Vir

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Vir

Příspěvekod jaro3 » 01 úno 2014 11:39

Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR
CHR - Extension: Pen\u011B\u017Eenka Google = C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 0
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O33 - MountPoints2\{0c3b1ea8-64b0-11e1-aab8-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{0c3b1ea8-64b0-11e1-aab8-806e6f6e6963}\Shell\AutoRun\command - "" = D:\autorun\automoney.exe

:Files
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\System32\dllcache\*.tmp
C:\WINDOWS\system32\SET*.tmp
C:\WINDOWS\system32\DUMP*.tmp
c:\windows\Tasks\*.job /s
C:\*.tmp
C:\WINDOWS\System32\drivers\*.tmp
C:\Documents and Settings\All Users\Data aplikací\*.tmp
C:\Windows\SysNative\drivers\*.tmp
C:\Windows\SysWow64\drivers\*.tmp
C:\Program Files (x86)\*.tmp
C:\Windows\SysWow64\*.tmp
C:\Windows\SysNative\*.tmp
C:\Program Files (x86)\*.tmp

:Reg
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.

Error - 1.2.2014 4:18:54 | Computer Name = ENPED-SERVER | Source = Service Control Manager | ID = 7038
Description = Služba CobianBackup11 se nemohla přihlásit jako .\Administrator s
aktuálně konfigurovaným heslem z důvodu následující chyby: %%1326 Chcete-li zajistit
správnou konfiguraci služby, použijte modul snap-in Služby konzoly Microsoft Management
Console (MMC).


zkus přeinstalovat Cobian.

Je to bez nákazy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Reklama
jiri.muzikar
Level 1
Level 1
Příspěvky: 84
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: Vir

Příspěvekod jiri.muzikar » 01 úno 2014 12:16

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named firefox.exe was found!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\zh_TW folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\zh_CN folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\vi folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\uk folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\tr folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\th folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\sv folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\sr folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\sl folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\sk folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\ru folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\ro folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\pt_PT folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\pt_BR folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\pl folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\nl folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\nb folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\lv folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\lt folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\ko folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\ja folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\it folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\id folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\hu folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\hr folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\hi folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\fr folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\fil folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\fi folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\et folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\es_419 folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\es folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\en_GB folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\en folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\el folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\de folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\da folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\cs folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\ca folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales\bg folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\_locales folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\images folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\html folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\css folder moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1 folder moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\disablecad deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0c3b1ea8-64b0-11e1-aab8-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0c3b1ea8-64b0-11e1-aab8-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0c3b1ea8-64b0-11e1-aab8-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0c3b1ea8-64b0-11e1-aab8-806e6f6e6963}\ not found.
File D:\autorun\automoney.exe not found.
========== FILES ==========
File\Folder C:\WINDOWS\System32\*.tmp not found.
File\Folder C:\WINDOWS\*.tmp not found.
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\System32\dllcache\*.tmp not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
File\Folder C:\WINDOWS\system32\DUMP*.tmp not found.
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully.
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully.
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-464615954-2510813803-3062766883-500Core.job moved successfully.
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-464615954-2510813803-3062766883-500UA.job moved successfully.
File\Folder C:\*.tmp not found.
File\Folder C:\WINDOWS\System32\drivers\*.tmp not found.
File\Folder C:\Documents and Settings\All Users\Data aplikací\*.tmp not found.
File\Folder C:\Windows\SysNative\drivers\*.tmp not found.
File\Folder C:\Windows\SysWow64\drivers\*.tmp not found.
C:\Program Files (x86)\GUMCA55.tmp folder moved successfully.
C:\Program Files (x86)\GUMD9DF.tmp folder moved successfully.
C:\Program Files (x86)\GUTCA56.tmp moved successfully.
C:\Program Files (x86)\GUTD9E0.tmp moved successfully.
File\Folder C:\Windows\SysWow64\*.tmp not found.
File\Folder C:\Windows\SysNative\*.tmp not found.
File\Folder C:\Program Files (x86)\*.tmp not found.
========== REGISTRY ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 1828969 bytes
->Temporary Internet Files folder emptied: 7917 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 17913477 bytes
->Flash cache emptied: 3027 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: MARKETAM
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 1705148 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 6540450 bytes

User: MARKETAS
->Temp folder emptied: 36151 bytes
->Temporary Internet Files folder emptied: 13760346 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 10073634 bytes

User: Public

User: Uzivatel
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 529032 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 17867 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 50,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 02012014_121205

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

jiri.muzikar
Level 1
Level 1
Příspěvky: 84
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: Vir

Příspěvekod jiri.muzikar » 01 úno 2014 13:05

Chvílo OK a zase asi po půl hodině začalo odesílání dat - zastavil jsem službu TCPSVCS.EXE a odesílání přestalo. Už opravdu nevím, kde může ten VIR být schovaný.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Vir

Příspěvekod jaro3 » 02 úno 2014 10:41

TCPSVCS.EXE= TCP/IP Services

Stáhni si MiniToolBox
a spusť ho.
V okně zaškrtni čtverečky:
Report IE Proxy Settings
Report FF Proxy Settings
List content of Hosts
List IP configuration
List Winsock Entries
List last 10 Event Viewer log
List Installed Programs
List Users, Partitions and Memory size

Potom klikni na GO , po chvíli skenu se objeví log s názvem „Result“ , zkopíruj sem celý jeho obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

jiri.muzikar
Level 1
Level 1
Příspěvky: 84
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: Vir

Příspěvekod jiri.muzikar » 03 úno 2014 12:02

MiniToolBox by Farbar Version: 23-01-2014
Ran by Administrator (administrator) on 03-02-2014 at 12:01:26
Running from "C:\Users\Administrator\Desktop"
Microsoft Windows Server 2008 R2 Foundation Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.
========================= Hosts content: =================================



========================= IP Configuration: ================================

Intel(R) 82574L Gigabit Network Connection = Připojení k místní síti (Connected)
IBM USB Remote NDIS Network Device = Připojení k místní síti 3 (Hardware not present)
Intel(R) 82574L Gigabit Network Connection = Připojení k místní síti 2 (Media disconnected)


# ----------------------------------
# Konfigurace protokolu IPv4
# ----------------------------------
pushd interface ipv4

reset
set global icmpredirects=enabled
add route prefix=0.0.0.0/0 interface="Pýipojenˇ k mˇstnˇ sˇti" nexthop=192.168.111.254 publish=Ano
add address name="Pýipojenˇ k mˇstnˇ sˇti" address=192.168.111.194 mask=255.255.255.0


popd
# Konec konfigurace protokolu IPv4



Konfigurace protokolu IP syst‚mu Windows

N zev hostitele . . . . . . . . . : ENPED-SERVER
Prim rnˇ pýˇpona DNS. . . . . . . :
Typ uzlu . . . . . . . . . . . . : hybridnˇ
Povoleno smŘrov nˇ IP . . . . . . : Ne
WINS Proxy povoleno . . . . . . . : Ne

Adapt‚r sˇtŘ Ethernet Pýipojenˇ k mˇstnˇ sˇti 2:

Stav m‚dia . . . . . . . . . . . : odpojeno
Pýˇpona DNS podle pýipojenˇ . . . :
Popis . . . . . . . . . . . . . . : Intel(R) 82574L Gigabit Network Connection #2
Fyzick  Adresa. . . . . . . . . . : E4-1F-13-95-B4-E4
Protokol DHCP povolen . . . . . . : Ano
Automatick  konfigurace povolena : Ano

Adapt‚r sˇtŘ Ethernet Pýipojenˇ k mˇstnˇ sˇti:

Pýˇpona DNS podle pýipojenˇ . . . :
Popis . . . . . . . . . . . . . . : Intel(R) 82574L Gigabit Network Connection
Fyzick  Adresa. . . . . . . . . . : E4-1F-13-95-B4-E3
Protokol DHCP povolen . . . . . . : Ne
Automatick  konfigurace povolena : Ano
Adresa IPv4 . . . . . . . . . . . : 192.168.111.194(Preferovan‚)
Maska podsˇtŘ . . . . . . . . . . : 255.255.255.0
Věchozˇ br na . . . . . . . . . . : 192.168.111.254
Servery DNS . . . . . . . . . . . : 213.211.43.161
Rozhranˇ NetBios nad protokolem TCP/IP. . . . . . . . : Povoleno

Adapt‚r pro tunelov‚ pýipojenˇ isatap.{6B81293F-F8CF-4BA7-92E2-23955B5C8558}:

Stav m‚dia . . . . . . . . . . . : odpojeno
Pýˇpona DNS podle pýipojenˇ . . . :
Popis . . . . . . . . . . . . . . : Microsoft ISATAP Adapter
Fyzick  Adresa. . . . . . . . . . : 00-00-00-00-00-00-00-E0
Protokol DHCP povolen . . . . . . : Ne
Automatick  konfigurace povolena : Ano

Adapt‚r pro tunelov‚ pýipojenˇ Pýipojenˇ k mˇstnˇ sˇti*:

Pýˇpona DNS podle pýipojenˇ . . . :
Popis . . . . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Fyzick  Adresa. . . . . . . . . . : 00-00-00-00-00-00-00-E0
Protokol DHCP povolen . . . . . . : Ne
Automatick  konfigurace povolena : Ano
IPv6 adresa. . . . . . . . . . . : 2001:0:9d38:6abd:41d:418:3f57:903d(Preferovan‚)
Mˇstnˇ IPv6 adresa v r mci propojenˇ . . . : fe80::41d:418:3f57:903d%14(Preferovan‚)
Věchozˇ br na . . . . . . . . . . : ::
NetBIOS nad TCP/IP. . . . . . . . : zak z no

Adapt‚r pro tunelov‚ pýipojenˇ isatap.{CB2E1B7E-F862-4A7C-B342-2E768AA73E4F}:

Stav m‚dia . . . . . . . . . . . : odpojeno
Pýˇpona DNS podle pýipojenˇ . . . :
Popis . . . . . . . . . . . . . . : Microsoft ISATAP Adapter #2
Fyzick  Adresa. . . . . . . . . . : 00-00-00-00-00-00-00-E0
Protokol DHCP povolen . . . . . . : Ne
Automatick  konfigurace povolena : Ano
Server: 213-211-43-161.netstone.cz
Address: 213.211.43.161
Aliases: 161.43.211.213.in-addr.arpa

Nazev: google.com
Addresses: 2a00:1450:4014:80b::1008
173.194.122.3
173.194.122.4
173.194.122.5
173.194.122.6
173.194.122.7
173.194.122.8
173.194.122.9
173.194.122.14
173.194.122.0
173.194.122.1
173.194.122.2


Pýˇkaz PING na google.com [173.194.122.4] - 32 bajt… dat:
OdpovŘÔ od 173.194.122.4: bajty=32 źas=10ms TTL=58
OdpovŘÔ od 173.194.122.4: bajty=32 źas=10ms TTL=58

Statistika ping pro 173.194.122.4:
Pakety: Odeslan‚ = 2, Pýijat‚ = 2, Ztracen‚ = 0 (ztr ta 0%),
Pýibli§n  doba do pýijetˇ odezvy v milisekund ch:
Minimum = 10ms, Maximum = 10ms, Pr…mŘr = 10ms
Server: 213-211-43-161.netstone.cz
Address: 213.211.43.161
Aliases: 161.43.211.213.in-addr.arpa

Nazev: yahoo.com
Addresses: 98.138.253.109
98.139.183.24
206.190.36.45


Pýˇkaz PING na yahoo.com [98.139.183.24] - 32 bajt… dat:
OdpovŘÔ od 98.139.183.24: bajty=32 źas=119ms TTL=43
OdpovŘÔ od 98.139.183.24: bajty=32 źas=133ms TTL=43

Statistika ping pro 98.139.183.24:
Pakety: Odeslan‚ = 2, Pýijat‚ = 2, Ztracen‚ = 0 (ztr ta 0%),
Pýibli§n  doba do pýijetˇ odezvy v milisekund ch:
Minimum = 119ms, Maximum = 133ms, Pr…mŘr = 126ms

Pýˇkaz PING na 127.0.0.1 - 32 bajt… dat:
OdpovŘÔ od 127.0.0.1: bajty=32 źas < 1ms TTL=128
OdpovŘÔ od 127.0.0.1: bajty=32 źas < 1ms TTL=128

Statistika ping pro 127.0.0.1:
Pakety: Odeslan‚ = 2, Pýijat‚ = 2, Ztracen‚ = 0 (ztr ta 0%),
Pýibli§n  doba do pýijetˇ odezvy v milisekund ch:
Minimum = 0ms, Maximum = 0ms, Pr…mŘr = 0ms
===========================================================================
Seznam rozhranˇ
13...e4 1f 13 95 b4 e4 ......Intel(R) 82574L Gigabit Network Connection #2
11...e4 1f 13 95 b4 e3 ......Intel(R) 82574L Gigabit Network Connection
1...........................Software Loopback Interface 1
12...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
14...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
15...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2
===========================================================================

IPv4 SmŘrovacˇ tabulka
===========================================================================
Aktivnˇ smŘrov nˇ:
Cˇl v sˇti Sˇśov  maska Br na Rozhranˇ Metrika
0.0.0.0 0.0.0.0 192.168.111.254 192.168.111.194 276
127.0.0.0 255.0.0.0 Propojen‚ 127.0.0.1 306
127.0.0.1 255.255.255.255 Propojen‚ 127.0.0.1 306
127.255.255.255 255.255.255.255 Propojen‚ 127.0.0.1 306
192.168.111.0 255.255.255.0 Propojen‚ 192.168.111.194 276
192.168.111.194 255.255.255.255 Propojen‚ 192.168.111.194 276
192.168.111.255 255.255.255.255 Propojen‚ 192.168.111.194 276
224.0.0.0 240.0.0.0 Propojen‚ 127.0.0.1 306
224.0.0.0 240.0.0.0 Propojen‚ 192.168.111.194 276
255.255.255.255 255.255.255.255 Propojen‚ 127.0.0.1 306
255.255.255.255 255.255.255.255 Propojen‚ 192.168.111.194 276
===========================================================================
Trval‚ trasy:
Sˇśov  adresa Maska Adresa br ny Metrika
0.0.0.0 0.0.0.0 192.168.111.254 Věchozˇ
===========================================================================

IPv6 SmŘrovacˇ tabulka
===========================================================================
Aktivnˇ smŘrov nˇ:
Rozhranˇ Metrika Cˇl v sˇti Br na
14 58 ::/0 Propojen‚
1 306 ::1/128 Propojen‚
14 58 2001::/32 Propojen‚
14 306 2001:0:9d38:6abd:41d:418:3f57:903d/128
Propojen‚
14 306 fe80::/64 Propojen‚
14 306 fe80::41d:418:3f57:903d/128
Propojen‚
1 306 ff00::/8 Propojen‚
14 306 ff00::/8 Propojen‚
===========================================================================
Trval‚ trasy:
¦ dn‚
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (02/03/2014 11:54:27 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/02/2014 02:00:19 PM) (Source: Microsoft-Windows-Backup) (User: ENPED-SERVER)
Description: Operaci zálohování v 2014-02-02T13:00:19.743322000Z se nepodařilo spustit. Kód chyby 2155348081 (%%2155348081). V podrobnostech o události vyhledejte řešení problému a po jeho vyřešení spusťte operaci zálohování znovu.

Error: (02/01/2014 02:00:22 PM) (Source: Microsoft-Windows-Backup) (User: ENPED-SERVER)
Description: Operaci zálohování v 2014-02-01T13:00:22.475548400Z se nepodařilo spustit. Kód chyby 2155348081 (%%2155348081). V podrobnostech o události vyhledejte řešení problému a po jeho vyřešení spusťte operaci zálohování znovu.

Error: (02/01/2014 00:16:17 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/01/2014 09:20:21 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/31/2014 10:20:32 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/30/2014 08:23:32 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/30/2014 05:10:47 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/30/2014 08:27:59 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/29/2014 05:23:04 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (02/01/2014 01:02:33 PM) (Source: Service Control Manager) (User: )
Description: Služba Jednoduché služby TCP/IP byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (02/01/2014 00:14:49 PM) (Source: Service Control Manager) (User: )
Description: Služba Cobian Backup 11 Gravity neuspěla při spuštění v důsledku následující chyby:
%%1069

Error: (02/01/2014 00:14:49 PM) (Source: Service Control Manager) (User: )
Description: Služba CobianBackup11 se nemohla přihlásit jako .\Administrator s aktuálně konfigurovaným heslem z důvodu následující chyby:
%%1326

Chcete-li zajistit správnou konfiguraci služby, použijte modul snap-in Služby konzoly Microsoft Management Console (MMC).

Error: (02/01/2014 00:12:05 PM) (Source: Service Control Manager) (User: )
Description: Služba Adobe Acrobat Update Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (02/01/2014 09:18:54 AM) (Source: Service Control Manager) (User: )
Description: Služba Cobian Backup 11 Gravity neuspěla při spuštění v důsledku následující chyby:
%%1069

Error: (02/01/2014 09:18:54 AM) (Source: Service Control Manager) (User: )
Description: Služba CobianBackup11 se nemohla přihlásit jako .\Administrator s aktuálně konfigurovaným heslem z důvodu následující chyby:
%%1326

Chcete-li zajistit správnou konfiguraci služby, použijte modul snap-in Služby konzoly Microsoft Management Console (MMC).

Error: (01/31/2014 04:30:09 PM) (Source: Service Control Manager) (User: )
Description: Služba Jednoduché služby TCP/IP byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (01/31/2014 10:19:04 AM) (Source: Service Control Manager) (User: )
Description: Služba Cobian Backup 11 Gravity neuspěla při spuštění v důsledku následující chyby:
%%1069

Error: (01/31/2014 10:19:04 AM) (Source: Service Control Manager) (User: )
Description: Služba CobianBackup11 se nemohla přihlásit jako .\Administrator s aktuálně konfigurovaným heslem z důvodu následující chyby:
%%1326

Chcete-li zajistit správnou konfiguraci služby, použijte modul snap-in Služby konzoly Microsoft Management Console (MMC).

Error: (01/30/2014 08:22:02 PM) (Source: Service Control Manager) (User: )
Description: Služba Cobian Backup 11 Gravity neuspěla při spuštění v důsledku následující chyby:
%%1069


Microsoft Office Sessions:
=========================
Error: (02/03/2014 11:54:27 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/02/2014 02:00:19 PM) (Source: Microsoft-Windows-Backup)(User: ENPED-SERVER)
Description: 2014-02-02T13:00:19.743322000Z2155348081%%2155348081

Error: (02/01/2014 02:00:22 PM) (Source: Microsoft-Windows-Backup)(User: ENPED-SERVER)
Description: 2014-02-01T13:00:22.475548400Z2155348081%%2155348081

Error: (02/01/2014 00:16:17 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/01/2014 09:20:21 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/31/2014 10:20:32 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/30/2014 08:23:32 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/30/2014 05:10:47 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/30/2014 08:27:59 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/29/2014 05:23:04 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


CodeIntegrity Errors:
===================================
Date: 2014-02-01 16:19:23.976
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.

Date: 2014-01-30 20:54:07.889
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.

Date: 2014-01-30 20:23:57.509
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.

Date: 2014-01-30 20:16:31.326
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.

Date: 2014-01-30 19:59:18.502
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.

Date: 2014-01-30 18:57:27.080
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.

Date: 2014-01-27 20:14:16.770
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.

Date: 2014-01-27 19:08:33.991
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.

Date: 2014-01-26 14:40:52.482
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.

Date: 2013-12-28 11:46:58.416
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.


=========================== Installed Programs ============================

Adobe Reader X (10.1.9) - Czech (Version: 10.1.9)
CCleaner (Version: 4.09)
ClamWin Free Antivirus 0.98.1
Ekonomický systém Money S3 (Version: 14.101 (20140122_12))
Google Chrome (Version: 32.0.1700.102)
Google Update Helper (Version: 1.3.22.3)
Java 7 Update 51 (Version: 7.0.510)
Java Auto Updater (Version: 2.1.9.8)
Licenční server verze 3.002
Microsoft .NET Framework 4 Client Profile CSY Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended CSY Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
OpenOffice.org 3.3 (Version: 3.3.9567)
PDFCreator (Version: 1.3.2)
SAPIENS
TeamViewer 9 (Version: 9.0.25790)
Total Commander 64-bit (Remove or Repair) (Version: 8.01)
WMI Tools (Version: 1.50.1131.0001)

========================= Memory info: ===================================

Percentage of memory in use: 59%
Total physical RAM: 2036.28 MB
Available physical RAM: 827.06 MB
Total Pagefile: 4072.55 MB
Available Pagefile: 2888.84 MB
Total Virtual: 4095.88 MB
Available Virtual: 3974.88 MB

========================= Partitions: =====================================

1 Drive c: () (Fixed) (Total:232.56 GB) (Free:205.62 GB) NTFS

========================= Users: ========================================

U§ivatelsk‚ Łźty pro \\ENPED-SERVER

Administrator Guest MARKETAM
MARKETAS Uzivatel
Pýˇkaz byl ŁspŘçnŘ dokonźen.


**** End of log ****

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Vir

Příspěvekod jaro3 » 03 úno 2014 18:51

Nevidím zásadní problém.

problém:
File Description: MPEG Layer-3 Audio Codec for MSACM Product Name: MPEG Layer-3 Audio Codec for MSACM

zkus přeinstalovat..

Spusť znovu MiniToolBox.
Zaškrtni čtverečky:
Flush DNS
Reset IE Proxy Settings
Reset FF Proxy Settings
List Device * Only problem * No Driver *All
List Minidump Files
Potom klikni na GO , po chvíli skenu se objeví log s názvem „Result“ , zkopíruj sem celý jeho obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

jiri.muzikar
Level 1
Level 1
Příspěvky: 84
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: Vir

Příspěvekod jiri.muzikar » 03 úno 2014 19:26

Omlouvám se, ale nemůžu najít, kde se ten Audio Codec odinstaluje.
Jinak - dnes ráno jsem pc pustil a odešel. Nikdo se na něho nemohl dostat (přes vzdálenou plochu), protože zase odesílal data. Potom odpoledne jsem zastavil TCPSVC a bylo vše OK.
Asi nezbude, než přeinstalovat Windows - na což si netroufám.
Děkuji moc za rady. Ještě třeba společně něco vymyslíme.
Samozřejmě pošlu nějaký příspěvek na Vaši práci.

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Vir

Příspěvekod Orcus » 03 úno 2014 22:47

Ani nemusíš ten kodek odebírat, zkrátka ho přeinstaluj. Google nahodí pár odkazů na stažení. Teoreticky by šlo ještě přes Wireshark zjistit, kam ty pakety vlastně odcházej.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

jiri.muzikar
Level 1
Level 1
Příspěvky: 84
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: Vir

Příspěvekod jiri.muzikar » 05 úno 2014 11:34

Wireshark jsem nainstaloval - data zase dnes zablokovala net - takže sem dám večer kousek logu s Wiresharku - něco ta data přece misí posílat.

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Vir

Příspěvekod Orcus » 05 úno 2014 11:38

Wireshark logy maj velikost v GB, takže to ani nemá cenu upínat, pokud se v něm sám nevyznáš.

Provedl jsi ten MiniToolbox co psal Jaro?
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

jiri.muzikar
Level 1
Level 1
Příspěvky: 84
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: Vir

Příspěvekod jiri.muzikar » 05 úno 2014 16:30

MiniToolBox by Farbar Version: 23-01-2014
Ran by Administrator (administrator) on 05-02-2014 at 16:29:23
Running from "C:\Users\Administrator\Desktop"
Microsoft Windows Server 2008 R2 Foundation Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Konfigurace protokolu IP syst‚mu Windows

MezipamŘś pýekl d nˇ DNS byla ŁspŘçnŘ vypr zdnŘna.

"Reset IE Proxy Settings": IE Proxy Settings were reset.

========================= Devices: ================================

Name: IBM USB Remote NDIS Network Device
Description: IBM USB Remote NDIS Network Device
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: IBM Corporation
Service: usb_rndisx
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Intel(R) 82574L Gigabit Network Connection #2
Description: Intel(R) 82574L Gigabit Network Connection
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Intel
Service: e1qexpress
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Řadič sběrnice SM
Description: Řadič sběrnice SM
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

========================= Minidump Files ==================================

No minidump file found


**** End of log ****

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Vir

Příspěvekod jaro3 » 05 úno 2014 19:02

Name: Intel(R) 82574L Gigabit Network Connection #2
Description: Intel(R) 82574L Gigabit Network Connection
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Intel
Service: e1qexpress
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Řadič sběrnice SM
Description: Řadič sběrnice SM
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


Zkus provést , co tam píšou.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Seznam[Bot] a 114 hostů