
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o preventivku - občas zamrzne IE8, nelze ukončit
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Prosím o preventivku - občas zamrzne IE8, nelze ukončit
ComboFix 11-12-12.02 - Miloš 15.12.2011 20:43:40.7.4 - FAT32x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3326.2275 [GMT 1:00]
Spuštěný z: C:\ComboFix.exe
Použité ovládací přepínače :: C:\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *Disabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
.
FILE ::
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\askcom.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-1.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-10.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-2.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-3.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-4.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-5.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-6.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-7.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-8.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-9.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\SearchResults.xml"
"c:\program files\Vuze_Remote\prxtbVuz0.dll"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\tasks\Norton Security Scan for Miloš.job"
"c:\windows\tasks\RealUpgradeLogonTaskS-1-5-21-4036164967-4113303836-1484400983-1005.job"
"c:\windows\tasks\RealUpgradeScheduledTaskS-1-5-21-4036164967-4113303836-1484400983-1005.job"
"c:\windows\tasks\Scheduled Update for Ask Toolbar.job"
"c:\windows\tasks\SpeedUpMyPC.job"
"c:\windows\tasks\User_Feed_Synchronization-{27F5AB2D-4486-4DE2-BDE0-21639BA93517}.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\tasks\RealUpgradeLogonTaskS-1-5-21-4036164967-4113303836-1484400983-1005.job
c:\windows\tasks\RealUpgradeScheduledTaskS-1-5-21-4036164967-4113303836-1484400983-1005.job
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-11-15 do 2011-12-15 )))))))))))))))))))))))))))))))
.
.
2011-12-12 22:13 . 2011-12-12 22:13 -------- d-----w- C:\FOUND.001
2011-12-12 21:52 . 2011-12-12 21:52 -------- d-----w- C:\FOUND.000
2011-12-10 15:27 . 2011-12-10 15:27 -------- d-----w- c:\documents and settings\Miloš\Local Settings\Data aplikací\AskToolbar
2011-12-10 15:27 . 2011-12-10 15:27 -------- d-----w- c:\program files\FotoSketcher
2011-11-29 15:39 . 2011-11-29 15:39 -------- d-----w- c:\program files\BT
2011-11-25 16:55 . 2011-11-25 16:55 -------- d--h--w- c:\windows\ie8
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-28 07:31 . 2011-10-28 07:31 25248 ----a-w- c:\windows\system32\drivers\AmgHips.sys
2011-10-10 14:22 . 2009-01-19 09:19 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 1979-12-31 23:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 10:41 . 2008-07-29 18:59 613376 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 10:41 . 1979-12-31 23:00 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 10:41 . 1979-12-31 23:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-03-18 17:55 . 2011-03-23 20:23 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-14_17.06.08 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-07 05:12 . 2011-12-15 19:45 217609 c:\windows\system32\inetsrv\MetaBase.bin
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"USB Safely Remove"="c:\program files\USB Safely Remove\USBSafelyRemove.exe" [2010-12-25 1794392]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="c:\progra~1\SYMANT~1\\vptray.exe" [2006-07-17 125072]
"RTHDCPL"="RTHDCPL.EXE" [2008-12-09 18063872]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-03-24 53408]
"MDS_Menu"="c:\program files\CyberLink\MediaShow4\MUITransfer\MUIStartMenu.exe" [2009-02-25 218408]
"TrayServer"="c:\program files\MAGIX\Movie_Edit_Pro_15_silver\TrayServer.exe" [2008-11-13 90112]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
RAMASST.lnk - c:\windows\system32\RAMAsst.exe [2009-2-26 167936]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Foxit Software\\PDF Editor\\PDFEdit.exe"=
"c:\\Program Files\\Real\\RealPlayer\\RecordingManager.exe"=
"c:\\Program Files\\Java\\JRE6\\BIN\\java.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe"=
"c:\\Program Files\\SnugTV\\SnugTV Station\\ConfigMaster.exe"=
"c:\\Program Files\\SnugTV\\SnugTV Station\\ConfigWizard.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\EPLAN\\Electric P8\\1.9.11\\BIN\\W3u.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\WINDOWS\\System32\\hasplms.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\ICQ7.6\\ICQ.exe"=
"c:\\Program Files\\SnugTV\\SnugTV Station\\AMAServer.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R1 AmgHips;AmgHips;c:\windows\system32\drivers\AmgHips.sys [28.10.2011 8:31 25248]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
R2 hasplms;Sentinel HASP License Manager;c:\windows\system32\hasplms.exe -run --> c:\windows\system32\hasplms.exe -run [?]
R2 SZASSIST;SecretZone Assist Service;c:\program files\Clarus\Samsung SecretZone\SZAssistSVC.exe [16.1.2011 23:29 90112]
R2 USBSafelyRemoveService;USB Safely Remove Assistant;c:\program files\USB Safely Remove\USBSRService.exe [27.8.2011 22:31 246616]
R2 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\eengine\EraserUtilRebootDrv.sys [19.2.2009 19:01 106104]
R3 mdf15;mdf15;c:\program files\Clarus\Samsung SecretZone\mdf15.sys [16.1.2011 23:29 12288]
R3 mvd21;mvd21;c:\program files\Clarus\Samsung SecretZone\mvd21.sys [16.1.2011 23:29 64512]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [25.2.2009 20:49 47360]
S3 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [6.12.2007 21:03 660768]
S3 AVerAF35;AVerMedia A867 USB DVB-T;c:\windows\system32\drivers\AVerAF35.sys [9.11.2010 22:03 477312]
S3 AVerRemote;AVerRemote;c:\program files\Common Files\AVerMedia\Service\AVerRemote.exe [9.11.2010 22:04 348160]
S3 AVerScheduleService;AVerScheduleService;c:\program files\Common Files\AVerMedia\Service\AVerScheduleService.exe [9.11.2010 22:04 397312]
S3 AVerUpdateServer;AVerUpdateServer;c:\program files\AVerMedia\AVerUpdate\AVerUpdateServer.exe [6.1.2011 13:42 168448]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe [3.9.2011 15:34 1527900]
S3 OODefragAgent;O&O Defrag Agent;c:\program files\OO Software\Defrag\oodag.exe [25.1.2011 11:41 2336072]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [28.5.2010 13:04 14896]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [17.7.2006 17:38 118928]
S3 SnugTV Service;SnugTV Service;c:\program files\SnugTV\SnugTV Station\AMAServer.exe [5.1.2011 3:31 570880]
S3 XHASP;XHASP;c:\windows\system32\drivers\XHASP.sys [28.5.2011 15:25 259584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A8D647C8-65AC-409F-B7B2-3C0FEE1A32F2}]
2010-02-16 18:02 114688 ----a-w- c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2011-12-15 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-02-23 16:58]
.
2011-12-15 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 14:07]
.
2011-12-14 c:\windows\Tasks\Norton Security Scan for Miloš.job
- c:\progra~1\NORTON~2\Engine\301~1.8\Nss.exe [2011-01-17 22:47]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: &Winamp Search - c:\documents and settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Free YouTube Download - c:\documents and settings\Miloš\Data aplikací\DVDVideoSoftIEHelpers\youtubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\documents and settings\Miloš\Data aplikací\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files\ICQ7.6\ICQ.exe
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
DPF: {4FEE6316-7B6F-4A6C-BD4E-4157C59A9E9D} - hxxp://static.s2g.gate5.de/ovi_maps/OviMapsPlugin_4.0.12.11.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://62.168.0.189/activex/AMC.cab
FF - ProfilePath - c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-15 20:58
Windows 5.1.2600 Service Pack 3 FAT NTAPI
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-4036164967-4113303836-1484400983-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1028)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(7428)
c:\program files\ScanSoft\OmniPageSE4\OpHookSE4.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\windows\system32\bgsvcgen.exe
c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe
c:\progra~1\SYMANT~1\vptray.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\windows\System32\DVDRAMSV.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\hasplms.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
c:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
c:\windows\system32\IoctlSvc.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2011-12-15 21:00:11 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-12-15 20:00
ComboFix2.txt 2011-12-15 19:26
ComboFix3.txt 2011-12-14 17:09
ComboFix4.txt 2011-04-16 11:23
C:\DeQuarantine.txt
.
Před spuštěním: Volných bajtů: 277 416 509 440
Po spuštění: Volných bajtů: 277 409 693 696
.
- - End Of File - - C3A61B39DF8F531AF1569242163C9D4D
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3326.2275 [GMT 1:00]
Spuštěný z: C:\ComboFix.exe
Použité ovládací přepínače :: C:\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *Disabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
.
FILE ::
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\askcom.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-1.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-10.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-2.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-3.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-4.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-5.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-6.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-7.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-8.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-9.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\SearchResults.xml"
"c:\program files\Vuze_Remote\prxtbVuz0.dll"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\tasks\Norton Security Scan for Miloš.job"
"c:\windows\tasks\RealUpgradeLogonTaskS-1-5-21-4036164967-4113303836-1484400983-1005.job"
"c:\windows\tasks\RealUpgradeScheduledTaskS-1-5-21-4036164967-4113303836-1484400983-1005.job"
"c:\windows\tasks\Scheduled Update for Ask Toolbar.job"
"c:\windows\tasks\SpeedUpMyPC.job"
"c:\windows\tasks\User_Feed_Synchronization-{27F5AB2D-4486-4DE2-BDE0-21639BA93517}.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\tasks\RealUpgradeLogonTaskS-1-5-21-4036164967-4113303836-1484400983-1005.job
c:\windows\tasks\RealUpgradeScheduledTaskS-1-5-21-4036164967-4113303836-1484400983-1005.job
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-11-15 do 2011-12-15 )))))))))))))))))))))))))))))))
.
.
2011-12-12 22:13 . 2011-12-12 22:13 -------- d-----w- C:\FOUND.001
2011-12-12 21:52 . 2011-12-12 21:52 -------- d-----w- C:\FOUND.000
2011-12-10 15:27 . 2011-12-10 15:27 -------- d-----w- c:\documents and settings\Miloš\Local Settings\Data aplikací\AskToolbar
2011-12-10 15:27 . 2011-12-10 15:27 -------- d-----w- c:\program files\FotoSketcher
2011-11-29 15:39 . 2011-11-29 15:39 -------- d-----w- c:\program files\BT
2011-11-25 16:55 . 2011-11-25 16:55 -------- d--h--w- c:\windows\ie8
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-28 07:31 . 2011-10-28 07:31 25248 ----a-w- c:\windows\system32\drivers\AmgHips.sys
2011-10-10 14:22 . 2009-01-19 09:19 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 1979-12-31 23:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 10:41 . 2008-07-29 18:59 613376 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 10:41 . 1979-12-31 23:00 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 10:41 . 1979-12-31 23:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-03-18 17:55 . 2011-03-23 20:23 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-14_17.06.08 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-07 05:12 . 2011-12-15 19:45 217609 c:\windows\system32\inetsrv\MetaBase.bin
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"USB Safely Remove"="c:\program files\USB Safely Remove\USBSafelyRemove.exe" [2010-12-25 1794392]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="c:\progra~1\SYMANT~1\\vptray.exe" [2006-07-17 125072]
"RTHDCPL"="RTHDCPL.EXE" [2008-12-09 18063872]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-03-24 53408]
"MDS_Menu"="c:\program files\CyberLink\MediaShow4\MUITransfer\MUIStartMenu.exe" [2009-02-25 218408]
"TrayServer"="c:\program files\MAGIX\Movie_Edit_Pro_15_silver\TrayServer.exe" [2008-11-13 90112]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
RAMASST.lnk - c:\windows\system32\RAMAsst.exe [2009-2-26 167936]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Foxit Software\\PDF Editor\\PDFEdit.exe"=
"c:\\Program Files\\Real\\RealPlayer\\RecordingManager.exe"=
"c:\\Program Files\\Java\\JRE6\\BIN\\java.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe"=
"c:\\Program Files\\SnugTV\\SnugTV Station\\ConfigMaster.exe"=
"c:\\Program Files\\SnugTV\\SnugTV Station\\ConfigWizard.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\EPLAN\\Electric P8\\1.9.11\\BIN\\W3u.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\WINDOWS\\System32\\hasplms.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\ICQ7.6\\ICQ.exe"=
"c:\\Program Files\\SnugTV\\SnugTV Station\\AMAServer.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R1 AmgHips;AmgHips;c:\windows\system32\drivers\AmgHips.sys [28.10.2011 8:31 25248]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
R2 hasplms;Sentinel HASP License Manager;c:\windows\system32\hasplms.exe -run --> c:\windows\system32\hasplms.exe -run [?]
R2 SZASSIST;SecretZone Assist Service;c:\program files\Clarus\Samsung SecretZone\SZAssistSVC.exe [16.1.2011 23:29 90112]
R2 USBSafelyRemoveService;USB Safely Remove Assistant;c:\program files\USB Safely Remove\USBSRService.exe [27.8.2011 22:31 246616]
R2 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\eengine\EraserUtilRebootDrv.sys [19.2.2009 19:01 106104]
R3 mdf15;mdf15;c:\program files\Clarus\Samsung SecretZone\mdf15.sys [16.1.2011 23:29 12288]
R3 mvd21;mvd21;c:\program files\Clarus\Samsung SecretZone\mvd21.sys [16.1.2011 23:29 64512]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [25.2.2009 20:49 47360]
S3 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [6.12.2007 21:03 660768]
S3 AVerAF35;AVerMedia A867 USB DVB-T;c:\windows\system32\drivers\AVerAF35.sys [9.11.2010 22:03 477312]
S3 AVerRemote;AVerRemote;c:\program files\Common Files\AVerMedia\Service\AVerRemote.exe [9.11.2010 22:04 348160]
S3 AVerScheduleService;AVerScheduleService;c:\program files\Common Files\AVerMedia\Service\AVerScheduleService.exe [9.11.2010 22:04 397312]
S3 AVerUpdateServer;AVerUpdateServer;c:\program files\AVerMedia\AVerUpdate\AVerUpdateServer.exe [6.1.2011 13:42 168448]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe [3.9.2011 15:34 1527900]
S3 OODefragAgent;O&O Defrag Agent;c:\program files\OO Software\Defrag\oodag.exe [25.1.2011 11:41 2336072]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [28.5.2010 13:04 14896]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [17.7.2006 17:38 118928]
S3 SnugTV Service;SnugTV Service;c:\program files\SnugTV\SnugTV Station\AMAServer.exe [5.1.2011 3:31 570880]
S3 XHASP;XHASP;c:\windows\system32\drivers\XHASP.sys [28.5.2011 15:25 259584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A8D647C8-65AC-409F-B7B2-3C0FEE1A32F2}]
2010-02-16 18:02 114688 ----a-w- c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2011-12-15 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-02-23 16:58]
.
2011-12-15 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 14:07]
.
2011-12-14 c:\windows\Tasks\Norton Security Scan for Miloš.job
- c:\progra~1\NORTON~2\Engine\301~1.8\Nss.exe [2011-01-17 22:47]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: &Winamp Search - c:\documents and settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Free YouTube Download - c:\documents and settings\Miloš\Data aplikací\DVDVideoSoftIEHelpers\youtubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\documents and settings\Miloš\Data aplikací\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files\ICQ7.6\ICQ.exe
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
DPF: {4FEE6316-7B6F-4A6C-BD4E-4157C59A9E9D} - hxxp://static.s2g.gate5.de/ovi_maps/OviMapsPlugin_4.0.12.11.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://62.168.0.189/activex/AMC.cab
FF - ProfilePath - c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-15 20:58
Windows 5.1.2600 Service Pack 3 FAT NTAPI
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-4036164967-4113303836-1484400983-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1028)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(7428)
c:\program files\ScanSoft\OmniPageSE4\OpHookSE4.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\windows\system32\bgsvcgen.exe
c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe
c:\progra~1\SYMANT~1\vptray.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\windows\System32\DVDRAMSV.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\hasplms.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
c:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
c:\windows\system32\IoctlSvc.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2011-12-15 21:00:11 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-12-15 20:00
ComboFix2.txt 2011-12-15 19:26
ComboFix3.txt 2011-12-14 17:09
ComboFix4.txt 2011-04-16 11:23
C:\DeQuarantine.txt
.
Před spuštěním: Volných bajtů: 277 416 509 440
Po spuštění: Volných bajtů: 277 409 693 696
.
- - End Of File - - C3A61B39DF8F531AF1569242163C9D4D
Re: Prosím o preventivku - občas zamrzne IE8, nelze ukončit



- Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
- Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
Kód: Vybrat vše
:reg [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MDS_Menu"=- :files C:\FOUND.001 C:\FOUND.000 c:\documents and settings\Miloš\Local Settings\Data aplikací\AskToolbar c:\windows\Tasks\OGALogon.job %windir%\system32\*.tmp.dll /s %windir%\system32\SET*.tmp /s %windir%\*.tmp :commands [RESETHOSTS] [EMPTYTEMP] [EMPTYFLASH]
- Kliknete na cervene tlacitko MoveIt!
- Budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles, obsah sem vlozte
Re: Prosím o preventivku - občas zamrzne IE8, nelze ukončit
All processes killed
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus\\"DisableMonitoring"|dword:00000000 /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\MDS_Menu deleted successfully.
========== FILES ==========
C:\FOUND.001 folder moved successfully.
C:\FOUND.000 folder moved successfully.
c:\documents and settings\Miloš\Local Settings\Data aplikací\AskToolbar folder moved successfully.
c:\windows\Tasks\OGALogon.job moved successfully.
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: All Users
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32835 bytes
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Miloš
->Temp folder emptied: 339090 bytes
->Temporary Internet Files folder emptied: 3125984 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 54277715 bytes
->Google Chrome cache emptied: 6528756 bytes
->Flash cache emptied: 1097 bytes
User: miloa
User: Milo�
User: Milo
User: Miloç
User: DVDVideoSoft
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 8405015 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 69,00 mb
[EMPTYFLASH]
User: Default User
User: All Users
User: NetworkService
User: LocalService
User: Administrator
User: Miloš
->Flash cache emptied: 0 bytes
User: miloa
User: Milo�
User: Milo
User: Miloç
User: DVDVideoSoft
Total Flash Files Cleaned = 0,00 mb
OTM by OldTimer - Version 3.1.19.0 log created on 12152011_211342
Files moved on Reboot...
C:\WINDOWS\temp\hlktmp moved successfully.
Registry entries deleted on Reboot...
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus\\"DisableMonitoring"|dword:00000000 /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\MDS_Menu deleted successfully.
========== FILES ==========
C:\FOUND.001 folder moved successfully.
C:\FOUND.000 folder moved successfully.
c:\documents and settings\Miloš\Local Settings\Data aplikací\AskToolbar folder moved successfully.
c:\windows\Tasks\OGALogon.job moved successfully.
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: All Users
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32835 bytes
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Miloš
->Temp folder emptied: 339090 bytes
->Temporary Internet Files folder emptied: 3125984 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 54277715 bytes
->Google Chrome cache emptied: 6528756 bytes
->Flash cache emptied: 1097 bytes
User: miloa
User: Milo�
User: Milo
User: Miloç
User: DVDVideoSoft
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 8405015 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 69,00 mb
[EMPTYFLASH]
User: Default User
User: All Users
User: NetworkService
User: LocalService
User: Administrator
User: Miloš
->Flash cache emptied: 0 bytes
User: miloa
User: Milo�
User: Milo
User: Miloç
User: DVDVideoSoft
Total Flash Files Cleaned = 0,00 mb
OTM by OldTimer - Version 3.1.19.0 log created on 12152011_211342
Files moved on Reboot...
C:\WINDOWS\temp\hlktmp moved successfully.
Registry entries deleted on Reboot...
Re: Prosím o preventivku - občas zamrzne IE8, nelze ukončit
Jak se chova nas pacient 

Re: Prosím o preventivku - občas zamrzne IE8, nelze ukončit
Myslím, že to bude v pořádku. Děkuji za trpělivost a doufám, že si PC více "pohlídám".
Miloš M.
Miloš M.
Naposledy upravil(a) miloš dne 15 pro 2011 21:51, celkem upraveno 1 x.
Re: Prosím o preventivku - občas zamrzne IE8, nelze ukončit



- Prejmenujte ComboFix na Uninstall
- Spustte jej
- Tohle smaze Combofix a jeho slozky

- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)

- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC

- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte

Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy
Re: Prosím o preventivku - občas zamrzne IE8, nelze ukončit
Děkuji za pomoc,
CCleaner pravidelně používám minimálně 1x týdně.
Miloš M.
CCleaner pravidelně používám minimálně 1x týdně.
Miloš M.
Re: Prosím o preventivku - občas zamrzne IE8, nelze ukončit
za odmazani linku dekuji, doufam ze se to nebude opakovat...
Nemate zac, rad jsem pomohl
Zase nekdy 
Nemate zac, rad jsem pomohl

