Dobrý deň, poprosil by som o kontrolu logu (combofix) z dôvodu spomalenia pc. Ďakujem
ComboFix 14-05-19.01 - Marek 25.05.2014 17:22:47.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.1918.1004 [GMT 2:00]
Running from: c:\documents and settings\Marek\Desktop\ComboFix.exe
AV: ESET Endpoint Security 5.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: Eset Pesonálny Firewall *Disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Marek\WINDOWS
c:\windows\system32\MUI\041b\tourstart.exe
c:\windows\UA000106.DLL
E:\resycled
e:\resycled\boot.com
.
.
((((((((((((((((((((((((( Files Created from 2014-04-25 to 2014-05-25 )))))))))))))))))))))))))))))))
.
.
2014-05-25 13:14 . 2014-05-25 15:08 -------- d-----w- c:\windows\LastGood
2014-05-25 07:06 . 2014-05-25 07:06 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\COMODO
2014-05-18 16:10 . 2014-01-03 11:16 18776 ----a-w- c:\windows\system32\roboot.exe
2014-05-18 16:10 . 2014-05-18 16:10 -------- d-----w- c:\program files\RegClean Pro
2014-05-15 04:58 . 2014-05-15 04:58 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\COMODO
2014-05-14 21:42 . 2014-05-14 21:42 10594416 ----a-w- c:\program files\Mozilla Firefox\icudt52.dll
2014-05-14 21:42 . 2014-05-14 21:42 1266800 ----a-w- c:\program files\Mozilla Firefox\icuin52.dll
2014-05-14 21:42 . 2014-05-14 21:42 965232 ----a-w- c:\program files\Mozilla Firefox\icuuc52.dll
2014-04-26 16:47 . 2014-04-26 16:48 -------- d-----w- c:\documents and settings\Marek\Local Settings\Application Data\COMODO
2014-04-26 16:47 . 2014-04-26 16:47 48392 ----a-w- c:\windows\system32\certsentry.dll
2014-04-26 16:46 . 2014-04-26 16:46 -------- d-----w- c:\program files\Comodo
2014-04-26 16:42 . 2014-04-26 16:42 -------- d-----w- c:\documents and settings\All Users\Application Data\APN
2014-04-26 16:41 . 2014-04-26 16:41 -------- d-----w- c:\program files\FreeTime
2014-04-26 13:04 . 2014-04-26 13:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Big Fish
2014-04-26 13:04 . 2014-04-26 13:04 -------- d-----w- c:\program files\bfgclient
2014-04-26 13:03 . 2014-04-26 13:05 -------- d-----w- c:\documents and settings\All Users\Application Data\BigFishCache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-14 13:29 . 2013-03-20 21:25 692400 -c--a-w- c:\windows\system32\FlashPlayerApp.exe
2014-05-14 13:29 . 2011-12-08 21:40 70832 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2014-02-10 20922016]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"AtiPTA"="atiptaxx.exe" [2006-02-22 344064]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-12 16264192]
"egui"="c:\program files\ESET\ESET Endpoint Security\egui.exe" [2012-07-04 3154464]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2007-10-30 15360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-2-27 561213]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Hostia\\Local Settings\\Application Data\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\WINDOWS\\system32\\muzapp.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\TeamViewer\\Version9\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version9\\TeamViewer_Service.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [20.12.2010 20:16 691696]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [29.3.2012 12:03 123760]
R2 DragonUpdater;COMODO Dragon Update Service;c:\program files\Comodo\Dragon\dragon_updater.exe [8.3.2014 0:47 2135232]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Endpoint Security\ekrn.exe [4.7.2012 11:17 999704]
R2 TeamViewer9;TeamViewer 9;c:\program files\TeamViewer\Version9\TeamViewer_Service.exe [25.5.2014 14:54 5024576]
R4 35804691;35804691;c:\windows\system32\DRIVERS\35804691.sys --> c:\windows\system32\DRIVERS\35804691.sys [?]
S2 Skype C2C Service;Skype C2C Service;c:\documents and settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [9.10.2013 10:58 3275136]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [23.10.2013 9:15 172192]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [8.9.2013 12:45 84248]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys --> c:\windows\system32\drivers\dgderdrv.sys [?]
S3 ESHASRV;ESET SHA Service;c:\program files\ESET\ESET Endpoint Security\EShaSrv.exe [4.7.2012 11:18 183944]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [8.9.2013 12:45 181912]
S3 ssudserd;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.);c:\windows\system32\drivers\ssudserd.sys [8.9.2013 12:45 181912]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - 35804691
*NewlyCreated* - 35804692
*NewlyCreated* - SETUP_9.0.1.722_25.05.2014_15-54DRV
*NewlyCreated* - TEAMVIEWER9
.
Contents of the 'Scheduled Tasks' folder
.
2014-05-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-20 13:29]
.
2014-05-25 c:\windows\Tasks\RegClean Pro_DEFAULT.job
- c:\program files\RegClean Pro\RegCleanPro.exe [2014-05-18 11:16]
.
2014-05-21 c:\windows\Tasks\RegClean Pro_UPDATES.job
- c:\program files\RegClean Pro\RegCleanPro.exe [2014-05-18 11:16]
.
2014-05-25 c:\windows\Tasks\User_Feed_Synchronization-{86BD5A9D-EFD0-4EE3-AD7D-0D5174A92AD7}.job
- c:\windows\system32\msfeedssync.exe [2010-12-19 03:31]
.
2014-05-25 c:\windows\Tasks\User_Feed_Synchronization-{88A30878-9DB8-45DD-920B-696C8E86A209}.job
- c:\windows\system32\msfeedssync.exe [2010-12-19 03:31]
.
.
------- Supplementary Scan -------
.
uStart Page = my.daemon-search.com
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: DhcpNameServer = 192.168.0.1
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Marek\Application Data\Mozilla\Firefox\Profiles\j58y600f.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.sk
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: content.notify.ontimer - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.switch.threshold - 750000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-2kv4.8.442 - c:\windows\Radeon Omega Drivers v4.8.442
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-05-25 17:28
Windows 5.1.2600 Service Pack 3, v.5938 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(1172)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2014-05-25 17:30:38
ComboFix-quarantined-files.txt 2014-05-25 15:30
.
Pre-Run: 6 812 577 792 bytes free
Post-Run: 6 889 689 088 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 1113D403957FC2F04CF4EDACE69A93F8
8F558EB6672622401DA993E1E865C861
Prosím o kontrolu logu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Prosím o kontrolu logu
Naposledy upravil(a) vyosek dne 26 Kvě 2014 19:53, celkem upraveno 1 x.
Důvod: log odstranen z code
Důvod: log odstranen z code
Re: Prosím o kontrolu logu
Zdravim
Ohledne CF jsem Vam jiz psal v minulem tematu
Mala technicka, toto je domaci PC nebo nejake firemni??



Přispějete na provoz fóra?