Files\Wise Installation Wizard\WISB83FC356B7C0441F8A4DD71E088E7974_9_09_0428.MST" WISE_SETUP_EXE_PATH="c:\nvidia\displaydriver\186.18\international\PhysX_9.09.0428_SystemSoftware.exe"
O4 - Startup: fsutil.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
--
End of file - 7498 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\avast! Emergency Update.job - C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
C:\WINDOWS\tasks\Check for updates (Spybot - Search & Destroy).job - C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe /autoupdate /silent /autoclose /background
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job - C:\WINDOWS\system32\xp_eos.exe
C:\WINDOWS\tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job - C:\WINDOWS\system32\xp_eos.exe -c
C:\WINDOWS\tasks\Refresh immunization (Spybot - Search & Destroy).job - C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe /immunize /silent /autoclose
C:\WINDOWS\tasks\Scan the system (Spybot - Search & Destroy).job - C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe /scan /cleanclose
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Honza\Data aplikací\Mozilla\Firefox\Profiles\ks8kmsns.default
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
"{20a82645-c095-46ed-80e3-08825760534b}"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.145 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\plugins\
NPOFF12.DLL
nppdf32.dll
npwachk.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2013-05-08 77424]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2011-08-09 20055144]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-07-31 4085896]
"nwiz"=nwiz.exe /install []
"SDTray"=C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [2014-06-24 4101576]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2014-09-26 4811032]
"Ivdksoft"=C:\Documents and Settings\Honza\Local Settings\Data aplikací\Ivdksoft\tmp5.exe []
"Ufzmedia"=regsvr32.exe C:\Documents and Settings\Honza\Local Settings\Data aplikací\Ufzmedia\ITunestst.dll []
"UZGmedia"=C:\WINDOWS\system32\regsvr32.exe [2008-04-14 12288]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WiseStubReboot"=MSIEXEC /quiet SKIP_PPU_DRIVER_INSTALL=1 /I C:\Program Files\Common Files\Wise Installation Wizard\WISB83FC356B7C0441F8A4DD71E088E7974_9_09_0428.MSI TRANSFORMS=C:\Program Files\Common Files\Wise Installation Wizard\WISB83FC356B7C0441F8A4DD71E088E7974_9_09_0428.MST WISE_SETUP_EXE_PATH=c:\nvidia\displaydriver\186.18\international\PhysX_9.09.0428_SystemSoftware.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2013-05-08 41056]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2012-04-17 3671872]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EasyTuneV]
C:\Program Files\Gigabyte\ET5\ETcall.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ivdksoft]
C:\Documents and Settings\Honza\Local Settings\Data aplikací\Ivdksoft\tmp4D.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
C:\Program Files\Labtec\WebCam10\WebCam10.exe /hide []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS\system32\NvCpl.dll [2009-06-10 13758464]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2009-06-10 86016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce]
C:\Program Files\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files\Steam\steam.exe [2014-10-21 1938624]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ufzmedia]
regsvr32.exe C:\Documents and Settings\Honza\Local Settings\Data aplikací\Ufzmedia\wmi3xx.dll []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UZGmedia]
C:\WINDOWS\system32\regsvr32.exe [2008-04-14 12288]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebCake Desktop]
C:\Documents and Settings\Honza\Data aplikací\WebCake\WebCakeDesktop.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SkypeUpdate"=2
C:\Documents and Settings\Honza\Nabídka Start\Programy\Po spuštění
fsutil.lnk - C:\Documents and Settings\Honza\Data aplikací\Microsoft\Windows\IEUpdate\fsutil.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SDWinLogon]
SDWinLogon.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Winamp\winamp.exe"="C:\Program Files\Winamp\winamp.exe:*:Enabled:Winamp"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Half Life 2\root\hl2.exe"="C:\Program Files\Half Life 2\root\hl2.exe:*:Enabled:hl2"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Call of Duty 4\iw3mp.exe"="C:\Call of Duty 4\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Documents and Settings\Honza\Plocha\Call of Duty 4\iw3mp.exe"="C:\Documents and Settings\Honza\Plocha\Call of Duty 4\iw3mp.exe:*:Enabled:iw3mp"
"C:\Documents and Settings\Honza\Plocha\Call of Duty 2\CoD2MP_s.exe"="C:\Documents and Settings\Honza\Plocha\Call of Duty 2\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"C:\Documents and Settings\Honza\Plocha\Age II\empires2.exe"="C:\Documents and Settings\Honza\Plocha\Age II\empires2.exe:*:Enabled:Age of Empires II"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"C:\Games\World_of_Tanks\WoTLauncher.exe"="C:\Games\World_of_Tanks\WoTLauncher.exe:*:Enabled:World of Tanks Launcher"
"C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe"="C:\Program Files\Steam\SteamApps\common\dota 2 beta\dota.exe:*:Enabled:Dota 2"
"C:\Program Files\Google\Chrome\Application\chrome.exe"="C:\Program Files\Google\Chrome\Application\chrome.exe:*:Enabled:Google Chrome"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Enabled:Windows Expolrer"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Windows host process (Rundll32)"
"C:\Program Files\Activision\Modern Warfare 2\iw4mp.exe"="C:\Program Files\Activision\Modern Warfare 2\iw4mp.exe:*:Disabled:iw4mp"
"C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot - Search & Destroy tray access"
"C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service"
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater"
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=lvcodec2.dll
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo"=vfwwdm32.dll
"MSVideo8"=VfWWDM32.dll
======List of files/folders created in the last 1 month======
2014-10-29 21:14:32 ----D---- C:\Documents and Settings\Honza\Data aplikací\Malwarebytes
2014-10-29 21:13:49 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2014-10-29 21:13:49 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2014-10-28 15:13:48 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2014-10-27 16:05:51 ----D---- C:\WINDOWS\system32\_avast_
2014-10-27 16:00:32 ----D---- C:\Documents and Settings\Honza\Data aplikací\ParetoLogic
2014-10-27 16:00:32 ----D---- C:\Documents and Settings\Honza\Data aplikací\DriverCure
2014-10-27 15:55:30 ----D---- C:\TEMP
2014-10-27 15:52:00 ----D---- C:\Documents and Settings\All Users\Data aplikací\ParetoLogic
2014-10-27 14:35:27 ----A---- C:\WINDOWS\system32\sdnclean.exe
2014-10-27 14:35:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2014-10-27 14:35:18 ----D---- C:\Program Files\Spybot - Search & Destroy 2
2014-10-22 19:58:55 ----D---- C:\_OTM
2014-10-12 18:05:24 ----D---- C:\Documents and Settings\Honza\Data aplikací\Mozilla
2014-10-02 14:49:31 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
======List of files/folders modified in the last 1 month======
2014-10-31 23:11:33 ----D---- C:\WINDOWS\Prefetch
2014-10-31 23:11:24 ----D---- C:\Program Files\trend micro
2014-10-31 19:41:25 ----D---- C:\WINDOWS\system32
2014-10-31 19:41:25 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-10-31 19:37:00 ----D---- C:\WINDOWS\system32\CatRoot2
2014-10-31 19:35:31 ----A---- C:\WINDOWS\SchedLgU.Txt
2014-10-31 19:31:32 ----D---- C:\Documents and Settings\Honza\Data aplikací\uTorrent
2014-10-31 19:21:17 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2014-10-31 19:21:17 ----D---- C:\WINDOWS\system32\drivers
2014-10-30 22:01:10 ----D---- C:\WINDOWS
2014-10-30 21:50:32 ----D---- C:\Program Files\Steam
2014-10-29 22:06:23 ----SD---- C:\Documents and Settings\Honza\Data aplikací\Microsoft
2014-10-29 21:13:49 ----D---- C:\Program Files
2014-10-28 15:23:23 ----D---- C:\WINDOWS\Temp
2014-10-27 22:05:02 ----SH---- C:\boot.ini
2014-10-27 22:05:02 ----A---- C:\WINDOWS\win.ini
2014-10-27 22:05:02 ----A---- C:\WINDOWS\system.ini
2014-10-27 16:09:08 ----SD---- C:\WINDOWS\Tasks
2014-10-27 16:09:08 ----D---- C:\Program Files\Common Files
2014-10-27 14:58:35 ----D---- C:\WINDOWS\system32\drivers\etc
2014-10-27 14:57:14 ----D---- C:\WINDOWS\system32\inetsrv
2014-10-27 14:35:33 ----D---- C:\WINDOWS\system32\config
2014-10-27 14:35:32 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2014-10-26 20:45:14 ----D---- C:\AdwCleaner
2014-10-26 19:11:38 ----A---- C:\WINDOWS\NeroDigital.ini
2014-10-25 17:05:06 ----SHD---- C:\WINDOWS\Installer
2014-10-25 17:00:30 ----D---- C:\WINDOWS\Debug
2014-10-24 18:22:54 ----D---- C:\WINDOWS\system32\MRT
2014-10-24 18:17:33 ----A---- C:\WINDOWS\system32\MRT.exe
2014-10-21 21:14:12 ----D---- C:\Documents and Settings\Honza\Data aplikací\TS3Client
2014-10-21 20:37:30 ----D---- C:\WINDOWS\Minidump
2014-10-21 20:36:08 ----D---- C:\Program Files\CCleaner
2014-10-10 14:58:00 ----D---- C:\WINDOWS\Microsoft.NET
2014-10-10 14:57:56 ----RSD---- C:\WINDOWS\assembly
2014-10-05 19:59:58 ----D---- C:\Program Files\Common Files\Steam
2014-10-03 15:41:59 ----D---- C:\WINDOWS\WinSxS
2014-10-02 14:51:05 ----D---- C:\WINDOWS\system32\CatRoot
2014-10-02 14:50:17 ----HD---- C:\WINDOWS\inf
2014-10-02 14:49:42 ----RSHDC---- C:\WINDOWS\system32\dllcache
2014-10-02 14:36:27 ----D---- C:\WINDOWS\system32\XPSViewer
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2014-07-09 49944]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2014-07-09 192352]
R0 nvata;nvata; C:\WINDOWS\system32\DRIVERS\nvata.sys [2006-04-24 100736]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2011-03-04 45648]
R1 AswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2014-07-09 55112]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2014-07-09 779536]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2014-07-09 414520]
R1 aswTdi;aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [2014-07-09 57800]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2012-11-07 242240]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2014-07-09 24184]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2014-07-09 67824]
R2 Hardlock;Hardlock; \??\C:\WINDOWS\system32\drivers\hardlock.sys []
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2011-08-16 6427240]
R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys []
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-06-10 8087712]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-03-22 52736]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-03-22 18944]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 ALSysIO;ALSysIO; \??\C:\DOCUME~1\Honza\LOCALS~1\Temp\ALSysIO.sys []
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 BthEnum;Služba Bluetooth Enumerator; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
S3 BTHMODEM;Ovladač pro sériovou komunikaci protokolem Bluetooth; C:\WINDOWS\system32\DRIVERS\bthmodem.sys [2008-04-13 37888]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
S3 BTHPORT;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 272128]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\DRIVERS\LVUSBSta.sys []
S3 MarkFun_NT;MarkFun_NT; \??\C:\Program Files\Gigabyte\ET5\markfun.w32 []
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 PID_0928;Logitech QuickCam Express(PID_0928); C:\WINDOWS\system32\DRIVERS\LV561AV.SYS []
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-07-03 14976]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-07-09 50344]
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2012-12-27 66872]
R2 SDScannerService;Spybot-S&D 2 Scanner Service; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [2014-06-24 1738168]
R2 SDUpdateService;Spybot-S&D 2 Updating Service; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2014-06-27 2088408]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-01-26 116648]
S2 SDWSCService;Spybot-S&D 2 Security Center Service; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [2014-04-25 171928]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-16 262320]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-01-26 116648]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-04-13 792112]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-05-16 271920]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2012-11-12 72704]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2014-09-23 833728]
S4 CCALib8;Canon Camera Access Library 8; C:\Program Files\Canon\CAL\CALMAIN.exe [2006-03-30 96341]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-06-10 168004]
S4 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-01-08 161536]
-----------------EOF-----------------
zavirované pc
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: zavirované pc
Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.
Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
Stáhni AdwCleaner (by Xplode)
http://www.bleepingcomputer.com/download/adwcleaner/
Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.
Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.
Stáhni AdwCleaner (by Xplode)
http://www.bleepingcomputer.com/download/adwcleaner/
Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.
Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit
-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: zavirované pc
TFC běží na zavirovaném PC (druhém stolním) už asi 3/4 hodiny, a žádný progres není vidět. jako by byl seknutý. on se totiž při prvním pokusu, kdy běžel asi 20 minut a bez zjevných známek progresu seknul (když jsem pohnul s oknem, tak tam bylo že neodpovídá, tak jsem resetnul PC a postup opakuji). ale už to zase běží asi 3/4hodiny a nic ....kontrolka procesoru jen sem tam problikne.
ještě jedna poznámka, když mi běžel, tak AVG zablokoval nějaký Cidox-d proces, asi ten rootkit, jestli vám to pomůže...
díky za pomoc
Honza
ještě jedna poznámka, když mi běžel, tak AVG zablokoval nějaký Cidox-d proces, asi ten rootkit, jestli vám to pomůže...
díky za pomoc
Honza
Re: zavirované pc
tak asi nai po hodině se to nehlo z místa, tak sem znovu resetoval pc....jak dlouho by ten proces měl trvat?
- Orcus
- člen Security týmu
-
Elite Level 10.5
- Příspěvky: 10645
- Registrován: duben 10
- Bydliště: Okolo rostou 3 růže =o)
- Pohlaví:
- Stav:
Offline
Re: zavirované pc
Takhle dlouho ne. Pokud mrzne, spusť jej v nouzovém režimu.
Láska hřeje, ale uhlí je uhlí.
Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.
Pár rad k bezpečnosti PC.
Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix
Pokud budete spokojeni , můžete podpořit naše fórum.

Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.
Pár rad k bezpečnosti PC.
Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix
Pokud budete spokojeni , můžete podpořit naše fórum.
Re: zavirované pc
už se to podařilo. jdu na ten ADW....
Re: zavirované pc
# AdwCleaner v4.001 - Report created 01/11/2014 at 19:44:33
# Updated 20/10/2014 by Xplode
# Database :
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Honza - HONZA-2C8DE4C0D
# Running from : C:\Documents and Settings\Honza\Plocha\adwcleaner_4.001.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Found : C:\Documents and Settings\All Users\Data aplikací\ParetoLogic
Folder Found : C:\Documents and Settings\Honza\Data aplikací\DriverCure
Folder Found : C:\Documents and Settings\Honza\Data aplikací\ParetoLogic
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\ParetoLogic
Key Found : HKLM\SOFTWARE\ParetoLogic
Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe]
Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe]
Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe]
Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe]
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.6001.18702
-\\ Mozilla Firefox v32.0.1 (x86 cs)
-\\ Google Chrome v38.0.2125.111
*************************
AdwCleaner[R0].txt - [4760 octets] - [20/03/2014 19:49:00]
AdwCleaner[R1].txt - [4820 octets] - [21/03/2014 14:32:08]
AdwCleaner[R2].txt - [992 octets] - [21/03/2014 14:38:47]
AdwCleaner[R3].txt - [1015 octets] - [23/03/2014 20:48:10]
AdwCleaner[R4].txt - [2010 octets] - [22/10/2014 15:58:19]
AdwCleaner[R5].txt - [1249 octets] - [26/10/2014 20:40:56]
AdwCleaner[R6].txt - [2103 octets] - [01/11/2014 19:44:33]
AdwCleaner[S0].txt - [4823 octets] - [21/03/2014 14:33:23]
AdwCleaner[S1].txt - [2014 octets] - [22/10/2014 16:00:57]
AdwCleaner[S2].txt - [1306 octets] - [26/10/2014 20:45:13]
########## EOF - C:\AdwCleaner\AdwCleaner[R6].txt - [2343 octets] ##########
# Updated 20/10/2014 by Xplode
# Database :
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Honza - HONZA-2C8DE4C0D
# Running from : C:\Documents and Settings\Honza\Plocha\adwcleaner_4.001.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Found : C:\Documents and Settings\All Users\Data aplikací\ParetoLogic
Folder Found : C:\Documents and Settings\Honza\Data aplikací\DriverCure
Folder Found : C:\Documents and Settings\Honza\Data aplikací\ParetoLogic
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\ParetoLogic
Key Found : HKLM\SOFTWARE\ParetoLogic
Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe]
Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe]
Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe]
Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe]
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.6001.18702
-\\ Mozilla Firefox v32.0.1 (x86 cs)
-\\ Google Chrome v38.0.2125.111
*************************
AdwCleaner[R0].txt - [4760 octets] - [20/03/2014 19:49:00]
AdwCleaner[R1].txt - [4820 octets] - [21/03/2014 14:32:08]
AdwCleaner[R2].txt - [992 octets] - [21/03/2014 14:38:47]
AdwCleaner[R3].txt - [1015 octets] - [23/03/2014 20:48:10]
AdwCleaner[R4].txt - [2010 octets] - [22/10/2014 15:58:19]
AdwCleaner[R5].txt - [1249 octets] - [26/10/2014 20:40:56]
AdwCleaner[R6].txt - [2103 octets] - [01/11/2014 19:44:33]
AdwCleaner[S0].txt - [4823 octets] - [21/03/2014 14:33:23]
AdwCleaner[S1].txt - [2014 octets] - [22/10/2014 16:00:57]
AdwCleaner[S2].txt - [1306 octets] - [26/10/2014 20:45:13]
########## EOF - C:\AdwCleaner\AdwCleaner[R6].txt - [2343 octets] ##########
Re: zavirované pc
ještě jdu na ten Roguekiller. Ještě pro doplnění - když jsem skenoval pc AVGčkem, našel mi tam červa nebo co Cidox-d. dal jsem automaticky vyčistit, a dopadlo to, že akce přesunuta do dalšího restartu, po restartu se ale nic dalšího nedělo....
Re: zavirované pc
RogueKiller V10.0.4.0 [Oct 29 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Operační systém : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Spuštěno : Normální režim
Uživatel : Honza [Práva správce]
Mód : Prohledat -- Datum : 11/01/2014 20:23:37
¤¤¤ Procesy : 0 ¤¤¤
¤¤¤ Registry : 13 ¤¤¤
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ALSysIO (\??\C:\DOCUME~1\Honza\LOCALS~1\Temp\ALSysIO.sys) -> Nalezeno
[Hidden.From.SCM] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\UnlockerDriver5 (\??\C:\Program Files\Unlocker\UnlockerDriver5.sys) -> Nalezeno
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ALSysIO (\??\C:\DOCUME~1\Honza\LOCALS~1\Temp\ALSysIO.sys) -> Nalezeno
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\ALSysIO (\??\C:\DOCUME~1\Honza\LOCALS~1\Temp\ALSysIO.sys) -> Nalezeno
[PUM.SearchPage] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 -> Nalezeno
[PUM.SearchPage] HKEY_USERS\S-1-5-21-1085031214-926492609-725345543-1003\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 -> Nalezeno
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 77.48.254.254 77.48.100.254 [(Unknown Country?) (XX)] -> Nalezeno
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 77.48.254.254 77.48.100.254 [(Unknown Country?) (XX)] -> Nalezeno
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters | DhcpNameServer : 77.48.254.254 77.48.100.254 [(Unknown Country?) (XX)] -> Nalezeno
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C4A0FC24-76DC-4CE4-B6A1-C5904F672AC1} | DhcpNameServer : 77.48.254.254 77.48.100.254 [(Unknown Country?) (XX)] -> Nalezeno
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{C4A0FC24-76DC-4CE4-B6A1-C5904F672AC1} | DhcpNameServer : 77.48.254.254 77.48.100.254 [(Unknown Country?) (XX)] -> Nalezeno
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters\Interfaces\{C4A0FC24-76DC-4CE4-B6A1-C5904F672AC1} | DhcpNameServer : 77.48.254.254 77.48.100.254 [(Unknown Country?) (XX)] -> Nalezeno
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Nalezeno
¤¤¤ Úlohy : 0 ¤¤¤
¤¤¤ Soubory : 1 ¤¤¤
[Suspicious.Path][Soubor] fsutil.lnk -- C:\Documents and Settings\Honza\Nabídka Start\Programy\Po spuštění\fsutil.lnk [LNK@] C:\Documents and Settings\Honza\Data aplikací\Microsoft\Windows\IEUpdate\fsutil.exe -> Nalezeno
¤¤¤ Soubor HOSTS : 0 [Too big!] ¤¤¤
¤¤¤ Antirootkit : 46 (Driver: Nahrán) ¤¤¤
[IAT:Inl] (iexplore.exe @ SHLWAPI.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ SHELL32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ SHELL32.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ ole32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ urlmon.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ urlmon.dll) WININET.dll - HttpOpenRequestW : Unknown @ 0xdeb804 (push dword 0xdeb804|ret )
[IAT:Inl] (iexplore.exe @ IMM32.DLL) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ IMM32.DLL) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ comctl32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ comctl32.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ comctl32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ comctl32.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ IEFRAME.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ IEFRAME.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ comdlg32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ uxtheme.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ SETUPAPI.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ mshtml.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ msctfime.ime) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ dsound.dll) WINMM.dll - waveOutOpen : Unknown @ 0xdec38c (push dword 0xdec38c|ret )
[IAT:Inl] (iexplore.exe @ MSACM32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ MSACM32.dll) WINMM.dll - waveOutOpen : Unknown @ 0xdec38c (push dword 0xdec38c|ret )
[IAT:Inl] (iexplore.exe @ TAPI32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ SHLWAPI.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ SHELL32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ SHELL32.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ ole32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ urlmon.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ urlmon.dll) WININET.dll - HttpOpenRequestW : Unknown @ 0xdeb804 (push dword 0xdeb804|ret )
[IAT:Inl] (iexplore.exe @ IMM32.DLL) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ IMM32.DLL) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ comctl32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ comctl32.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ comctl32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ comctl32.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ IEFRAME.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ IEFRAME.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ comdlg32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ uxtheme.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ SETUPAPI.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ mshtml.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ msctfime.ime) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ dsound.dll) WINMM.dll - waveOutOpen : Unknown @ 0xdec38c (push dword 0xdec38c|ret )
[IAT:Inl] (iexplore.exe @ MSACM32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ MSACM32.dll) WINMM.dll - waveOutOpen : Unknown @ 0xdec38c (push dword 0xdec38c|ret )
[IAT:Inl] (iexplore.exe @ TAPI32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: ST500DM002-1BD142 +++++
--- User ---
[MBR] 83b6360573f808a39cb15f275bcb9351
[BSP] 236304dbfdf9a817ae09566387544af8 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 476929 MB
User = LL1 ... OK
Error reading LL2 MBR! ([1] Nesprávná funkce. )
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com
Operační systém : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Spuštěno : Normální režim
Uživatel : Honza [Práva správce]
Mód : Prohledat -- Datum : 11/01/2014 20:23:37
¤¤¤ Procesy : 0 ¤¤¤
¤¤¤ Registry : 13 ¤¤¤
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ALSysIO (\??\C:\DOCUME~1\Honza\LOCALS~1\Temp\ALSysIO.sys) -> Nalezeno
[Hidden.From.SCM] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\UnlockerDriver5 (\??\C:\Program Files\Unlocker\UnlockerDriver5.sys) -> Nalezeno
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ALSysIO (\??\C:\DOCUME~1\Honza\LOCALS~1\Temp\ALSysIO.sys) -> Nalezeno
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\ALSysIO (\??\C:\DOCUME~1\Honza\LOCALS~1\Temp\ALSysIO.sys) -> Nalezeno
[PUM.SearchPage] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 -> Nalezeno
[PUM.SearchPage] HKEY_USERS\S-1-5-21-1085031214-926492609-725345543-1003\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 -> Nalezeno
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 77.48.254.254 77.48.100.254 [(Unknown Country?) (XX)] -> Nalezeno
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 77.48.254.254 77.48.100.254 [(Unknown Country?) (XX)] -> Nalezeno
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters | DhcpNameServer : 77.48.254.254 77.48.100.254 [(Unknown Country?) (XX)] -> Nalezeno
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C4A0FC24-76DC-4CE4-B6A1-C5904F672AC1} | DhcpNameServer : 77.48.254.254 77.48.100.254 [(Unknown Country?) (XX)] -> Nalezeno
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{C4A0FC24-76DC-4CE4-B6A1-C5904F672AC1} | DhcpNameServer : 77.48.254.254 77.48.100.254 [(Unknown Country?) (XX)] -> Nalezeno
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters\Interfaces\{C4A0FC24-76DC-4CE4-B6A1-C5904F672AC1} | DhcpNameServer : 77.48.254.254 77.48.100.254 [(Unknown Country?) (XX)] -> Nalezeno
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Nalezeno
¤¤¤ Úlohy : 0 ¤¤¤
¤¤¤ Soubory : 1 ¤¤¤
[Suspicious.Path][Soubor] fsutil.lnk -- C:\Documents and Settings\Honza\Nabídka Start\Programy\Po spuštění\fsutil.lnk [LNK@] C:\Documents and Settings\Honza\Data aplikací\Microsoft\Windows\IEUpdate\fsutil.exe -> Nalezeno
¤¤¤ Soubor HOSTS : 0 [Too big!] ¤¤¤
¤¤¤ Antirootkit : 46 (Driver: Nahrán) ¤¤¤
[IAT:Inl] (iexplore.exe @ SHLWAPI.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ SHELL32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ SHELL32.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ ole32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ urlmon.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ urlmon.dll) WININET.dll - HttpOpenRequestW : Unknown @ 0xdeb804 (push dword 0xdeb804|ret )
[IAT:Inl] (iexplore.exe @ IMM32.DLL) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ IMM32.DLL) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ comctl32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ comctl32.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ comctl32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ comctl32.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ IEFRAME.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ IEFRAME.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ comdlg32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ uxtheme.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ SETUPAPI.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ mshtml.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ msctfime.ime) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ dsound.dll) WINMM.dll - waveOutOpen : Unknown @ 0xdec38c (push dword 0xdec38c|ret )
[IAT:Inl] (iexplore.exe @ MSACM32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ MSACM32.dll) WINMM.dll - waveOutOpen : Unknown @ 0xdec38c (push dword 0xdec38c|ret )
[IAT:Inl] (iexplore.exe @ TAPI32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ SHLWAPI.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ SHELL32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ SHELL32.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ ole32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ urlmon.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ urlmon.dll) WININET.dll - HttpOpenRequestW : Unknown @ 0xdeb804 (push dword 0xdeb804|ret )
[IAT:Inl] (iexplore.exe @ IMM32.DLL) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ IMM32.DLL) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ comctl32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ comctl32.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ comctl32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ comctl32.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ IEFRAME.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ IEFRAME.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ comdlg32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ uxtheme.dll) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ SETUPAPI.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ mshtml.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ msctfime.ime) USER32.dll - DrawTextExW : Unknown @ 0xdea0f4 (push dword 0xdea0f4|ret )
[IAT:Inl] (iexplore.exe @ dsound.dll) WINMM.dll - waveOutOpen : Unknown @ 0xdec38c (push dword 0xdec38c|ret )
[IAT:Inl] (iexplore.exe @ MSACM32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
[IAT:Inl] (iexplore.exe @ MSACM32.dll) WINMM.dll - waveOutOpen : Unknown @ 0xdec38c (push dword 0xdec38c|ret )
[IAT:Inl] (iexplore.exe @ TAPI32.dll) USER32.dll - MessageBeep : Unknown @ 0xdf1444 (push dword 0xdf1444|ret )
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: ST500DM002-1BD142 +++++
--- User ---
[MBR] 83b6360573f808a39cb15f275bcb9351
[BSP] 236304dbfdf9a817ae09566387544af8 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 476929 MB
User = LL1 ... OK
Error reading LL2 MBR! ([1] Nesprávná funkce. )
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43298
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: zavirované pc
Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce“
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
Stáhni si Junkware Removal Tool by Thisisu
na svojí plochu.
Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:
- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)
(musíš dát myší zatržítko do toho čtverečku vlevo od registru ap.)
- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Stáhni
Zoek.exe
a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:
klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean“
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.
Stáhni si Junkware Removal Tool by Thisisu
na svojí plochu.
Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.
Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:
- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)
(musíš dát myší zatržítko do toho čtverečku vlevo od registru ap.)
- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Stáhni
Zoek.exe
a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:
Kód: Vybrat vše
autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;
klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: zavirované pc
# AdwCleaner v4.001 - Report created 02/11/2014 at 11:05:08
# DB v
# Updated 20/10/2014 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Honza - HONZA-2C8DE4C0D
# Running from : C:\Documents and Settings\Honza\Plocha\adwcleaner_4.001.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Documents and Settings\Honza\Data aplikací\DriverCure
Folder Deleted : C:\Documents and Settings\All Users\Data aplikací\ParetoLogic
Folder Deleted : C:\Documents and Settings\Honza\Data aplikací\ParetoLogic
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe]
Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe]
Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe]
Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe]
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\ParetoLogic
Key Deleted : HKLM\SOFTWARE\ParetoLogic
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.6001.18702
-\\ Mozilla Firefox v32.0.1 (x86 cs)
-\\ Google Chrome v38.0.2125.111
*************************
AdwCleaner[R0].txt - [4760 octets] - [20/03/2014 19:49:00]
AdwCleaner[R1].txt - [4820 octets] - [21/03/2014 14:32:08]
AdwCleaner[R2].txt - [992 octets] - [21/03/2014 14:38:47]
AdwCleaner[R3].txt - [1015 octets] - [23/03/2014 20:48:10]
AdwCleaner[R4].txt - [2010 octets] - [22/10/2014 15:58:19]
AdwCleaner[R5].txt - [1249 octets] - [26/10/2014 20:40:56]
AdwCleaner[R6].txt - [2423 octets] - [01/11/2014 19:44:33]
AdwCleaner[R7].txt - [2518 octets] - [02/11/2014 11:00:29]
AdwCleaner[S0].txt - [4823 octets] - [21/03/2014 14:33:23]
AdwCleaner[S1].txt - [2014 octets] - [22/10/2014 16:00:57]
AdwCleaner[S2].txt - [1306 octets] - [26/10/2014 20:45:13]
AdwCleaner[S3].txt - [2452 octets] - [02/11/2014 11:05:08]
########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [2512 octets] ##########
# DB v
# Updated 20/10/2014 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Honza - HONZA-2C8DE4C0D
# Running from : C:\Documents and Settings\Honza\Plocha\adwcleaner_4.001.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Documents and Settings\Honza\Data aplikací\DriverCure
Folder Deleted : C:\Documents and Settings\All Users\Data aplikací\ParetoLogic
Folder Deleted : C:\Documents and Settings\Honza\Data aplikací\ParetoLogic
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe]
Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe]
Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe]
Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe]
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\ParetoLogic
Key Deleted : HKLM\SOFTWARE\ParetoLogic
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.6001.18702
-\\ Mozilla Firefox v32.0.1 (x86 cs)
-\\ Google Chrome v38.0.2125.111
*************************
AdwCleaner[R0].txt - [4760 octets] - [20/03/2014 19:49:00]
AdwCleaner[R1].txt - [4820 octets] - [21/03/2014 14:32:08]
AdwCleaner[R2].txt - [992 octets] - [21/03/2014 14:38:47]
AdwCleaner[R3].txt - [1015 octets] - [23/03/2014 20:48:10]
AdwCleaner[R4].txt - [2010 octets] - [22/10/2014 15:58:19]
AdwCleaner[R5].txt - [1249 octets] - [26/10/2014 20:40:56]
AdwCleaner[R6].txt - [2423 octets] - [01/11/2014 19:44:33]
AdwCleaner[R7].txt - [2518 octets] - [02/11/2014 11:00:29]
AdwCleaner[S0].txt - [4823 octets] - [21/03/2014 14:33:23]
AdwCleaner[S1].txt - [2014 octets] - [22/10/2014 16:00:57]
AdwCleaner[S2].txt - [1306 octets] - [26/10/2014 20:45:13]
AdwCleaner[S3].txt - [2452 octets] - [02/11/2014 11:05:08]
########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [2512 octets] ##########
Re: zavirované pc
JRT mi nejede...EROR DURING EXECUTION ""%TEMP%\JRT\GET.BAT"". SYSTEM NEMUZE NALEZT UVEDENY SOUBOR
přitom, když se podívám do adresáře co se vytvořil na ploše %temp% tak tam ten get.bat soubor je....
ten samý problém v nouzovém režimu
přitom, když se podívám do adresáře co se vytvořil na ploše %temp% tak tam ten get.bat soubor je....
ten samý problém v nouzovém režimu
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 112 hostů