Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Pomalý PC, CPU 100% porad

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
JaxFrings
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 02 led 2010 17:15

Pomalý PC, CPU 100% porad

#1 Příspěvek od JaxFrings »

Dobrý den prosím o pomoc,nez jsem pc zkontroloval pres Avast tak mi dokonce i neco piípalo v kompu myslím že to byl hard. :D

Logfile of random's system information tool 1.06 (written by random/random)
Run by Administrator at 2010-01-02 17:58:48
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 8 GB (3%) free of 238 GB
Total RAM: 511 MB (30% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:59:09, on 2.1.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\MP4 Player\mp4Player.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\totalcmd\TOTALCMD.EXE
c:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Administrator\Dokumenty\Downloads\RSIT.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
c:\Program Files\Hijackthis\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFDTV\WFWIZ.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [sysgif32] C:\WINDOWS\TEMP\~TME.tmp
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent
O4 - HKCU\..\Run: [MP4 Player] "C:\Program Files\MP4 Player\mp4Player.exe" hmw
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: siszyd32.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe

--
End of file - 7242 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-583907252-1801674531-725345543-500Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-583907252-1801674531-725345543-500UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-03-27 1082880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2004-09-16 69632]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-09 153136]
"DAEMON Tools"=C:\Program Files\DAEMON Tools\daemon.exe [2006-11-12 157592]
"WinFastDTV"=C:\Program Files\WinFast\WFDTV\DTVSchdl.exe [2007-05-16 69632]
"WinFast Schedule"=C:\Program Files\WinFast\WFDTV\WFWIZ.exe [2007-05-22 405504]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-09-29 61440]
"sysgif32"=C:\WINDOWS\TEMP\~TME.tmp [2010-01-02 32768]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-09-15 81000]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2009-12-30 429392]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2004-08-17 1667584]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-03-12 153136]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-03-27 24103720]
"Google Update"=C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-04-18 133104]
"AdobeUpdater"=C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe [2009-04-14 2356088]
"ICQ"=C:\Program Files\ICQ6.5\ICQ.exe [2009-11-16 172792]
"MP4 Player"=C:\Program Files\MP4 Player\mp4Player.exe [2008-11-06 772096]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe

C:\Documents and Settings\Administrator\Nabídka Start\Programy\Po spuštění
siszyd32.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-09-30 155648]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\World of Warcraft\Launcher.exe"="C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:World of Warcraft"
"C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe"="C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe:*:Enabled:Nero ShowTime"
"C:\Games\Paintball2\paintball2.exe"="C:\Games\Paintball2\paintball2.exe:*:Enabled:paintball2"
"C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe"="C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"C:\Program Files\Sports Interactive\Football Manager 2009\fm.exe"="C:\Program Files\Sports Interactive\Football Manager 2009\fm.exe:*:Enabled:Football Manager 2009"
"C:\Program Files\EA Games\Command and Conquer Generals\game.dat"="C:\Program Files\EA Games\Command and Conquer Generals\game.dat:*:Enabled:game"
"C:\Wolfenstein\ET.exe"="C:\Wolfenstein\ET.exe:*:Enabled:ET"
"C:\Program Files\EA Games\Command & Conquer Generals Zero Hour\game.dat"="C:\Program Files\EA Games\Command & Conquer Generals Zero Hour\game.dat:*:Enabled:game"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\Program Files\3DO\Heroes 3 Complete\HEROES3.ICD"="C:\Program Files\3DO\Heroes 3 Complete\HEROES3.ICD:*:Enabled:Heroes of Might and Magic® III"
"C:\Documents and Settings\Administrator\Plocha\Tekken 3\Tekken 3\ePSXe.exe"="C:\Documents and Settings\Administrator\Plocha\Tekken 3\Tekken 3\ePSXe.exe:*:Enabled:ePSXe"
"C:\Codemasters\Blade of Darkness\Bin\Blade.exe"="C:\Codemasters\Blade of Darkness\Bin\Blade.exe:*:Enabled:Blade"
"C:\Program Files\KONAMI\Pro Evolution Soccer 2008\PES2008.exe"="C:\Program Files\KONAMI\Pro Evolution Soccer 2008\PES2008.exe:*:Enabled:Pro Evolution Soccer 2008"
"C:\crack pes 2008\PES2008.exe"="C:\crack pes 2008\PES2008.exe:*:Enabled:Pro Evolution Soccer 2008"
"C:\Program Files\EA Games\Bitwa o Śródziemie\patchget.dat"="C:\Program Files\EA Games\Bitwa o Śródziemie\patchget.dat:*:Enabled:patchgrabber"
"C:\Program Files\EA Games\Bitwa o Śródziemie\game.dat"="C:\Program Files\EA Games\Bitwa o Śródziemie\game.dat:*:Enabled:Bitwa o Śródziemie (tm)"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\id Software\Enemy Territory - QUAKE Wars Demo\etqw.exe"="C:\Program Files\id Software\Enemy Territory - QUAKE Wars Demo\etqw.exe:*:Enabled:Enemy Territory - QUAKE Wars(TM) Demo"
"C:\Program Files\id Software\Enemy Territory - QUAKE Wars Demo\etqwded.exe"="C:\Program Files\id Software\Enemy Territory - QUAKE Wars Demo\etqwded.exe:*:Enabled:etqwded.exe"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\EA Games\Command & Conquer Generals Zero Hour\generals.exe"="C:\Program Files\EA Games\Command & Conquer Generals Zero Hour\generals.exe:*:Enabled:Command and ConquerTM Generals Zero Hour"
"C:\Program Files\EA Games\Command and Conquer Generals\generals.exe"="C:\Program Files\EA Games\Command and Conquer Generals\generals.exe:*:Enabled:Command & Conquer Generals"
"C:\Program Files\UBISOFT\Ghost Recon Advanced Warfighter 2\graw2.exe"="C:\Program Files\UBISOFT\Ghost Recon Advanced Warfighter 2\graw2.exe:*:Enabled:Ghost Recon Advanced Warfighter® 2"
"C:\Program Files\UBISOFT\Ghost Recon Advanced Warfighter 2\graw2_dedicated.exe"="C:\Program Files\UBISOFT\Ghost Recon Advanced Warfighter 2\graw2_dedicated.exe:*:Enabled:Ghost Recon Advanced Warfighter® 2 Dedicated Server"
"C:\Program Files\Valve\hl.exe"="C:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat"="C:\Program Files\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat:*:Enabled:The Battle for Middle-earth(tm) II"
"C:\Program Files\Electronic Arts\The Lord of the Rings, The Rise of the Witch-king\game.dat"="C:\Program Files\Electronic Arts\The Lord of the Rings, The Rise of the Witch-king\game.dat:*:Enabled:The Lord of the Rings, The Rise of the Witch-king"
"C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"="C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5cc45b66-35a8-11de-b21d-00508d4dfbb1}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs


======List of files/folders created in the last 1 months======

2010-01-02 17:58:47 ----D---- C:\rsit
2010-01-02 17:46:55 ----D---- C:\Program Files\Hijackthis
2010-01-02 17:22:02 ----D---- C:\Program Files\Ultimate Process Manager
2010-01-02 17:01:13 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Malwarebytes
2010-01-02 17:00:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-01-02 17:00:53 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-01-02 13:03:18 ----A---- C:\WINDOWS\system32\MSVCR71.dll
2010-01-02 13:03:18 ----A---- C:\WINDOWS\system32\MSVCP71.dll
2010-01-02 13:03:18 ----A---- C:\WINDOWS\system32\MFC71.dll
2010-01-02 13:03:18 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-01-02 13:03:15 ----D---- C:\Program Files\Alwil Software
2010-01-02 11:37:31 ----D---- C:\WINDOWS\Minidump
2010-01-02 11:35:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\Kaspersky Lab Setup Files
2010-01-01 23:44:20 ----D---- C:\Program Files\1C Company
2010-01-01 23:28:09 ----D---- C:\kings bounty datadisk
2009-12-29 21:52:51 ----H---- C:\Documents and Settings\Administrator\Data aplikací\swk.ini
2009-12-29 21:52:48 ----D---- C:\Program Files\MP4 Player
2009-12-29 21:34:35 ----D---- C:\ve sparech yakuzy
2009-12-26 18:16:16 ----SHD---- C:\WINDOWS\system32\28463
2009-12-25 17:28:51 ----D---- C:\Documents and Settings\All Users\Data aplikací\ATI
2009-12-25 17:16:41 ----SHD---- C:\Config.Msi
2009-12-19 23:15:43 ----D---- C:\Documents and Settings\All Users\Data aplikací\Blizzard
2009-12-19 22:27:01 ----A---- C:\WINDOWS\War3Unin.exe
2009-12-19 20:41:26 ----D---- C:\Program Files\Warcraft III
2009-12-18 20:47:11 ----D---- C:\Program Files\StepMania
2009-12-17 16:31:24 ----D---- C:\Program Files\FLV Player
2009-12-13 15:41:22 ----D---- C:\Documents and Settings\Administrator\Data aplikací\runic games
2009-12-13 15:33:16 ----D---- C:\Program Files\Runic Games
2009-12-09 16:43:36 ----D---- C:\wog
2009-12-04 22:00:39 ----D---- C:\south park
2009-12-03 19:53:39 ----D---- C:\homam5 datadisk1
2009-12-03 17:59:51 ----D---- C:\homam5
2009-12-03 15:27:49 ----D---- C:\Downloads
2009-12-03 15:25:19 ----D---- C:\Program Files\FlashGet

======List of files/folders modified in the last 1 months======

2010-01-02 17:51:36 ----A---- C:\WINDOWS\wincmd.ini
2010-01-02 17:46:55 ----RD---- C:\Program Files
2010-01-02 17:44:02 ----D---- C:\Program Files\Mozilla Firefox
2010-01-02 17:00:58 ----D---- C:\WINDOWS\system32\drivers
2010-01-02 16:57:58 ----D---- C:\WINDOWS\Temp
2010-01-02 16:40:25 ----D---- C:\WINDOWS\system32\CatRoot2
2010-01-02 16:10:22 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Skype
2010-01-02 16:08:20 ----D---- C:\WINDOWS\system32\config
2010-01-02 14:55:16 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-02 14:55:12 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-01-02 14:55:05 ----D---- C:\Program Files\Internet Explorer
2010-01-02 14:54:57 ----D---- C:\WINDOWS\system32
2010-01-02 14:22:17 ----D---- C:\WINDOWS\Prefetch
2010-01-02 14:08:20 ----D---- C:\WINDOWS
2010-01-02 11:45:16 ----SHD---- C:\WINDOWS\Installer
2010-01-02 11:38:47 ----D---- C:\Documents and Settings\Administrator\Data aplikací\ICQ
2010-01-02 01:41:25 ----D---- C:\WINDOWS\Debug
2010-01-02 01:41:22 ----D---- C:\totalcmd
2010-01-02 01:41:18 ----D---- C:\Program Files\TuneUp Utilities 2007
2010-01-02 00:41:47 ----D---- C:\WINDOWS\system32\DirectX
2010-01-02 00:41:27 ----HD---- C:\WINDOWS\inf
2010-01-02 00:35:49 ----RSD---- C:\WINDOWS\assembly
2009-12-30 00:05:13 ----A---- C:\WINDOWS\NeroDigital.ini
2009-12-29 15:59:31 ----D---- C:\Program Files\ICQ6.5
2009-12-29 13:40:17 ----D---- C:\Program Files\World of Warcraft
2009-12-29 13:10:59 ----A---- C:\WINDOWS\win.ini
2009-12-25 22:01:27 ----D---- C:\filmy
2009-12-25 17:18:55 ----D---- C:\WINDOWS\WinSxS
2009-12-25 17:18:44 ----D---- C:\Program Files\ATI Technologies
2009-12-20 17:58:38 ----D---- C:\WINDOWS\system32\Restore
2009-12-20 11:40:17 ----D---- C:\Program Files\EA Games
2009-12-19 23:10:57 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
2009-12-17 16:31:42 ----D---- C:\amiga
2009-12-04 16:00:55 ----HD---- C:\Program Files\InstallShield Installation Information
2009-12-03 18:11:01 ----D---- C:\Program Files\UBISOFT

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-09-15 27408]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-09-15 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-09-15 52368]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2004-08-17 39936]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-09-15 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-09-15 94160]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-09-21 2278784]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-09-15 23152]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2009-09-30 3565056]
R3 RTL8023xp;Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2004-04-13 70144]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 WFIOCTL;WFIOCTL; \??\C:\Program Files\WinFast\WFDTV\WFIOCTL.SYS []
R3 WFLR6654;WinFast DTV1800 H (Video); C:\WINDOWS\system32\drivers\wfeaglxt.sys [2007-01-19 393088]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-03 60800]
S3 atvrhzyv;atvrhzyv; C:\WINDOWS\system32\drivers\atvrhzyv.sys []
S3 BthEnum;Služba Bluetooth Enumerator; C:\WINDOWS\System32\DRIVERS\BthEnum.sys [2004-08-03 17024]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2004-08-03 100992]
S3 BTHPORT;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2004-08-17 274304]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2004-08-03 18944]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-11-12 25280]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 MPE;Filtr MPE BDA; C:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-03 15360]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-03 61824]
S3 NTACCESS;NTACCESS; \??\D:\NTACCESS.sys []
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2004-08-03 59648]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 SetupNTGLM7X;SetupNTGLM7X; \??\D:\NTGLM7X.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 ZDPSp50;ZDPSp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\ZDPSp50.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-09-15 18752]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-09-30 602112]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-09-15 138680]
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-09-25 75064]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2004-12-13 49152]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2004-08-17 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-09-15 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-09-15 352920]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-03-12 271920]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2009-09-29 593920]
S2 WinVNC4;VNC Server Version 4; C:\Program Files\RealVNC\VNC4\WinVNC4.exe [2008-10-15 439632]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-01-15 774144]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]

-----------------EOF-----------------

JaxFrings
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 02 led 2010 17:15

Re: Pomalý PC, CPU 100% porad

#2 Příspěvek od JaxFrings »

ok tady to je :)

ComboFix 10-01-01.05 - Administrator 02.01.2010 18:26:58.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.511.220 [GMT 1:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
AV: avast! antivirus 4.8.1356 [VPS 091023-0] *On-access scanning disabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\install.exe
c:\program files\ICQ6.5\ICQLRun.exe
c:\windows\system32\28463
c:\windows\system32\SIntf16.dll

.
((((((((((((((((((((((((( Soubory vytvořené od 2009-12-02 do 2010-01-02 )))))))))))))))))))))))))))))))
.

2010-01-02 16:58 . 2010-01-02 16:59 -------- d-----w- C:\rsit
2010-01-02 16:22 . 2010-01-02 16:30 -------- d-----w- c:\program files\Ultimate Process Manager
2010-01-02 16:00 . 2009-12-30 13:55 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-02 16:00 . 2010-01-02 16:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-02 16:00 . 2009-12-30 13:54 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-02 12:04 . 2009-09-15 11:54 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-01-02 12:03 . 2009-09-15 11:54 52368 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-01-02 12:03 . 2009-09-15 11:53 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-01-02 12:03 . 2009-09-15 11:53 97480 ----a-w- c:\windows\system32\AvastSS.scr
2010-01-02 12:03 . 2009-09-15 11:56 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-01-02 12:03 . 2009-09-15 11:56 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-01-02 12:03 . 2009-09-15 11:55 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-01-02 12:03 . 2009-09-15 11:55 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-01-02 12:03 . 2009-09-15 11:59 1279968 ----a-w- c:\windows\system32\aswBoot.exe
2010-01-02 12:03 . 2003-03-18 21:20 1060864 ----a-w- c:\windows\system32\MFC71.dll
2010-01-02 12:03 . 2003-03-18 20:14 499712 ----a-w- c:\windows\system32\MSVCP71.dll
2010-01-02 12:03 . 2003-02-21 04:42 348160 ----a-w- c:\windows\system32\MSVCR71.dll
2010-01-02 12:03 . 2010-01-02 12:03 -------- d-----w- c:\program files\Alwil Software
2010-01-01 22:44 . 2010-01-01 22:44 -------- d-----w- c:\program files\1C Company
2010-01-01 22:28 . 2010-01-01 22:28 -------- d-----w- C:\kings bounty datadisk
2009-12-30 22:41 . 2010-01-02 17:33 763904 ----a-w- c:\windows\system32\drivers\mfipufob.sys
2009-12-29 20:52 . 2009-12-29 20:52 -------- d-----w- c:\program files\MP4 Player
2009-12-29 20:34 . 2009-12-29 21:40 -------- d-----w- C:\ve sparech yakuzy
2009-12-25 16:08 . 2009-12-25 16:08 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-12-19 21:27 . 2009-12-19 21:33 52152 ----a-w- c:\windows\War3Unin.dat
2009-12-19 21:27 . 2009-12-19 21:33 2829 ----a-w- c:\windows\War3Unin.pif
2009-12-19 21:27 . 2009-12-19 21:33 139264 ----a-w- c:\windows\War3Unin.exe
2009-12-19 19:41 . 2009-12-23 08:25 -------- d-----w- c:\program files\Warcraft III
2009-12-18 19:47 . 2009-12-31 15:24 -------- d-----w- c:\program files\StepMania
2009-12-17 15:31 . 2009-12-17 15:31 -------- d-----w- c:\program files\FLV Player
2009-12-13 14:33 . 2009-12-13 14:33 -------- d-----w- c:\program files\Runic Games
2009-12-09 15:43 . 2009-12-09 15:44 -------- d-----w- C:\wog
2009-12-04 21:00 . 2009-12-04 21:00 -------- d-----w- C:\south park
2009-12-03 18:53 . 2009-12-03 19:24 -------- d-----w- C:\homam5 datadisk1

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-02 17:32 . 2009-10-14 13:36 -------- d-----w- c:\program files\ICQ6.5
2010-01-02 00:41 . 2009-04-03 21:36 -------- d-----w- c:\program files\TuneUp Utilities 2007
2010-01-02 00:40 . 2009-12-03 14:25 -------- d-----w- c:\program files\FlashGet
2009-12-29 12:40 . 2009-04-04 06:39 -------- d-----w- c:\program files\World of Warcraft
2009-12-25 16:18 . 2009-04-03 19:45 -------- d-----w- c:\program files\ATI Technologies
2009-12-20 10:40 . 2009-06-30 10:33 -------- d-----w- c:\program files\EA Games
2009-12-19 22:10 . 2009-04-04 06:39 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2009-12-04 15:00 . 2009-04-03 19:45 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-03 17:11 . 2009-10-26 14:51 -------- d-----w- c:\program files\UBISOFT
2009-11-29 12:40 . 2009-12-17 20:51 11567 ----a-w- c:\program files\MatotazkySPS08.DOC
2009-11-22 15:55 . 2009-11-22 15:55 -------- d-----w- c:\program files\Vivendi Universal Games
2009-11-12 18:08 . 2009-11-12 18:05 25280 ----a-w- c:\windows\system32\drivers\hamachi.sys
2009-11-07 18:58 . 2009-11-07 18:48 -------- d-----w- c:\program files\Electronic Arts
2009-11-07 15:58 . 2009-06-06 21:55 139904 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-11-07 15:58 . 2009-06-06 21:54 189744 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-10-25 13:34 . 2009-06-30 10:35 980 ----a-w- c:\windows\eReg.dat
2009-10-25 08:22 . 2001-10-25 12:00 76516 ----a-w- c:\windows\system32\perfc005.dat
2009-10-25 08:22 . 2001-10-25 12:00 424082 ----a-w- c:\windows\system32\perfh005.dat
2009-10-15 19:13 . 2009-10-15 19:13 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2009-10-15 19:13 . 2009-10-15 19:13 110592 ----a-w- c:\windows\system32\OpenAL32.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-17 1667584]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-03-27 24103720]
"Google Update"="c:\documents and settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2009-04-18 133104]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2009-04-14 2356088]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" [2009-11-16 172792]
"MP4 Player"="c:\program files\MP4 Player\mp4Player.exe" [2008-11-06 772096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-17 110592]
"SoundMan"="SOUNDMAN.EXE" [2004-09-16 69632]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2006-11-12 157592]
"WinFastDTV"="c:\program files\WinFast\WFDTV\DTVSchdl.exe" [2007-05-16 69632]
"WinFast Schedule"="c:\program files\WinFast\WFDTV\WFWIZ.exe" [2007-05-22 405504]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-09-29 61440]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-09-15 81000]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-17 15360]

c:\documents and settings\Administrator\Nabˇdka Start\Programy\Po spuçtŘnˇ\
siszyd32.exe [2004-8-17 31232]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Games\\Paintball2\\paintball2.exe"=
"c:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"c:\\Program Files\\Sports Interactive\\Football Manager 2009\\fm.exe"=
"c:\\Program Files\\EA Games\\Command and Conquer Generals\\game.dat"=
"c:\\Wolfenstein\\ET.exe"=
"c:\\Program Files\\EA Games\\Command & Conquer Generals Zero Hour\\game.dat"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\3DO\\Heroes 3 Complete\\HEROES3.ICD"=
"c:\\Documents and Settings\\Administrator\\Plocha\\Tekken 3\\Tekken 3\\ePSXe.exe"=
"c:\\Codemasters\\Blade of Darkness\\Bin\\Blade.exe"=
"c:\\Program Files\\KONAMI\\Pro Evolution Soccer 2008\\PES2008.exe"=
"c:\\crack pes 2008\\PES2008.exe"=
"c:\\Program Files\\EA Games\\Bitwa o Śródziemie\\patchget.dat"=
"c:\\Program Files\\EA Games\\Bitwa o Śródziemie\\game.dat"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\id Software\\Enemy Territory - QUAKE Wars Demo\\etqw.exe"=
"c:\\Program Files\\id Software\\Enemy Territory - QUAKE Wars Demo\\etqwded.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\EA Games\\Command & Conquer Generals Zero Hour\\generals.exe"=
"c:\\Program Files\\EA Games\\Command and Conquer Generals\\generals.exe"=
"c:\\Program Files\\UBISOFT\\Ghost Recon Advanced Warfighter 2\\graw2.exe"=
"c:\\Program Files\\UBISOFT\\Ghost Recon Advanced Warfighter 2\\graw2_dedicated.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth (tm) II\\game.dat"=
"c:\\Program Files\\Electronic Arts\\The Lord of the Rings, The Rise of the Witch-king\\game.dat"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2.1.2010 13:03 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2.1.2010 13:03 20560]
R3 WFLR6654;WinFast DTV1800 H (Video);c:\windows\system32\drivers\wfeaglxt.sys [16.8.2009 21:41 393088]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [3.4.2009 22:33 639224]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]
S3 WFIOCTL;WFIOCTL;c:\program files\WinFast\WFDTV\WFIOCTL.sys [16.8.2009 21:46 9446]

--- Ostatní služby/ovladače v paměti ---

*Deregistered* - mfipufob

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'

2010-01-02 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 04:51]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://start.icq.com/
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\qf372y3k.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://start.icq.com/

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

AddRemove-{B931FB80-537A-4600-00AD-AC5DEDB6C25B} - c:\program files\Electronic Arts\The Lord of the Rings



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-02 18:32
Windows 5.1.2600 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mfipufob]

.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(560)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2010-01-02 18:34:56
ComboFix-quarantined-files.txt 2010-01-02 17:34

Před spuštěním: 8 568 606 720
Po spuštění: 9 243 258 880

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

- - End Of File - - 5DFC3AE0CB65FF1C1DEA05CBBEB16504

JaxFrings
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 02 led 2010 17:15

Re: Pomalý PC, CPU 100% porad

#3 Příspěvek od JaxFrings »

jj myslim ze na icq jsou nejaci rusaci kteri tam spamovali , avast mi nic nehlasil, rootkit nvm jestli mam.

tady je ten CFScript:
ComboFix 10-01-01.05 - Administrator 02.01.2010 19:00:22.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.511.196 [GMT 1:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Administrator\Plocha\CFScript.txt
AV: avast! antivirus 4.8.1356 [VPS 091023-0] *On-access scanning disabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

file zipped: c:\documents and settings\Administrator\Nabídka Start\Programy\Po spuštění\siszyd32.exe
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator\Nabídka Start\Programy\Po spuštění\siszyd32.exe

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_MFIPUFOB
-------\Service_mfipufob


((((((((((((((((((((((((( Soubory vytvořené od 2009-12-02 do 2010-01-02 )))))))))))))))))))))))))))))))
.

2010-01-02 16:58 . 2010-01-02 16:59 -------- d-----w- C:\rsit
2010-01-02 16:22 . 2010-01-02 16:30 -------- d-----w- c:\program files\Ultimate Process Manager
2010-01-02 16:00 . 2009-12-30 13:55 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-02 16:00 . 2010-01-02 16:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-02 16:00 . 2009-12-30 13:54 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-02 12:04 . 2009-09-15 11:54 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-01-02 12:03 . 2009-09-15 11:54 52368 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-01-02 12:03 . 2009-09-15 11:53 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-01-02 12:03 . 2009-09-15 11:53 97480 ----a-w- c:\windows\system32\AvastSS.scr
2010-01-02 12:03 . 2009-09-15 11:56 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-01-02 12:03 . 2009-09-15 11:56 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-01-02 12:03 . 2009-09-15 11:55 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-01-02 12:03 . 2009-09-15 11:55 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-01-02 12:03 . 2009-09-15 11:59 1279968 ----a-w- c:\windows\system32\aswBoot.exe
2010-01-02 12:03 . 2003-03-18 21:20 1060864 ----a-w- c:\windows\system32\MFC71.dll
2010-01-02 12:03 . 2003-03-18 20:14 499712 ----a-w- c:\windows\system32\MSVCP71.dll
2010-01-02 12:03 . 2003-02-21 04:42 348160 ----a-w- c:\windows\system32\MSVCR71.dll
2010-01-02 12:03 . 2010-01-02 12:03 -------- d-----w- c:\program files\Alwil Software
2010-01-01 22:44 . 2010-01-01 22:44 -------- d-----w- c:\program files\1C Company
2010-01-01 22:28 . 2010-01-01 22:28 -------- d-----w- C:\kings bounty datadisk
2009-12-30 22:41 . 2010-01-02 18:06 763904 ----a-w- c:\windows\system32\drivers\mfipufob.sys
2009-12-29 20:52 . 2009-12-29 20:52 -------- d-----w- c:\program files\MP4 Player
2009-12-29 20:34 . 2009-12-29 21:40 -------- d-----w- C:\ve sparech yakuzy
2009-12-25 16:08 . 2009-12-25 16:08 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-12-19 21:27 . 2009-12-19 21:33 52152 ----a-w- c:\windows\War3Unin.dat
2009-12-19 21:27 . 2009-12-19 21:33 2829 ----a-w- c:\windows\War3Unin.pif
2009-12-19 21:27 . 2009-12-19 21:33 139264 ----a-w- c:\windows\War3Unin.exe
2009-12-19 19:41 . 2009-12-23 08:25 -------- d-----w- c:\program files\Warcraft III
2009-12-18 19:47 . 2009-12-31 15:24 -------- d-----w- c:\program files\StepMania
2009-12-17 15:31 . 2009-12-17 15:31 -------- d-----w- c:\program files\FLV Player
2009-12-13 14:33 . 2009-12-13 14:33 -------- d-----w- c:\program files\Runic Games
2009-12-09 15:43 . 2009-12-09 15:44 -------- d-----w- C:\wog
2009-12-04 21:00 . 2009-12-04 21:00 -------- d-----w- C:\south park
2009-12-03 18:53 . 2009-12-03 19:24 -------- d-----w- C:\homam5 datadisk1

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-02 17:32 . 2009-10-14 13:36 -------- d-----w- c:\program files\ICQ6.5
2010-01-02 00:41 . 2009-04-03 21:36 -------- d-----w- c:\program files\TuneUp Utilities 2007
2010-01-02 00:40 . 2009-12-03 14:25 -------- d-----w- c:\program files\FlashGet
2009-12-29 12:40 . 2009-04-04 06:39 -------- d-----w- c:\program files\World of Warcraft
2009-12-25 16:18 . 2009-04-03 19:45 -------- d-----w- c:\program files\ATI Technologies
2009-12-20 10:40 . 2009-06-30 10:33 -------- d-----w- c:\program files\EA Games
2009-12-19 22:10 . 2009-04-04 06:39 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2009-12-04 15:00 . 2009-04-03 19:45 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-03 17:11 . 2009-10-26 14:51 -------- d-----w- c:\program files\UBISOFT
2009-11-29 12:40 . 2009-12-17 20:51 11567 ----a-w- c:\program files\MatotazkySPS08.DOC
2009-11-22 15:55 . 2009-11-22 15:55 -------- d-----w- c:\program files\Vivendi Universal Games
2009-11-12 18:08 . 2009-11-12 18:05 25280 ----a-w- c:\windows\system32\drivers\hamachi.sys
2009-11-07 18:58 . 2009-11-07 18:48 -------- d-----w- c:\program files\Electronic Arts
2009-11-07 15:58 . 2009-06-06 21:55 139904 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-11-07 15:58 . 2009-06-06 21:54 189744 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-10-25 13:34 . 2009-06-30 10:35 980 ----a-w- c:\windows\eReg.dat
2009-10-25 08:22 . 2001-10-25 12:00 76516 ----a-w- c:\windows\system32\perfc005.dat
2009-10-25 08:22 . 2001-10-25 12:00 424082 ----a-w- c:\windows\system32\perfh005.dat
2009-10-15 19:13 . 2009-10-15 19:13 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2009-10-15 19:13 . 2009-10-15 19:13 110592 ----a-w- c:\windows\system32\OpenAL32.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-01-02_17.32.50 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-02 18:07 . 2010-01-02 18:07 16384 c:\windows\Temp\Perflib_Perfdata_540.dat
- 2010-01-02 17:21 . 2010-01-02 17:21 16384 c:\windows\Temp\Perflib_Perfdata_540.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-17 1667584]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-03-27 24103720]
"Google Update"="c:\documents and settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2009-04-18 133104]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2009-04-14 2356088]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" [2009-11-16 172792]
"MP4 Player"="c:\program files\MP4 Player\mp4Player.exe" [2008-11-06 772096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-17 110592]
"SoundMan"="SOUNDMAN.EXE" [2004-09-16 69632]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2006-11-12 157592]
"WinFastDTV"="c:\program files\WinFast\WFDTV\DTVSchdl.exe" [2007-05-16 69632]
"WinFast Schedule"="c:\program files\WinFast\WFDTV\WFWIZ.exe" [2007-05-22 405504]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-09-29 61440]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-09-15 81000]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-17 15360]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Games\\Paintball2\\paintball2.exe"=
"c:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"c:\\Program Files\\Sports Interactive\\Football Manager 2009\\fm.exe"=
"c:\\Program Files\\EA Games\\Command and Conquer Generals\\game.dat"=
"c:\\Wolfenstein\\ET.exe"=
"c:\\Program Files\\EA Games\\Command & Conquer Generals Zero Hour\\game.dat"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\3DO\\Heroes 3 Complete\\HEROES3.ICD"=
"c:\\Documents and Settings\\Administrator\\Plocha\\Tekken 3\\Tekken 3\\ePSXe.exe"=
"c:\\Codemasters\\Blade of Darkness\\Bin\\Blade.exe"=
"c:\\Program Files\\KONAMI\\Pro Evolution Soccer 2008\\PES2008.exe"=
"c:\\crack pes 2008\\PES2008.exe"=
"c:\\Program Files\\EA Games\\Bitwa o Śródziemie\\patchget.dat"=
"c:\\Program Files\\EA Games\\Bitwa o Śródziemie\\game.dat"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\id Software\\Enemy Territory - QUAKE Wars Demo\\etqw.exe"=
"c:\\Program Files\\id Software\\Enemy Territory - QUAKE Wars Demo\\etqwded.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\EA Games\\Command & Conquer Generals Zero Hour\\generals.exe"=
"c:\\Program Files\\EA Games\\Command and Conquer Generals\\generals.exe"=
"c:\\Program Files\\UBISOFT\\Ghost Recon Advanced Warfighter 2\\graw2.exe"=
"c:\\Program Files\\UBISOFT\\Ghost Recon Advanced Warfighter 2\\graw2_dedicated.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth (tm) II\\game.dat"=
"c:\\Program Files\\Electronic Arts\\The Lord of the Rings, The Rise of the Witch-king\\game.dat"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [3.4.2009 22:33 639224]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2.1.2010 13:03 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2.1.2010 13:03 20560]
R3 WFIOCTL;WFIOCTL;c:\program files\WinFast\WFDTV\WFIOCTL.sys [16.8.2009 21:46 9446]
R3 WFLR6654;WinFast DTV1800 H (Video);c:\windows\system32\drivers\wfeaglxt.sys [16.8.2009 21:41 393088]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'

2010-01-02 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 04:51]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://start.icq.com/
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\qf372y3k.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://start.icq.com/

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-02 19:08
Windows 5.1.2600 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8236A1D8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf8579fc3
\Driver\ACPI -> ACPI.sys @ 0xf83fdcb8
\Driver\atapi -> 0x8236a1d8
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a1afe
ParseProcedure -> ntoskrnl.exe @ 0x80570a6e
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a1afe
ParseProcedure -> ntoskrnl.exe @ 0x80570a6e
NDIS: Realtek RTL8139/810x Family Fast Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf8177bc3
PacketIndicateHandler -> NDIS.sys @ 0xf8183b21
SendHandler -> NDIS.sys @ 0xf8177d33
Warning: possible MBR rootkit infection !
user & kernel MBR OK

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(604)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(472)
c:\windows\system32\msi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\system32\wdfmgr.exe
c:\program files\RealVNC\VNC4\WinVNC4.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\windows\SOUNDMAN.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Alwil Software\Avast4\setup\avast.setup
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Celkový čas: 2010-01-02 19:14:06 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-01-02 18:14
ComboFix2.txt 2010-01-02 17:34

Před spuštěním: 9 257 009 152
Po spuštění: 9 170 173 952

- - End Of File - - 50305246E95B2C3E3DB89549C297D48E

JaxFrings
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 02 led 2010 17:15

Re: Pomalý PC, CPU 100% porad

#4 Příspěvek od JaxFrings »

Už jsem odeslal i ten soubor :)

JaxFrings
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 02 led 2010 17:15

Re: Pomalý PC, CPU 100% porad

#5 Příspěvek od JaxFrings »

-ok uz jsem ten soubor odeslal nevadi doufam ze jsem ho zabalil pres winrar?
-jak se na te strance virutotal.com pracuje ? :)

JaxFrings
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 02 led 2010 17:15

Re: Pomalý PC, CPU 100% porad

#6 Příspěvek od JaxFrings »

ok zkontroloval jsem ten soubor na virustotal.com a tady je vysledek :

Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.46 2010.01.02 -
AhnLab-V3 5.0.0.2 2010.01.02 -
AntiVir 7.9.1.122 2009.12.31 -
Antiy-AVL 2.0.3.7 2009.12.31 -
Authentium 5.2.0.5 2010.01.02 -
Avast 4.8.1351.0 2010.01.02 -
AVG 8.5.0.430 2010.01.02 -
BitDefender 7.2 2010.01.02 -
CAT-QuickHeal 10.00 2010.01.02 -
ClamAV 0.94.1 2010.01.01 -
Comodo 3449 2010.01.02 -
DrWeb 5.0.1.12222 2010.01.02 -
eSafe 7.0.17.0 2009.12.31 -
eTrust-Vet 35.1.7210 2010.01.01 -
F-Prot 4.5.1.85 2010.01.02 -
F-Secure 9.0.15370.0 2010.01.02 -
Fortinet 4.0.14.0 2010.01.02 -
GData 19 2010.01.02 -
Ikarus T3.1.1.79.0 2009.12.31 -
Jiangmin 13.0.900 2010.01.02 -
K7AntiVirus 7.10.936 2010.01.02 -
Kaspersky 7.0.0.125 2010.01.02 -
McAfee 5849 2010.01.02 -
McAfee+Artemis 5849 2010.01.02 Artemis!A5E7A32A05AF
McAfee-GW-Edition 6.8.5 2010.01.01 -
Microsoft 1.5302 2010.01.02 -
NOD32 4738 2010.01.02 a variant of Win32/Rootkit.Kryptik.AF
Norman 6.04.03 2009.12.31 -
nProtect 2009.1.8.0 2009.12.31 -
Panda 10.0.2.2 2010.01.02 -
PCTools 7.0.3.5 2010.01.02 -
Prevx 3.0 2010.01.02 High Risk Rootkit
Rising 22.28.03.04 2009.12.31 -
Sophos 4.49.0 2010.01.02 Sus/UnkPack-C
Sunbelt 3.2.1858.2 2010.01.02 -
TheHacker 6.5.0.3.125 2010.01.02 -
TrendMicro 9.120.0.1004 2010.01.02 -
VBA32 3.12.12.1 2010.01.01 -
ViRobot 2009.12.31.2118 2009.12.31 -
VirusBuster 5.0.21.0 2010.01.02 -
Rozšiřující informace
File size: 763904 bytes
MD5...: a5e7a32a05af52b5807038a24c8b97e0
SHA1..: f9d3b45f20eb06ba1d2b1c330bda160d5d30779c
SHA256: 95ccd80dd8cc1caa7957fdf0dc11732c2277f5143e6e8ed66bd1ff65a7b4cdc6
ssdeep: 12288:eT5BlNAfUkGhRz3rGOmxPQhtnGQvXQpX3T8uZZgiPshs/4KAjjF+ZGZo3H
Ho:e9BIfUk8z3rnmxe6XAs/4jBo3
PEiD..: -
PEInfo: PE Structure information

JaxFrings
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 02 led 2010 17:15

Re: Pomalý PC, CPU 100% porad

#7 Příspěvek od JaxFrings »

Ještě nemusím zkontrolovat PC přes gmer.exe :D?

JaxFrings
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 02 led 2010 17:15

Re: Pomalý PC, CPU 100% porad

#8 Příspěvek od JaxFrings »

Tady posilam výsledek rychlého scanu pres gmer : :)

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-01-02 20:12:36
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ufncaaog.sys


---- System - GMER 1.0.15 ----

SSDT sptd.sys ZwEnumerateKey [0xF844384E]
SSDT sptd.sys ZwEnumerateValueKey [0xF8443BEE]

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 823691D8

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

---- EOF - GMER 1.0.15 ----

JaxFrings
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 02 led 2010 17:15

Re: Pomalý PC, CPU 100% porad

#9 Příspěvek od JaxFrings »

Tn klasicky scan je fakt pomaly :(

JaxFrings
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 02 led 2010 17:15

Re: Pomalý PC, CPU 100% porad

#10 Příspěvek od JaxFrings »

Malwarebytes' Anti-Malware mi tam neco nesel predtim ale radsi jsem nic nedelal radsi jsem to nechal odbornikum :D , Ultimate proces manager toho jsem ani tak moc nevyuzil :mrgreen:

JaxFrings
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 02 led 2010 17:15

Re: Pomalý PC, CPU 100% porad

#11 Příspěvek od JaxFrings »

Tu havěť jsem ti poslal v SZ :P , jinak gmer porad kontroluje , ale pc se uz mi zda docela ok :) , vyuziti pc uz jen malo kdy ukaze 100% :)

JaxFrings
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 02 led 2010 17:15

Re: Pomalý PC, CPU 100% porad

#12 Příspěvek od JaxFrings »

Konečně :) , tady ti posilam ten log z gmeru :P :

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-02 21:34:43
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ufncaaog.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xA956E6B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xA956E574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xA956EA52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xA956E14C]
SSDT sptd.sys ZwEnumerateKey [0xF844384E]
SSDT sptd.sys ZwEnumerateValueKey [0xF8443BEE]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xA956E64E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xA956E08C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xA956E0F0]
SSDT sptd.sys ZwQueryKey [0xF8443CC6]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xA956E76E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xA956E72E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xA956E8AE]

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 823691D8

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\usbuhci \Device\USBPDO-0 820CA2C8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 823D71D8
Device \Driver\dmio \Device\DmControl\DmConfig 823D71D8
Device \Driver\dmio \Device\DmControl\DmPnP 823D71D8
Device \Driver\dmio \Device\DmControl\DmInfo 823D71D8
Device \Driver\usbuhci \Device\USBPDO-1 820CA2C8
Device \Driver\usbuhci \Device\USBPDO-2 820CA2C8
Device \Driver\usbuhci \Device\USBPDO-3 820CA2C8
Device \Driver\usbehci \Device\USBPDO-4 8216D1D8

AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\00000047 \Device\00000049 sptd.sys
Device \Driver\NetBT \Device\NetBT_Tcpip_{BA7B2601-F64B-4359-B990-30283D9EC777} 81F47980
Device \Driver\Ftdisk \Device\HarddiskVolume1 8236B1D8
Device \Driver\Cdrom \Device\CdRom0 8204A980
Device \Driver\atapi \Device\Ide\IdePort0 8236A1D8
Device \Driver\atapi \Device\Ide\IdePort1 8236A1D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 8236A1D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e 8236A1D8
Device \Driver\NetBT \Device\NetBt_Wins_Export 81F47980
Device \Driver\NetBT \Device\NetbiosSmb 81F47980

AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\usbuhci \Device\USBFDO-0 820CA2C8
Device \Driver\usbuhci \Device\USBFDO-1 820CA2C8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 81F5A770
Device \Driver\usbuhci \Device\USBFDO-2 820CA2C8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 81F5A770
Device \Driver\usbuhci \Device\USBFDO-3 820CA2C8
Device \Driver\usbehci \Device\USBFDO-4 8216D1D8
Device \Driver\Ftdisk \Device\FtControl 8236B1D8
Device \Driver\a8usxl8n \Device\Scsi\a8usxl8n1 820947E0
Device \FileSystem\Cdfs \Cdfs 81FCE4B8

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0013eff0cd60
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 -986934591
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 -32006448
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x55 0x69 0x21 0x3B ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x3C 0xE4 0xB4 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF3 0xAB 0xBA 0xEE ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0013eff0cd60 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x55 0x69 0x21 0x3B ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x3C 0xE4 0xB4 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF3 0xAB 0xBA 0xEE ...

---- EOF - GMER 1.0.15 ----

JaxFrings
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 02 led 2010 17:15

Re: Pomalý PC, CPU 100% porad

#13 Příspěvek od JaxFrings »

vyčištěno :) , RSIT :

Logfile of random's system information tool 1.06 (written by random/random)
Run by Administrator at 2010-01-02 22:20:59
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 9 GB (4%) free of 238 GB
Total RAM: 511 MB (37% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:21:07, on 2.1.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\MP4 Player\mp4Player.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Administrator\Dokumenty\Downloads\RSIT.exe
c:\Program Files\Hijackthis\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFDTV\WFWIZ.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [combofix] "C:\ComboFix\CF14589.cfxxe" /c "C:\ComboFix\C.bat"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent
O4 - HKCU\..\Run: [MP4 Player] "C:\Program Files\MP4 Player\mp4Player.exe" hmw
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe

--
End of file - 6319 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-03-27 1082880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2004-09-16 69632]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-09 153136]
"DAEMON Tools"=C:\Program Files\DAEMON Tools\daemon.exe [2006-11-12 157592]
"WinFastDTV"=C:\Program Files\WinFast\WFDTV\DTVSchdl.exe [2007-05-16 69632]
"WinFast Schedule"=C:\Program Files\WinFast\WFDTV\WFWIZ.exe [2007-05-22 405504]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-09-29 61440]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-09-15 81000]
"combofix"=C:\ComboFix\CF14589.cfxxe /c C:\ComboFix\C.bat []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2004-08-17 1667584]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-03-12 153136]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-03-27 24103720]
"Google Update"=C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-04-18 133104]
"AdobeUpdater"=C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe [2009-04-14 2356088]
"ICQ"=C:\Program Files\ICQ6.5\ICQ.exe [2009-11-16 172792]
"MP4 Player"=C:\Program Files\MP4 Player\mp4Player.exe [2008-11-06 772096]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-09-30 155648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\World of Warcraft\Launcher.exe"="C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:World of Warcraft"
"C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe"="C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe:*:Enabled:Nero ShowTime"
"C:\Games\Paintball2\paintball2.exe"="C:\Games\Paintball2\paintball2.exe:*:Enabled:paintball2"
"C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe"="C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"C:\Program Files\Sports Interactive\Football Manager 2009\fm.exe"="C:\Program Files\Sports Interactive\Football Manager 2009\fm.exe:*:Enabled:Football Manager 2009"
"C:\Program Files\EA Games\Command and Conquer Generals\game.dat"="C:\Program Files\EA Games\Command and Conquer Generals\game.dat:*:Enabled:game"
"C:\Wolfenstein\ET.exe"="C:\Wolfenstein\ET.exe:*:Enabled:ET"
"C:\Program Files\EA Games\Command & Conquer Generals Zero Hour\game.dat"="C:\Program Files\EA Games\Command & Conquer Generals Zero Hour\game.dat:*:Enabled:game"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\Program Files\3DO\Heroes 3 Complete\HEROES3.ICD"="C:\Program Files\3DO\Heroes 3 Complete\HEROES3.ICD:*:Enabled:Heroes of Might and Magic® III"
"C:\Documents and Settings\Administrator\Plocha\Tekken 3\Tekken 3\ePSXe.exe"="C:\Documents and Settings\Administrator\Plocha\Tekken 3\Tekken 3\ePSXe.exe:*:Enabled:ePSXe"
"C:\Codemasters\Blade of Darkness\Bin\Blade.exe"="C:\Codemasters\Blade of Darkness\Bin\Blade.exe:*:Enabled:Blade"
"C:\Program Files\KONAMI\Pro Evolution Soccer 2008\PES2008.exe"="C:\Program Files\KONAMI\Pro Evolution Soccer 2008\PES2008.exe:*:Enabled:Pro Evolution Soccer 2008"
"C:\crack pes 2008\PES2008.exe"="C:\crack pes 2008\PES2008.exe:*:Enabled:Pro Evolution Soccer 2008"
"C:\Program Files\EA Games\Bitwa o Śródziemie\patchget.dat"="C:\Program Files\EA Games\Bitwa o Śródziemie\patchget.dat:*:Enabled:patchgrabber"
"C:\Program Files\EA Games\Bitwa o Śródziemie\game.dat"="C:\Program Files\EA Games\Bitwa o Śródziemie\game.dat:*:Enabled:Bitwa o Śródziemie (tm)"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\id Software\Enemy Territory - QUAKE Wars Demo\etqw.exe"="C:\Program Files\id Software\Enemy Territory - QUAKE Wars Demo\etqw.exe:*:Enabled:Enemy Territory - QUAKE Wars(TM) Demo"
"C:\Program Files\id Software\Enemy Territory - QUAKE Wars Demo\etqwded.exe"="C:\Program Files\id Software\Enemy Territory - QUAKE Wars Demo\etqwded.exe:*:Enabled:etqwded.exe"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\EA Games\Command & Conquer Generals Zero Hour\generals.exe"="C:\Program Files\EA Games\Command & Conquer Generals Zero Hour\generals.exe:*:Enabled:Command and ConquerTM Generals Zero Hour"
"C:\Program Files\EA Games\Command and Conquer Generals\generals.exe"="C:\Program Files\EA Games\Command and Conquer Generals\generals.exe:*:Enabled:Command & Conquer Generals"
"C:\Program Files\UBISOFT\Ghost Recon Advanced Warfighter 2\graw2.exe"="C:\Program Files\UBISOFT\Ghost Recon Advanced Warfighter 2\graw2.exe:*:Enabled:Ghost Recon Advanced Warfighter® 2"
"C:\Program Files\UBISOFT\Ghost Recon Advanced Warfighter 2\graw2_dedicated.exe"="C:\Program Files\UBISOFT\Ghost Recon Advanced Warfighter 2\graw2_dedicated.exe:*:Enabled:Ghost Recon Advanced Warfighter® 2 Dedicated Server"
"C:\Program Files\Valve\hl.exe"="C:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat"="C:\Program Files\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat:*:Enabled:The Battle for Middle-earth(tm) II"
"C:\Program Files\Electronic Arts\The Lord of the Rings, The Rise of the Witch-king\game.dat"="C:\Program Files\Electronic Arts\The Lord of the Rings, The Rise of the Witch-king\game.dat:*:Enabled:The Lord of the Rings, The Rise of the Witch-king"
"C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"="C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2010-01-02 22:20:59 ----D---- C:\rsit
2010-01-02 19:40:21 ----SHD---- C:\RECYCLER
2010-01-02 18:25:21 ----A---- C:\Boot.bak
2010-01-02 18:25:15 ----RASHD---- C:\cmdcons
2010-01-02 18:21:33 ----D---- C:\WINDOWS\ERDNT
2010-01-02 17:46:55 ----D---- C:\Program Files\Hijackthis
2010-01-02 17:22:02 ----D---- C:\Program Files\Ultimate Process Manager
2010-01-02 17:01:13 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Malwarebytes
2010-01-02 17:00:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-01-02 17:00:53 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-01-02 13:03:18 ----A---- C:\WINDOWS\system32\MSVCR71.dll
2010-01-02 13:03:18 ----A---- C:\WINDOWS\system32\MSVCP71.dll
2010-01-02 13:03:18 ----A---- C:\WINDOWS\system32\MFC71.dll
2010-01-02 13:03:18 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-01-02 13:03:15 ----D---- C:\Program Files\Alwil Software
2010-01-02 11:37:31 ----D---- C:\WINDOWS\Minidump
2010-01-02 11:35:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\Kaspersky Lab Setup Files
2010-01-01 23:44:20 ----D---- C:\Program Files\1C Company
2010-01-01 23:28:09 ----D---- C:\kings bounty datadisk
2009-12-29 21:52:51 ----H---- C:\Documents and Settings\Administrator\Data aplikací\swk.ini
2009-12-29 21:52:48 ----D---- C:\Program Files\MP4 Player
2009-12-29 21:34:35 ----D---- C:\ve sparech yakuzy
2009-12-25 17:28:51 ----D---- C:\Documents and Settings\All Users\Data aplikací\ATI
2009-12-25 17:16:41 ----D---- C:\Config.Msi
2009-12-19 23:15:43 ----D---- C:\Documents and Settings\All Users\Data aplikací\Blizzard
2009-12-19 22:27:01 ----A---- C:\WINDOWS\War3Unin.exe
2009-12-19 20:41:26 ----D---- C:\Program Files\Warcraft III
2009-12-18 20:47:11 ----D---- C:\Program Files\StepMania
2009-12-17 16:31:24 ----D---- C:\Program Files\FLV Player
2009-12-13 15:41:22 ----D---- C:\Documents and Settings\Administrator\Data aplikací\runic games
2009-12-13 15:33:16 ----D---- C:\Program Files\Runic Games
2009-12-09 16:43:36 ----D---- C:\wog
2009-12-04 22:00:39 ----D---- C:\south park
2009-12-03 19:53:39 ----D---- C:\homam5 datadisk1
2009-12-03 17:59:51 ----D---- C:\homam5
2009-12-03 15:27:49 ----D---- C:\Downloads
2009-12-03 15:25:19 ----D---- C:\Program Files\FlashGet

======List of files/folders modified in the last 1 months======

2010-01-02 22:17:50 ----D---- C:\Program Files\Mozilla Firefox
2010-01-02 22:17:05 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Skype
2010-01-02 22:16:58 ----D---- C:\WINDOWS\Temp
2010-01-02 22:14:45 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-02 22:14:26 ----D---- C:\WINDOWS\Prefetch
2010-01-02 22:11:28 ----A---- C:\WINDOWS\wincmd.ini
2010-01-02 22:06:36 ----D---- C:\WINDOWS\system32
2010-01-02 22:06:36 ----D---- C:\WINDOWS
2010-01-02 22:05:12 ----SHD---- C:\System Volume Information
2010-01-02 22:05:12 ----D---- C:\WINDOWS\system32\Restore
2010-01-02 21:54:26 ----D---- C:\WINDOWS\system32\CatRoot2
2010-01-02 19:40:21 ----D---- C:\WINDOWS\system32\drivers
2010-01-02 19:08:24 ----A---- C:\WINDOWS\system.ini
2010-01-02 19:06:11 ----D---- C:\WINDOWS\system32\config
2010-01-02 19:03:34 ----D---- C:\WINDOWS\AppPatch
2010-01-02 19:03:29 ----D---- C:\Program Files\Common Files
2010-01-02 18:34:17 ----SD---- C:\WINDOWS\Tasks
2010-01-02 18:32:09 ----D---- C:\Program Files\ICQ6.5
2010-01-02 18:25:21 ----RASH---- C:\boot.ini
2010-01-02 17:46:55 ----RD---- C:\Program Files
2010-01-02 14:55:12 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-01-02 14:55:05 ----D---- C:\Program Files\Internet Explorer
2010-01-02 11:45:16 ----SHD---- C:\WINDOWS\Installer
2010-01-02 11:38:47 ----D---- C:\Documents and Settings\Administrator\Data aplikací\ICQ
2010-01-02 01:41:25 ----D---- C:\WINDOWS\Debug
2010-01-02 01:41:22 ----D---- C:\totalcmd
2010-01-02 01:41:18 ----D---- C:\Program Files\TuneUp Utilities 2007
2010-01-02 00:41:47 ----D---- C:\WINDOWS\system32\DirectX
2010-01-02 00:41:27 ----HD---- C:\WINDOWS\inf
2010-01-02 00:35:49 ----RSD---- C:\WINDOWS\assembly
2009-12-30 00:05:13 ----A---- C:\WINDOWS\NeroDigital.ini
2009-12-29 13:40:17 ----D---- C:\Program Files\World of Warcraft
2009-12-29 13:10:59 ----A---- C:\WINDOWS\win.ini
2009-12-25 22:01:27 ----D---- C:\filmy
2009-12-25 17:18:55 ----D---- C:\WINDOWS\WinSxS
2009-12-25 17:18:44 ----D---- C:\Program Files\ATI Technologies
2009-12-20 11:40:17 ----D---- C:\Program Files\EA Games
2009-12-19 23:10:57 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
2009-12-17 16:31:42 ----D---- C:\amiga
2009-12-04 16:00:55 ----HD---- C:\Program Files\InstallShield Installation Information
2009-12-03 18:11:01 ----D---- C:\Program Files\UBISOFT

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-09-15 27408]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-09-15 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-09-15 52368]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2004-08-17 39936]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-09-15 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-09-15 94160]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-09-21 2278784]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-09-15 23152]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2009-09-30 3565056]
R3 RTL8023xp;Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2004-04-13 70144]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 WFIOCTL;WFIOCTL; \??\C:\Program Files\WinFast\WFDTV\WFIOCTL.SYS []
R3 WFLR6654;WinFast DTV1800 H (Video); C:\WINDOWS\system32\drivers\wfeaglxt.sys [2007-01-19 393088]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-03 60800]
S3 BthEnum;Služba Bluetooth Enumerator; C:\WINDOWS\System32\DRIVERS\BthEnum.sys [2004-08-03 17024]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2004-08-03 100992]
S3 BTHPORT;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2004-08-17 274304]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2004-08-03 18944]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-11-12 25280]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 MPE;Filtr MPE BDA; C:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-03 15360]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-03 61824]
S3 NTACCESS;NTACCESS; \??\D:\NTACCESS.sys []
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2004-08-03 59648]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 SetupNTGLM7X;SetupNTGLM7X; \??\D:\NTGLM7X.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 ZDPSp50;ZDPSp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\ZDPSp50.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-04-03 639224]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-09-15 18752]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-09-30 602112]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-09-15 138680]
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-09-25 75064]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2004-12-13 49152]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2004-08-17 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-09-15 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-09-15 352920]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-03-12 271920]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2009-09-29 593920]
S2 WinVNC4;VNC Server Version 4; C:\Program Files\RealVNC\VNC4\WinVNC4.exe [2008-10-15 439632]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-01-15 774144]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]

-----------------EOF-----------------

JaxFrings
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 02 led 2010 17:15

Re: Pomalý PC, CPU 100% porad

#14 Příspěvek od JaxFrings »

tak co jak to vypada ? :)

JaxFrings
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 02 led 2010 17:15

Re: Pomalý PC, CPU 100% porad

#15 Příspěvek od JaxFrings »

Ja jsem ten ComboFix odinstaloval tak jak jsi psal , po restartu mi to napsalo odinstalace proběhla v pořádku tak nvm :D

tady je RSIT:

Logfile of random's system information tool 1.06 (written by random/random)
Run by Administrator at 2010-01-03 12:05:33
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 9 GB (4%) free of 238 GB
Total RAM: 511 MB (42% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:05:41, on 3.1.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\MP4 Player\mp4Player.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Administrator\Dokumenty\Downloads\RSIT.exe
c:\Program Files\Hijackthis\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFDTV\WFWIZ.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [combofix] "C:\ComboFix\CF14589.cfxxe" /c "C:\ComboFix\C.bat"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent
O4 - HKCU\..\Run: [MP4 Player] "C:\Program Files\MP4 Player\mp4Player.exe" hmw
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe

--
End of file - 6230 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-03-27 1082880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2004-09-16 69632]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-09 153136]
"DAEMON Tools"=C:\Program Files\DAEMON Tools\daemon.exe [2006-11-12 157592]
"WinFastDTV"=C:\Program Files\WinFast\WFDTV\DTVSchdl.exe [2007-05-16 69632]
"WinFast Schedule"=C:\Program Files\WinFast\WFDTV\WFWIZ.exe [2007-05-22 405504]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-09-29 61440]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-09-15 81000]
"combofix"=C:\ComboFix\CF14589.cfxxe /c C:\ComboFix\C.bat []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2004-08-17 1667584]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-03-12 153136]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-03-27 24103720]
"Google Update"=C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-04-18 133104]
"AdobeUpdater"=C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe [2009-04-14 2356088]
"ICQ"=C:\Program Files\ICQ6.5\ICQ.exe [2009-11-16 172792]
"MP4 Player"=C:\Program Files\MP4 Player\mp4Player.exe [2008-11-06 772096]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-09-30 155648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\World of Warcraft\Launcher.exe"="C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:World of Warcraft"
"C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe"="C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe:*:Enabled:Nero ShowTime"
"C:\Games\Paintball2\paintball2.exe"="C:\Games\Paintball2\paintball2.exe:*:Enabled:paintball2"
"C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe"="C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"C:\Program Files\Sports Interactive\Football Manager 2009\fm.exe"="C:\Program Files\Sports Interactive\Football Manager 2009\fm.exe:*:Enabled:Football Manager 2009"
"C:\Program Files\EA Games\Command and Conquer Generals\game.dat"="C:\Program Files\EA Games\Command and Conquer Generals\game.dat:*:Enabled:game"
"C:\Wolfenstein\ET.exe"="C:\Wolfenstein\ET.exe:*:Enabled:ET"
"C:\Program Files\EA Games\Command & Conquer Generals Zero Hour\game.dat"="C:\Program Files\EA Games\Command & Conquer Generals Zero Hour\game.dat:*:Enabled:game"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\Program Files\3DO\Heroes 3 Complete\HEROES3.ICD"="C:\Program Files\3DO\Heroes 3 Complete\HEROES3.ICD:*:Enabled:Heroes of Might and Magic® III"
"C:\Documents and Settings\Administrator\Plocha\Tekken 3\Tekken 3\ePSXe.exe"="C:\Documents and Settings\Administrator\Plocha\Tekken 3\Tekken 3\ePSXe.exe:*:Enabled:ePSXe"
"C:\Codemasters\Blade of Darkness\Bin\Blade.exe"="C:\Codemasters\Blade of Darkness\Bin\Blade.exe:*:Enabled:Blade"
"C:\Program Files\KONAMI\Pro Evolution Soccer 2008\PES2008.exe"="C:\Program Files\KONAMI\Pro Evolution Soccer 2008\PES2008.exe:*:Enabled:Pro Evolution Soccer 2008"
"C:\crack pes 2008\PES2008.exe"="C:\crack pes 2008\PES2008.exe:*:Enabled:Pro Evolution Soccer 2008"
"C:\Program Files\EA Games\Bitwa o Śródziemie\patchget.dat"="C:\Program Files\EA Games\Bitwa o Śródziemie\patchget.dat:*:Enabled:patchgrabber"
"C:\Program Files\EA Games\Bitwa o Śródziemie\game.dat"="C:\Program Files\EA Games\Bitwa o Śródziemie\game.dat:*:Enabled:Bitwa o Śródziemie (tm)"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\id Software\Enemy Territory - QUAKE Wars Demo\etqw.exe"="C:\Program Files\id Software\Enemy Territory - QUAKE Wars Demo\etqw.exe:*:Enabled:Enemy Territory - QUAKE Wars(TM) Demo"
"C:\Program Files\id Software\Enemy Territory - QUAKE Wars Demo\etqwded.exe"="C:\Program Files\id Software\Enemy Territory - QUAKE Wars Demo\etqwded.exe:*:Enabled:etqwded.exe"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\EA Games\Command & Conquer Generals Zero Hour\generals.exe"="C:\Program Files\EA Games\Command & Conquer Generals Zero Hour\generals.exe:*:Enabled:Command and ConquerTM Generals Zero Hour"
"C:\Program Files\EA Games\Command and Conquer Generals\generals.exe"="C:\Program Files\EA Games\Command and Conquer Generals\generals.exe:*:Enabled:Command & Conquer Generals"
"C:\Program Files\UBISOFT\Ghost Recon Advanced Warfighter 2\graw2.exe"="C:\Program Files\UBISOFT\Ghost Recon Advanced Warfighter 2\graw2.exe:*:Enabled:Ghost Recon Advanced Warfighter® 2"
"C:\Program Files\UBISOFT\Ghost Recon Advanced Warfighter 2\graw2_dedicated.exe"="C:\Program Files\UBISOFT\Ghost Recon Advanced Warfighter 2\graw2_dedicated.exe:*:Enabled:Ghost Recon Advanced Warfighter® 2 Dedicated Server"
"C:\Program Files\Valve\hl.exe"="C:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat"="C:\Program Files\Electronic Arts\The Battle for Middle-earth (tm) II\game.dat:*:Enabled:The Battle for Middle-earth(tm) II"
"C:\Program Files\Electronic Arts\The Lord of the Rings, The Rise of the Witch-king\game.dat"="C:\Program Files\Electronic Arts\The Lord of the Rings, The Rise of the Witch-king\game.dat:*:Enabled:The Lord of the Rings, The Rise of the Witch-king"
"C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"="C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2010-01-02 22:40:19 ----D---- C:\Kings bounty armored princess
2010-01-02 22:20:59 ----D---- C:\rsit
2010-01-02 19:40:21 ----SHD---- C:\RECYCLER
2010-01-02 18:25:21 ----A---- C:\Boot.bak
2010-01-02 18:25:15 ----RASHD---- C:\cmdcons
2010-01-02 18:21:33 ----D---- C:\WINDOWS\ERDNT
2010-01-02 17:46:55 ----D---- C:\Program Files\Hijackthis
2010-01-02 17:22:02 ----D---- C:\Program Files\Ultimate Process Manager
2010-01-02 17:01:13 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Malwarebytes
2010-01-02 17:00:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-01-02 17:00:53 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-01-02 13:03:18 ----A---- C:\WINDOWS\system32\MSVCR71.dll
2010-01-02 13:03:18 ----A---- C:\WINDOWS\system32\MSVCP71.dll
2010-01-02 13:03:18 ----A---- C:\WINDOWS\system32\MFC71.dll
2010-01-02 13:03:18 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-01-02 13:03:15 ----D---- C:\Program Files\Alwil Software
2010-01-02 11:37:31 ----D---- C:\WINDOWS\Minidump
2010-01-02 11:35:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\Kaspersky Lab Setup Files
2010-01-01 23:44:20 ----D---- C:\Program Files\1C Company
2010-01-01 23:28:09 ----D---- C:\kings bounty datadisk
2009-12-29 21:52:51 ----H---- C:\Documents and Settings\Administrator\Data aplikací\swk.ini
2009-12-29 21:52:48 ----D---- C:\Program Files\MP4 Player
2009-12-29 21:34:35 ----D---- C:\ve sparech yakuzy
2009-12-25 17:28:51 ----D---- C:\Documents and Settings\All Users\Data aplikací\ATI
2009-12-25 17:16:41 ----D---- C:\Config.Msi
2009-12-19 23:15:43 ----D---- C:\Documents and Settings\All Users\Data aplikací\Blizzard
2009-12-19 22:27:01 ----A---- C:\WINDOWS\War3Unin.exe
2009-12-19 20:41:26 ----D---- C:\Program Files\Warcraft III
2009-12-18 20:47:11 ----D---- C:\Program Files\StepMania
2009-12-17 16:31:24 ----D---- C:\Program Files\FLV Player
2009-12-13 15:41:22 ----D---- C:\Documents and Settings\Administrator\Data aplikací\runic games
2009-12-13 15:33:16 ----D---- C:\Program Files\Runic Games
2009-12-09 16:43:36 ----D---- C:\wog
2009-12-04 22:00:39 ----D---- C:\south park

======List of files/folders modified in the last 1 months======

2010-01-03 12:05:21 ----D---- C:\Program Files\Mozilla Firefox
2010-01-03 12:05:18 ----A---- C:\WINDOWS\wincmd.ini
2010-01-03 11:59:50 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Skype
2010-01-03 11:59:15 ----D---- C:\WINDOWS\Prefetch
2010-01-03 11:54:47 ----D---- C:\WINDOWS\Temp
2010-01-03 03:09:48 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-02 22:06:36 ----D---- C:\WINDOWS\system32
2010-01-02 22:06:36 ----D---- C:\WINDOWS
2010-01-02 22:05:12 ----SHD---- C:\System Volume Information
2010-01-02 22:05:12 ----D---- C:\WINDOWS\system32\Restore
2010-01-02 21:54:26 ----D---- C:\WINDOWS\system32\CatRoot2
2010-01-02 19:40:21 ----D---- C:\WINDOWS\system32\drivers
2010-01-02 19:08:24 ----A---- C:\WINDOWS\system.ini
2010-01-02 19:06:11 ----D---- C:\WINDOWS\system32\config
2010-01-02 19:03:34 ----D---- C:\WINDOWS\AppPatch
2010-01-02 19:03:29 ----D---- C:\Program Files\Common Files
2010-01-02 18:34:17 ----SD---- C:\WINDOWS\Tasks
2010-01-02 18:32:09 ----D---- C:\Program Files\ICQ6.5
2010-01-02 18:25:21 ----RASH---- C:\boot.ini
2010-01-02 17:46:55 ----RD---- C:\Program Files
2010-01-02 14:55:12 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-01-02 14:55:05 ----D---- C:\Program Files\Internet Explorer
2010-01-02 11:45:16 ----SHD---- C:\WINDOWS\Installer
2010-01-02 11:38:47 ----D---- C:\Documents and Settings\Administrator\Data aplikací\ICQ
2010-01-02 01:41:25 ----D---- C:\WINDOWS\Debug
2010-01-02 01:41:22 ----D---- C:\totalcmd
2010-01-02 01:41:18 ----D---- C:\Program Files\TuneUp Utilities 2007
2010-01-02 01:40:53 ----D---- C:\Program Files\FlashGet
2010-01-02 00:41:47 ----D---- C:\WINDOWS\system32\DirectX
2010-01-02 00:41:27 ----HD---- C:\WINDOWS\inf
2010-01-02 00:35:49 ----RSD---- C:\WINDOWS\assembly
2009-12-30 00:05:13 ----A---- C:\WINDOWS\NeroDigital.ini
2009-12-29 13:40:17 ----D---- C:\Program Files\World of Warcraft
2009-12-29 13:10:59 ----A---- C:\WINDOWS\win.ini
2009-12-25 22:01:27 ----D---- C:\filmy
2009-12-25 17:18:55 ----D---- C:\WINDOWS\WinSxS
2009-12-25 17:18:44 ----D---- C:\Program Files\ATI Technologies
2009-12-20 11:40:17 ----D---- C:\Program Files\EA Games
2009-12-19 23:10:57 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
2009-12-17 16:31:42 ----D---- C:\amiga
2009-12-04 16:00:55 ----HD---- C:\Program Files\InstallShield Installation Information

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-09-15 27408]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-09-15 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-09-15 52368]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2004-08-17 39936]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-09-15 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-09-15 94160]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-09-21 2278784]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-09-15 23152]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2009-09-30 3565056]
R3 RTL8023xp;Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2004-04-13 70144]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 WFIOCTL;WFIOCTL; \??\C:\Program Files\WinFast\WFDTV\WFIOCTL.SYS []
R3 WFLR6654;WinFast DTV1800 H (Video); C:\WINDOWS\system32\drivers\wfeaglxt.sys [2007-01-19 393088]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-03 60800]
S3 BthEnum;Služba Bluetooth Enumerator; C:\WINDOWS\System32\DRIVERS\BthEnum.sys [2004-08-03 17024]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2004-08-03 100992]
S3 BTHPORT;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2004-08-17 274304]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2004-08-03 18944]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-11-12 25280]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 MPE;Filtr MPE BDA; C:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-03 15360]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-03 61824]
S3 NTACCESS;NTACCESS; \??\D:\NTACCESS.sys []
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2004-08-03 59648]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 SetupNTGLM7X;SetupNTGLM7X; \??\D:\NTGLM7X.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 ZDPSp50;ZDPSp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\ZDPSp50.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-04-03 639224]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-09-15 18752]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-09-30 602112]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-09-15 138680]
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-09-25 75064]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2004-12-13 49152]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2004-08-17 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-09-15 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-09-15 352920]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-03-12 271920]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2009-09-29 593920]
S2 WinVNC4;VNC Server Version 4; C:\Program Files\RealVNC\VNC4\WinVNC4.exe [2008-10-15 439632]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-01-15 774144]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]

-----------------EOF-----------------

Odpovědět