po par desitkach minut nefunkcnost internetu a firewalu?

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zamčeno
Zpráva
Autor
dyx
Návštěvník
Návštěvník
Příspěvky: 1
Registrován: 04 Dub 2013 21:50

po par desitkach minut nefunkcnost internetu a firewalu?

#1 Příspěvek od dyx »

Omlouvam se predem za formalni chyby v prvnim prispevku.
Stava se mi posledni dobou ze z niceho nic ze mi po par desitkach minut prestane fungovat internet a zaroven integrovany firewall XP.
Mam trochu podezreni na nejaky konflikt mezi antivirem a antispywarem, popripade skutecnym virem ktery mi neodhali MS Essentials..
Prikladam log z Combofixu vytvoreny po autom.restartu, je na vystupu logu neco podezreleho na co bych se mel zamerit?

predem moc diky
-------------------

ComboFix 13-04-04.01 - ag 04.04.2013 22:29:57.2.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.420.1033.18.3071.2231 [GMT 2:00]
Spuštěný z: c:\documents and settings\ag\Local Settings\Application Data\Opera\Opera 10 Beta\temporary_downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\1359234239.bdinstall.bin
c:\documents and settings\All Users\Application Data\1359234488.bdinstall.bin
c:\documents and settings\All Users\Application Data\1359234539.bdinstall.bin
c:\documents and settings\All Users\Application Data\1359236305.bdinstall.bin
c:\documents and settings\All Users\Application Data\1360516053.bdinstall.bin
c:\documents and settings\All Users\Application Data\1360516054.bdinstall.bin
c:\documents and settings\All Users\Application Data\1360516385.bdinstall.bin
c:\documents and settings\All Users\Application Data\TEMP
c:\program files\Downloaded Installers
c:\program files\Downloaded Installers\{0BEB28E4-E5EA-40DE-8982-1F13005DC08B}\setup.msi
c:\windows\system32\Cache
c:\windows\system32\Cache\26c630d098e22dd5.fb
c:\windows\system32\Cache\272512937d9e61a4.fb
c:\windows\system32\Cache\287204568329e189.fb
c:\windows\system32\Cache\28bc8f716fd76a47.fb
c:\windows\system32\Cache\31a0997e9a5b5eb3.fb
c:\windows\system32\Cache\32c84fe32bb74d60.fb
c:\windows\system32\Cache\3917078cb68ec657.fb
c:\windows\system32\Cache\4145068b443ae4bc.fb
c:\windows\system32\Cache\590ba23ce359fd0c.fb
c:\windows\system32\Cache\610289e025a3ee9a.fb
c:\windows\system32\Cache\651c5d3cdbfb8bd1.fb
c:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb
c:\windows\system32\Cache\6d03dad1035885d3.fb
c:\windows\system32\Cache\77eb015fbe336662.fb
c:\windows\system32\Cache\8c12dc3b048d25e7.fb
c:\windows\system32\Cache\95f567698be8a182.fb
c:\windows\system32\Cache\a8556537add6dfc5.fb
c:\windows\system32\Cache\ad10a52aff5e038d.fb
c:\windows\system32\Cache\c1fa887b03019701.fb
c:\windows\system32\Cache\c4d28dca2e7648be.fb
c:\windows\system32\Cache\d201ef9910cd39de.fb
c:\windows\system32\Cache\d2e94710a5708128.fb
c:\windows\system32\Cache\d79b9dfe81484ec4.fb
c:\windows\system32\Cache\f998975c9cc711ee.fb
c:\windows\system32\Cache\f9c986d105020258.fb
c:\windows\system32\SET118.tmp
c:\windows\system32\SET11A.tmp
c:\windows\system32\w32apiw.dll
.
---- Předchozí spuštění -------
.
c:\documents and settings\ag\Application Data\.#
c:\documents and settings\ag\Application Data\.#\MBX@F5C@3F37C8.###
c:\documents and settings\ag\Application Data\.#\MBX@F5C@3F37D8.###
c:\documents and settings\ag\Application Data\.#\MBX@F5C@3F37E8.###
c:\documents and settings\ag\Application Data\langInstall.exe
c:\documents and settings\ag\Application Data\PriceGong
c:\documents and settings\ag\Application Data\setup.exe
c:\documents and settings\ag\System
c:\documents and settings\ag\System\win_qs8.jqx
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\{E3739848-5329-48E3-8D28-5BBD6E8BE384}\PostBuild.exe
c:\documents and settings\All Users\Application Data\TEMP\07BF512B.TMP
c:\windows\d.ini
c:\windows\iun6002.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\_000004_.tmp.dll
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\AF15BDAEX.dll
c:\windows\system32\muzapp.exe
c:\windows\system32\System32\MASetupCleaner.exe
c:\windows\system32\System32\muzapp.exe
c:\windows\system32\UNWISE.EXE
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\wininit.ini
c:\windows\XSxS
E:\explorer.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_PASSWORD
-------\Legacy_NPF
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-03-04 do 2013-04-04 )))))))))))))))))))))))))))))))
.
.
2013-04-04 20:10 . 2013-03-15 07:21 7108640 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{005AFE00-1F02-423B-B4F3-88BDD84F23F4}\mpengine.dll
2013-04-03 19:08 . 2013-03-15 07:21 7108640 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-03-31 21:13 . 2013-04-01 21:31 -------- d-----w- c:\documents and settings\ag\Application Data\vlc
2013-03-31 21:08 . 2013-03-31 21:08 -------- d-----w- c:\documents and settings\ag\Local Settings\Application Data\Graboid Inc
2013-03-31 21:08 . 2013-03-31 21:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Graboid Inc
2013-03-31 21:08 . 2013-03-31 21:08 -------- d-----w- c:\documents and settings\ag\Local Settings\Application Data\Graboid
2013-03-31 21:08 . 2013-03-31 21:08 -------- d-----w- c:\documents and settings\ag\Local Settings\Application Data\Geckofx
2013-03-31 21:06 . 2013-03-31 21:07 -------- d-----w- c:\program files\Graboid
2013-03-31 21:06 . 2013-04-01 07:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Package Cache
2013-03-31 20:59 . 2013-03-31 20:59 -------- d-----w- c:\program files\VirusTotalUploader2
2013-03-31 14:18 . 2013-03-31 14:18 -------- d-----w- c:\program files\SubDownloader2
2013-03-31 14:10 . 2013-03-31 14:10 -------- d-----w- c:\documents and settings\ag\Local Settings\Application Data\SublightCache
2013-03-31 14:02 . 2013-03-31 14:02 -------- d-----w- c:\documents and settings\ag\Local Settings\Application Data\IsolatedStorage
2013-03-31 14:01 . 2013-03-31 14:01 -------- d-----w- c:\documents and settings\ag\Local Settings\Application Data\Sublight_Labs
2013-03-31 14:01 . 2013-03-31 14:01 -------- d-----w- c:\program files\Sublight
2013-03-31 11:44 . 2013-03-31 11:44 -------- d-----w- c:\documents and settings\LocalService\Application Data\Samsung
2013-03-31 11:44 . 2013-03-31 11:44 -------- d-----w- C:\Download
2013-03-31 11:44 . 2013-03-31 11:44 -------- d-----w- C:\AllShare
2013-03-30 12:45 . 2013-03-30 12:45 -------- d-----w- c:\documents and settings\ag\Application Data\NVIDIA 3D Vision Video Player
2013-03-24 23:42 . 2013-03-24 23:43 -------- d-----w- c:\program files\Kindle Auto eBook Converter
2013-03-24 03:22 . 2013-03-24 03:22 -------- d-----w- c:\windows\system32\Hotspot Shield
2013-03-23 18:16 . 2013-03-23 19:41 -------- d-----w- c:\documents and settings\ag\Application Data\TeamViewer
2013-03-23 14:20 . 2013-03-23 14:20 -------- d-----w- c:\program files\Common Files\Skype
2013-03-23 14:12 . 2013-03-26 23:00 -------- d-----w- c:\documents and settings\ag\Application Data\Mp3tag
2013-03-23 14:11 . 2013-03-23 14:11 -------- d-----w- c:\program files\Mp3tag
2013-03-22 19:04 . 2013-02-08 08:10 19448 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\TeamViewer_PrintProcessor.dll
2013-03-22 19:04 . 2013-03-22 19:04 -------- d-----w- c:\program files\TeamViewer
2013-03-20 20:02 . 2013-04-04 20:15 -------- d-----w- c:\windows\system32\CatRoot2
2013-03-20 19:58 . 2013-03-24 13:36 -------- d-----w- c:\windows\system32\wbem\Repository
2013-03-17 16:24 . 2013-03-17 16:24 -------- d-----w- c:\documents and settings\ag\Application Data\nCleaner
2013-03-17 16:24 . 2013-03-17 16:24 -------- d-----w- c:\program files\NKProds
2013-03-14 21:24 . 2013-03-14 21:24 -------- d-----w- c:\windows\system32\winrm
2013-03-14 21:24 . 2013-03-14 21:24 -------- dc-h--w- c:\windows\$968930Uinstall_KB968930$
2013-03-13 21:04 . 2013-03-15 08:00 -------- d-----w- c:\program files\Mozilla Thunderbird
2013-03-08 19:43 . 2013-03-08 19:43 21664 ----a-w- c:\windows\system32\drivers\HWiNFO32.SYS
2013-03-08 19:43 . 2013-03-08 19:43 -------- d-----w- c:\program files\HWiNFO32
2013-03-08 07:19 . 2013-03-08 07:19 143872 ----a-w- c:\windows\system32\javacpl.cpl
2013-03-08 07:19 . 2013-03-08 07:19 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-02 10:33 . 2009-12-05 16:03 237088 ------w- c:\windows\system32\MpSigStub.exe
2013-03-20 19:59 . 2013-02-16 12:21 47 ----a-w- C:\WorkstationProcessStart.bat
2013-03-14 23:44 . 2012-04-02 08:16 693976 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-14 23:44 . 2011-05-17 19:26 73432 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-08 07:19 . 2012-04-07 18:48 861088 ----a-w- c:\windows\system32\npdeployJava1.dll
2013-03-08 07:19 . 2010-05-08 17:35 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-03-04 19:58 . 2013-01-09 18:21 13024 ----a-w- c:\windows\system32\drivers\SWDUMon.sys
2013-02-24 20:18 . 2008-04-14 12:00 361600 ----a-w- c:\windows\system32\drivers\TCPIP.SYS
2013-02-24 17:15 . 2013-02-10 17:27 181064 ----a-w- c:\windows\PSEXESVC.EXE
2013-02-24 12:34 . 2013-02-24 12:34 361600 ----a-w- c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL
2013-02-16 07:04 . 2013-02-16 07:02 18158315 ----a-w- c:\documents and settings\ag\Local Settings\Application Data\OcrMap.bin
2013-02-12 00:32 . 2009-03-29 15:45 12928 ----a-w- c:\windows\system32\drivers\usb8023x.sys
2013-02-12 00:32 . 2008-04-14 12:00 12928 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-02-05 20:05 . 2008-04-14 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2013-02-05 20:05 . 2008-04-14 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2013-02-05 20:05 . 2008-04-14 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2013-02-05 05:53 . 2008-04-14 12:00 385024 ----a-w- c:\windows\system32\html.iec
2013-01-26 03:55 . 2008-04-14 12:00 552448 ----a-w- c:\windows\system32\oleaut32.dll
2013-01-20 14:59 . 2012-08-30 21:03 195296 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2013-01-19 23:55 . 2010-07-24 19:39 429056 ----a-w- c:\windows\system32\MACDll.dll
2013-01-17 07:38 . 2013-01-21 22:03 121600 ----a-w- c:\windows\system32\drivers\WinisoCDBus.sys
2013-01-15 17:49 . 2013-02-15 23:04 23360 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2013-01-14 23:25 . 2013-01-14 23:25 3014496 ----a-w- c:\windows\system32\AutoPartNt.exe
2013-01-14 23:22 . 2013-01-14 23:22 177568 ----a-w- c:\windows\system32\drivers\snapman.sys
2013-01-14 23:22 . 2013-01-14 23:22 80416 ----a-w- c:\windows\system32\drivers\fltsrv.sys
2013-01-07 01:19 . 2008-04-14 12:00 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-01-07 00:37 . 2008-04-14 00:01 2027520 ----a-w- c:\windows\system32\ntkrnlpa.exe
2008-03-09 05:25 . 2010-10-24 17:58 236 ----a-w- c:\program files\Common Files\dx.reg
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2012-12-17 18:50 556648 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2012-12-17 18:50 556648 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2012-12-17 18:50 556648 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2012-12-17 18:50 556648 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\HardLinkMenu]
@="{0A479751-02BC-11d3-A855-0004AC2568AA}"
[HKEY_CLASSES_ROOT\CLSID\{0A479751-02BC-11d3-A855-0004AC2568AA}]
2011-08-13 10:13 374984 ----a-w- c:\program files\LinkShellExtension\HardlinkShellExt.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IconOverlayHardLink]
@="{0A479751-02BC-11d3-A855-0004AC2568DD}"
[HKEY_CLASSES_ROOT\CLSID\{0A479751-02BC-11d3-A855-0004AC2568DD}]
2011-08-13 10:13 374984 ----a-w- c:\program files\LinkShellExtension\HardlinkShellExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 6"="c:\program files\IObit\Advanced SystemCare 6\ASCTray.exe" [2013-01-15 491840]
"RMClock"="c:\program files\RMClock\RMClockLauncher.exe" [2008-02-29 61440]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 947152]
"IObit Malware Fighter"="c:\program files\IObit\IObit Malware Fighter\IMF.exe" [2012-12-25 4474832]
"MSIAfterburner"="c:\program files\MSI AFTERBURNER\MSIAFTERBURNER.EXE" [2010-08-31 355640]
"Ai Nap"="c:\program files\asus\ai suite\ainap\ainap.exe" [2009-07-01 1435136]
"36X Raid Configurer"="c:\windows\system32\xraidsetup.exe" [2000-01-01 1976920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2011-07-27 434080]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DocAction (Plustek OpticBook 4600).lnk]
path=c:\documents and settings\ag\Start Menu\Programs\SYSTEM\Plustek OpticBook 4600 V4.0.2.3\DocAction (Plustek OpticBook 4600).lnk
backup=c:\windows\pss\DocAction (Plustek OpticBook 4600).lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Update Checker]
2009-12-28 16:49 121472 ----a-w- c:\program files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bonus.SSR.FR11]
2011-08-31 10:22 925960 ----a-w- c:\program files\ABBYY FineReader 11\Bonus.ScreenshotReader.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Core Temp]
2012-10-14 20:21 763856 ----a-w- c:\program files\Core Temp\Core Temp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpu Level Up help]
2007-11-30 19:03 881152 ----a-w- c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EaseUS EPM tray]
2012-11-29 09:32 2086984 ----a-w- c:\program files\EASEUS\EaseUS Partition Master 9.2.1 Home Edition\bin\EpmNews.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-06-28 12:42 133104 ----atw- c:\documents and settings\ag\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X Configure]
2006-01-03 15:59 360448 ----a-w- c:\windows\system32\JMRaidTool.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
2000-01-01 00:00 19968 ------w- c:\windows\LOGI_MWX.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSIAfterburner]
2010-08-31 03:04 355640 ----a-w- c:\program files\MSI Afterburner\MSIAfterburner.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2012-12-29 10:31 1982312 ----a-w- c:\program files\NVIDIA Corporation\nView\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RMClock]
2008-02-29 17:26 61440 ----a-w- c:\program files\RMClock\RMClockLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartRAM]
2013-01-15 17:48 547648 ----a-w- c:\program files\IObit\Advanced SystemCare 6\Suo10_SmartRAM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2005-08-21 15:16 847872 ----a-w- c:\program files\Analog Devices\Core\smax4pnp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-07-03 08:04 252848 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-01-26 00:06 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
2010-07-04 19:51 17408 ----a-w- c:\program files\Unlocker\UnlockerAssistant.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2013-03-23 20:14 984408 ----a-w- c:\documents and settings\ag\Application Data\uTorrent\uTorrent.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\ag\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Microsoft Security Client\\msseces.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\Program Files\\DreamCom\\DreamCom.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Opera 10 Beta\\opera.exe"=
"c:\\Program Files\\Java\\jre7\\bin\\javaw.exe"=
"c:\\Documents and Settings\\ag\\Application Data\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Dude\\dude.exe"=
"c:\\Program Files\\ZyXEL\\NSU\\NSU.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 eBoost;eBoostr caching filter driver;c:\windows\system32\drivers\eBoost.sys [15.4.2010 15:58 150616]
R0 fltsrv;Acronis Storage Filter Management;c:\windows\system32\drivers\fltsrv.sys [15.1.2013 1:22 80416]
R0 FSProFilter;FSPro File Filter;c:\windows\system32\drivers\FSPFltd.sys [22.12.2012 17:28 41912]
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [3.3.2013 21:11 14776]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [18.11.2009 20:26 691696]
R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [6.11.2010 23:15 11448]
R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [1.6.2010 19:00 15464]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [4.6.2010 11:55 229312]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [1.6.2010 19:00 25240]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO32.SYS [8.3.2013 21:43 21664]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [17.2.2010 20:25 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10.5.2010 20:41 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [29.6.2010 19:48 116608]
R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [6.12.2007 22:03 660768]
R2 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\program files\IObit\Advanced SystemCare 6\ASCService.exe [16.2.2013 0:52 465216]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [1.2.2009 2:19 38144]
R2 hshld;Hotspot Shield Service;c:\program files\Hotspot Shield\bin\openvpnas.exe [13.7.2012 2:52 471408]
R2 IMFservice;IMF Service;c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe [3.3.2013 21:11 821592]
R2 NSHE;Guardant Emulator Driver;c:\windows\system32\drivers\NSHE.SYS [12.9.2010 11:47 97792]
R2 Printer Control;Printer Control;c:\windows\system32\PrintCtrl.exe [19.12.2009 21:36 77824]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [11.2.2010 23:20 14976]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [28.2.2013 20:25 161384]
R2 TeamViewer8;TeamViewer 8;c:\program files\TeamViewer\Version8\TeamViewer_Service.exe [22.3.2013 21:04 3560288]
R2 WinFLdrv;WinFLdrv;c:\windows\system32\WinFLdrv.sys [26.11.2010 21:52 10752]
R2 WinisoCDBus;WinISO Virtual CD Drive;c:\windows\system32\drivers\WinisoCDBus.sys [22.1.2013 0:03 121600]
R3 AX88178;ASIX AX88178 USB2.0 to Gigabit Ethernet Adapter;c:\windows\system32\drivers\ax88178.sys [11.7.2012 12:11 39936]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [14.1.2012 17:35 80184]
R3 FileMonitor;FileMonitor;c:\program files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys [3.3.2013 21:11 246816]
R3 RegFilter;RegFilter;c:\program files\IObit\IObit Malware Fighter\Drivers\wxp_x86\RegFilter.sys [3.3.2013 21:11 30408]
R3 RTCore32;RTCore32;c:\program files\MSI Afterburner\RTCore32.sys [31.8.2010 5:04 12088]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [14.1.2012 17:35 181432]
R3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [8.10.2005 12:00 22272]
R3 UrlFilter;UrlFilter;c:\program files\IObit\IObit Malware Fighter\Drivers\wxp_x86\UrlFilter.sys [3.3.2013 21:11 16248]
R3 VPPP;DrayTek Virtual PPP Adapter;c:\windows\system32\drivers\VPPP.sys [18.6.2008 10:09 32784]
S0 mgyww;mgyww;c:\windows\system32\drivers\wahrie.sys --> c:\windows\system32\drivers\wahrie.sys [?]
S1 archlp;archlp;c:\windows\system32\drivers\archlp.sys --> c:\windows\system32\drivers\archlp.sys [?]
S1 MpKsl37774952;MpKsl37774952;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{005AFE00-1F02-423B-B4F3-88BDD84F23F4}\MpKsl37774952.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{005AFE00-1F02-423B-B4F3-88BDD84F23F4}\MpKsl37774952.sys [?]
S2 Updater Service for StartNow Toolbar;Updater Service for StartNow Toolbar; [x]
S3 ALSysIO;ALSysIO;\??\c:\docume~1\ag\LOCALS~1\Temp\ALSysIO.sys --> c:\docume~1\ag\LOCALS~1\Temp\ALSysIO.sys [?]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys --> c:\windows\system32\drivers\dgderdrv.sys [?]
S3 emusba10;E-MU USB-Audio 1.0 Driver;c:\windows\system32\DRIVERS\emusba10.sys --> c:\windows\system32\DRIVERS\emusba10.sys [?]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [4.1.2013 20:43 13896]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [4.1.2013 20:43 9160]
S3 gupdate1c98c33c08f96ca;Google Update Service (gupdate1c98c33c08f96ca);c:\program files\Google\Update\GoogleUpdate.exe [11.2.2009 12:30 133104]
S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.12.2;c:\windows\system32\drivers\libusb0.sys [21.11.2009 0:32 28160]
S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [16.11.2010 2:10 267568]
S3 MEMSWEEP2;MEMSWEEP2; [x]
S3 NCHSSVAD;SoundTap Recorder;c:\windows\system32\drivers\nchssvad.sys [30.3.2009 0:29 27136]
S3 pneteth;PdaNet Broadband;c:\windows\system32\drivers\pneteth.sys [14.1.2012 18:13 13440]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [10.12.2008 16:17 7808]
S3 RoxMediaDB13;RoxMediaDB13;c:\program files\Common Files\Roxio Shared\13.0\SharedCOM\RoxMediaDB13.exe [16.7.2010 6:48 1099248]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [9.1.2013 11:13 332928]
S3 SjyPkt;SjyPkt;c:\windows\system32\drivers\SjyPkt.sys [16.1.2009 11:51 13532]
S3 SWDUMon;SWDUMon;c:\windows\system32\drivers\SWDUMon.sys [9.1.2013 20:21 13024]
S3 tap0801co;TAP-Win32 Adapter V8 (coLinux);c:\windows\system32\drivers\tap0801co.sys [8.3.2009 13:47 25856]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; [x]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [12.2.2010 21:34 99152]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys --> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [6.5.2008 16:06 11520]
S3 XENFilt;XENFilt;c:\windows\system32\drivers\XENFilt.sys --> c:\windows\system32\drivers\XENFilt.sys [?]
S4 ElcomSoftDistributedPasswordRecoveryServer;Elcomsoft Distributed Password Recovery Server; [x]
S4 IObitUnlocker;IObitUnlocker;c:\program files\IObit\IObit Unlocker\IObitUnlocker.sys [3.3.2013 21:45 27552]
S4 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files\Common Files\Roxio Shared\13.0\SharedCOM\RoxWatch13.exe [16.7.2010 6:48 354288]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
2008-04-14 12:00 73216 -c--a-w- c:\windows\system32\dllcache\setup50.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-03-13 20:13 1629648 ----a-w- c:\program files\Google\Chrome\Application\25.0.1364.172\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-04-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 23:44]
.
2013-04-04 c:\windows\Tasks\ASC6_PerformanceMonitor.job
- c:\program files\IObit\Advanced SystemCare 6\Monitor.exe [2013-02-15 17:47]
.
2013-02-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-11 10:30]
.
2013-02-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-11 10:30]
.
2013-04-04 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2013-01-27 10:11]
.
2013-04-04 c:\windows\Tasks\MpIdleTask.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2013-01-27 10:11]
.
2013-04-03 c:\windows\Tasks\SlimCleaner Scan.job
- c:\program files\SlimCleaner\SlimCleaner.exe [2012-12-12 14:49]
.
2013-04-04 c:\windows\Tasks\User_Feed_Synchronization-{FD1E72A2-3115-4258-9A80-62EE40A35792}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
2013-04-04 c:\windows\Tasks\WpsUpdateTask_ag.job
- c:\program files\Kingsoft\Kingsoft Office\office6\wpsupdate.exe [2011-11-03 16:00]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyServer = socks=
uInternet Settings,ProxyOverride = plimus.com,www.plimus.com,regnow.com,www.regnow.com,
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: {{328ECD19-C167-40eb-A0C7-16FE7634105F} - {CC68A724-B5F7-4bd3-865C-7D97141A140F} - c:\program files\FRITZ!Box\AddOn (IE)\FBoxIESplitButton.dll
TCP: DhcpNameServer = 10.89.1.2 10.89.1.3
TCP: Interfaces\{B312C3D8-01AB-4223-9374-639344F5847F}: NameServer = 156.154.70.22,156.154.71.22
TCP: Interfaces\{F0A93223-A564-4AAB-AA43-5D7B4B91595F}: NameServer = 156.154.70.22,156.154.71.22
DPF: {1384A8DE-7296-49DA-B7F8-8A9A5984BE52} - hxxp://178.217.146.85:122/AxRTSP.cab
DPF: {87D48502-D1FF-4D25-B66C-9DA4F7CB2722} - hxxp://178.217.146.85:123/classes/CamV_H264.cab
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
FF - ProfilePath - c:\documents and settings\ag\Application Data\Mozilla\Firefox\Profiles\kfv2z8at.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/
FF - ExtSQL: 2013-03-04 23:14; {c2921baa-9930-4d73-a203-f69db858f139}; c:\documents and settings\ag\Application Data\Mozilla\Firefox\Profiles\kfv2z8at.default\extensions\{c2921baa-9930-4d73-a203-f69db858f139}.xpi
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
WebBrowser-{081230F8-EA50-42A9-983C-D22ABC2EED3B} - (no file)
ShellExecuteHooks-{56F9679E-7826-4C84-81F3-532071A8BCC5} - (no file)
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
MSConfigStartUp-CTAPR2 - c:\program files\creative\sound blaster tactic(3d) alpha\sound blaster tactic(3d) control panel\ctapr2.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-04-04 22:40
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
.
c:\documents and settings\ag\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-19-2009 - 01-27-04.DSC 35 bytes
c:\documents and settings\ag\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-19-2009 - 01-27-04.SBU 69085 bytes
c:\documents and settings\ag\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-19-2009 - 08-34-55.DSC 35 bytes
c:\documents and settings\ag\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-19-2009 - 08-34-55.SBU 495 bytes
c:\documents and settings\ag\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-21-2009 - 13-39-31.DSC 35 bytes
c:\documents and settings\ag\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-21-2009 - 13-39-31.SBU 201504 bytes
c:\documents and settings\ag\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-08-2009 - 19-05-03.DSC 35 bytes
c:\documents and settings\ag\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-08-2009 - 19-05-03.SBU 495 bytes
c:\documents and settings\ag\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-18-2009 - 21-54-41.DSC 35 bytes
c:\documents and settings\ag\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 03-18-2009 - 21-54-41.SBU 1733 bytes
.
sken byl úspešně dokončen
skryté soubory: 10
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1123561945-789336058-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{060E4731-6323-8445-0C97-8684C70767C7}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-1123561945-789336058-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{96965077-46B7-BC7F-B2D7-7ADA6156B7A5}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"papfnmopikcnahenfmehnmndfcjegmop"=hex:61,62,69,6d,70,65,63,63,70,66,61,70,6b,
6d,6a,64,6a,6a,69,62,62,63,6e,6b,61,64,6c,6e,6b,6b,65,6c,6c,67,00,01
.
[HKEY_USERS\S-1-5-21-1123561945-789336058-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DC9F0E17-DF2C-2024-93FC-FE478F6FE0F2}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"palafndffocbbnookmjijjhnbcilhoie"=hex:61,62,69,6f,65,66,63,6e,68,62,63,68,62,
63,61,68,69,6b,6a,63,63,6e,6e,66,6d,65,68,6f,6f,65,65,6c,68,65,00,ff
"palpojogakigodkmnjjffbgoglbgiiif"=hex:61,62,69,6f,65,66,63,6e,68,62,63,68,62,
63,61,68,69,6b,6a,63,63,6e,66,6f,69,65,70,6f,6f,66,64,6a,69,68,00,00
.
[HKEY_USERS\S-1-5-21-1123561945-789336058-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E3DB0FD6-416D-66CF-93F3-59B77879A875}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(320)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
- - - - - - - > 'explorer.exe'(7188)
c:\windows\system32\WININET.dll
c:\program files\MSI AFTERBURNER\Bundle\OSDServer\RTSSHooks.dll
c:\program files\Google\Drive\googledrivesync32.dll
c:\program files\LinkShellExtension\HardlinkShellExt.dll
c:\program files\LinkShellExtension\RockallDLL.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\windows\ATKKBService.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\windows\system32\locator.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\MSI AFTERBURNER\Bundle\OSDServer\RTSS.exe
c:\windows\System32\wudfhost.exe
.
**************************************************************************
.
Celkový čas: 2013-04-04 22:42:56 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-04-04 20:42
.
Před spuštěním: 78754746368 bytes free
Po spuštění: 79059750912 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /TUTag=BK6EPH noguiboot
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional (TuneUp Backup)" /noexecute=optin /fastdetect /TUTag=BK6EPH-BAK
.
- - End Of File - - 5901949133FE798972673E24040420DC

Avatar uživatele
JaRon
Moderátor
Moderátor
Příspěvky: 15924
Registrován: 29 Bře 2005 13:39
Místo/Bydliště: BB-SK

Re: po par desitkach minut nefunkcnost internetu a firewalu?

#2 Příspěvek od JaRon »

ahoj,
na formalne chyby sa mozes vykaslat, ale svojvolne pouzivanie ComboFix-u moze narobit problemy OS ,,, :!:
1. vycisti PC s ADWCleanerom - volba delete
2. prescanuj PC s MBAM - kompletna kontrola - log vloz
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Zamčeno