Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
zdenek72
3. Stupeň Varování
Příspěvky: 103
Registrován: 09 úno 2010 15:18
Bydliště: Plzen, Czech Republic
Kontaktovat uživatele:

Re: Prosím o kontrolu

#16 Příspěvek od zdenek72 »

PC celkem klidné, jen mě nechtěl otevřít e mail :)

zdenek72
3. Stupeň Varování
Příspěvky: 103
Registrován: 09 úno 2010 15:18
Bydliště: Plzen, Czech Republic
Kontaktovat uživatele:

Re: Prosím o kontrolu

#17 Příspěvek od zdenek72 »

Logfile of random's system information tool 1.06 (written by random/random)
Run by zdenek at 2010-02-10 00:00:53
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 547 MB (9%) free of 6 GB
Total RAM: 511 MB (46% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 0:01:12, on 10.2.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\avast\aswUpdSv.exe
D:\avast\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpm.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
D:\avast\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\365dníNET\365dniNET.exe
D:\avast\ashMaiSv.exe
D:\avast\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\zdenek\Plocha\RSIT.exe
C:\Documents and Settings\zdenek\Plocha\zdenek.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.centrum.cz/?ms=ge
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://centrum.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SMSender.E.ToolbarsHelper - {24bcda96-8fcb-4d3b-0500-000000000004} - mscoree.dll (file missing)
O2 - BHO: (no name) - {53707962-6f74-2d53-2644-206d7942484f} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O3 - Toolbar: SMSender - {24BCDA96-8FCB-4D3B-0500-000000000003} - mscoree.dll (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [avast!] "D:\avast\ashDisp.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [365dni] C:\Program Files\365dníNET\365dniNET.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\PROGRA~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://D:\PROGRAMY\OFFICE\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Poslat jako MMS - res://C:\Program Files\O2\SMSender\SMSender.E.dll/1003
O8 - Extra context menu item: Poslat jako SMS - res://C:\Program Files\O2\SMSender\SMSender.E.dll/1001
O8 - Extra context menu item: Poslat MMS na - res://C:\Program Files\O2\SMSender\SMSender.E.dll/1002
O8 - Extra context menu item: Poslat SMS na - res://C:\Program Files\O2\SMSender\SMSender.E.dll/1000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Nastavení aplikace &Gears - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 0589278780
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\avast\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\avast\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\avast\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\avast\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate1ca2bc6187ee390) (gupdate1ca2bc6187ee390) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: KAV Monitor Service (KAVMonitorService) - Kaspersky Labs. - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpm.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 6854 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{24bcda96-8fcb-4d3b-0500-000000000004}]
SMSender.E.ToolbarsHelper - C:\WINDOWS\system32\mscoree.dll [2008-07-25 282112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6f74-2d53-2644-206d7942484f}]
D:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2005-05-31 853672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll [2008-02-22 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-01-29 279664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll [2010-01-04 812528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{24BCDA96-8FCB-4D3B-0500-000000000003} - SMSender - C:\WINDOWS\system32\mscoree.dll [2008-07-25 282112]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-01-29 279664]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast!"=D:\avast\ashDisp.exe [2009-11-25 81000]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]
"365dni"=C:\Program Files\365dníNET\365dniNET.exe [2007-01-06 753664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"undockwithoutlogon"=1
"ShutdownWithoutLogon"=1
"NoDispCPL"=0
"NoDispSettingsPage"=0
"NoDispScrSavPage"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0
"GreyMSIAds"=1
"HideClock"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveTypeAutoRun"=
"NoResolveTrack"=
"NoViewContextMenu"=
"NoFileAssociate"=
"NoFind"=
"NoRun"=
"NoClose"=
"StartMenuLogoff"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\filmy\WinDVD.exe"="D:\filmy\WinDVD.exe:*:Enabled:WinDVD"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"D:\hry\Vietcong Fist Alpha MP demo\vietcong.exe"="D:\hry\Vietcong Fist Alpha MP demo\vietcong.exe:*:Enabled:vietcong"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\ICQ7.0\ICQ.exe"="C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"C:\Program Files\ICQ7.0\aolload.exe"="C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"
"D:\Program Files\Skype\Phone\Skype.exe"="D:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.0\ICQ.exe"="C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"C:\Program Files\ICQ7.0\aolload.exe"="C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{60cad2d1-4c02-11dd-b514-00e07deb69fe}]
shell\autorun\command - F:\AutoTransfer.exe


======List of files/folders created in the last 1 months======

2010-02-10 00:00:53 ----DC---- C:\rsit
2010-02-09 21:18:11 ----D---- C:\Documents and Settings\zdenek\Data aplikací\Malwarebytes
2010-02-09 21:17:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-02-06 10:28:20 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-02-06 10:26:47 ----D---- C:\Program Files\Windows Media Connect 2
2010-02-02 10:26:19 ----D---- C:\WINDOWS\ie8updates
2010-02-02 10:15:17 ----HDC---- C:\WINDOWS\ie8
2010-01-29 19:08:31 ----D---- C:\Documents and Settings\zdenek\Data aplikací\Ashampoo
2010-01-25 10:53:39 ----D---- C:\Program Files\ICQ7.0
2010-01-22 02:32:59 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-01-21 12:14:02 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-01-17 14:34:56 ----D---- C:\Documents and Settings\All Users\Data aplikací\Kaspersky Lab Setup Files
2010-01-16 01:50:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\Macromedia
2010-01-16 01:49:43 ----D---- C:\Program Files\Common Files\Macromedia
2010-01-16 01:48:10 ----D---- C:\Program Files\Common Files\InstallShield
2010-01-16 01:46:28 ----D---- C:\WINDOWS\Downloaded Installations
2010-01-15 22:02:18 ----D---- C:\Program Files\Conduit
2010-01-13 15:42:27 ----A---- C:\WINDOWS\system32\oeminfo.ini
2010-01-13 14:41:30 ----D---- C:\Program Files\Glary Utilities
2010-01-13 09:09:53 ----DC---- C:\Zakazky
2010-01-13 09:08:42 ----DC---- C:\IDAPI
2010-01-12 22:42:27 ----A---- C:\WINDOWS\system32\vbCPUInf.dll
2010-01-12 22:34:35 ----D---- C:\WINDOWS\vbSkinner
2010-01-12 18:36:49 ----D---- C:\Program Files\Common Files\eBay
2010-01-11 20:16:33 ----D---- C:\Documents and Settings\zdenek\Data aplikací\GlarySoft

======List of files/folders modified in the last 1 months======

2010-02-09 23:58:17 ----D---- C:\Documents and Settings\zdenek\Data aplikací\365dni
2010-02-09 23:57:03 ----D---- C:\WINDOWS\Temp
2010-02-09 23:56:29 ----D---- C:\WINDOWS\Prefetch
2010-02-09 23:56:06 ----D---- C:\WINDOWS
2010-02-09 23:52:50 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-02-09 23:34:10 ----AC---- C:\WINDOWS\wincmd.ini
2010-02-09 22:03:35 ----D---- C:\WINDOWS\system32\drivers
2010-02-09 22:02:22 ----D---- C:\WINDOWS\system32
2010-02-09 22:02:22 ----D---- C:\Program Files
2010-02-09 20:59:28 ----SD---- C:\WINDOWS\Tasks
2010-02-07 22:31:17 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-07 22:23:28 ----D---- C:\Documents and Settings\zdenek\Data aplikací\Skype
2010-02-07 17:18:58 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-06 10:30:30 ----HD---- C:\WINDOWS\inf
2010-02-06 10:30:26 ----D---- C:\WINDOWS\system32\CatRoot
2010-02-06 10:27:16 ----D---- C:\Program Files\Windows Media Player
2010-02-06 10:26:33 ----D---- C:\WINDOWS\Help
2010-02-06 10:25:30 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-02-05 15:12:40 ----D---- C:\WINDOWS\Debug
2010-02-03 23:46:13 ----D---- C:\Documents and Settings\zdenek\Data aplikací\gtk-2.0
2010-02-02 10:35:40 ----D---- C:\WINDOWS\system32\cs-cz
2010-02-02 10:35:37 ----D---- C:\WINDOWS\Media
2010-02-02 10:35:36 ----D---- C:\Program Files\Internet Explorer
2010-02-02 10:29:55 ----HD---- C:\WINDOWS\$hf_mig$
2010-02-02 10:18:26 ----RD---- C:\WINDOWS\Offline Web Pages
2010-01-29 23:04:07 ----D---- C:\Program Files\Rozpisy pro Šťastných10 (KENO10) - free verze
2010-01-29 04:46:47 ----RSD---- C:\WINDOWS\assembly
2010-01-29 04:46:45 ----SHD---- C:\WINDOWS\Installer
2010-01-29 04:46:45 ----HD---- C:\Config.Msi
2010-01-29 04:46:35 ----D---- C:\WINDOWS\Microsoft.NET
2010-01-29 04:46:21 ----D---- C:\WINDOWS\WinSxS
2010-01-29 04:07:28 ----D---- C:\Documents and Settings\zdenek\Data aplikací\Google
2010-01-29 01:30:41 ----D---- C:\Program Files\Google
2010-01-29 01:30:23 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
2010-01-28 17:31:21 ----D---- C:\Documents and Settings\zdenek\Data aplikací\Adobe
2010-01-28 15:12:45 ----D---- C:\Documents and Settings\zdenek\Data aplikací\ICQ
2010-01-25 10:55:08 ----HD---- C:\Program Files\InstallShield Installation Information
2010-01-22 02:33:04 ----D---- C:\Program Files\Common Files\Adobe
2010-01-21 09:57:37 ----SD---- C:\WINDOWS\system32\Microsoft
2010-01-16 02:09:42 ----D---- C:\Documents and Settings\zdenek\Data aplikací\Macromedia
2010-01-16 01:49:43 ----D---- C:\Program Files\Common Files
2010-01-14 08:54:39 ----D---- C:\Program Files\Seznam.cz
2010-01-13 18:05:11 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-01-13 15:27:45 ----D---- C:\Program Files\Codec Pack - All In 1
2010-01-13 10:44:04 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-01-13 09:08:45 ----A---- C:\WINDOWS\win.ini
2010-01-13 09:08:43 ----D---- C:\WINDOWS\system
2010-01-12 22:40:06 ----D---- C:\WINDOWS\system32\NtmsData
2010-01-12 22:29:58 ----RSD---- C:\WINDOWS\Fonts
2010-01-12 22:26:11 ----A---- C:\WINDOWS\iun6002.exe
2010-01-12 11:49:28 ----D---- C:\Program Files\TuneUp Utilities 2009
2010-01-12 11:49:28 ----D---- C:\Program Files\Mozilla Firefox
2010-01-12 11:49:27 ----D---- C:\Program Files\DivX
2010-01-12 11:49:27 ----D---- C:\Program Files\365dníNET
2010-01-12 11:49:22 ----D---- C:\Documents and Settings\All Users\Data aplikací\Yahoo! Companion
2010-01-12 11:49:22 ----D---- C:\Documents and Settings\All Users\Data aplikací\Lavasoft
2010-01-11 20:42:16 ----D---- C:\WINDOWS\system32\config
2010-01-11 19:23:51 ----D---- C:\Program Files\Opera

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 P3;Ovladač procesoru Intel PentiumIII; C:\WINDOWS\System32\DRIVERS\p3.sys [2004-08-17 46336]
R1 PQNTDrv;PQNTDrv; C:\WINDOWS\system32\drivers\PQNTDrv.sys [2001-08-10 3252]
R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2009-09-11 5632]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-11-25 94160]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
R3 ati2mtaa;ati2mtaa; C:\WINDOWS\System32\DRIVERS\ati2mtaa.sys [2001-09-26 285088]
R3 es1371;Creative AudioPCI (ES1371,ES1373) (WDM); C:\WINDOWS\system32\drivers\es1371mp.sys [2002-06-03 40832]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2001-10-25 9600]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S1 d53b8eac;d53b8eac; C:\WINDOWS\System32\drivers\d53b8eac.sys []
S3 ati2mpaa;ati2mpaa; C:\WINDOWS\System32\DRIVERS\ati2mpaa.sys [2001-10-24 281856]
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2004-06-21 51088]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2004-06-21 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2004-06-21 21744]
S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2001-10-25 5888]
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM); C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2007-05-02 83592]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter; C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2007-05-02 15112]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers; C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2007-05-02 109704]
S3 TVICHW32;TVICHW32; \??\C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS []
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; D:\avast\aswUpdSv.exe [2009-11-25 18752]
R2 avast! Antivirus;avast! Antivirus; D:\avast\ashServ.exe [2009-11-25 138680]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 KAVMonitorService;KAV Monitor Service; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpm.exe [2004-07-01 622710]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R3 avast! Mail Scanner;avast! Mail Scanner; D:\avast\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; D:\avast\ashWebSv.exe [2009-11-25 352920]
S2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2000-11-30 57344]
S2 gupdate1ca2bc6187ee390;Služba Google Update (gupdate1ca2bc6187ee390); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-09-02 133104]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2007-12-09 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-01-29 182768]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-03-18 65536]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
Unlimited_Killer
Přítel fóra
Přítel fóra
Příspěvky: 1969
Registrován: 24 srp 2009 16:18

Re: Prosím o kontrolu

#18 Příspěvek od Unlimited_Killer »

Dokončíme. :happy:

~~~

1) Zkuste pročistit PC pomocí programu CCleaner.
Nainstalujte, jen dávejte pozor a při instalaci odškrtněte položku Instalovat Yahoo! Toolbar.
Spusťte.
  • Záložka Čistič -> nechte zatrženo vše, jak je, a klikněte na 'Spustit CCleaner'.
  • Záložka Registry -> klikněte na 'Hledej problémy'. Vyhledá problémy v registru, až dokončí analyzování, klikněte na 'Opravit vybrané problémy'. Nabídne Vám vytvoření zálohy - pro jistotu ji vytvořte a uložte například na Plochu.
  • CCleaner doporučuji používat pravidelně, celkem rapidně dokáže zrychlit PC.

1) Defragmentace
Zkuste defragmentovat disk. Buď pomocí integrovaného Windowsáckého nástroje (není moc dobrý), nebo například přes Defraggler. Dobré zkušenosti mám také s jednoduchým JKDefrag, který se nemusí instalovat.


3)
Po těchto mým 'zákrocích' Vám nebudou fungovat automatické aktualizace například Javy (spouštěly se zbytečně hned po startu systému a zatěžovaly RAM).
Proto doporučuji stáhnout si prográmek jménem FileHippo Update Checker, který stačit jednou týdně spustit a přehledně Vám zobrazí, který software je neaktuální.


4) Po všech těchto krocích budu chtít vidět nový RSIT log,
inactive

zdenek72
3. Stupeň Varování
Příspěvky: 103
Registrován: 09 úno 2010 15:18
Bydliště: Plzen, Czech Republic
Kontaktovat uživatele:

Re: Prosím o kontrolu

#19 Příspěvek od zdenek72 »

Logfile of random's system information tool 1.06 (written by random/random)
Run by zdenek at 2010-02-10 11:55:53
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 552 MB (9%) free of 6 GB
Total RAM: 511 MB (57% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:55:56, on 10.2.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Avira\AntiVir Desktop\sched.exe
D:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpm.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\zdenek\Plocha\RSIT.exe
C:\Documents and Settings\zdenek\Plocha\zdenek.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.centrum.cz/?ms=ge
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://centrum.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SMSender.E.ToolbarsHelper - {24bcda96-8fcb-4d3b-0500-000000000004} - mscoree.dll (file missing)
O2 - BHO: (no name) - {53707962-6f74-2d53-2644-206d7942484f} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O3 - Toolbar: SMSender - {24BCDA96-8FCB-4D3B-0500-000000000003} - mscoree.dll (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avgnt] "D:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [365dni] C:\Program Files\365dníNET\365dniNET.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [FileHippo.com] "D:\Program Files\FileHippo.com\UpdateChecker.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\PROGRA~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://D:\PROGRAMY\OFFICE\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Poslat jako MMS - res://C:\Program Files\O2\SMSender\SMSender.E.dll/1003
O8 - Extra context menu item: Poslat jako SMS - res://C:\Program Files\O2\SMSender\SMSender.E.dll/1001
O8 - Extra context menu item: Poslat MMS na - res://C:\Program Files\O2\SMSender\SMSender.E.dll/1002
O8 - Extra context menu item: Poslat SMS na - res://C:\Program Files\O2\SMSender\SMSender.E.dll/1000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Nastavení aplikace &Gears - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 0589278780
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - D:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - D:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate1ca2bc6187ee390) (gupdate1ca2bc6187ee390) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: KAV Monitor Service (KAVMonitorService) - Kaspersky Labs. - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpm.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 7047 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{24bcda96-8fcb-4d3b-0500-000000000004}]
SMSender.E.ToolbarsHelper - C:\WINDOWS\system32\mscoree.dll [2008-07-25 282112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6f74-2d53-2644-206d7942484f}]
D:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2005-05-31 853672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll [2008-02-22 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-01-29 279664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll [2010-01-04 812528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{24BCDA96-8FCB-4D3B-0500-000000000003} - SMSender - C:\WINDOWS\system32\mscoree.dll [2008-07-25 282112]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-01-29 279664]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
"avgnt"=D:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]
"365dni"=C:\Program Files\365dníNET\365dniNET.exe [2007-01-06 753664]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-09-02 39408]
"FileHippo.com"=D:\Program Files\FileHippo.com\UpdateChecker.exe [2010-02-05 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"undockwithoutlogon"=1
"ShutdownWithoutLogon"=1
"NoDispCPL"=0
"NoDispSettingsPage"=0
"NoDispScrSavPage"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0
"GreyMSIAds"=1
"HideClock"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveTypeAutoRun"=
"NoResolveTrack"=
"NoViewContextMenu"=
"NoFileAssociate"=
"NoFind"=
"NoRun"=
"NoClose"=
"StartMenuLogoff"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\filmy\WinDVD.exe"="D:\filmy\WinDVD.exe:*:Enabled:WinDVD"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"D:\hry\Vietcong Fist Alpha MP demo\vietcong.exe"="D:\hry\Vietcong Fist Alpha MP demo\vietcong.exe:*:Enabled:vietcong"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\ICQ7.0\ICQ.exe"="C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"C:\Program Files\ICQ7.0\aolload.exe"="C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"
"D:\Program Files\Skype\Phone\Skype.exe"="D:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.0\ICQ.exe"="C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"C:\Program Files\ICQ7.0\aolload.exe"="C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{60cad2d1-4c02-11dd-b514-00e07deb69fe}]
shell\autorun\command - F:\AutoTransfer.exe


======List of files/folders created in the last 1 months======

2010-02-10 11:39:36 ----D---- C:\Documents and Settings\zdenek\Data aplikací\FastStone
2010-02-10 00:54:16 ----D---- C:\Documents and Settings\All Users\Data aplikací\Avira
2010-02-10 00:00:53 ----DC---- C:\rsit
2010-02-09 21:18:11 ----D---- C:\Documents and Settings\zdenek\Data aplikací\Malwarebytes
2010-02-09 21:17:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-02-06 10:28:20 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-02-06 10:26:47 ----D---- C:\Program Files\Windows Media Connect 2
2010-02-02 10:26:19 ----D---- C:\WINDOWS\ie8updates
2010-02-02 10:15:17 ----HDC---- C:\WINDOWS\ie8
2010-01-29 19:08:31 ----D---- C:\Documents and Settings\zdenek\Data aplikací\Ashampoo
2010-01-25 10:53:39 ----D---- C:\Program Files\ICQ7.0
2010-01-22 02:32:59 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-01-17 14:34:56 ----D---- C:\Documents and Settings\All Users\Data aplikací\Kaspersky Lab Setup Files
2010-01-16 01:50:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\Macromedia
2010-01-16 01:49:43 ----D---- C:\Program Files\Common Files\Macromedia
2010-01-16 01:48:10 ----D---- C:\Program Files\Common Files\InstallShield
2010-01-16 01:46:28 ----D---- C:\WINDOWS\Downloaded Installations
2010-01-15 22:02:18 ----D---- C:\Program Files\Conduit
2010-01-13 15:42:27 ----A---- C:\WINDOWS\system32\oeminfo.ini
2010-01-13 14:41:30 ----D---- C:\Program Files\Glary Utilities
2010-01-13 09:09:53 ----DC---- C:\Zakazky
2010-01-13 09:08:42 ----DC---- C:\IDAPI
2010-01-12 22:42:27 ----A---- C:\WINDOWS\system32\vbCPUInf.dll
2010-01-12 22:34:35 ----D---- C:\WINDOWS\vbSkinner
2010-01-12 18:36:49 ----D---- C:\Program Files\Common Files\eBay
2010-01-11 20:16:33 ----D---- C:\Documents and Settings\zdenek\Data aplikací\GlarySoft

======List of files/folders modified in the last 1 months======

2010-02-10 11:49:20 ----D---- C:\WINDOWS\Prefetch
2010-02-10 11:36:39 ----D---- C:\WINDOWS\Temp
2010-02-10 11:36:39 ----D---- C:\WINDOWS
2010-02-10 11:34:03 ----D---- C:\Program Files
2010-02-10 09:04:38 ----D---- C:\Documents and Settings\zdenek\Data aplikací\365dni
2010-02-10 09:02:42 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-10 08:59:26 ----HD---- C:\WINDOWS\PIF
2010-02-10 08:59:26 ----D---- C:\WINDOWS\system32\drivers
2010-02-10 08:58:52 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-02-10 01:06:23 ----D---- C:\WINDOWS\system32
2010-02-10 00:54:54 ----HD---- C:\WINDOWS\inf
2010-02-10 00:50:36 ----SHD---- C:\WINDOWS\Installer
2010-02-10 00:50:36 ----HD---- C:\Config.Msi
2010-02-10 00:50:33 ----D---- C:\WINDOWS\WinSxS
2010-02-09 23:34:10 ----AC---- C:\WINDOWS\wincmd.ini
2010-02-09 20:59:28 ----SD---- C:\WINDOWS\Tasks
2010-02-07 22:23:28 ----D---- C:\Documents and Settings\zdenek\Data aplikací\Skype
2010-02-07 17:18:58 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-06 10:30:26 ----D---- C:\WINDOWS\system32\CatRoot
2010-02-06 10:27:16 ----D---- C:\Program Files\Windows Media Player
2010-02-06 10:26:33 ----D---- C:\WINDOWS\Help
2010-02-06 10:25:30 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-02-05 15:12:40 ----D---- C:\WINDOWS\Debug
2010-02-03 23:46:13 ----D---- C:\Documents and Settings\zdenek\Data aplikací\gtk-2.0
2010-02-02 10:35:40 ----D---- C:\WINDOWS\system32\cs-cz
2010-02-02 10:35:37 ----D---- C:\WINDOWS\Media
2010-02-02 10:35:36 ----D---- C:\Program Files\Internet Explorer
2010-02-02 10:29:55 ----HD---- C:\WINDOWS\$hf_mig$
2010-02-02 10:18:26 ----RD---- C:\WINDOWS\Offline Web Pages
2010-01-29 23:04:07 ----D---- C:\Program Files\Rozpisy pro Šťastných10 (KENO10) - free verze
2010-01-29 04:46:47 ----RSD---- C:\WINDOWS\assembly
2010-01-29 04:46:35 ----D---- C:\WINDOWS\Microsoft.NET
2010-01-29 04:07:28 ----D---- C:\Documents and Settings\zdenek\Data aplikací\Google
2010-01-29 01:30:41 ----D---- C:\Program Files\Google
2010-01-29 01:30:23 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
2010-01-28 17:31:21 ----D---- C:\Documents and Settings\zdenek\Data aplikací\Adobe
2010-01-28 15:12:45 ----D---- C:\Documents and Settings\zdenek\Data aplikací\ICQ
2010-01-25 10:55:08 ----HD---- C:\Program Files\InstallShield Installation Information
2010-01-22 02:33:04 ----D---- C:\Program Files\Common Files\Adobe
2010-01-21 09:57:37 ----SD---- C:\WINDOWS\system32\Microsoft
2010-01-16 02:09:42 ----D---- C:\Documents and Settings\zdenek\Data aplikací\Macromedia
2010-01-16 01:49:43 ----D---- C:\Program Files\Common Files
2010-01-14 08:54:39 ----D---- C:\Program Files\Seznam.cz
2010-01-13 18:05:11 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-01-13 15:27:45 ----D---- C:\Program Files\Codec Pack - All In 1
2010-01-13 10:44:04 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-01-13 09:08:45 ----A---- C:\WINDOWS\win.ini
2010-01-13 09:08:43 ----D---- C:\WINDOWS\system
2010-01-12 22:40:06 ----D---- C:\WINDOWS\system32\NtmsData
2010-01-12 22:29:58 ----RSD---- C:\WINDOWS\Fonts
2010-01-12 22:26:11 ----A---- C:\WINDOWS\iun6002.exe
2010-01-12 11:49:28 ----D---- C:\Program Files\TuneUp Utilities 2009
2010-01-12 11:49:28 ----D---- C:\Program Files\Mozilla Firefox
2010-01-12 11:49:27 ----D---- C:\Program Files\DivX
2010-01-12 11:49:27 ----D---- C:\Program Files\365dníNET
2010-01-12 11:49:22 ----D---- C:\Documents and Settings\All Users\Data aplikací\Yahoo! Companion
2010-01-12 11:49:22 ----D---- C:\Documents and Settings\All Users\Data aplikací\Lavasoft
2010-01-11 20:42:16 ----D---- C:\WINDOWS\system32\config
2010-01-11 19:23:51 ----D---- C:\Program Files\Opera

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avgio;avgio; \??\D:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 P3;Ovladač procesoru Intel PentiumIII; C:\WINDOWS\System32\DRIVERS\p3.sys [2004-08-17 46336]
R1 PQNTDrv;PQNTDrv; C:\WINDOWS\system32\drivers\PQNTDrv.sys [2001-08-10 3252]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2009-09-11 5632]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-11-25 56816]
R3 ati2mtaa;ati2mtaa; C:\WINDOWS\System32\DRIVERS\ati2mtaa.sys [2001-09-26 285088]
R3 es1371;Creative AudioPCI (ES1371,ES1373) (WDM); C:\WINDOWS\system32\drivers\es1371mp.sys [2002-06-03 40832]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2001-10-25 9600]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
R3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S1 d53b8eac;d53b8eac; C:\WINDOWS\System32\drivers\d53b8eac.sys []
S3 ati2mpaa;ati2mpaa; C:\WINDOWS\System32\DRIVERS\ati2mpaa.sys [2001-10-24 281856]
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2004-06-21 51088]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2004-06-21 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2004-06-21 21744]
S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2001-10-25 5888]
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM); C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2007-05-02 83592]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter; C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2007-05-02 15112]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers; C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2007-05-02 109704]
S3 TVICHW32;TVICHW32; \??\C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS []
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira AntiVir Guard; D:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; D:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 KAVMonitorService;KAV Monitor Service; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpm.exe [2004-07-01 622710]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
S2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2000-11-30 57344]
S2 gupdate1ca2bc6187ee390;Služba Google Update (gupdate1ca2bc6187ee390); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-09-02 133104]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2007-12-09 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-01-29 182768]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-03-18 65536]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
Unlimited_Killer
Přítel fóra
Přítel fóra
Příspěvky: 1969
Registrován: 24 srp 2009 16:18

Re: Prosím o kontrolu

#20 Příspěvek od Unlimited_Killer »

Poslední krok.

~~~

1) Fixnutí v HJT
  • Spusťte přejmenované HijackThis - C:\Program Files\Trend Micro\HijackThis\jmeno_uzivatele.exe
  • Klikněte na 'Do a system scan only'.
  • U níže uvedených položek udělejte fajfku do čtverečku a poté klikněte na 'Fix Checked'.

    Kód: Vybrat vše

    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKCU\..\Run: [FileHippo.com] "D:\Program Files\FileHippo.com\UpdateChecker.exe" /background
  • Pokud by tam nějaká položka nebyla, vynechte ji.
2) Je to vše. Jsou nějaké problémy? :happy:
inactive

zdenek72
3. Stupeň Varování
Příspěvky: 103
Registrován: 09 úno 2010 15:18
Bydliště: Plzen, Czech Republic
Kontaktovat uživatele:

Re: Prosím o kontrolu

#21 Příspěvek od zdenek72 »

Hotovo
Díky moc,

zdenek72
3. Stupeň Varování
Příspěvky: 103
Registrován: 09 úno 2010 15:18
Bydliště: Plzen, Czech Republic
Kontaktovat uživatele:

Re: Prosím o kontrolu

#22 Příspěvek od zdenek72 »

jak mohu podpořit tyto stránky?

Uživatelský avatar
Unlimited_Killer
Přítel fóra
Přítel fóra
Příspěvky: 1969
Registrován: 24 srp 2009 16:18

Re: Prosím o kontrolu

#23 Příspěvek od Unlimited_Killer »

Není zač, podpořit lze například takto. Pokud chcete bezplatně, můžete zde. :D

Třeba se zde ještě někdy setkáme. :bye: :closed:
inactive

Odpovědět