Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Anormné vyťažovanie Procesora

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
StigFird
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 17 črc 2011 11:59

Anormné vyťažovanie Procesora

#1 Příspěvek od StigFird »

Dobrý Deň.
Rád by som bol ak by ste mi pomohli.Procesy explorer.exe a dwm.exe mi anormne vyťažujú procesor.Taktiež si myslím že počítač je pomalší.
Pridávam aj log z RSIT


Logfile of random's system information tool 1.09 (written by random/random)
Run by dominik at 2012-02-06 11:48:39
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 25 GB (25%) free of 100 GB
Total RAM: 2047 MB (54% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:48:49, on 6. 2. 2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\VM305_STI.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Users\dominik\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Raxco\PerfectDisk\PDAgentS1.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\dominik\Downloads\RSIT.exe
C:\Program Files\trend micro\dominik.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/lionskin/{236 ... A8C199317F}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [BigDog305] C:\Windows\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\dominik\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-21-3678732471-1654464958-2998469604-1001\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3678732471-1654464958-2998469604-1001\..\Run: [] (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3678732471-1654464958-2998469604-1001\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3678732471-1654464958-2998469604-1001\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Cepstral License Server - Cepstral, LLC - C:\Program Files\Cepstral\bin\CepstralLicSrv.exe
O23 - Service: Dyyno Service (Dyyno Launcher) - Unknown owner - C:\Program Files\Dyyno\Dyyno Broadcaster\launcherd.exe
O23 - Service: FLEXnet Licensing Service - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Common Files\Raxco\Shared\PDEngine.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
O23 - Service: VMware Workstation Server (VMwareHostd) - Unknown owner - C:\Program Files\VMware\VMware Workstation\vmware-hostd.exe

--
End of file - 6500 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3678732471-1654464958-2998469604-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3678732471-1654464958-2998469604-1000UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-01-24 59272]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-09-06 3722416]
"BigDog305"=C:\Windows\VM305_STI.EXE [2005-08-05 61440]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2011-11-01 59240]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2012-01-16 421736]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
""= []
"Google Update"=C:\Users\dominik\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-28 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigDog305]
C:\Windows\VM305_STI.EXE [2005-08-05 61440]

C:\Users\dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 3.2.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoResolveTrack"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"VIDC.FPS1"=frapsvid.dll
"vidc.tscc"=C:\Windows\system32\tsccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.mjpg"=bdmjpeg.dll
"vidc.mpeg"=bdmpegv.dll
"msacm.bdmpeg"=bdmpega.acm
"VIDC.VMnc"=vmnc.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-02-06 11:48:39 ----D---- C:\rsit
2012-02-06 05:13:05 ----ASH---- C:\hiberfil.sys
2012-02-05 14:52:41 ----D---- C:\Minecraft_Backup
2012-02-04 16:48:03 ----D---- C:\Users\dominik\AppData\Roaming\.minecraft
2012-02-03 07:54:23 ----D---- C:\ProgramData\Raxco
2012-02-03 07:54:22 ----D---- C:\Program Files\Common Files\Raxco
2012-02-03 07:53:13 ----D---- C:\Program Files\Raxco
2012-02-02 17:53:03 ----D---- C:\Users\dominik\AppData\Roaming\OpenOffice.org
2012-02-02 17:50:24 ----D---- C:\Program Files\OpenOffice.org 3
2012-02-01 15:46:28 ----D---- C:\Users\dominik\AppData\Roaming\Apple Computer
2012-02-01 15:45:51 ----A---- C:\Windows\system32\GEARAspi.dll
2012-02-01 15:45:51 ----A---- C:\Windows\system32\drivers\GEARAspiWDM.sys
2012-02-01 15:44:01 ----D---- C:\Program Files\iPod
2012-02-01 15:44:00 ----D---- C:\ProgramData\Apple Computer
2012-02-01 15:44:00 ----D---- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2012-02-01 15:44:00 ----D---- C:\Program Files\iTunes
2012-02-01 15:42:48 ----D---- C:\Program Files\Apple Software Update
2012-02-01 15:42:00 ----D---- C:\ProgramData\Apple
2012-02-01 15:42:00 ----D---- C:\Program Files\Common Files\Apple
2012-01-31 18:34:09 ----D---- C:\Windows\system32\bin
2012-01-31 18:34:09 ----D---- C:\Windows\system32\backup
2012-01-31 18:24:41 ----A---- C:\Windows\system32\vmnetdhcp.exe
2012-01-31 18:24:37 ----A---- C:\Windows\system32\vmnat.exe
2012-01-31 18:24:36 ----A---- C:\Windows\system32\drivers\vmnetuserif.sys
2012-01-31 18:24:28 ----A---- C:\Windows\system32\vnetlib.dll
2012-01-31 18:22:41 ----D---- C:\Program Files\VMware
2012-01-31 18:22:14 ----D---- C:\Program Files\Common Files\VMware
2012-01-31 13:43:53 ----A---- C:\Windows\system32\schannel.dll
2012-01-31 13:43:53 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2012-01-31 13:43:52 ----A---- C:\Windows\system32\webio.dll
2012-01-31 13:43:52 ----A---- C:\Windows\system32\sspisrv.dll
2012-01-31 13:43:52 ----A---- C:\Windows\system32\sspicli.dll
2012-01-31 13:43:52 ----A---- C:\Windows\system32\secur32.dll
2012-01-31 13:43:52 ----A---- C:\Windows\system32\lsass.exe
2012-01-31 13:43:52 ----A---- C:\Windows\system32\lsasrv.dll
2012-01-31 13:43:52 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2012-01-31 13:43:52 ----A---- C:\Windows\system32\drivers\cng.sys
2012-01-30 07:40:10 ----D---- C:\Users\dominik\AppData\Roaming\Malwarebytes
2012-01-30 07:40:05 ----D---- C:\ProgramData\Malwarebytes
2012-01-29 17:40:26 ----RASH---- C:\MSDOS.SYS
2012-01-29 17:40:26 ----RASH---- C:\IO.SYS
2012-01-29 08:17:03 ----D---- C:\Users\dominik\AppData\Roaming\BANDISOFT
2012-01-29 08:15:35 ----D---- C:\Program Files\Bandicam
2012-01-29 08:15:34 ----D---- C:\Program Files\BandiMPEG1
2012-01-29 07:13:18 ----D---- C:\Users\dominik\AppData\Roaming\Notepad++
2012-01-29 07:13:18 ----D---- C:\Program Files\Notepad++
2012-01-29 05:48:46 ----D---- C:\Users\dominik\AppData\Roaming\fltk.org
2012-01-29 05:48:46 ----D---- C:\ProgramData\fltk.org
2012-01-28 20:17:16 ----D---- C:\Python27
2012-01-27 17:54:59 ----D---- C:\Users\dominik\AppData\Roaming\GHISLER
2012-01-27 17:54:59 ----D---- C:\totalcmd
2012-01-27 17:54:59 ----A---- C:\Windows\UC.PIF
2012-01-27 17:54:59 ----A---- C:\Windows\RAR.PIF
2012-01-27 17:54:59 ----A---- C:\Windows\PKZIP.PIF
2012-01-27 17:54:59 ----A---- C:\Windows\PKUNZIP.PIF
2012-01-27 17:54:59 ----A---- C:\Windows\NOCLOSE.PIF
2012-01-27 17:54:59 ----A---- C:\Windows\LHA.PIF
2012-01-27 17:54:59 ----A---- C:\Windows\ARJ.PIF
2012-01-25 06:25:46 ----D---- C:\Program Files\PIC Corporation
2012-01-25 06:21:54 ----D---- C:\Users\dominik\AppData\Roaming\Gretech
2012-01-25 06:21:06 ----D---- C:\Program Files\CoreAAC
2012-01-25 06:20:52 ----D---- C:\ProgramData\GRETECH
2012-01-25 06:20:47 ----D---- C:\Program Files\GRETECH
2012-01-24 15:54:02 ----D---- C:\Program Files\Common Files\Java
2012-01-24 15:53:38 ----A---- C:\Windows\system32\npdeployJava1.dll
2012-01-21 14:37:54 ----D---- C:\Program Files\Cepstral
2012-01-19 15:21:24 ----D---- C:\Users\dominik\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
2012-01-19 15:21:18 ----D---- C:\Program Files\Common Files\Adobe AIR
2012-01-19 14:32:43 ----D---- C:\Users\dominik\AppData\Roaming\NVIDIA
2012-01-18 20:03:12 ----D---- C:\ProgramData\AmUStor
2012-01-18 20:03:12 ----D---- C:\Program Files\AmIcoSingLun
2012-01-18 19:57:04 ----A---- C:\Windows\system32\OpenCL.dll
2012-01-18 19:57:04 ----A---- C:\Windows\system32\nvoglv32.dll
2012-01-18 19:57:04 ----A---- C:\Windows\system32\nvgenco32.dll
2012-01-18 19:57:04 ----A---- C:\Windows\system32\nvdispco32.dll
2012-01-18 19:57:04 ----A---- C:\Windows\system32\nvd3dum.dll
2012-01-18 19:57:04 ----A---- C:\Windows\system32\nvcuvid.dll
2012-01-18 19:57:04 ----A---- C:\Windows\system32\nvcuvenc.dll
2012-01-18 19:57:04 ----A---- C:\Windows\system32\nvcuda.dll
2012-01-18 19:57:04 ----A---- C:\Windows\system32\nvcompiler.dll
2012-01-18 19:57:04 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2012-01-18 19:50:05 ----D---- C:\NVIDIA
2012-01-18 19:47:43 ----D---- C:\Windows\system32\RTCOM
2012-01-18 19:45:44 ----A---- C:\Windows\system32\WavesLib.dll
2012-01-18 19:45:43 ----A---- C:\Windows\system32\WavesGUILib.dll
2012-01-18 19:45:43 ----A---- C:\Windows\system32\tosade.dll
2012-01-18 19:45:43 ----A---- C:\Windows\system32\TepeqAPO.dll
2012-01-18 19:45:43 ----A---- C:\Windows\system32\tadefxapo2.dll
2012-01-18 19:45:43 ----A---- C:\Windows\system32\tadefxapo.dll
2012-01-18 19:45:43 ----A---- C:\Windows\system32\SRSWOW.dll
2012-01-18 19:45:43 ----A---- C:\Windows\system32\SRSTSXT.dll
2012-01-18 19:45:43 ----A---- C:\Windows\system32\SRSTSHD.dll
2012-01-18 19:45:43 ----A---- C:\Windows\system32\SRSHP360.dll
2012-01-18 19:45:42 ----A---- C:\Windows\system32\SFSS_APO.dll
2012-01-18 19:45:42 ----A---- C:\Windows\system32\SFNHK.dll
2012-01-18 19:45:42 ----A---- C:\Windows\system32\SFCOM.dll
2012-01-18 19:45:42 ----A---- C:\Windows\system32\SFAPO.dll
2012-01-18 19:45:40 ----A---- C:\Windows\system32\RtkPgExt.dll
2012-01-18 19:45:40 ----A---- C:\Windows\system32\RtkCoLDR.dll
2012-01-18 19:45:40 ----A---- C:\Windows\system32\drivers\RTKVHDA.sys
2012-01-18 19:45:39 ----A---- C:\Windows\system32\RtkCoInstII.dll
2012-01-18 19:45:39 ----A---- C:\Windows\system32\RtkApoApi.dll
2012-01-18 19:45:39 ----A---- C:\Windows\system32\RtkAPO.dll
2012-01-18 19:45:38 ----A---- C:\Windows\system32\RTEEP32A.dll
2012-01-18 19:45:38 ----A---- C:\Windows\system32\RTEEL32A.dll
2012-01-18 19:45:38 ----A---- C:\Windows\system32\RTEEG32A.dll
2012-01-18 19:45:38 ----A---- C:\Windows\system32\RTEED32A.dll
2012-01-18 19:45:37 ----A---- C:\Windows\system32\RP3DHT32.dll
2012-01-18 19:45:37 ----A---- C:\Windows\system32\RP3DAA32.dll
2012-01-18 19:45:37 ----A---- C:\Windows\system32\RCoRes.dat
2012-01-18 19:45:37 ----A---- C:\Windows\system32\R4EEP32A.dll
2012-01-18 19:45:37 ----A---- C:\Windows\system32\R4EEL32A.dll
2012-01-18 19:45:37 ----A---- C:\Windows\system32\R4EEG32A.dll
2012-01-18 19:45:37 ----A---- C:\Windows\system32\R4EED32A.dll
2012-01-18 19:45:37 ----A---- C:\Windows\system32\R4EEA32A.dll
2012-01-18 19:45:37 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2012-01-18 19:45:36 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2012-01-18 19:45:36 ----A---- C:\Windows\system32\MaxxAudioRealtek2.dll
2012-01-18 19:45:35 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll
2012-01-18 19:45:35 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2012-01-18 19:45:35 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2012-01-18 19:45:35 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2012-01-18 19:45:35 ----A---- C:\Windows\system32\MaxxAudioAPO.dll
2012-01-18 19:45:35 ----A---- C:\Windows\system32\KAAPORT.dll
2012-01-18 19:45:31 ----D---- C:\Program Files\Realtek
2012-01-18 19:45:31 ----A---- C:\Windows\system32\FMAPO.dll
2012-01-18 19:45:31 ----A---- C:\Windows\system32\DTSVoiceClarityDLL.dll
2012-01-18 19:45:31 ----A---- C:\Windows\system32\DTSU2PREC32.dll
2012-01-18 19:45:31 ----A---- C:\Windows\system32\DTSU2PLFX32.dll
2012-01-18 19:45:31 ----A---- C:\Windows\system32\DTSU2PGFX32.dll
2012-01-18 19:45:31 ----A---- C:\Windows\system32\DTSSymmetryDLL.dll
2012-01-18 19:45:31 ----A---- C:\Windows\system32\DTSS2SpeakerDLL.dll
2012-01-18 19:45:31 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL.dll
2012-01-18 19:45:31 ----A---- C:\Windows\system32\DTSNeoPCDLL.dll
2012-01-18 19:45:31 ----A---- C:\Windows\system32\DTSLimiterDLL.dll
2012-01-18 19:45:31 ----A---- C:\Windows\system32\DTSLFXAPO.dll
2012-01-18 19:45:31 ----A---- C:\Windows\system32\DTSGFXAPONS.dll
2012-01-18 19:45:31 ----A---- C:\Windows\system32\DTSGFXAPO.dll
2012-01-18 19:45:31 ----A---- C:\Windows\system32\DTSGainCompensatorDLL.dll
2012-01-18 19:45:31 ----A---- C:\Windows\system32\DTSBoostDLL.dll
2012-01-18 19:45:31 ----A---- C:\Windows\system32\DTSBassEnhancementDLL.dll
2012-01-18 19:45:31 ----A---- C:\Windows\system32\AERTARen.dll
2012-01-18 19:45:31 ----A---- C:\Windows\system32\AERTACap.dll
2012-01-18 19:45:21 ----HD---- C:\Program Files\Temp
2012-01-18 19:45:20 ----A---- C:\Windows\RtlExUpd.dll
2012-01-18 19:22:00 ----D---- C:\ProgramData\DriverGenius
2012-01-18 19:21:40 ----D---- C:\Program Files\Driver-Soft
2012-01-18 15:47:36 ----A---- C:\Windows\system32\drivers\vmx86.sys
2012-01-18 15:47:32 ----A---- C:\Windows\system32\drivers\vmparport.sys
2012-01-18 13:41:32 ----A---- C:\Windows\system32\vmnc.dll
2012-01-18 13:06:02 ----A---- C:\Windows\system32\vnetinst.dll
2012-01-18 13:06:02 ----A---- C:\Windows\system32\vmnetbridge.dll
2012-01-18 13:06:02 ----A---- C:\Windows\system32\drivers\vmnetbridge.sys
2012-01-18 13:06:02 ----A---- C:\Windows\system32\drivers\vmnetadapter.sys
2012-01-18 13:06:02 ----A---- C:\Windows\system32\drivers\vmnet.sys
2012-01-17 18:04:01 ----A---- C:\Windows\system32\libmysql_d.dll
2012-01-17 18:03:56 ----D---- C:\Program Files\PremiumSoft
2012-01-14 14:08:22 ----D---- C:\Downloads
2012-01-11 06:23:57 ----A---- C:\Windows\system32\packager.dll
2012-01-11 06:23:57 ----A---- C:\Windows\system32\ntdll.dll
2012-01-11 06:23:54 ----A---- C:\Windows\system32\quartz.dll
2012-01-11 06:23:54 ----A---- C:\Windows\system32\qdvd.dll
2012-01-10 20:27:28 ----D---- C:\Users\dominik\AppData\Roaming\VMware
2012-01-10 20:10:23 ----D---- C:\ProgramData\VMware

======List of files/folders modified in the last 1 month======

2012-02-06 11:48:49 ----D---- C:\Windows\Prefetch
2012-02-06 11:48:41 ----D---- C:\Program Files\trend micro
2012-02-06 11:48:29 ----D---- C:\Users\dominik\AppData\Roaming\Skype
2012-02-06 11:47:09 ----D---- C:\Windows\Temp
2012-02-06 11:46:26 ----D---- C:\Windows\inf
2012-02-06 11:44:10 ----D---- C:\Windows
2012-02-06 11:44:09 ----D---- C:\ProgramData\NVIDIA
2012-02-06 06:55:27 ----D---- C:\Windows\system32\config
2012-02-06 06:55:19 ----D---- C:\Users\dominik\AppData\Roaming\uTorrent
2012-02-06 06:52:27 ----D---- C:\Users\dominik\AppData\Roaming\TS3Client
2012-02-05 18:27:13 ----SHD---- C:\System Volume Information
2012-02-05 14:26:57 ----D---- C:\Program Files\Common Files\Steam
2012-02-04 09:42:01 ----RSD---- C:\Windows\Fonts
2012-02-04 06:21:30 ----RD---- C:\Program Files
2012-02-03 07:59:17 ----D---- C:\Windows\System32
2012-02-03 07:57:20 ----SHD---- C:\Windows\Installer
2012-02-03 07:57:08 ----D---- C:\Windows\system32\drivers
2012-02-03 07:54:23 ----HD---- C:\ProgramData
2012-02-03 07:54:22 ----D---- C:\Program Files\Common Files
2012-02-03 07:52:01 ----D---- C:\Users\dominik\AppData\Roaming\FileZilla
2012-02-03 07:51:56 ----D---- C:\Windows\Minidump
2012-02-02 17:51:20 ----RSD---- C:\Windows\assembly
2012-02-02 14:43:54 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-02-01 15:45:51 ----DC---- C:\Windows\system32\DRVSTORE
2012-02-01 15:45:51 ----D---- C:\Windows\system32\catroot
2012-02-01 15:42:43 ----D---- C:\Windows\system32\DriverStore
2012-02-01 15:42:19 ----D---- C:\Program Files\Bonjour
2012-02-01 05:14:23 ----D---- C:\Windows\winsxs
2012-01-30 21:07:27 ----D---- C:\Windows\system32\catroot2
2012-01-27 17:42:55 ----D---- C:\Program Files\FileZilla FTP Client
2012-01-25 17:55:21 ----D---- C:\Users\dominik\AppData\Roaming\Hamachi
2012-01-24 15:53:32 ----A---- C:\Windows\system32\javaws.exe
2012-01-24 15:53:32 ----A---- C:\Windows\system32\javaw.exe
2012-01-24 15:53:32 ----A---- C:\Windows\system32\java.exe
2012-01-24 15:53:31 ----A---- C:\Windows\system32\deployJava1.dll
2012-01-24 15:53:30 ----D---- C:\Program Files\Java
2012-01-19 15:21:22 ----D---- C:\ProgramData\Adobe
2012-01-19 15:21:19 ----D---- C:\Program Files\Adobe
2012-01-19 15:20:36 ----D---- C:\Users\dominik\AppData\Roaming\Adobe
2012-01-18 20:04:09 ----HD---- C:\Program Files\InstallShield Installation Information
2012-01-18 20:00:10 ----D---- C:\Program Files\NVIDIA Corporation
2012-01-15 12:16:21 ----D---- C:\Program Files\Skin Pack Toolbar
2012-01-15 12:10:18 ----D---- C:\Windows\pss
2012-01-15 12:08:21 ----D---- C:\Users\dominik\AppData\Roaming\DAEMON Tools Lite
2012-01-15 12:08:15 ----D---- C:\Windows\debug
2012-01-14 09:47:44 ----D---- C:\Users\dominik\AppData\Roaming\HLSW
2012-01-11 14:29:49 ----D---- C:\Windows\Microsoft.NET
2012-01-11 07:07:12 ----A---- C:\Windows\system32\MRT.exe
2012-01-11 07:07:01 ----D---- C:\Windows\ehome
2012-01-09 07:06:27 ----D---- C:\Program Files\TeamViewer
2012-01-08 10:23:17 ----D---- C:\Users\dominik\AppData\Roaming\MAXON
2012-01-07 14:49:31 ----D---- C:\Projekty

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 nvstor32;nvstor32; C:\Windows\system32\DRIVERS\nvstor32.sys [2010-04-09 215656]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 vmci;VMware VMCI Bus Driver; C:\Windows\system32\DRIVERS\vmci.sys [2011-08-08 98928]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-09-06 34392]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-09-06 442200]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-09-06 320856]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-09-06 52568]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-10-23 232512]
R1 VBoxDrv;VirtualBox Service; C:\Windows\system32\DRIVERS\VBoxDrv.sys [2011-10-03 158512]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\Windows\system32\DRIVERS\VBoxUSBMon.sys [2011-10-03 91440]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-09-06 20568]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-09-06 54616]
R2 DefragFS;DefragFS; C:\Windows\system32\drivers\DefragFS.sys [2011-05-26 138768]
R2 hcmon;VMware hcmon; \??\C:\Windows\system32\drivers\hcmon.sys [2011-08-29 32496]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R2 PDFSFilter;PDFsFilter; C:\Windows\system32\DRIVERS\PDFsFilter.sys [2011-06-30 66320]
R2 VMnetBridge;VMware Bridge Protocol; C:\Windows\system32\DRIVERS\vmnetbridge.sys [2012-01-18 36464]
R2 VMnetuserif;VMware Network Application Interface; \??\C:\Windows\system32\drivers\vmnetuserif.sys [2012-01-18 25712]
R2 VMparport;VMware VMparport; \??\C:\Windows\system32\Drivers\VMparport.sys [2012-01-18 23792]
R2 vmx86;VMware vmx86; \??\C:\Windows\system32\Drivers\vmx86.sys [2012-01-18 55664]
R2 vstor2-mntapi10-shared;Vstor2 MntApi 1.0 Driver (shared); C:\Windows\system32\drivers\vstor2-mntapi10-shared.sys [2011-07-08 22768]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2011-10-24 25280]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2011-12-13 3921448]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 13216]
R3 NVNET;NVIDIA nForce Ethernet Driver; C:\Windows\system32\DRIVERS\nvmf6232.sys [2010-03-04 296936]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\Windows\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows\system32\DRIVERS\VBoxNetAdp.sys [2011-10-03 104752]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys [2011-10-03 116016]
R3 VMnetAdapter;VMware Virtual Ethernet Adapter Driver; C:\Windows\system32\DRIVERS\vmnetadapter.sys [2012-01-18 16624]
R3 ZSMC0305;A4 TECH PC Camera V; C:\Windows\System32\Drivers\usbVM305.sys [2006-05-08 391688]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 iaStor;iaStor; C:\Windows\system32\DRIVERS\iaStor.sys [2009-06-04 330264]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmb.sys [2011-08-17 18176]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbo.sys [2011-08-17 23168]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x32.sys [2009-07-13 347264]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2011-08-17 8192]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 27648]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys [2011-08-17 8192]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VSPerfDrv100;Performance Tools Driver 10.0; \??\C:\Program Files\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\VSPerfDrv100.sys [2009-12-08 48128]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
S4 RsFx0103;RsFx0103 Driver; C:\Windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 239336]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-10-24 55144]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-09-06 44768]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 Cepstral License Server;Cepstral License Server; C:\Program Files\Cepstral\bin\CepstralLicSrv.exe [2008-06-24 57344]
R2 Dyyno Launcher;Dyyno Service; C:\Program Files\Dyyno\Dyyno Broadcaster\launcherd.exe [2011-01-15 415072]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2009-03-30 43010392]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2011-10-15 1136448]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
R2 PDAgent;PDAgent; C:\Program Files\Raxco\PerfectDisk\PDAgent.exe [2011-07-07 1252616]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2011-10-27 75064]
R2 PnkBstrB;PnkBstrB; C:\Windows\system32\PnkBstrB.exe [2011-10-27 189248]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 98840]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-15 381248]
R2 TeamViewer6;TeamViewer 6; C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe [2011-08-30 2358656]
R2 TeamViewer7;TeamViewer 7; C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe [2011-12-14 2984832]
R2 VMAuthdService;VMware Authorization Service; C:\Program Files\VMware\VMware Workstation\vmware-authd.exe [2012-01-18 79872]
R2 VMnetDHCP;VMware DHCP Service; C:\Windows\system32\vmnetdhcp.exe [2012-01-18 354416]
R2 VMUSBArbService;VMware USB Arbitration Service; C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe [2011-08-29 665200]
R2 VMware NAT Service;VMware NAT Service; C:\Windows\system32\vmnat.exe [2012-01-18 433264]
R2 VMwareHostd;VMware Workstation Server; C:\Program Files\VMware\VMware Workstation\vmware-hostd.exe [2012-01-18 11839488]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 1713536]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2012-01-16 821608]
R3 PDEngine;PDEngine; C:\Program Files\Common Files\Raxco\Shared\PDEngine.exe [2011-07-07 2111752]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2011-11-06 1044816]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2011-10-27 718384]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-10-22 1343400]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-23 47128]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 366936]
S4 SQLBrowser;SQL Server Browser; C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2009-03-30 254808]
S4 TunngleService;TunngleService; C:\Program Files\Tunngle\TnglCtrl.exe [2011-10-14 745832]

-----------------EOF-----------------
Môj email:StigFird@hotmail.com
DoporučujemObrázek____Obrázek____Obrázek____Obrázek
Nepodporujem!!!:Obrázek

StigFird
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 17 črc 2011 11:59

Re: Anormné vyťažovanie Procesora

#2 Příspěvek od StigFird »

Prepáčte za zdržanie log z xuetr dávam do prilohy ale ten program od avastu mi nejde pustil som to a nahodilo mi to BSOD Modrú Obrazovku.A Pc po tej BSOD sa mi zdá zasa pomalší
Přílohy
xuetr.zip
(137.76 KiB) Staženo 61 x
Môj email:StigFird@hotmail.com
DoporučujemObrázek____Obrázek____Obrázek____Obrázek
Nepodporujem!!!:Obrázek

StigFird
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 17 črc 2011 11:59

Re: Anormné vyťažovanie Procesora

#3 Příspěvek od StigFird »

tu je log z mbrscan

Kód: Vybrat vše

MBRScan v1.1.0

OS             : Windows 7 Service Pack 1 (32 bit)
PROCESSOR      : x86 Family 15 Model 107 Stepping 2, AuthenticAMD
BOOT           : Normal Boot
DATE           : 2012/02/06 (ISO 8601) at 17:35:42
________________________________________________________________________________

DISK           : Device\Harddisk0\DR0 __WDC WD40 00AAKS-00YGA (12.0)
BUS_TYPE       : (0x03)  P-ATA
USE_PIO        : YES
MAX_TRANSFER   : 128 Kb
ALIGNMENT_MASK : word aligned
________________________________________________________________________________

DISK           : Device\Harddisk5\DR5 __Samsung G3 Station
BUS_TYPE       : (0x07)  USB
USE_PIO        : NO
MAX_TRANSFER   : 64 Kb
ALIGNMENT_MASK : byte aligned
________________________________________________________________________________

Device\Harddisk0\DR0	372.6 Go  [Fixed] ==> 7 MBR Code .

MBR_MD5   : 370DB0D78A52556C89FF6492668CDD1F
MBR_SHA1  : B20A95CD3599EA83C3222A0D86DB31993ED429BE

Device\Harddisk0\Partition1	97.65 Go  	0x07 NTFS / HPFS __ BOOTABLE __
Device\Harddisk0\Partition2	275.0 Go  	0x07 NTFS / HPFS
________________________________________________________________________________

Device\Harddisk5\DR5	931.5 Go  [Fixed] ==> Unknown MBR Code ....

MBR_MD5   : 193D2CA1A176EE52A3B8B7E877CB7D52
MBR_SHA1  : 631866F86F6D534196AD672B9DD0D5E5928DAB60

Device\Harddisk5\Partition1	931.5 Go  	0x0C FAT32 [LBA] 
________________________________________________________________________________

############################### Additional scan ################################

DRIVER  : C:\Windows\System32\Drivers\dump_diskdump.sys => Invisible on the disk
ADDRESS : 0x88C00000
SIZE    : 40.0 Ko

DRIVER  : C:\Windows\System32\Drivers\dump_nvstor32.sys => Invisible on the disk
ADDRESS : 0x83200000
SIZE    : 224.0 Ko

DRIVER  : C:\Windows\System32\Drivers\dump_dumpfve.sys => Invisible on the disk
ADDRESS : 0x88A25000
SIZE    : 68.0 Ko

BCD EmsSettings {0CE4991B-E6B3-4B16-B23C-5E0D9250E5D9} => BcdLibraryBoolean_EmsEnabled (16000020)

SystemStartOptions :  NOEXECUTE=OPTIN

________________________________________________________________________________

_______MBR   \Device\Harddisk0\DR0  

0x00000000   33 C0 8E D0 BC 00 7C 8E C0 8E D8 BE 00 7C BF 00   3À.м.|.À.ؾ.|¿.
0x00000010   06 B9 00 02 FC F3 A4 50 68 1C 06 CB FB B9 04 00   .¹..üó¤Ph..Ëû¹..
0x00000020   BD BE 07 80 7E 00 00 7C 0B 0F 85 0E 01 83 C5 10   ½¾..~..|......Å.
0x00000030   E2 F1 CD 18 88 56 00 55 C6 46 11 05 C6 46 10 00   âñÍ..V.UÆF..ÆF..
0x00000040   B4 41 BB AA 55 CD 13 5D 72 0F 81 FB 55 AA 75 09   ´A»ªUÍ.]r..ûUªu.
0x00000050   F7 C1 01 00 74 03 FE 46 10 66 60 80 7E 10 00 74   ÷Á..t.þF.f`.~..t
0x00000060   26 66 68 00 00 00 00 66 FF 76 08 68 00 00 68 00   &fh....f.v.h..h.
0x00000070   7C 68 01 00 68 10 00 B4 42 8A 56 00 8B F4 CD 13   |h..h..´B.V..ôÍ.
0x00000080   9F 83 C4 10 9E EB 14 B8 01 02 BB 00 7C 8A 56 00   ..Ä..ë.¸..».|.V.
0x00000090   8A 76 01 8A 4E 02 8A 6E 03 CD 13 66 61 73 1C FE   .v..N..n.Í.fas.þ
0x000000A0   4E 11 75 0C 80 7E 00 80 0F 84 8A 00 B2 80 EB 84   N.u..~......².ë.
0x000000B0   55 32 E4 8A 56 00 CD 13 5D EB 9E 81 3E FE 7D 55   U2ä.V.Í.]ë..>þ}U
0x000000C0   AA 75 6E FF 76 00 E8 8D 00 75 17 FA B0 D1 E6 64   ªun.v.è..u.ú°Ñæd
0x000000D0   E8 83 00 B0 DF E6 60 E8 7C 00 B0 FF E6 64 E8 75   è..°ßæ`è|.°.ædèu
0x000000E0   00 FB B8 00 BB CD 1A 66 23 C0 75 3B 66 81 FB 54   .û¸.»Í.f#Àu;f.ûT
0x000000F0   43 50 41 75 32 81 F9 02 01 72 2C 66 68 07 BB 00   CPAu2.ù..r,fh.».
0x00000100   00 66 68 00 02 00 00 66 68 08 00 00 00 66 53 66   .fh....fh....fSf
0x00000110   53 66 55 66 68 00 00 00 00 66 68 00 7C 00 00 66   SfUfh....fh.|..f
0x00000120   61 68 00 00 07 CD 1A 5A 32 F6 EA 00 7C 00 00 CD   ah...Í.Z2öê.|..Í
0x00000130   18 A0 B7 07 EB 08 A0 B6 07 EB 03 A0 B5 07 32 E4   ..·.ë..¶.ë..µ.2ä
0x00000140   05 00 07 8B F0 AC 3C 00 74 09 BB 07 00 B4 0E CD   ....ð¬<.t.»..´.Í
0x00000150   10 EB F2 F4 EB FD 2B C9 E4 64 EB 00 24 02 E0 F8   .ëòôëý+Éädë.$.àø
0x00000160   24 02 C3 49 6E 76 61 6C 69 64 20 70 61 72 74 69   $.ÃInvalid parti
0x00000170   74 69 6F 6E 20 74 61 62 6C 65 00 45 72 72 6F 72   tion table.Error
0x00000180   20 6C 6F 61 64 69 6E 67 20 6F 70 65 72 61 74 69    loading operati
0x00000190   6E 67 20 73 79 73 74 65 6D 00 4D 69 73 73 69 6E   ng system.Missin
0x000001A0   67 20 6F 70 65 72 61 74 69 6E 67 20 73 79 73 74   g operating syst
0x000001B0   65 6D 00 00 00 63 7B 9A A0 26 A1 26 00 00 80 01   em...c{..&¡&....
0x000001C0   01 00 07 FE FF FF 3F 00 00 00 8D EA 34 0C 00 FE   ...þ..?....ê4..þ
0x000001D0   FF FF 07 FE FF FF 00 F0 34 0C 00 98 5E 22 00 00   ...þ...ð4...^"..
0x000001E0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001F0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 55 AA   ..............Uª

__________________________16_BIT_ASM_CODE
   
0x0000    33c0            XOR AX, AX   
0x0002    8ed0            MOV SS, AX   
0x0004    bc 007c         MOV SP, 0x7c00   
0x0007    8ec0            MOV ES, AX   
0x0009    8ed8            MOV DS, AX   
0x000B    be 007c         MOV SI, 0x7c00   
0x000E    bf 0006         MOV DI, 0x600   
0x0011    b9 0002         MOV CX, 0x200   
0x0014    fc              CLD   
0x0015    f3 a4           REP MOVSB   
0x0017    50              PUSH AX   
0x0018    68 1c06         PUSH 0x61c   
0x001B    cb              RETF   
0x001C    fb              STI   
0x001D    b9 0400         MOV CX, 0x4   
0x0020    bd be07         MOV BP, 0x7be   
0x0023    807e 00 00      CMP BYTE [BP+0x0], 0x0   
0x0027    7c 0b           JL 0x34   
0x0029    0f85 0e01       JNZ 0x13b   
0x002D    83c5 10         ADD BP, 0x10   
0x0030    e2 f1           LOOP 0x23   
0x0032    cd 18           INT 0x18   
0x0034    8856 00         MOV [BP+0x0], DL   
0x0037    55              PUSH BP   
0x0038    c646 11 05      MOV BYTE [BP+0x11], 0x5   
0x003C    c646 10 00      MOV BYTE [BP+0x10], 0x0   
0x0040    b4 41           MOV AH, 0x41   
0x0042    bb aa55         MOV BX, 0x55aa   
0x0045    cd 13           INT 0x13   
0x0047    5d              POP BP   
0x0048    72 0f           JB 0x59   
0x004A    81fb 55aa       CMP BX, 0xaa55   
0x004E    75 09           JNZ 0x59   
0x0050    f7c1 0100       TEST CX, 0x1   
0x0054    74 03           JZ 0x59   
0x0056    fe46 10         INC BYTE [BP+0x10]   
0x0059    66 60           PUSHAD   
0x005B    807e 10 00      CMP BYTE [BP+0x10], 0x0   
0x005F    74 26           JZ 0x87   
0x0061    66 68 00000000  PUSH 0x0   
0x0067    66 ff76 08      PUSH DWORD [BP+0x8]   
0x006B    68 0000         PUSH 0x0   
0x006E    68 007c         PUSH 0x7c00   
0x0071    68 0100         PUSH 0x1   
0x0074    68 1000         PUSH 0x10   
0x0077    b4 42           MOV AH, 0x42   
0x0079    8a56 00         MOV DL, [BP+0x0]   
0x007C    8bf4            MOV SI, SP   
0x007E    cd 13           INT 0x13   
0x0080    9f              LAHF   
0x0081    83c4 10         ADD SP, 0x10   
0x0084    9e              SAHF   
0x0085    eb 14           JMP 0x9b   
0x0087    b8 0102         MOV AX, 0x201   
0x008A    bb 007c         MOV BX, 0x7c00   
0x008D    8a56 00         MOV DL, [BP+0x0]   
0x0090    8a76 01         MOV DH, [BP+0x1]   
0x0093    8a4e 02         MOV CL, [BP+0x2]   
0x0096    8a6e 03         MOV CH, [BP+0x3]   
0x0099    cd 13           INT 0x13   
0x009B    66 61           POPAD   
0x009D    73 1c           JAE 0xbb   
0x009F    fe4e 11         DEC BYTE [BP+0x11]   
0x00A2    75 0c           JNZ 0xb0   
0x00A4    807e 00 80      CMP BYTE [BP+0x0], 0x80   
0x00A8    0f84 8a00       JZ 0x136   
0x00AC    b2 80           MOV DL, 0x80   
0x00AE    eb 84           JMP 0x34   
0x00B0    55              PUSH BP   
0x00B1    32e4            XOR AH, AH   
0x00B3    8a56 00         MOV DL, [BP+0x0]   
0x00B6    cd 13           INT 0x13   
0x00B8    5d              POP BP   
0x00B9    eb 9e           JMP 0x59   
0x00BB    813e fe7d 55aa  CMP WORD [0x7dfe], 0xaa55   
0x00C1    75 6e           JNZ 0x131   
0x00C3    ff76 00         PUSH WORD [BP+0x0]   
0x00C6    e8 8d00         CALL 0x156   
0x00C9    75 17           JNZ 0xe2   
0x00CB    fa              CLI   
0x00CC    b0 d1           MOV AL, 0xd1   
0x00CE    e6 64           OUT 0x64, AL   
0x00D0    e8 8300         CALL 0x156   
0x00D3    b0 df           MOV AL, 0xdf   
0x00D5    e6 60           OUT 0x60, AL   
0x00D7    e8 7c00         CALL 0x156   
0x00DA    b0 ff           MOV AL, 0xff   
0x00DC    e6 64           OUT 0x64, AL   
0x00DE    e8 7500         CALL 0x156   
0x00E1    fb              STI   
0x00E2    b8 00bb         MOV AX, 0xbb00   
0x00E5    cd 1a           INT 0x1a   
0x00E7    66 23c0         AND EAX, EAX   
0x00EA    75 3b           JNZ 0x127   
0x00EC    66 81fb 54435041CMP EBX, 0x41504354   
0x00F3    75 32           JNZ 0x127   
0x00F5    81f9 0201       CMP CX, 0x102   
0x00F9    72 2c           JB 0x127   
0x00FB    66 68 07bb0000  PUSH 0xbb07   
0x0101    66 68 00020000  PUSH 0x200   
0x0107    66 68 08000000  PUSH 0x8   
0x010D    66 53           PUSH EBX   
0x010F    66 53           PUSH EBX   
0x0111    66 55           PUSH EBP   
0x0113    66 68 00000000  PUSH 0x0   
0x0119    66 68 007c0000  PUSH 0x7c00   
0x011F    66 61           POPAD   
0x0121    68 0000         PUSH 0x0   
0x0124    07              POP ES   
0x0125    cd 1a           INT 0x1a   
0x0127    5a              POP DX   
0x0128    32f6            XOR DH, DH   
0x012A    ea 007c 0000    JMP FAR 0x0:0x7c00   
0x012F    cd 18           INT 0x18   
0x0131    a0 b707         MOV AL, [0x7b7]   
0x0134    eb 08           JMP 0x13e   
0x0136    a0 b607         MOV AL, [0x7b6]   
0x0139    eb 03           JMP 0x13e   
0x013B    a0 b507         MOV AL, [0x7b5]   
0x013E    32e4            XOR AH, AH   
0x0140    05 0007         ADD AX, 0x700   
0x0143    8bf0            MOV SI, AX   
0x0145    ac              LODSB   
0x0146    3c 00           CMP AL, 0x0   
0x0148    74 09           JZ 0x153   
0x014A    bb 0700         MOV BX, 0x7   
0x014D    b4 0e           MOV AH, 0xe   
0x014F    cd 10           INT 0x10   
0x0151    eb f2           JMP 0x145   
0x0153    f4              HLT   
0x0154    eb fd           JMP 0x153   
0x0156    2bc9            SUB CX, CX   
0x0158    e4 64           IN AL, 0x64   
0x015A    eb 00           JMP 0x15c   
0x015C    24 02           AND AL, 0x2   
0x015E    e0 f8           LOOPNZ 0x158   
0x0160    24 02           AND AL, 0x2   
0x0162    c3              RET   
0x0163    49              DEC CX   
0x0164    6e              OUTSB   
0x0165    76 61           JBE 0x1c8   
0x0167    6c              INSB   
0x0168    6964 20 7061    IMUL SP, [SI+0x20], 0x6170   
0x016D    72 74           JB 0x1e3   
0x016F    6974 69 6f6e    IMUL SI, [SI+0x69], 0x6e6f   
0x0174    2074 61         AND [SI+0x61], DH   
0x0177    626c 65         BOUND BP, [SI+0x65]   
0x017A    0045 72         ADD [DI+0x72], AL   
0x017D    72 6f           JB 0x1ee   
0x017F    72 20           JB 0x1a1   
0x0181    6c              INSB   
0x0182    6f              OUTSW   
0x0183    61              POPA   
0x0184    64 696e 67 206f IMUL BP, FS:[BP+0x67], 0x6f20   
0x018A    70 65           JO 0x1f1   
0x018C    72 61           JB 0x1ef   
0x018E    74 69           JZ 0x1f9   
0x0190    6e              OUTSB   
0x0191    67 2073 79      AND [EBX+0x79], DH   
0x0195    73 74           JAE 0x20b   
0x0197    65 6d           INS WORD GS:[DI], DX   
0x0199    004d 69         ADD [DI+0x69], CL   
0x019C    73 73           JAE 0x211   
0x019E    696e 67 206f    IMUL BP, [BP+0x67], 0x6f20   
0x01A3    70 65           JO 0x20a   
0x01A5    72 61           JB 0x208   
0x01A7    74 69           JZ 0x212   
0x01A9    6e              OUTSB   
0x01AA    67 2073 79      AND [EBX+0x79], DH   
0x01AE    73 74           JAE 0x224   
0x01B0    65 6d           INS WORD GS:[DI], DX   
0x01B2    0000            ADD [BX+SI], AL   
0x01B4    0063 7b         ADD [BP+DI+0x7b], AH   
0x01B7    9a a026 a126    CALL FAR 0x26a1:0x26a0   
0x01BC    0000            ADD [BX+SI], AL   
0x01BE    8001 01         ADD BYTE [BX+DI], 0x1   
0x01C1    0007            ADD [BX], AL   
0x01C3    fe              DB 0xfe   
0x01C4    ff              DB 0xff   
0x01C5    ff              DB 0xff   
0x01C6    3f              AAS   
0x01C7    0000            ADD [BX+SI], AL   
0x01C9    008d ea34       ADD [DI+0x34ea], CL   
0x01CD    0c 00           OR AL, 0x0   
0x01CF    fe              DB 0xfe   
0x01D0    ff              DB 0xff   
0x01D1    ff07            INC WORD [BX]   
0x01D3    fe              DB 0xfe   
0x01D4    ff              DB 0xff   
0x01D5    ff00            INC WORD [BX+SI]   
0x01D7    f0              DB 0xf0   
0x01D7    f0 34 0c        XOR AL, 0xc   
0x01DA    0098 5e22       ADD [BX+SI+0x225e], BL   
0x01DE    0000            ADD [BX+SI], AL   
0x01E0    0000            ADD [BX+SI], AL   
0x01E2    0000            ADD [BX+SI], AL   
0x01E4    0000            ADD [BX+SI], AL   
0x01E6    0000            ADD [BX+SI], AL   
0x01E8    0000            ADD [BX+SI], AL   
0x01EA    0000            ADD [BX+SI], AL   
0x01EC    0000            ADD [BX+SI], AL   
0x01EE    0000            ADD [BX+SI], AL   
0x01F0    0000            ADD [BX+SI], AL   
0x01F2    0000            ADD [BX+SI], AL   
0x01F4    0000            ADD [BX+SI], AL   
0x01F6    0000            ADD [BX+SI], AL   
0x01F8    0000            ADD [BX+SI], AL   
0x01FA    0000            ADD [BX+SI], AL   
0x01FC    0000            ADD [BX+SI], AL   
0x01FE    55              PUSH BP   
0x01FF    aa              STOSB   


_______MBR   \Device\Harddisk5\DR5  

0x00000000   33 C0 8E D0 BC 00 7C FB 50 07 50 1F FC BE 1B 7C   3À.м.|ûP.P.ü¾.|
0x00000010   BF 1B 06 50 57 B9 E5 01 F3 A4 CB BD BE 07 B1 04   ¿..PW¹å.ó¤Ë½¾.±.
0x00000020   38 6E 00 7C 09 75 13 83 C5 10 E2 F4 CD 18 8B F5   8n.|.u..Å.âôÍ..õ
0x00000030   83 C6 10 49 74 19 38 2C 74 F6 A0 B5 07 B4 07 8B   .Æ.It.8,tö.µ.´..
0x00000040   F0 AC 3C 00 74 FC BB 07 00 B4 0E CD 10 EB F2 88   ð¬<.tü»..´.Í.ëò.
0x00000050   4E 10 E8 46 00 73 2A FE 46 10 80 7E 04 0B 74 0B   N.èF.s*þF..~..t.
0x00000060   80 7E 04 0C 74 05 A0 B6 07 75 D2 80 46 02 06 83   .~..t..¶.uÒ.F...
0x00000070   46 08 06 83 56 0A 00 E8 21 00 73 05 A0 B6 07 EB   F...V..è!.s..¶.ë
0x00000080   BC 81 3E FE 7D 55 AA 74 0B 80 7E 10 00 74 C8 A0   ¼.>þ}Uªt..~..tÈ.
0x00000090   B7 07 EB A9 8B FC 1E 57 8B F5 CB BF 05 00 8A 56   ·.ë©.ü.W.õË¿...V
0x000000A0   00 B4 08 CD 13 72 23 8A C1 24 3F 98 8A DE 8A FC   .´.Í.r#.Á$?..Þ.ü
0x000000B0   43 F7 E3 8B D1 86 D6 B1 06 D2 EE 42 F7 E2 39 56   C÷ã.Ñ.Ö±.ÒîB÷â9V
0x000000C0   0A 77 23 72 05 39 46 08 73 1C EB 1A 90 BB 00 7C   .w#r.9F.s.ë..».|
0x000000D0   8B 4E 02 8B 56 00 CD 13 73 51 4F 74 4E 32 E4 8A   .N..V.Í.sQOtN2ä.
0x000000E0   56 00 CD 13 EB E4 8A 56 00 60 BB AA 55 B4 41 CD   V.Í.ëä.V.`»ªU´AÍ
0x000000F0   13 72 36 81 FB 55 AA 75 30 F6 C1 01 74 2B 61 60   .r6.ûUªu0öÁ.t+a`
0x00000100   6A 00 6A 00 FF 76 0A FF 76 08 6A 00 68 00 7C 6A   j.j..v..v.j.h.|j
0x00000110   01 6A 10 B4 42 8B F4 CD 13 61 61 73 0E 4F 74 0B   .j.´B.ôÍ.aas.Ot.
0x00000120   32 E4 8A 56 00 CD 13 EB D6 61 F9 C3 49 6E 76 61   2ä.V.Í.ëÖaùÃInva
0x00000130   6C 69 64 20 70 61 72 74 69 74 69 6F 6E 20 74 61   lid partition ta
0x00000140   62 6C 65 00 45 72 72 6F 72 20 6C 6F 61 64 69 6E   ble.Error loadin
0x00000150   67 20 6F 70 65 72 61 74 69 6E 67 20 73 79 73 74   g operating syst
0x00000160   65 6D 00 4D 69 73 73 69 6E 67 20 6F 70 65 72 61   em.Missing opera
0x00000170   74 69 6E 67 20 73 79 73 74 65 6D 00 00 00 00 00   ting system.....
0x00000180   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x00000190   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001A0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001B0   00 00 00 00 00 2C 44 63 A2 BB 29 C0 00 00 00 01   .....,Dc¢»)À....
0x000001C0   01 00 0C FE FF FF 3F 00 00 00 82 59 70 74 00 00   ...þ..?....Ypt..
0x000001D0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001E0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001F0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 55 AA   ..............Uª

__________________________16_BIT_ASM_CODE
   
0x0000    33c0            XOR AX, AX   
0x0002    8ed0            MOV SS, AX   
0x0004    bc 007c         MOV SP, 0x7c00   
0x0007    fb              STI   
0x0008    50              PUSH AX   
0x0009    07              POP ES   
0x000A    50              PUSH AX   
0x000B    1f              POP DS   
0x000C    fc              CLD   
0x000D    be 1b7c         MOV SI, 0x7c1b   
0x0010    bf 1b06         MOV DI, 0x61b   
0x0013    50              PUSH AX   
0x0014    57              PUSH DI   
0x0015    b9 e501         MOV CX, 0x1e5   
0x0018    f3 a4           REP MOVSB   
0x001A    cb              RETF   
0x001B    bd be07         MOV BP, 0x7be   
0x001E    b1 04           MOV CL, 0x4   
0x0020    386e 00         CMP [BP+0x0], CH   
0x0023    7c 09           JL 0x2e   
0x0025    75 13           JNZ 0x3a   
0x0027    83c5 10         ADD BP, 0x10   
0x002A    e2 f4           LOOP 0x20   
0x002C    cd 18           INT 0x18   
0x002E    8bf5            MOV SI, BP   
0x0030    83c6 10         ADD SI, 0x10   
0x0033    49              DEC CX   
0x0034    74 19           JZ 0x4f   
0x0036    382c            CMP [SI], CH   
0x0038    74 f6           JZ 0x30   
0x003A    a0 b507         MOV AL, [0x7b5]   
0x003D    b4 07           MOV AH, 0x7   
0x003F    8bf0            MOV SI, AX   
0x0041    ac              LODSB   
0x0042    3c 00           CMP AL, 0x0   
0x0044    74 fc           JZ 0x42   
0x0046    bb 0700         MOV BX, 0x7   
0x0049    b4 0e           MOV AH, 0xe   
0x004B    cd 10           INT 0x10   
0x004D    eb f2           JMP 0x41   
0x004F    884e 10         MOV [BP+0x10], CL   
0x0052    e8 4600         CALL 0x9b   
0x0055    73 2a           JAE 0x81   
0x0057    fe46 10         INC BYTE [BP+0x10]   
0x005A    807e 04 0b      CMP BYTE [BP+0x4], 0xb   
0x005E    74 0b           JZ 0x6b   
0x0060    807e 04 0c      CMP BYTE [BP+0x4], 0xc   
0x0064    74 05           JZ 0x6b   
0x0066    a0 b607         MOV AL, [0x7b6]   
0x0069    75 d2           JNZ 0x3d   
0x006B    8046 02 06      ADD BYTE [BP+0x2], 0x6   
0x006F    8346 08 06      ADD WORD [BP+0x8], 0x6   
0x0073    8356 0a 00      ADC WORD [BP+0xa], 0x0   
0x0077    e8 2100         CALL 0x9b   
0x007A    73 05           JAE 0x81   
0x007C    a0 b607         MOV AL, [0x7b6]   
0x007F    eb bc           JMP 0x3d   
0x0081    813e fe7d 55aa  CMP WORD [0x7dfe], 0xaa55   
0x0087    74 0b           JZ 0x94   
0x0089    807e 10 00      CMP BYTE [BP+0x10], 0x0   
0x008D    74 c8           JZ 0x57   
0x008F    a0 b707         MOV AL, [0x7b7]   
0x0092    eb a9           JMP 0x3d   
0x0094    8bfc            MOV DI, SP   
0x0096    1e              PUSH DS   
0x0097    57              PUSH DI   
0x0098    8bf5            MOV SI, BP   
0x009A    cb              RETF   
0x009B    bf 0500         MOV DI, 0x5   
0x009E    8a56 00         MOV DL, [BP+0x0]   
0x00A1    b4 08           MOV AH, 0x8   
0x00A3    cd 13           INT 0x13   
0x00A5    72 23           JB 0xca   
0x00A7    8ac1            MOV AL, CL   
0x00A9    24 3f           AND AL, 0x3f   
0x00AB    98              CBW   
0x00AC    8ade            MOV BL, DH   
0x00AE    8afc            MOV BH, AH   
0x00B0    43              INC BX   
0x00B1    f7e3            MUL BX   
0x00B3    8bd1            MOV DX, CX   
0x00B5    86d6            XCHG DH, DL   
0x00B7    b1 06           MOV CL, 0x6   
0x00B9    d2ee            SHR DH, CL   
0x00BB    42              INC DX   
0x00BC    f7e2            MUL DX   
0x00BE    3956 0a         CMP [BP+0xa], DX   
0x00C1    77 23           JA 0xe6   
0x00C3    72 05           JB 0xca   
0x00C5    3946 08         CMP [BP+0x8], AX   
0x00C8    73 1c           JAE 0xe6   
0x00CA    eb 1a           JMP 0xe6   
0x00CC    90              NOP   
0x00CD    bb 007c         MOV BX, 0x7c00   
0x00D0    8b4e 02         MOV CX, [BP+0x2]   
0x00D3    8b56 00         MOV DX, [BP+0x0]   
0x00D6    cd 13           INT 0x13   
0x00D8    73 51           JAE 0x12b   
0x00DA    4f              DEC DI   
0x00DB    74 4e           JZ 0x12b   
0x00DD    32e4            XOR AH, AH   
0x00DF    8a56 00         MOV DL, [BP+0x0]   
0x00E2    cd 13           INT 0x13   
0x00E4    eb e4           JMP 0xca   
0x00E6    8a56 00         MOV DL, [BP+0x0]   
0x00E9    60              PUSHA   
0x00EA    bb aa55         MOV BX, 0x55aa   
0x00ED    b4 41           MOV AH, 0x41   
0x00EF    cd 13           INT 0x13   
0x00F1    72 36           JB 0x129   
0x00F3    81fb 55aa       CMP BX, 0xaa55   
0x00F7    75 30           JNZ 0x129   
0x00F9    f6c1 01         TEST CL, 0x1   
0x00FC    74 2b           JZ 0x129   
0x00FE    61              POPA   
0x00FF    60              PUSHA   
0x0100    6a 00           PUSH 0x0   
0x0102    6a 00           PUSH 0x0   
0x0104    ff76 0a         PUSH WORD [BP+0xa]   
0x0107    ff76 08         PUSH WORD [BP+0x8]   
0x010A    6a 00           PUSH 0x0   
0x010C    68 007c         PUSH 0x7c00   
0x010F    6a 01           PUSH 0x1   
0x0111    6a 10           PUSH 0x10   
0x0113    b4 42           MOV AH, 0x42   
0x0115    8bf4            MOV SI, SP   
0x0117    cd 13           INT 0x13   
0x0119    61              POPA   
0x011A    61              POPA   
0x011B    73 0e           JAE 0x12b   
0x011D    4f              DEC DI   
0x011E    74 0b           JZ 0x12b   
0x0120    32e4            XOR AH, AH   
0x0122    8a56 00         MOV DL, [BP+0x0]   
0x0125    cd 13           INT 0x13   
0x0127    eb d6           JMP 0xff   
0x0129    61              POPA   
0x012A    f9              STC   
0x012B    c3              RET   
0x012C    49              DEC CX   
0x012D    6e              OUTSB   
0x012E    76 61           JBE 0x191   
0x0130    6c              INSB   
0x0131    6964 20 7061    IMUL SP, [SI+0x20], 0x6170   
0x0136    72 74           JB 0x1ac   
0x0138    6974 69 6f6e    IMUL SI, [SI+0x69], 0x6e6f   
0x013D    2074 61         AND [SI+0x61], DH   
0x0140    626c 65         BOUND BP, [SI+0x65]   
0x0143    0045 72         ADD [DI+0x72], AL   
0x0146    72 6f           JB 0x1b7   
0x0148    72 20           JB 0x16a   
0x014A    6c              INSB   
0x014B    6f              OUTSW   
0x014C    61              POPA   
0x014D    64 696e 67 206f IMUL BP, FS:[BP+0x67], 0x6f20   
0x0153    70 65           JO 0x1ba   
0x0155    72 61           JB 0x1b8   
0x0157    74 69           JZ 0x1c2   
0x0159    6e              OUTSB   
0x015A    67 2073 79      AND [EBX+0x79], DH   
0x015E    73 74           JAE 0x1d4   
0x0160    65 6d           INS WORD GS:[DI], DX   
0x0162    004d 69         ADD [DI+0x69], CL   
0x0165    73 73           JAE 0x1da   
0x0167    696e 67 206f    IMUL BP, [BP+0x67], 0x6f20   
0x016C    70 65           JO 0x1d3   
0x016E    72 61           JB 0x1d1   
0x0170    74 69           JZ 0x1db   
0x0172    6e              OUTSB   
0x0173    67 2073 79      AND [EBX+0x79], DH   
0x0177    73 74           JAE 0x1ed   
0x0179    65 6d           INS WORD GS:[DI], DX   
0x017B    0000            ADD [BX+SI], AL   
0x017D    0000            ADD [BX+SI], AL   
0x017F    0000            ADD [BX+SI], AL   
0x0181    0000            ADD [BX+SI], AL   
0x0183    0000            ADD [BX+SI], AL   
0x0185    0000            ADD [BX+SI], AL   
0x0187    0000            ADD [BX+SI], AL   
0x0189    0000            ADD [BX+SI], AL   
0x018B    0000            ADD [BX+SI], AL   
0x018D    0000            ADD [BX+SI], AL   
0x018F    0000            ADD [BX+SI], AL   
0x0191    0000            ADD [BX+SI], AL   
0x0193    0000            ADD [BX+SI], AL   
0x0195    0000            ADD [BX+SI], AL   
0x0197    0000            ADD [BX+SI], AL   
0x0199    0000            ADD [BX+SI], AL   
0x019B    0000            ADD [BX+SI], AL   
0x019D    0000            ADD [BX+SI], AL   
0x019F    0000            ADD [BX+SI], AL   
0x01A1    0000            ADD [BX+SI], AL   
0x01A3    0000            ADD [BX+SI], AL   
0x01A5    0000            ADD [BX+SI], AL   
0x01A7    0000            ADD [BX+SI], AL   
0x01A9    0000            ADD [BX+SI], AL   
0x01AB    0000            ADD [BX+SI], AL   
0x01AD    0000            ADD [BX+SI], AL   
0x01AF    0000            ADD [BX+SI], AL   
0x01B1    0000            ADD [BX+SI], AL   
0x01B3    0000            ADD [BX+SI], AL   
0x01B5    2c 44           SUB AL, 0x44   
0x01B7    63a2 bb29       ARPL [BP+SI+0x29bb], SP   
0x01BB    c000 00         ROL BYTE [BX+SI], 0x0   
0x01BE    0001            ADD [BX+DI], AL   
0x01C0    0100            ADD [BX+SI], AX   
0x01C2    0c fe           OR AL, 0xfe   
0x01C4    ff              DB 0xff   
0x01C5    ff              DB 0xff   
0x01C6    3f              AAS   
0x01C7    0000            ADD [BX+SI], AL   
0x01C9    0082 5970       ADD [BP+SI+0x7059], AL   
0x01CD    74 00           JZ 0x1cf   
0x01CF    0000            ADD [BX+SI], AL   
0x01D1    0000            ADD [BX+SI], AL   
0x01D3    0000            ADD [BX+SI], AL   
0x01D5    0000            ADD [BX+SI], AL   
0x01D7    0000            ADD [BX+SI], AL   
0x01D9    0000            ADD [BX+SI], AL   
0x01DB    0000            ADD [BX+SI], AL   
0x01DD    0000            ADD [BX+SI], AL   
0x01DF    0000            ADD [BX+SI], AL   
0x01E1    0000            ADD [BX+SI], AL   
0x01E3    0000            ADD [BX+SI], AL   
0x01E5    0000            ADD [BX+SI], AL   
0x01E7    0000            ADD [BX+SI], AL   
0x01E9    0000            ADD [BX+SI], AL   
0x01EB    0000            ADD [BX+SI], AL   
0x01ED    0000            ADD [BX+SI], AL   
0x01EF    0000            ADD [BX+SI], AL   
0x01F1    0000            ADD [BX+SI], AL   
0x01F3    0000            ADD [BX+SI], AL   
0x01F5    0000            ADD [BX+SI], AL   
0x01F7    0000            ADD [BX+SI], AL   
0x01F9    0000            ADD [BX+SI], AL   
0x01FB    0000            ADD [BX+SI], AL   
0x01FD    0055 aa         ADD [DI-0x56], DL   

Môj email:StigFird@hotmail.com
DoporučujemObrázek____Obrázek____Obrázek____Obrázek
Nepodporujem!!!:Obrázek

StigFird
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 17 črc 2011 11:59

Re: Anormné vyťažovanie Procesora

#4 Příspěvek od StigFird »

prihadzujem sem aj log z combofixu


ComboFix 12-02-06.02 - dominik . 02. 2012 17:43:36.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.421.1029.18.2047.1095 [GMT 1:00]
Running from: c:\users\dominik\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Skin Pack Toolbar\tbHElper.dll
c:\users\dominik\AppData\Local\Minibar
c:\users\dominik\AppData\Local\Minibar\common.js
c:\users\dominik\AppData\Local\Minibar\chrome\background.html
c:\users\dominik\AppData\Local\Minibar\chrome\cached_http_request.js
c:\users\dominik\AppData\Local\Minibar\chrome\extension_info.json
c:\users\dominik\AppData\Local\Minibar\chrome\icons\icon128.png
c:\users\dominik\AppData\Local\Minibar\chrome\icons\icon19.png
c:\users\dominik\AppData\Local\Minibar\chrome\icons\icon32.png
c:\users\dominik\AppData\Local\Minibar\chrome\icons\icon48.png
c:\users\dominik\AppData\Local\Minibar\chrome\includes\content.js
c:\users\dominik\AppData\Local\Minibar\chrome\includes\content_kango.js
c:\users\dominik\AppData\Local\Minibar\chrome\includes\content_messaging.js
c:\users\dominik\AppData\Local\Minibar\chrome\includes\content_userscript.js
c:\users\dominik\AppData\Local\Minibar\chrome\kango-ui\button.js
c:\users\dominik\AppData\Local\Minibar\chrome\kango-ui\ui.js
c:\users\dominik\AppData\Local\Minibar\chrome\kango\browser.js
c:\users\dominik\AppData\Local\Minibar\chrome\kango\console.js
c:\users\dominik\AppData\Local\Minibar\chrome\kango\event_listener.js
c:\users\dominik\AppData\Local\Minibar\chrome\kango\initialize.js
c:\users\dominik\AppData\Local\Minibar\chrome\kango\io.js
c:\users\dominik\AppData\Local\Minibar\chrome\kango\jsonstorage.js
c:\users\dominik\AppData\Local\Minibar\chrome\kango\kango.js
c:\users\dominik\AppData\Local\Minibar\chrome\kango\lang.js
c:\users\dominik\AppData\Local\Minibar\chrome\kango\messaging.js
c:\users\dominik\AppData\Local\Minibar\chrome\kango\userscript_engine.js
c:\users\dominik\AppData\Local\Minibar\chrome\kango\xhr.js
c:\users\dominik\AppData\Local\Minibar\chrome\main.js
c:\users\dominik\AppData\Local\Minibar\chrome\manifest.json
c:\users\dominik\AppData\Local\Minibar\chrome\minibar\actions.js
c:\users\dominik\AppData\Local\Minibar\chrome\minibar\cachedxhr.js
c:\users\dominik\AppData\Local\Minibar\chrome\minibar\config.js
c:\users\dominik\AppData\Local\Minibar\chrome\minibar\macros.js
c:\users\dominik\AppData\Local\Minibar\chrome\minibar\minibar.js
c:\users\dominik\AppData\Local\Minibar\chrome\popup.html
c:\users\dominik\AppData\Local\Minibar\chrome\popup.js
c:\users\dominik\AppData\Local\Minibar\chrome\tab.html
c:\users\dominik\AppData\Local\Minibar\chrome\tab.js
c:\users\dominik\AppData\Local\Minibar\chrome_installer.js
c:\users\dominik\AppData\Local\Minibar\install.json
c:\users\dominik\AppData\Local\Minibar\minibar.crx
c:\users\dominik\AppData\Local\Minibar\sqlite3.exe
c:\users\dominik\AppData\Local\Minibar\Uninstall.exe
c:\users\dominik\AppData\Local\TempDIR
c:\users\dominik\AppData\Local\TempDIR\BetterInstaller.exe
c:\users\dominik\AppData\Roaming\Microsoft\Windows\Recent\Nový zástupce internetové adresy.url
c:\users\dominik\AppData\Roaming\Microsoft\Windows\Recent\TechSupport.url
c:\users\dominik\javawbac
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\bin
c:\windows\system32\tmpB7C0.tmp
c:\windows\system32\tmpB7E0.tmp
c:\windows\VM305Cap.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-01-06 to 2012-02-06 )))))))))))))))))))))))))))))))
.
.
2012-02-06 17:04 . 2012-02-06 17:04 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-02-06 17:04 . 2012-02-06 17:04 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-02-06 13:37 . 2012-02-06 16:07 -------- d-----w- C:\Nová složka
2012-02-06 10:48 . 2012-02-06 10:48 -------- d-----w- C:\rsit
2012-02-05 13:52 . 2012-02-05 13:52 -------- d-----w- C:\Minecraft_Backup
2012-02-04 15:48 . 2012-02-06 15:55 -------- d-----w- c:\users\dominik\AppData\Roaming\.minecraft
2012-02-03 06:54 . 2012-02-03 06:54 -------- d-----w- c:\programdata\Raxco
2012-02-03 06:54 . 2012-02-03 06:54 -------- d-----w- c:\program files\Common Files\Raxco
2012-02-03 06:53 . 2012-02-03 06:54 -------- d-----w- c:\program files\Raxco
2012-02-02 16:53 . 2012-02-02 16:53 -------- d-----w- c:\users\dominik\AppData\Roaming\OpenOffice.org
2012-02-02 16:50 . 2012-02-02 16:50 -------- d-----w- c:\program files\OpenOffice.org 3
2012-02-01 14:46 . 2012-02-01 14:47 -------- d-----w- c:\users\dominik\AppData\Roaming\Apple Computer
2012-02-01 14:46 . 2012-02-01 14:46 -------- d-----w- c:\users\dominik\AppData\Local\Apple Computer
2012-02-01 14:45 . 2009-05-18 12:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-02-01 14:45 . 2008-04-17 11:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2012-02-01 14:44 . 2012-02-01 14:44 -------- d-----w- c:\program files\iPod
2012-02-01 14:44 . 2012-02-01 14:45 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2012-02-01 14:44 . 2012-02-01 14:45 -------- d-----w- c:\program files\iTunes
2012-02-01 14:44 . 2012-02-01 14:44 -------- d-----w- c:\programdata\Apple Computer
2012-02-01 14:42 . 2012-02-01 14:42 -------- d-----w- c:\users\dominik\AppData\Local\Apple
2012-02-01 14:42 . 2012-02-01 14:42 -------- d-----w- c:\program files\Apple Software Update
2012-02-01 14:42 . 2012-02-01 14:44 -------- d-----w- c:\program files\Common Files\Apple
2012-02-01 14:42 . 2012-02-01 14:42 -------- d-----w- c:\programdata\Apple
2012-01-31 17:34 . 2012-01-31 17:34 -------- d-----w- c:\windows\system32\backup
2012-01-31 17:24 . 2012-01-18 14:47 354416 ----a-w- c:\windows\system32\vmnetdhcp.exe
2012-01-31 17:24 . 2012-01-18 14:47 433264 ----a-w- c:\windows\system32\vmnat.exe
2012-01-31 17:24 . 2012-01-18 14:46 25712 ----a-w- c:\windows\system32\drivers\vmnetuserif.sys
2012-01-31 17:24 . 2012-01-18 14:47 783472 ----a-w- c:\windows\system32\vnetlib.dll
2012-01-31 17:22 . 2012-01-31 17:22 -------- d-----w- c:\program files\VMware
2012-01-31 17:22 . 2012-01-31 17:22 -------- d-----w- c:\program files\Common Files\VMware
2012-01-31 12:43 . 2011-11-17 05:41 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-01-31 12:43 . 2011-11-17 05:34 224768 ----a-w- c:\windows\system32\schannel.dll
2012-01-31 12:43 . 2011-11-17 05:41 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-01-31 12:43 . 2011-11-17 05:39 369352 ----a-w- c:\windows\system32\drivers\cng.sys
2012-01-31 12:43 . 2011-11-17 05:35 314880 ----a-w- c:\windows\system32\webio.dll
2012-01-31 12:43 . 2011-11-17 05:34 15872 ----a-w- c:\windows\system32\sspisrv.dll
2012-01-31 12:43 . 2011-11-17 05:34 100352 ----a-w- c:\windows\system32\sspicli.dll
2012-01-31 12:43 . 2011-11-17 05:34 22016 ----a-w- c:\windows\system32\secur32.dll
2012-01-31 12:43 . 2011-11-17 05:32 1038848 ----a-w- c:\windows\system32\lsasrv.dll
2012-01-31 12:43 . 2011-11-17 05:29 22528 ----a-w- c:\windows\system32\lsass.exe
2012-01-30 06:40 . 2012-01-30 06:40 -------- d-----w- c:\users\dominik\AppData\Roaming\Malwarebytes
2012-01-30 06:40 . 2012-01-30 06:40 -------- d-----w- c:\programdata\Malwarebytes
2012-01-29 07:17 . 2012-01-29 07:17 -------- d-----w- c:\users\dominik\AppData\Roaming\BANDISOFT
2012-01-29 07:15 . 2012-01-29 07:15 -------- d-----w- c:\program files\Bandicam
2012-01-29 07:15 . 2012-01-29 07:15 -------- d-----w- c:\program files\BandiMPEG1
2012-01-29 06:13 . 2012-01-29 06:27 -------- d-----w- c:\users\dominik\AppData\Roaming\Notepad++
2012-01-29 06:13 . 2012-01-29 06:13 -------- d-----w- c:\program files\Notepad++
2012-01-29 04:48 . 2012-01-29 04:48 -------- d-----w- c:\users\dominik\AppData\Roaming\fltk.org
2012-01-29 04:48 . 2012-01-29 04:48 -------- d-----w- c:\programdata\fltk.org
2012-01-28 19:17 . 2012-01-28 19:17 -------- d-----w- C:\Python27
2012-01-28 12:16 . 2012-01-28 12:16 -------- d-----w- c:\users\dominik\AppData\Local\GHISLER
2012-01-27 16:54 . 2012-01-27 16:56 -------- d-----w- c:\users\dominik\AppData\Roaming\GHISLER
2012-01-27 16:54 . 2012-01-27 16:55 -------- d-----w- C:\totalcmd
2012-01-27 16:54 . 2010-12-17 06:56 545 ----a-w- c:\windows\UC.PIF
2012-01-27 16:54 . 2010-12-17 06:56 545 ----a-w- c:\windows\RAR.PIF
2012-01-27 16:54 . 2010-12-17 06:56 545 ----a-w- c:\windows\NOCLOSE.PIF
2012-01-27 16:54 . 2010-12-17 06:56 545 ----a-w- c:\windows\LHA.PIF
2012-01-27 16:54 . 2010-12-17 06:56 545 ----a-w- c:\windows\ARJ.PIF
2012-01-25 05:25 . 2012-01-25 05:25 -------- d-----w- c:\program files\PIC Corporation
2012-01-25 05:21 . 2012-01-25 05:21 -------- d-----w- c:\users\dominik\AppData\Roaming\Gretech
2012-01-25 05:21 . 2012-01-25 05:21 -------- d-----w- c:\program files\CoreAAC
2012-01-25 05:20 . 2012-01-25 05:20 -------- d-----w- c:\programdata\GRETECH
2012-01-25 05:20 . 2012-01-25 05:20 -------- d-----w- c:\program files\GRETECH
2012-01-24 14:54 . 2012-01-24 14:54 -------- d-----w- c:\program files\Common Files\Java
2012-01-24 14:53 . 2012-01-24 14:53 637848 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-01-21 13:37 . 2012-01-21 13:37 -------- d-----w- c:\program files\Cepstral
2012-01-19 14:21 . 2012-01-19 14:21 -------- d-----w- c:\users\dominik\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
2012-01-19 14:21 . 2012-01-19 14:21 -------- d-----w- c:\program files\Common Files\Adobe AIR
2012-01-19 13:32 . 2012-01-19 13:32 -------- d-----w- c:\users\dominik\AppData\Roaming\NVIDIA
2012-01-18 19:03 . 2012-01-18 19:03 -------- d-----w- c:\program files\AmIcoSingLun
2012-01-18 19:03 . 2012-01-18 19:03 -------- d-----w- c:\programdata\AmUStor
2012-01-18 18:57 . 2011-10-15 08:53 919872 ----a-w- c:\windows\system32\nvdispco32.dll
2012-01-18 18:57 . 2011-10-15 08:53 877376 ----a-w- c:\windows\system32\nvgenco32.dll
2012-01-18 18:57 . 2011-10-15 08:53 61248 ----a-w- c:\windows\system32\OpenCL.dll
2012-01-18 18:57 . 2011-10-15 08:53 5578560 ----a-w- c:\windows\system32\nvcuda.dll
2012-01-18 18:57 . 2011-10-15 08:53 2401088 ----a-w- c:\windows\system32\nvcuvid.dll
2012-01-18 18:57 . 2011-10-15 08:53 2099520 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-01-18 18:57 . 2011-10-15 08:53 18871616 ----a-w- c:\windows\system32\nvoglv32.dll
2012-01-18 18:57 . 2011-10-15 08:53 17248576 ----a-w- c:\windows\system32\nvcompiler.dll
2012-01-18 18:57 . 2011-10-15 08:53 13205312 ----a-w- c:\windows\system32\nvd3dum.dll
2012-01-18 18:57 . 2011-10-15 08:53 10327360 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2012-01-18 18:50 . 2012-01-18 18:54 -------- d-----w- C:\NVIDIA
2012-01-18 18:47 . 2012-01-18 18:47 -------- d-----w- c:\windows\system32\RTCOM
2012-01-18 18:22 . 2012-01-18 18:43 -------- d-----w- c:\programdata\DriverGenius
2012-01-18 18:21 . 2012-01-18 18:21 -------- d-----w- c:\program files\Driver-Soft
2012-01-18 14:47 . 2012-01-18 14:47 55664 ----a-w- c:\windows\system32\drivers\vmx86.sys
2012-01-18 14:47 . 2012-01-18 14:47 23792 ----a-w- c:\windows\system32\drivers\vmparport.sys
2012-01-18 12:41 . 2012-01-18 12:41 252016 ----a-w- c:\windows\system32\vmnc.dll
2012-01-18 12:06 . 2012-01-18 12:06 55408 ----a-w- c:\windows\system32\vmnetbridge.dll
2012-01-18 12:06 . 2012-01-18 12:06 49776 ----a-w- c:\windows\system32\vnetinst.dll
2012-01-18 12:06 . 2012-01-18 12:06 36464 ----a-w- c:\windows\system32\drivers\vmnetbridge.sys
2012-01-18 12:06 . 2012-01-18 12:06 19568 ----a-w- c:\windows\system32\drivers\vmnet.sys
2012-01-18 12:06 . 2012-01-18 12:06 16624 ----a-w- c:\windows\system32\drivers\vmnetadapter.sys
2012-01-17 17:10 . 2012-01-17 17:10 -------- d-----w- c:\users\dominik\AppData\Local\ProphetX
2012-01-17 17:04 . 2011-11-24 09:48 1589248 ----a-w- c:\windows\system32\libmysql_d.dll
2012-01-17 17:03 . 2012-01-17 17:03 -------- d-----w- c:\program files\PremiumSoft
2012-01-14 13:08 . 2012-01-14 13:10 -------- d-----w- C:\Downloads
2012-01-11 05:23 . 2011-11-19 14:01 67072 ----a-w- c:\windows\system32\packager.dll
2012-01-11 05:23 . 2011-11-17 05:38 1288472 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 05:23 . 2011-10-26 04:32 514560 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 05:23 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\system32\quartz.dll
2012-01-10 19:27 . 2012-01-31 17:36 -------- d-----w- c:\users\dominik\AppData\Local\VMware
2012-01-10 19:27 . 2012-01-31 17:35 -------- d-----w- c:\users\dominik\AppData\Roaming\VMware
2012-01-10 19:10 . 2012-02-06 16:11 -------- d-----w- c:\programdata\VMware
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-24 14:53 . 2011-10-22 16:06 567184 ----a-w- c:\windows\system32\deployJava1.dll
2012-01-24 12:59 . 2011-10-23 12:23 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-13 18:31 . 2011-10-24 16:30 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2011-12-13 18:31 . 2011-10-24 15:22 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2011-12-11 15:34 . 2009-07-13 23:40 249856 ----a-w- c:\windows\system32\uxtheme.dll
2011-12-11 15:15 . 2011-10-22 14:47 2755072 ----a-w- c:\windows\system32\themeui.dll
2011-12-11 15:15 . 2009-07-13 23:39 37376 ----a-w- c:\windows\system32\themeservice.dll
2011-12-10 09:42 . 2011-12-10 09:42 284672 ----a-w- c:\windows\7za.dll
2011-12-01 15:11 . 2011-12-01 15:11 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2011-11-26 22:40 . 2011-11-25 17:00 2478272 ----a-w- c:\programdata\Microsoft\VisualStudio\10.0\1033\ResourceCache.dll
2011-11-24 04:25 . 2011-12-15 04:39 2342912 ----a-w- c:\windows\system32\win32k.sys
2011-11-17 05:34 . 2012-01-31 12:43 224768 ----a-w- c:\windows\system32\schannel.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2011-02-26 . 255CF508D7CFB10E0794D6AC93280BD8 . 2614784 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[7] 2011-02-26 . 2AF58D15EDC06EC6FDACCE1F19482BBF . 2614784 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[7] 2011-02-26 . 0FB9C74046656D1579A64660AD67B746 . 2616320 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[-] 2011-02-25 . 6FD4F71F59268E729829CFB099F42C11 . 2616320 . . [6.1.7600.16385] . . c:\windows\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-09-06 20:45 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-09-06 3722416]
"BigDog305"="c:\windows\VM305_STI.EXE" [2005-08-05 61440]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-01-16 421736]
.
c:\users\dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-6-7 1195520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigDog305]
2005-08-05 20:15 61440 ----a-w- c:\windows\VM305_STI.EXE
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 VMwareHostd;VMware Workstation Server;c:\program files\VMware\VMware Workstation\vmware-hostd.exe [2012-01-18 11839488]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 VSPerfDrv100;Performance Tools Driver 10.0;c:\program files\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\VSPerfDrv100.sys [2009-12-08 48128]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2011-10-22 1343400]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-23 47128]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 239336]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 366936]
R4 TunngleService;TunngleService;c:\program files\Tunngle\TnglCtrl.exe [2011-10-14 745832]
S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys [2011-08-08 98928]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-10-23 232512]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2011-10-03 158512]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2011-10-03 91440]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-09-06 54616]
S2 Cepstral License Server;Cepstral License Server;c:\program files\Cepstral\bin\CepstralLicSrv.exe [2008-06-24 57344]
S2 Dyyno Launcher;Dyyno Service;c:\program files\Dyyno\Dyyno Broadcaster\launcherd.exe [2011-01-15 415072]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
S2 PDFSFilter;PDFSFilter;c:\windows\system32\DRIVERS\PDFsFilter.sys [2011-06-30 66320]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-14 381248]
S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-08-30 2358656]
S2 TeamViewer7;TeamViewer 7;c:\program files\TeamViewer\Version7\TeamViewer_Service.exe [2011-12-14 2984832]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files\Common Files\VMware\USB\vmware-usbarbitrator.exe [2011-08-29 665200]
S2 vstor2-mntapi10-shared;Vstor2 MntApi 1.0 Driver (shared);c:\windows\system32\drivers\vstor2-mntapi10-shared.sys [2011-07-08 22768]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2011-10-03 104752]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2011-10-03 116016]
S3 ZSMC0305;A4 TECH PC Camera V;c:\windows\system32\Drivers\usbVM305.sys [2006-05-08 391688]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3678732471-1654464958-2998469604-1000Core.job
- c:\users\dominik\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-28 18:03]
.
2012-02-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3678732471-1654464958-2998469604-1000UA.job
- c:\users\dominik\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-28 18:03]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
mStart Page = hxxp://www.bigseekpro.com/lionskin/{236A6501-E ... A8C199317F}
uInternet Settings,ProxyOverride = *.local
LSP: %SystemRoot%\system32\vsocklib.dll
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-3678732471-1654464958-2998469604-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-02-06 18:12:20
ComboFix-quarantined-files.txt 2012-02-06 17:12
.
Pre-Run: Volných bajtů: 25 556 492 288
Post-Run: Volných bajtů: 25 461 170 176
.
- - End Of File - - 338240FF2A8F79ACA6AAA8D78C913E69
Môj email:StigFird@hotmail.com
DoporučujemObrázek____Obrázek____Obrázek____Obrázek
Nepodporujem!!!:Obrázek

StigFird
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 17 črc 2011 11:59

Re: Anormné vyťažovanie Procesora

#5 Příspěvek od StigFird »

Môj email:StigFird@hotmail.com
DoporučujemObrázek____Obrázek____Obrázek____Obrázek
Nepodporujem!!!:Obrázek

StigFird
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 17 črc 2011 11:59

Re: Anormné vyťažovanie Procesora

#6 Příspěvek od StigFird »

ComboFix 12-02-06.02 - dominik . 02. 2012 20:07:15.2.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.421.1029.18.2047.1146 [GMT 1:00]
Running from: c:\users\dominik\Desktop\ComboFix.exe
Command switches used :: c:\users\dominik\Desktop\CFScript.txt
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
file zipped: c:\windows\System32\drivers\ASACPI.sys
file zipped: c:\windows\System32\dwm.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-01-06 to 2012-02-06 )))))))))))))))))))))))))))))))
.
.
2012-02-06 19:34 . 2012-02-06 19:34 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-02-06 19:34 . 2012-02-06 19:34 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-02-06 17:12 . 2012-02-06 19:34 -------- d-----w- c:\users\dominik\AppData\Local\temp
2012-02-06 13:37 . 2012-02-06 16:07 -------- d-----w- C:\Nová složka
2012-02-06 10:48 . 2012-02-06 10:48 -------- d-----w- C:\rsit
2012-02-05 13:52 . 2012-02-05 13:52 -------- d-----w- C:\Minecraft_Backup
2012-02-04 15:48 . 2012-02-06 18:00 -------- d-----w- c:\users\dominik\AppData\Roaming\.minecraft
2012-02-03 06:54 . 2012-02-03 06:54 -------- d-----w- c:\programdata\Raxco
2012-02-03 06:54 . 2012-02-03 06:54 -------- d-----w- c:\program files\Common Files\Raxco
2012-02-03 06:53 . 2012-02-03 06:54 -------- d-----w- c:\program files\Raxco
2012-02-02 16:53 . 2012-02-02 16:53 -------- d-----w- c:\users\dominik\AppData\Roaming\OpenOffice.org
2012-02-02 16:50 . 2012-02-02 16:50 -------- d-----w- c:\program files\OpenOffice.org 3
2012-02-01 14:46 . 2012-02-01 14:47 -------- d-----w- c:\users\dominik\AppData\Roaming\Apple Computer
2012-02-01 14:46 . 2012-02-01 14:46 -------- d-----w- c:\users\dominik\AppData\Local\Apple Computer
2012-02-01 14:45 . 2009-05-18 12:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-02-01 14:45 . 2008-04-17 11:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2012-02-01 14:44 . 2012-02-01 14:44 -------- d-----w- c:\program files\iPod
2012-02-01 14:44 . 2012-02-01 14:45 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2012-02-01 14:44 . 2012-02-01 14:45 -------- d-----w- c:\program files\iTunes
2012-02-01 14:44 . 2012-02-01 14:44 -------- d-----w- c:\programdata\Apple Computer
2012-02-01 14:42 . 2012-02-01 14:42 -------- d-----w- c:\users\dominik\AppData\Local\Apple
2012-02-01 14:42 . 2012-02-01 14:42 -------- d-----w- c:\program files\Apple Software Update
2012-02-01 14:42 . 2012-02-01 14:44 -------- d-----w- c:\program files\Common Files\Apple
2012-02-01 14:42 . 2012-02-01 14:42 -------- d-----w- c:\programdata\Apple
2012-01-31 17:34 . 2012-01-31 17:34 -------- d-----w- c:\windows\system32\backup
2012-01-31 17:24 . 2012-01-18 14:47 354416 ----a-w- c:\windows\system32\vmnetdhcp.exe
2012-01-31 17:24 . 2012-01-18 14:47 433264 ----a-w- c:\windows\system32\vmnat.exe
2012-01-31 17:24 . 2012-01-18 14:46 25712 ----a-w- c:\windows\system32\drivers\vmnetuserif.sys
2012-01-31 17:24 . 2012-01-18 14:47 783472 ----a-w- c:\windows\system32\vnetlib.dll
2012-01-31 17:22 . 2012-01-31 17:22 -------- d-----w- c:\program files\VMware
2012-01-31 17:22 . 2012-01-31 17:22 -------- d-----w- c:\program files\Common Files\VMware
2012-01-31 12:43 . 2011-11-17 05:41 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-01-31 12:43 . 2011-11-17 05:34 224768 ----a-w- c:\windows\system32\schannel.dll
2012-01-31 12:43 . 2011-11-17 05:41 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-01-31 12:43 . 2011-11-17 05:39 369352 ----a-w- c:\windows\system32\drivers\cng.sys
2012-01-31 12:43 . 2011-11-17 05:35 314880 ----a-w- c:\windows\system32\webio.dll
2012-01-31 12:43 . 2011-11-17 05:34 15872 ----a-w- c:\windows\system32\sspisrv.dll
2012-01-31 12:43 . 2011-11-17 05:34 100352 ----a-w- c:\windows\system32\sspicli.dll
2012-01-31 12:43 . 2011-11-17 05:34 22016 ----a-w- c:\windows\system32\secur32.dll
2012-01-31 12:43 . 2011-11-17 05:32 1038848 ----a-w- c:\windows\system32\lsasrv.dll
2012-01-31 12:43 . 2011-11-17 05:29 22528 ----a-w- c:\windows\system32\lsass.exe
2012-01-30 06:40 . 2012-01-30 06:40 -------- d-----w- c:\users\dominik\AppData\Roaming\Malwarebytes
2012-01-30 06:40 . 2012-01-30 06:40 -------- d-----w- c:\programdata\Malwarebytes
2012-01-29 07:17 . 2012-01-29 07:17 -------- d-----w- c:\users\dominik\AppData\Roaming\BANDISOFT
2012-01-29 07:15 . 2012-01-29 07:15 -------- d-----w- c:\program files\Bandicam
2012-01-29 07:15 . 2012-01-29 07:15 -------- d-----w- c:\program files\BandiMPEG1
2012-01-29 06:13 . 2012-01-29 06:27 -------- d-----w- c:\users\dominik\AppData\Roaming\Notepad++
2012-01-29 06:13 . 2012-01-29 06:13 -------- d-----w- c:\program files\Notepad++
2012-01-29 04:48 . 2012-01-29 04:48 -------- d-----w- c:\users\dominik\AppData\Roaming\fltk.org
2012-01-29 04:48 . 2012-01-29 04:48 -------- d-----w- c:\programdata\fltk.org
2012-01-28 19:17 . 2012-01-28 19:17 -------- d-----w- C:\Python27
2012-01-28 12:16 . 2012-01-28 12:16 -------- d-----w- c:\users\dominik\AppData\Local\GHISLER
2012-01-27 16:54 . 2012-01-27 16:56 -------- d-----w- c:\users\dominik\AppData\Roaming\GHISLER
2012-01-27 16:54 . 2012-01-27 16:55 -------- d-----w- C:\totalcmd
2012-01-27 16:54 . 2010-12-17 06:56 545 ----a-w- c:\windows\UC.PIF
2012-01-27 16:54 . 2010-12-17 06:56 545 ----a-w- c:\windows\RAR.PIF
2012-01-27 16:54 . 2010-12-17 06:56 545 ----a-w- c:\windows\NOCLOSE.PIF
2012-01-27 16:54 . 2010-12-17 06:56 545 ----a-w- c:\windows\LHA.PIF
2012-01-27 16:54 . 2010-12-17 06:56 545 ----a-w- c:\windows\ARJ.PIF
2012-01-25 05:25 . 2012-01-25 05:25 -------- d-----w- c:\program files\PIC Corporation
2012-01-25 05:21 . 2012-01-25 05:21 -------- d-----w- c:\users\dominik\AppData\Roaming\Gretech
2012-01-25 05:21 . 2012-01-25 05:21 -------- d-----w- c:\program files\CoreAAC
2012-01-25 05:20 . 2012-01-25 05:20 -------- d-----w- c:\programdata\GRETECH
2012-01-25 05:20 . 2012-01-25 05:20 -------- d-----w- c:\program files\GRETECH
2012-01-24 14:54 . 2012-01-24 14:54 -------- d-----w- c:\program files\Common Files\Java
2012-01-24 14:53 . 2012-01-24 14:53 637848 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-01-21 13:37 . 2012-01-21 13:37 -------- d-----w- c:\program files\Cepstral
2012-01-19 14:21 . 2012-01-19 14:21 -------- d-----w- c:\users\dominik\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
2012-01-19 14:21 . 2012-01-19 14:21 -------- d-----w- c:\program files\Common Files\Adobe AIR
2012-01-19 13:32 . 2012-01-19 13:32 -------- d-----w- c:\users\dominik\AppData\Roaming\NVIDIA
2012-01-18 19:03 . 2012-01-18 19:03 -------- d-----w- c:\program files\AmIcoSingLun
2012-01-18 19:03 . 2012-01-18 19:03 -------- d-----w- c:\programdata\AmUStor
2012-01-18 18:57 . 2011-10-15 08:53 919872 ----a-w- c:\windows\system32\nvdispco32.dll
2012-01-18 18:57 . 2011-10-15 08:53 877376 ----a-w- c:\windows\system32\nvgenco32.dll
2012-01-18 18:57 . 2011-10-15 08:53 61248 ----a-w- c:\windows\system32\OpenCL.dll
2012-01-18 18:57 . 2011-10-15 08:53 5578560 ----a-w- c:\windows\system32\nvcuda.dll
2012-01-18 18:57 . 2011-10-15 08:53 2401088 ----a-w- c:\windows\system32\nvcuvid.dll
2012-01-18 18:57 . 2011-10-15 08:53 2099520 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-01-18 18:57 . 2011-10-15 08:53 18871616 ----a-w- c:\windows\system32\nvoglv32.dll
2012-01-18 18:57 . 2011-10-15 08:53 17248576 ----a-w- c:\windows\system32\nvcompiler.dll
2012-01-18 18:57 . 2011-10-15 08:53 13205312 ----a-w- c:\windows\system32\nvd3dum.dll
2012-01-18 18:57 . 2011-10-15 08:53 10327360 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2012-01-18 18:50 . 2012-01-18 18:54 -------- d-----w- C:\NVIDIA
2012-01-18 18:47 . 2012-01-18 18:47 -------- d-----w- c:\windows\system32\RTCOM
2012-01-18 18:22 . 2012-01-18 18:43 -------- d-----w- c:\programdata\DriverGenius
2012-01-18 18:21 . 2012-01-18 18:21 -------- d-----w- c:\program files\Driver-Soft
2012-01-18 14:47 . 2012-01-18 14:47 55664 ----a-w- c:\windows\system32\drivers\vmx86.sys
2012-01-18 14:47 . 2012-01-18 14:47 23792 ----a-w- c:\windows\system32\drivers\vmparport.sys
2012-01-18 12:41 . 2012-01-18 12:41 252016 ----a-w- c:\windows\system32\vmnc.dll
2012-01-18 12:06 . 2012-01-18 12:06 55408 ----a-w- c:\windows\system32\vmnetbridge.dll
2012-01-18 12:06 . 2012-01-18 12:06 49776 ----a-w- c:\windows\system32\vnetinst.dll
2012-01-18 12:06 . 2012-01-18 12:06 36464 ----a-w- c:\windows\system32\drivers\vmnetbridge.sys
2012-01-18 12:06 . 2012-01-18 12:06 19568 ----a-w- c:\windows\system32\drivers\vmnet.sys
2012-01-18 12:06 . 2012-01-18 12:06 16624 ----a-w- c:\windows\system32\drivers\vmnetadapter.sys
2012-01-17 17:10 . 2012-01-17 17:10 -------- d-----w- c:\users\dominik\AppData\Local\ProphetX
2012-01-17 17:04 . 2011-11-24 09:48 1589248 ----a-w- c:\windows\system32\libmysql_d.dll
2012-01-17 17:03 . 2012-01-17 17:03 -------- d-----w- c:\program files\PremiumSoft
2012-01-14 13:08 . 2012-01-14 13:10 -------- d-----w- C:\Downloads
2012-01-11 05:23 . 2011-11-19 14:01 67072 ----a-w- c:\windows\system32\packager.dll
2012-01-11 05:23 . 2011-11-17 05:38 1288472 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 05:23 . 2011-10-26 04:32 514560 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 05:23 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\system32\quartz.dll
2012-01-10 19:27 . 2012-01-31 17:36 -------- d-----w- c:\users\dominik\AppData\Local\VMware
2012-01-10 19:27 . 2012-01-31 17:35 -------- d-----w- c:\users\dominik\AppData\Roaming\VMware
2012-01-10 19:10 . 2012-02-06 18:44 -------- d-----w- c:\programdata\VMware
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-24 14:53 . 2011-10-22 16:06 567184 ----a-w- c:\windows\system32\deployJava1.dll
2012-01-24 12:59 . 2011-10-23 12:23 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-13 18:31 . 2011-10-24 16:30 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2011-12-13 18:31 . 2011-10-24 15:22 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2011-12-11 15:34 . 2009-07-13 23:40 249856 ----a-w- c:\windows\system32\uxtheme.dll
2011-12-11 15:15 . 2011-10-22 14:47 2755072 ----a-w- c:\windows\system32\themeui.dll
2011-12-11 15:15 . 2009-07-13 23:39 37376 ----a-w- c:\windows\system32\themeservice.dll
2011-12-10 09:42 . 2011-12-10 09:42 284672 ----a-w- c:\windows\7za.dll
2011-12-01 15:11 . 2011-12-01 15:11 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2011-11-26 22:40 . 2011-11-25 17:00 2478272 ----a-w- c:\programdata\Microsoft\VisualStudio\10.0\1033\ResourceCache.dll
2011-11-24 04:25 . 2011-12-15 04:39 2342912 ----a-w- c:\windows\system32\win32k.sys
2011-11-17 05:34 . 2012-01-31 12:43 224768 ----a-w- c:\windows\system32\schannel.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2011-02-26 . 255CF508D7CFB10E0794D6AC93280BD8 . 2614784 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[7] 2011-02-26 . 2AF58D15EDC06EC6FDACCE1F19482BBF . 2614784 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[7] 2011-02-26 . 0FB9C74046656D1579A64660AD67B746 . 2616320 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[-] 2011-02-25 . 6FD4F71F59268E729829CFB099F42C11 . 2616320 . . [6.1.7600.16385] . . c:\windows\explorer.exe
[7] 2011-02-25 . 8B88EBBB05A0E56B7DCC708498C02B3E . 2616320 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[7] 2010-11-20 . 40D777B7A95E00593EB1568C68514493 . 2616320 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[7] 2009-10-31 . C76153C7ECA00FA852BB0C193378F917 . 2614272 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe
[7] 2009-10-31 . 2626FC9755BE22F805D3CFA0CE3EE727 . 2614272 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[7] 2009-08-03 . 9FF6C4C91A3711C0A3B18F87B08B518D . 2613248 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[7] 2009-08-03 . B95EEB0F4E5EFBF1038A35B3351CF047 . 2613248 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[7] 2009-07-14 . 15BC38A7492BEFE831966ADB477CF76F . 2613248 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-09-06 20:45 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-09-06 3722416]
"BigDog305"="c:\windows\VM305_STI.EXE" [2005-08-05 61440]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-01-16 421736]
.
c:\users\dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-6-7 1195520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigDog305]
2005-08-05 20:15 61440 ----a-w- c:\windows\VM305_STI.EXE
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 VMwareHostd;VMware Workstation Server;c:\program files\VMware\VMware Workstation\vmware-hostd.exe [2012-01-18 11839488]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 VSPerfDrv100;Performance Tools Driver 10.0;c:\program files\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\VSPerfDrv100.sys [2009-12-08 48128]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2011-10-22 1343400]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-23 47128]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 239336]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 366936]
R4 TunngleService;TunngleService;c:\program files\Tunngle\TnglCtrl.exe [2011-10-14 745832]
S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys [2011-08-08 98928]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-10-23 232512]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2011-10-03 158512]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2011-10-03 91440]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-09-06 54616]
S2 Cepstral License Server;Cepstral License Server;c:\program files\Cepstral\bin\CepstralLicSrv.exe [2008-06-24 57344]
S2 Dyyno Launcher;Dyyno Service;c:\program files\Dyyno\Dyyno Broadcaster\launcherd.exe [2011-01-15 415072]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
S2 PDFSFilter;PDFSFilter;c:\windows\system32\DRIVERS\PDFsFilter.sys [2011-06-30 66320]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-14 381248]
S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-08-30 2358656]
S2 TeamViewer7;TeamViewer 7;c:\program files\TeamViewer\Version7\TeamViewer_Service.exe [2011-12-14 2984832]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files\Common Files\VMware\USB\vmware-usbarbitrator.exe [2011-08-29 665200]
S2 vstor2-mntapi10-shared;Vstor2 MntApi 1.0 Driver (shared);c:\windows\system32\drivers\vstor2-mntapi10-shared.sys [2011-07-08 22768]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2011-10-03 104752]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2011-10-03 116016]
S3 ZSMC0305;A4 TECH PC Camera V;c:\windows\system32\Drivers\usbVM305.sys [2006-05-08 391688]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3678732471-1654464958-2998469604-1000Core.job
- c:\users\dominik\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-28 18:03]
.
2012-02-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3678732471-1654464958-2998469604-1000UA.job
- c:\users\dominik\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-28 18:03]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
mStart Page = hxxp://www.bigseekpro.com/lionskin/{236A6501-E ... A8C199317F}
uInternet Settings,ProxyOverride = *.local
LSP: %SystemRoot%\system32\vsocklib.dll
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-3678732471-1654464958-2998469604-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-02-06 20:46:57
ComboFix-quarantined-files.txt 2012-02-06 19:46
ComboFix2.txt 2012-02-06 17:12
.
Pre-Run: Volných bajtů: 25 157 808 128
Post-Run: Volných bajtů: 25 093 144 576
.
- - End Of File - - CCC3E6CFA777DEAA923756201A88CDC5
Upload was successful
Môj email:StigFird@hotmail.com
DoporučujemObrázek____Obrázek____Obrázek____Obrázek
Nepodporujem!!!:Obrázek

StigFird
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 17 črc 2011 11:59

Re: Anormné vyťažovanie Procesora

#7 Příspěvek od StigFird »

ComboFix 12-02-06.02 - dominik . 02. 2012 12:01:36.3.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.421.1029.18.2047.1249 [GMT 1:00]
Running from: c:\users\dominik\Desktop\ComboFix.exe
Command switches used :: c:\users\dominik\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
file zipped: c:\windows\explorer.exe
file zipped: c:\windows\System32\drivers\ASACPI.sys
file zipped: c:\windows\System32\dwm.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-01-08 to 2012-02-08 )))))))))))))))))))))))))))))))
.
.
2012-02-08 11:19 . 2012-02-08 11:19 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-02-08 11:19 . 2012-02-08 11:19 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-02-07 15:57 . 2012-02-07 15:57 -------- d-----w- c:\program files\CDA to MP3 Converter 3
2012-02-07 15:38 . 2012-02-07 15:38 -------- d-----w- c:\program files\Common Files\DeskShare Shared
2012-02-07 15:38 . 2004-12-07 09:11 258352 ----a-w- c:\windows\system32\Unicows.dll
2012-02-07 15:38 . 2012-02-07 15:38 -------- d-----w- c:\program files\Deskshare
2012-02-07 05:24 . 2012-02-07 19:10 -------- d-----w- c:\users\dominik\AppData\Roaming\.minecraft
2012-02-06 17:12 . 2012-02-08 11:19 -------- d-----w- c:\users\dominik\AppData\Local\temp
2012-02-06 13:37 . 2012-02-06 16:07 -------- d-----w- C:\Nová složka
2012-02-06 10:48 . 2012-02-06 10:48 -------- d-----w- C:\rsit
2012-02-05 13:52 . 2012-02-07 12:09 -------- d-----w- C:\Minecraft_Backup
2012-02-03 06:54 . 2012-02-03 06:54 -------- d-----w- c:\programdata\Raxco
2012-02-03 06:54 . 2012-02-03 06:54 -------- d-----w- c:\program files\Common Files\Raxco
2012-02-03 06:53 . 2012-02-03 06:54 -------- d-----w- c:\program files\Raxco
2012-02-02 16:53 . 2012-02-02 16:53 -------- d-----w- c:\users\dominik\AppData\Roaming\OpenOffice.org
2012-02-02 16:50 . 2012-02-02 16:50 -------- d-----w- c:\program files\OpenOffice.org 3
2012-02-01 14:46 . 2012-02-01 14:47 -------- d-----w- c:\users\dominik\AppData\Roaming\Apple Computer
2012-02-01 14:46 . 2012-02-01 14:46 -------- d-----w- c:\users\dominik\AppData\Local\Apple Computer
2012-02-01 14:45 . 2009-05-18 12:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-02-01 14:45 . 2008-04-17 11:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2012-02-01 14:44 . 2012-02-01 14:44 -------- d-----w- c:\program files\iPod
2012-02-01 14:44 . 2012-02-01 14:45 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2012-02-01 14:44 . 2012-02-01 14:45 -------- d-----w- c:\program files\iTunes
2012-02-01 14:44 . 2012-02-01 14:44 -------- d-----w- c:\programdata\Apple Computer
2012-02-01 14:42 . 2012-02-01 14:42 -------- d-----w- c:\users\dominik\AppData\Local\Apple
2012-02-01 14:42 . 2012-02-01 14:42 -------- d-----w- c:\program files\Apple Software Update
2012-02-01 14:42 . 2012-02-01 14:44 -------- d-----w- c:\program files\Common Files\Apple
2012-02-01 14:42 . 2012-02-01 14:42 -------- d-----w- c:\programdata\Apple
2012-01-31 17:34 . 2012-01-31 17:34 -------- d-----w- c:\windows\system32\backup
2012-01-31 17:24 . 2012-01-18 14:47 354416 ----a-w- c:\windows\system32\vmnetdhcp.exe
2012-01-31 17:24 . 2012-01-18 14:47 433264 ----a-w- c:\windows\system32\vmnat.exe
2012-01-31 17:24 . 2012-01-18 14:46 25712 ----a-w- c:\windows\system32\drivers\vmnetuserif.sys
2012-01-31 17:24 . 2012-01-18 14:47 783472 ----a-w- c:\windows\system32\vnetlib.dll
2012-01-31 17:22 . 2012-01-31 17:22 -------- d-----w- c:\program files\VMware
2012-01-31 17:22 . 2012-01-31 17:22 -------- d-----w- c:\program files\Common Files\VMware
2012-01-31 12:43 . 2011-11-17 05:41 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-01-31 12:43 . 2011-11-17 05:34 224768 ----a-w- c:\windows\system32\schannel.dll
2012-01-31 12:43 . 2011-11-17 05:41 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-01-31 12:43 . 2011-11-17 05:39 369352 ----a-w- c:\windows\system32\drivers\cng.sys
2012-01-31 12:43 . 2011-11-17 05:35 314880 ----a-w- c:\windows\system32\webio.dll
2012-01-31 12:43 . 2011-11-17 05:34 15872 ----a-w- c:\windows\system32\sspisrv.dll
2012-01-31 12:43 . 2011-11-17 05:34 100352 ----a-w- c:\windows\system32\sspicli.dll
2012-01-31 12:43 . 2011-11-17 05:34 22016 ----a-w- c:\windows\system32\secur32.dll
2012-01-31 12:43 . 2011-11-17 05:32 1038848 ----a-w- c:\windows\system32\lsasrv.dll
2012-01-31 12:43 . 2011-11-17 05:29 22528 ----a-w- c:\windows\system32\lsass.exe
2012-01-30 06:40 . 2012-01-30 06:40 -------- d-----w- c:\users\dominik\AppData\Roaming\Malwarebytes
2012-01-30 06:40 . 2012-01-30 06:40 -------- d-----w- c:\programdata\Malwarebytes
2012-01-29 07:17 . 2012-01-29 07:17 -------- d-----w- c:\users\dominik\AppData\Roaming\BANDISOFT
2012-01-29 07:15 . 2012-01-29 07:15 -------- d-----w- c:\program files\Bandicam
2012-01-29 07:15 . 2012-01-29 07:15 -------- d-----w- c:\program files\BandiMPEG1
2012-01-29 06:13 . 2012-01-29 06:27 -------- d-----w- c:\users\dominik\AppData\Roaming\Notepad++
2012-01-29 06:13 . 2012-01-29 06:13 -------- d-----w- c:\program files\Notepad++
2012-01-29 04:48 . 2012-01-29 04:48 -------- d-----w- c:\users\dominik\AppData\Roaming\fltk.org
2012-01-29 04:48 . 2012-01-29 04:48 -------- d-----w- c:\programdata\fltk.org
2012-01-28 19:17 . 2012-01-28 19:17 -------- d-----w- C:\Python27
2012-01-28 12:16 . 2012-01-28 12:16 -------- d-----w- c:\users\dominik\AppData\Local\GHISLER
2012-01-27 16:54 . 2012-01-27 16:56 -------- d-----w- c:\users\dominik\AppData\Roaming\GHISLER
2012-01-27 16:54 . 2012-01-27 16:55 -------- d-----w- C:\totalcmd
2012-01-27 16:54 . 2010-12-17 06:56 545 ----a-w- c:\windows\UC.PIF
2012-01-27 16:54 . 2010-12-17 06:56 545 ----a-w- c:\windows\RAR.PIF
2012-01-27 16:54 . 2010-12-17 06:56 545 ----a-w- c:\windows\NOCLOSE.PIF
2012-01-27 16:54 . 2010-12-17 06:56 545 ----a-w- c:\windows\LHA.PIF
2012-01-27 16:54 . 2010-12-17 06:56 545 ----a-w- c:\windows\ARJ.PIF
2012-01-25 05:25 . 2012-01-25 05:25 -------- d-----w- c:\program files\PIC Corporation
2012-01-25 05:21 . 2012-01-25 05:21 -------- d-----w- c:\users\dominik\AppData\Roaming\Gretech
2012-01-25 05:21 . 2012-01-25 05:21 -------- d-----w- c:\program files\CoreAAC
2012-01-25 05:20 . 2012-01-25 05:20 -------- d-----w- c:\programdata\GRETECH
2012-01-25 05:20 . 2012-01-25 05:20 -------- d-----w- c:\program files\GRETECH
2012-01-24 14:54 . 2012-01-24 14:54 -------- d-----w- c:\program files\Common Files\Java
2012-01-24 14:53 . 2012-01-24 14:53 637848 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-01-21 13:37 . 2012-01-21 13:37 -------- d-----w- c:\program files\Cepstral
2012-01-19 14:21 . 2012-01-19 14:21 -------- d-----w- c:\users\dominik\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
2012-01-19 14:21 . 2012-01-19 14:21 -------- d-----w- c:\program files\Common Files\Adobe AIR
2012-01-19 13:32 . 2012-01-19 13:32 -------- d-----w- c:\users\dominik\AppData\Roaming\NVIDIA
2012-01-18 19:03 . 2012-01-18 19:03 -------- d-----w- c:\program files\AmIcoSingLun
2012-01-18 19:03 . 2012-01-18 19:03 -------- d-----w- c:\programdata\AmUStor
2012-01-18 18:57 . 2011-10-15 08:53 919872 ----a-w- c:\windows\system32\nvdispco32.dll
2012-01-18 18:57 . 2011-10-15 08:53 877376 ----a-w- c:\windows\system32\nvgenco32.dll
2012-01-18 18:57 . 2011-10-15 08:53 61248 ----a-w- c:\windows\system32\OpenCL.dll
2012-01-18 18:57 . 2011-10-15 08:53 5578560 ----a-w- c:\windows\system32\nvcuda.dll
2012-01-18 18:57 . 2011-10-15 08:53 2401088 ----a-w- c:\windows\system32\nvcuvid.dll
2012-01-18 18:57 . 2011-10-15 08:53 2099520 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-01-18 18:57 . 2011-10-15 08:53 18871616 ----a-w- c:\windows\system32\nvoglv32.dll
2012-01-18 18:57 . 2011-10-15 08:53 17248576 ----a-w- c:\windows\system32\nvcompiler.dll
2012-01-18 18:57 . 2011-10-15 08:53 13205312 ----a-w- c:\windows\system32\nvd3dum.dll
2012-01-18 18:57 . 2011-10-15 08:53 10327360 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2012-01-18 18:50 . 2012-01-18 18:54 -------- d-----w- C:\NVIDIA
2012-01-18 18:47 . 2012-01-18 18:47 -------- d-----w- c:\windows\system32\RTCOM
2012-01-18 18:22 . 2012-01-18 18:43 -------- d-----w- c:\programdata\DriverGenius
2012-01-18 18:21 . 2012-01-18 18:21 -------- d-----w- c:\program files\Driver-Soft
2012-01-18 14:47 . 2012-01-18 14:47 55664 ----a-w- c:\windows\system32\drivers\vmx86.sys
2012-01-18 14:47 . 2012-01-18 14:47 23792 ----a-w- c:\windows\system32\drivers\vmparport.sys
2012-01-18 12:41 . 2012-01-18 12:41 252016 ----a-w- c:\windows\system32\vmnc.dll
2012-01-18 12:06 . 2012-01-18 12:06 55408 ----a-w- c:\windows\system32\vmnetbridge.dll
2012-01-18 12:06 . 2012-01-18 12:06 49776 ----a-w- c:\windows\system32\vnetinst.dll
2012-01-18 12:06 . 2012-01-18 12:06 36464 ----a-w- c:\windows\system32\drivers\vmnetbridge.sys
2012-01-18 12:06 . 2012-01-18 12:06 19568 ----a-w- c:\windows\system32\drivers\vmnet.sys
2012-01-18 12:06 . 2012-01-18 12:06 16624 ----a-w- c:\windows\system32\drivers\vmnetadapter.sys
2012-01-17 17:10 . 2012-01-17 17:10 -------- d-----w- c:\users\dominik\AppData\Local\ProphetX
2012-01-17 17:04 . 2011-11-24 09:48 1589248 ----a-w- c:\windows\system32\libmysql_d.dll
2012-01-17 17:03 . 2012-01-17 17:03 -------- d-----w- c:\program files\PremiumSoft
2012-01-14 13:08 . 2012-01-14 13:10 -------- d-----w- C:\Downloads
2012-01-11 05:23 . 2011-11-19 14:01 67072 ----a-w- c:\windows\system32\packager.dll
2012-01-11 05:23 . 2011-11-17 05:38 1288472 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 05:23 . 2011-10-26 04:32 514560 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 05:23 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\system32\quartz.dll
2012-01-10 19:27 . 2012-01-31 17:36 -------- d-----w- c:\users\dominik\AppData\Local\VMware
2012-01-10 19:27 . 2012-01-31 17:35 -------- d-----w- c:\users\dominik\AppData\Roaming\VMware
2012-01-10 19:10 . 2012-02-08 10:38 -------- d-----w- c:\programdata\VMware
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-24 14:53 . 2011-10-22 16:06 567184 ----a-w- c:\windows\system32\deployJava1.dll
2012-01-24 12:59 . 2011-10-23 12:23 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-13 18:31 . 2011-10-24 16:30 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2011-12-13 18:31 . 2011-10-24 15:22 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2011-12-11 15:34 . 2009-07-13 23:40 249856 ----a-w- c:\windows\system32\uxtheme.dll
2011-12-11 15:15 . 2011-10-22 14:47 2755072 ----a-w- c:\windows\system32\themeui.dll
2011-12-11 15:15 . 2009-07-13 23:39 37376 ----a-w- c:\windows\system32\themeservice.dll
2011-12-10 09:42 . 2011-12-10 09:42 284672 ----a-w- c:\windows\7za.dll
2011-12-01 15:11 . 2011-12-01 15:11 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2011-11-26 22:40 . 2011-11-25 17:00 2478272 ----a-w- c:\programdata\Microsoft\VisualStudio\10.0\1033\ResourceCache.dll
2011-11-24 04:25 . 2011-12-15 04:39 2342912 ----a-w- c:\windows\system32\win32k.sys
2011-11-17 05:34 . 2012-01-31 12:43 224768 ----a-w- c:\windows\system32\schannel.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2011-02-26 . 255CF508D7CFB10E0794D6AC93280BD8 . 2614784 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[7] 2011-02-26 . 2AF58D15EDC06EC6FDACCE1F19482BBF . 2614784 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[7] 2011-02-26 . 0FB9C74046656D1579A64660AD67B746 . 2616320 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[-] 2011-02-25 . 6FD4F71F59268E729829CFB099F42C11 . 2616320 . . [6.1.7600.16385] . . c:\windows\explorer.exe
[7] 2011-02-25 . 8B88EBBB05A0E56B7DCC708498C02B3E . 2616320 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[7] 2010-11-20 . 40D777B7A95E00593EB1568C68514493 . 2616320 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[7] 2009-10-31 . C76153C7ECA00FA852BB0C193378F917 . 2614272 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe
[7] 2009-10-31 . 2626FC9755BE22F805D3CFA0CE3EE727 . 2614272 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[7] 2009-08-03 . 9FF6C4C91A3711C0A3B18F87B08B518D . 2613248 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[7] 2009-08-03 . B95EEB0F4E5EFBF1038A35B3351CF047 . 2613248 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[7] 2009-07-14 . 15BC38A7492BEFE831966ADB477CF76F . 2613248 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-09-06 20:45 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-08-02 4910912]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-09-06 3722416]
"BigDog305"="c:\windows\VM305_STI.EXE" [2005-08-05 61440]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigDog305]
2005-08-05 20:15 61440 ----a-w- c:\windows\VM305_STI.EXE
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 VMwareHostd;VMware Workstation Server;c:\program files\VMware\VMware Workstation\vmware-hostd.exe [2012-01-18 11839488]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 VSPerfDrv100;Performance Tools Driver 10.0;c:\program files\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\VSPerfDrv100.sys [2009-12-08 48128]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2011-10-22 1343400]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-23 47128]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 239336]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 366936]
R4 TunngleService;TunngleService;c:\program files\Tunngle\TnglCtrl.exe [2011-10-14 745832]
S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys [2011-08-08 98928]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-10-23 232512]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2011-10-03 158512]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2011-10-03 91440]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-09-06 54616]
S2 Cepstral License Server;Cepstral License Server;c:\program files\Cepstral\bin\CepstralLicSrv.exe [2008-06-24 57344]
S2 Dyyno Launcher;Dyyno Service;c:\program files\Dyyno\Dyyno Broadcaster\launcherd.exe [2011-01-15 415072]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
S2 PDFSFilter;PDFSFilter;c:\windows\system32\DRIVERS\PDFsFilter.sys [2011-06-30 66320]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-14 381248]
S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-08-30 2358656]
S2 TeamViewer7;TeamViewer 7;c:\program files\TeamViewer\Version7\TeamViewer_Service.exe [2011-12-14 2984832]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files\Common Files\VMware\USB\vmware-usbarbitrator.exe [2011-08-29 665200]
S2 vstor2-mntapi10-shared;Vstor2 MntApi 1.0 Driver (shared);c:\windows\system32\drivers\vstor2-mntapi10-shared.sys [2011-07-08 22768]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2011-10-03 104752]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2011-10-03 116016]
S3 ZSMC0305;A4 TECH PC Camera V;c:\windows\system32\Drivers\usbVM305.sys [2006-05-08 391688]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3678732471-1654464958-2998469604-1000Core.job
- c:\users\dominik\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-28 18:03]
.
2012-02-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3678732471-1654464958-2998469604-1000UA.job
- c:\users\dominik\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-28 18:03]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
mStart Page = hxxp://www.bigseekpro.com/lionskin/{236A6501-E ... A8C199317F}
uInternet Settings,ProxyOverride = *.local
LSP: %SystemRoot%\system32\vsocklib.dll
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-3678732471-1654464958-2998469604-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-02-08 12:26:26
ComboFix-quarantined-files.txt 2012-02-08 11:26
ComboFix2.txt 2012-02-06 19:50
ComboFix3.txt 2012-02-06 17:12
.
Pre-Run: Volných bajtů: 24 731 099 136
Post-Run: Volných bajtů: 24 691 777 536
.
- - End Of File - - 8FF56AA59A0D2965796E47431965E6FE
Upload was successful

Výkon procesora sa ustálil
Môj email:StigFird@hotmail.com
DoporučujemObrázek____Obrázek____Obrázek____Obrázek
Nepodporujem!!!:Obrázek

StigFird
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 17 črc 2011 11:59

Re: Anormné vyťažovanie Procesora

#8 Příspěvek od StigFird »

Je vidieť že to nebolo vírusom v núdzovom režime mi to tak isto bralo ale aj tak ďakujem za pomoc
Môj email:StigFird@hotmail.com
DoporučujemObrázek____Obrázek____Obrázek____Obrázek
Nepodporujem!!!:Obrázek

Odpovědět