
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o kontrolu logu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Prosím o kontrolu logu
NOD nič nenájde, počítaču dlho trvá kým niečo otvorí, po čase sa to zlepší.
XP, SP3, Pentium 4, 1,7GHz, 256 MB RAM
Ďakujem
Run by Mapo at 2010-08-08 15:24:05
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 3 GB (16%) free of 21 GB
Total RAM: 255 MB (11% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:25:07, on 8. 8. 2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\ZSSnp211.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Documents and Settings\Mapo\Dokumenty\Preberanie\RSIT.exe
C:\Program Files\trend micro\Mapo.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: MHURLSearchHook Class - {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - (no file)
O2 - BHO: MHTBPos00 - {0C37B053-FD68-456a-82E1-D788EE342E6F} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Family Toolbar - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - (no file)
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [reset] regedit /s reset.reg
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GEARSecurity - GEAR Software Inc. - (no file)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
--
End of file - 5181 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-117609710-706699826-1060284298-1003.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-117609710-706699826-1060284298-1003.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0C37B053-FD68-456a-82E1-D788EE342E6F}]
MHTBPos00 Class
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-05-27 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-05-27 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{FD2FD708-1F6F-4B68-B141-C5778F0C19BB} -
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AGRSMMSG"=C:\WINDOWS\AGRSMMSG.exe [2005-03-04 88209]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2007-04-16 577536]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"ZSSnp211"=C:\WINDOWS\ZSSnp211.exe [2006-08-19 49152]
"AdobeCS4ServiceManager"=C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]
"reset"=regedit /s reset.reg []
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-05-14 2029640]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"NBJ"=C:\Program Files\Ahead\Nero BackItUp\NBJ.exe [2005-07-14 1961984]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Uniblue RegistryBooster 2009"=C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe [2009-03-06 2019624]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2010-02-15 417792]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe"="C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2010-08-08 15:24:10 ----D---- C:\Program Files\trend micro
2010-08-08 15:24:05 ----D---- C:\rsit
2010-08-08 13:02:15 ----D---- C:\Program Files\Uniblue
2010-08-08 13:01:30 ----HDC---- C:\Documents and Settings\All Users\Data aplikací\{92E7A367-8E12-4830-AA70-29C32E331A81}
2010-08-08 11:37:49 ----D---- C:\Documents and Settings\Mapo\Data aplikací\Uniblue
2010-08-06 13:39:49 ----D---- C:\Program Files\Common Files\Real
2010-08-06 13:39:46 ----D---- C:\Documents and Settings\All Users\Data aplikací\Real
2010-08-06 13:39:29 ----D---- C:\Documents and Settings\Mapo\Data aplikací\Real
2010-07-29 15:59:25 ----A---- C:\WINDOWS\system32\iacenc.dll
2010-07-29 15:57:18 ----D---- C:\WINDOWS\APPLOG
2010-07-29 15:57:18 ----A---- C:\WINDOWS\system32\mvut20n.dll
2010-07-29 15:57:18 ----A---- C:\WINDOWS\system32\mvtl20n.dll
2010-07-29 15:57:18 ----A---- C:\WINDOWS\system32\mvsr20n.dll
2010-07-29 15:57:18 ----A---- C:\WINDOWS\system32\ivwsvr2.DLL
2010-07-29 15:57:18 ----A---- C:\WINDOWS\system32\InstallHelp.dll
2010-07-29 15:57:18 ----A---- C:\WINDOWS\system32\GMTUninstall.exe
2010-07-29 15:57:17 ----A---- C:\WINDOWS\system32\Rarv1032.dll
2010-07-29 15:57:17 ----A---- C:\WINDOWS\system32\Raocx32.dll
2010-07-29 15:57:17 ----A---- C:\WINDOWS\system32\Ra32sipr.dll
2010-07-29 15:57:17 ----A---- C:\WINDOWS\system32\Ra32rv10.dll
2010-07-29 15:57:17 ----A---- C:\WINDOWS\system32\Ra32dnet.dll
2010-07-29 15:57:17 ----A---- C:\WINDOWS\system32\mvmg20n.dll
2010-07-29 15:57:17 ----A---- C:\WINDOWS\system32\mvcl20n.dll
2010-07-29 15:57:17 ----A---- C:\WINDOWS\system32\mvbk20n.dll
2010-07-29 15:57:17 ----A---- C:\WINDOWS\system32\iyvu9_32.dll
2010-07-29 15:57:17 ----A---- C:\WINDOWS\COMMAND.PIF
2010-07-29 15:57:16 ----A---- C:\WINDOWS\system32\Ra3228_8.dll
2010-07-29 15:57:16 ----A---- C:\WINDOWS\system32\Ra3214_4.dll
2010-07-29 15:57:16 ----A---- C:\WINDOWS\system32\Pnui3250.dll
2010-07-29 15:57:16 ----A---- C:\WINDOWS\system32\Pnen3250.dll
2010-07-29 15:57:16 ----A---- C:\WINDOWS\system32\Decdnet.dll
2010-07-29 15:57:15 ----A---- C:\WINDOWS\system32\Msvcrtd.dll
2010-07-29 15:57:15 ----A---- C:\WINDOWS\system32\Mfco42d.dll
2010-07-29 15:57:15 ----A---- C:\WINDOWS\system32\Mfcn42d.dll
2010-07-29 15:57:15 ----A---- C:\WINDOWS\system32\Mfc42d.dll
2010-07-27 18:35:16 ----D---- C:\Documents and Settings\All Users\Data aplikací\NETGATE
2010-07-26 20:06:46 ----SHD---- C:\Config.Msi
2010-07-26 12:36:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2010-07-26 09:26:20 ----N---- C:\WINDOWS\system32\MpSigStub.exe
======List of files/folders modified in the last 1 months======
2010-08-08 15:24:13 ----D---- C:\WINDOWS\Temp
2010-08-08 15:24:10 ----RD---- C:\Program Files
2010-08-08 15:23:30 ----D---- C:\WINDOWS\Prefetch
2010-08-08 13:02:18 ----SHD---- C:\WINDOWS\Installer
2010-08-08 12:54:10 ----SD---- C:\WINDOWS\Tasks
2010-08-08 12:51:35 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2010-08-08 11:36:29 ----D---- C:\WINDOWS
2010-08-08 09:10:31 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-08-07 15:47:53 ----D---- C:\WINDOWS\system32
2010-08-06 14:43:37 ----D---- C:\Program Files\Common Files
2010-08-05 08:18:25 ----D---- C:\WINDOWS\system32\drivers
2010-08-04 09:12:11 ----A---- C:\WINDOWS\NeroDigital.ini
2010-07-29 16:04:05 ----D---- C:\WINDOWS\Minidump
2010-07-29 15:57:18 ----RSD---- C:\WINDOWS\Fonts
2010-07-29 13:45:55 ----D---- C:\WINDOWS\system32\CatRoot2
2010-07-28 17:52:21 ----D---- C:\Program Files\ESET
2010-07-27 22:01:26 ----D---- C:\WINDOWS\system32\drivers\etc
2010-07-27 08:45:42 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-07-26 20:10:55 ----HD---- C:\WINDOWS\inf
2010-07-26 16:46:41 ----D---- C:\Program Files\Mozilla Firefox
2010-07-26 12:36:18 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-07-26 12:35:24 ----HD---- C:\WINDOWS\$hf_mig$
2010-07-26 12:14:33 ----D---- C:\WINDOWS\Microsoft.NET
2010-07-26 12:14:16 ----RSD---- C:\WINDOWS\assembly
2010-07-26 11:21:06 ----D---- C:\WINDOWS\Debug
2010-07-26 10:53:03 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-07-26 10:51:13 ----D---- C:\WINDOWS\WinSxS
2010-07-21 10:53:15 ----D---- C:\Documents and Settings\Mapo\Data aplikací\Canon
2010-07-13 09:19:23 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-07-11 11:15:37 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-07-09 18:08:33 ----D---- C:\WINDOWS\system32\config
2010-07-09 18:08:13 ----D---- C:\WINDOWS\system32\wbem
2010-07-09 18:08:11 ----D---- C:\WINDOWS\Registration
2010-07-09 17:57:19 ----D---- C:\WINDOWS\system32\Restore
2010-07-09 15:07:02 ----D---- C:\WINDOWS\system32\NtmsData
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 viaagp;Filtr VIA sběrnice AGP ; C:\WINDOWS\System32\DRIVERS\viaagp.sys [2008-04-13 42240]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-05-14 107256]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2009-05-14 55768]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 adfs;adfs; C:\WINDOWS\system32\drivers\adfs.sys [2008-08-14 74720]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-05-14 114472]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2009-05-14 133000]
R2 HWiNFO32;HWiNFO32 Kernel Driver; \??\C:\Program Files\HWiNFO32\HWiNFO32.SYS []
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\System32\DRIVERS\AGRSM.sys [2005-03-04 1066278]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2008-09-24 4122368]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2009-05-14 33096]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 GEARAspiWDM;GearAspiWDM; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-18 2944]
R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S0 Lbd;Lbd; C:\WINDOWS\system32\DRIVERS\Lbd.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\Mapo\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 cmuda;cmuda; C:\WINDOWS\system32\drivers\cmuda.sys []
S3 EverestDriver;Lavalys EVEREST Kernel Driver; \??\C:\Documents and Settings\Mapo\Dokumenty\Preberanie\kerneld.wnt []
S3 GenericMount;Generic Mount Driver; C:\WINDOWS\system32\DRIVERS\GenericMount.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 nv4;nv4; C:\WINDOWS\System32\DRIVERS\nv4.sys [2001-08-17 731648]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 ZSMC211;USB PC Camera (ZS0211); C:\WINDOWS\System32\Drivers\ZS211.sys [2006-08-08 391836]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2009-05-14 731840]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-04-12 153376]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-05-14 20680]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-04-22 655624]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
XP, SP3, Pentium 4, 1,7GHz, 256 MB RAM
Ďakujem
Run by Mapo at 2010-08-08 15:24:05
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 3 GB (16%) free of 21 GB
Total RAM: 255 MB (11% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:25:07, on 8. 8. 2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\ZSSnp211.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Documents and Settings\Mapo\Dokumenty\Preberanie\RSIT.exe
C:\Program Files\trend micro\Mapo.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: MHURLSearchHook Class - {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - (no file)
O2 - BHO: MHTBPos00 - {0C37B053-FD68-456a-82E1-D788EE342E6F} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Family Toolbar - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - (no file)
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [reset] regedit /s reset.reg
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GEARSecurity - GEAR Software Inc. - (no file)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
--
End of file - 5181 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-117609710-706699826-1060284298-1003.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-117609710-706699826-1060284298-1003.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0C37B053-FD68-456a-82E1-D788EE342E6F}]
MHTBPos00 Class
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-05-27 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-05-27 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{FD2FD708-1F6F-4B68-B141-C5778F0C19BB} -
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AGRSMMSG"=C:\WINDOWS\AGRSMMSG.exe [2005-03-04 88209]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2007-04-16 577536]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"ZSSnp211"=C:\WINDOWS\ZSSnp211.exe [2006-08-19 49152]
"AdobeCS4ServiceManager"=C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]
"reset"=regedit /s reset.reg []
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-05-14 2029640]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"NBJ"=C:\Program Files\Ahead\Nero BackItUp\NBJ.exe [2005-07-14 1961984]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Uniblue RegistryBooster 2009"=C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe [2009-03-06 2019624]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2010-02-15 417792]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe"="C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2010-08-08 15:24:10 ----D---- C:\Program Files\trend micro
2010-08-08 15:24:05 ----D---- C:\rsit
2010-08-08 13:02:15 ----D---- C:\Program Files\Uniblue
2010-08-08 13:01:30 ----HDC---- C:\Documents and Settings\All Users\Data aplikací\{92E7A367-8E12-4830-AA70-29C32E331A81}
2010-08-08 11:37:49 ----D---- C:\Documents and Settings\Mapo\Data aplikací\Uniblue
2010-08-06 13:39:49 ----D---- C:\Program Files\Common Files\Real
2010-08-06 13:39:46 ----D---- C:\Documents and Settings\All Users\Data aplikací\Real
2010-08-06 13:39:29 ----D---- C:\Documents and Settings\Mapo\Data aplikací\Real
2010-07-29 15:59:25 ----A---- C:\WINDOWS\system32\iacenc.dll
2010-07-29 15:57:18 ----D---- C:\WINDOWS\APPLOG
2010-07-29 15:57:18 ----A---- C:\WINDOWS\system32\mvut20n.dll
2010-07-29 15:57:18 ----A---- C:\WINDOWS\system32\mvtl20n.dll
2010-07-29 15:57:18 ----A---- C:\WINDOWS\system32\mvsr20n.dll
2010-07-29 15:57:18 ----A---- C:\WINDOWS\system32\ivwsvr2.DLL
2010-07-29 15:57:18 ----A---- C:\WINDOWS\system32\InstallHelp.dll
2010-07-29 15:57:18 ----A---- C:\WINDOWS\system32\GMTUninstall.exe
2010-07-29 15:57:17 ----A---- C:\WINDOWS\system32\Rarv1032.dll
2010-07-29 15:57:17 ----A---- C:\WINDOWS\system32\Raocx32.dll
2010-07-29 15:57:17 ----A---- C:\WINDOWS\system32\Ra32sipr.dll
2010-07-29 15:57:17 ----A---- C:\WINDOWS\system32\Ra32rv10.dll
2010-07-29 15:57:17 ----A---- C:\WINDOWS\system32\Ra32dnet.dll
2010-07-29 15:57:17 ----A---- C:\WINDOWS\system32\mvmg20n.dll
2010-07-29 15:57:17 ----A---- C:\WINDOWS\system32\mvcl20n.dll
2010-07-29 15:57:17 ----A---- C:\WINDOWS\system32\mvbk20n.dll
2010-07-29 15:57:17 ----A---- C:\WINDOWS\system32\iyvu9_32.dll
2010-07-29 15:57:17 ----A---- C:\WINDOWS\COMMAND.PIF
2010-07-29 15:57:16 ----A---- C:\WINDOWS\system32\Ra3228_8.dll
2010-07-29 15:57:16 ----A---- C:\WINDOWS\system32\Ra3214_4.dll
2010-07-29 15:57:16 ----A---- C:\WINDOWS\system32\Pnui3250.dll
2010-07-29 15:57:16 ----A---- C:\WINDOWS\system32\Pnen3250.dll
2010-07-29 15:57:16 ----A---- C:\WINDOWS\system32\Decdnet.dll
2010-07-29 15:57:15 ----A---- C:\WINDOWS\system32\Msvcrtd.dll
2010-07-29 15:57:15 ----A---- C:\WINDOWS\system32\Mfco42d.dll
2010-07-29 15:57:15 ----A---- C:\WINDOWS\system32\Mfcn42d.dll
2010-07-29 15:57:15 ----A---- C:\WINDOWS\system32\Mfc42d.dll
2010-07-27 18:35:16 ----D---- C:\Documents and Settings\All Users\Data aplikací\NETGATE
2010-07-26 20:06:46 ----SHD---- C:\Config.Msi
2010-07-26 12:36:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2010-07-26 09:26:20 ----N---- C:\WINDOWS\system32\MpSigStub.exe
======List of files/folders modified in the last 1 months======
2010-08-08 15:24:13 ----D---- C:\WINDOWS\Temp
2010-08-08 15:24:10 ----RD---- C:\Program Files
2010-08-08 15:23:30 ----D---- C:\WINDOWS\Prefetch
2010-08-08 13:02:18 ----SHD---- C:\WINDOWS\Installer
2010-08-08 12:54:10 ----SD---- C:\WINDOWS\Tasks
2010-08-08 12:51:35 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2010-08-08 11:36:29 ----D---- C:\WINDOWS
2010-08-08 09:10:31 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-08-07 15:47:53 ----D---- C:\WINDOWS\system32
2010-08-06 14:43:37 ----D---- C:\Program Files\Common Files
2010-08-05 08:18:25 ----D---- C:\WINDOWS\system32\drivers
2010-08-04 09:12:11 ----A---- C:\WINDOWS\NeroDigital.ini
2010-07-29 16:04:05 ----D---- C:\WINDOWS\Minidump
2010-07-29 15:57:18 ----RSD---- C:\WINDOWS\Fonts
2010-07-29 13:45:55 ----D---- C:\WINDOWS\system32\CatRoot2
2010-07-28 17:52:21 ----D---- C:\Program Files\ESET
2010-07-27 22:01:26 ----D---- C:\WINDOWS\system32\drivers\etc
2010-07-27 08:45:42 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-07-26 20:10:55 ----HD---- C:\WINDOWS\inf
2010-07-26 16:46:41 ----D---- C:\Program Files\Mozilla Firefox
2010-07-26 12:36:18 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-07-26 12:35:24 ----HD---- C:\WINDOWS\$hf_mig$
2010-07-26 12:14:33 ----D---- C:\WINDOWS\Microsoft.NET
2010-07-26 12:14:16 ----RSD---- C:\WINDOWS\assembly
2010-07-26 11:21:06 ----D---- C:\WINDOWS\Debug
2010-07-26 10:53:03 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-07-26 10:51:13 ----D---- C:\WINDOWS\WinSxS
2010-07-21 10:53:15 ----D---- C:\Documents and Settings\Mapo\Data aplikací\Canon
2010-07-13 09:19:23 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-07-11 11:15:37 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-07-09 18:08:33 ----D---- C:\WINDOWS\system32\config
2010-07-09 18:08:13 ----D---- C:\WINDOWS\system32\wbem
2010-07-09 18:08:11 ----D---- C:\WINDOWS\Registration
2010-07-09 17:57:19 ----D---- C:\WINDOWS\system32\Restore
2010-07-09 15:07:02 ----D---- C:\WINDOWS\system32\NtmsData
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 viaagp;Filtr VIA sběrnice AGP ; C:\WINDOWS\System32\DRIVERS\viaagp.sys [2008-04-13 42240]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-05-14 107256]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2009-05-14 55768]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 adfs;adfs; C:\WINDOWS\system32\drivers\adfs.sys [2008-08-14 74720]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-05-14 114472]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2009-05-14 133000]
R2 HWiNFO32;HWiNFO32 Kernel Driver; \??\C:\Program Files\HWiNFO32\HWiNFO32.SYS []
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\System32\DRIVERS\AGRSM.sys [2005-03-04 1066278]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2008-09-24 4122368]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2009-05-14 33096]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 GEARAspiWDM;GearAspiWDM; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-18 2944]
R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S0 Lbd;Lbd; C:\WINDOWS\system32\DRIVERS\Lbd.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\Mapo\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 cmuda;cmuda; C:\WINDOWS\system32\drivers\cmuda.sys []
S3 EverestDriver;Lavalys EVEREST Kernel Driver; \??\C:\Documents and Settings\Mapo\Dokumenty\Preberanie\kerneld.wnt []
S3 GenericMount;Generic Mount Driver; C:\WINDOWS\system32\DRIVERS\GenericMount.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 nv4;nv4; C:\WINDOWS\System32\DRIVERS\nv4.sys [2001-08-17 731648]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 ZSMC211;USB PC Camera (ZS0211); C:\WINDOWS\System32\Drivers\ZS211.sys [2006-08-08 391836]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2009-05-14 731840]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-04-12 153376]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-05-14 20680]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-04-22 655624]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Re: Prosím o kontrolu logu
Zdravim,
operacni pameti je celkem malo na ty XP.
Odinstalujte Spybot,jednak je zastaraly a navic mate v pc ESS.
Provedte nekolikrat po sobe defragmentaci systemoveho disku C:
Stahnete si OTM , spustte (pokud mate vistu spuste run as administrator) a
do leveho policka se zlutym hornim okrajem Paste Instructions for Items to be Moved zkopirujte toto:
Kliknete na MoveIt, v okne se zelenym hornim okrajem Results se objevi vysledek,obsah okna zkopirujte sem. Kdyby OTMoveIt vyzadoval restart - povolit. Nasledujici log najdete v C:\_OTMoveIt\MovedFiles\xxxxx.log (x je zastupny znak) ktery otevrete v poznamkovem bloku.
Pro zrychleni startu Windows stahnete a spustte program StartUpLite
Program vypise seznam zbytecnych programu spoustejicich se pri startu Windows .
K vypnuti spousteni techto programu zaskrtnete u prislusnych radku Disable a kliknete na Continue.
Pak popiste chovani pc.
operacni pameti je celkem malo na ty XP.



do leveho policka se zlutym hornim okrajem Paste Instructions for Items to be Moved zkopirujte toto:
Kód: Vybrat vše
:processes
explorer.exe
:files
:services
:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"reset"=-
:commands
[purity]
[emptytemp]
[resethosts]
[start explorer]
[reboot]
Kliknete na MoveIt, v okne se zelenym hornim okrajem Results se objevi vysledek,obsah okna zkopirujte sem. Kdyby OTMoveIt vyzadoval restart - povolit. Nasledujici log najdete v C:\_OTMoveIt\MovedFiles\xxxxx.log (x je zastupny znak) ktery otevrete v poznamkovem bloku.

Program vypise seznam zbytecnych programu spoustejicich se pri startu Windows .
K vypnuti spousteni techto programu zaskrtnete u prislusnych radku Disable a kliknete na Continue.
Pak popiste chovani pc.
Autoruns + HitmanPro + UPM + Avenger + GMER + OTM + AVPTool + RSIT + RootRepeal
________________________________________________________________________________________
AKTUALIZOVANY ANTIVIR A PERSONALNI FIREWALL JSOU DVE NEZBYTNE OCHRANNE KOMPONENTY KAZDEHO PC,PRIPOJENEHO DO INTERNETU!!!
ZALOHOVANIM OSOBNICH DAT O NE NEPRIJDETE V PRIPADE FATALNICH PROBLEMU SE SOFTWAREM I HARDWAREM!!
NEPOUZIVEJTE COMBOFIX NA VLASTNI PEST, POUZE, POKUD K TOMU BUDETE VYZVANI.PRI NESPRAVNE MANIPULACI S NIM MUZE DOJIT K ZNEFUNKCNENI SYSTEMU!


___________________________________________________________
----------------------earl@forum.viry.cz-----------------------
________________________________________________________________________________________







___________________________________________________________
----------------------earl@forum.viry.cz-----------------------
Re: Prosím o kontrolu logu
Zdravím, všetko som urobil ako ste opísali, mnou opísané problémy zostali. Nič sa nezmenilo. Chvíľu to vyzeralo keď som použil StartUpLite, že sa rozbehol, ale po chvíli je to rovnaké. Keď spustím nejaké okno na lištu, roluje dolu pomaly a ak ho chcem otvoriť napr. aj túto stránku, tak sa načítava postupne a dlho. Tak isto ako toto píšem, niekedy písmená nabehnú až po chvíľke. Niekedy ako keby niečo robil, cvrliká a potom ide zase ako keby nič.
Nerobievalo to, napriek malej pamäti. Nijaký nový program som nenainštaloval.
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\reset deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: Mapo
->Temp folder emptied: 20693544 bytes
->Temporary Internet Files folder emptied: 124856306 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 83847372 bytes
->Flash cache emptied: 7875 bytes
User: NetworkService
->Temp folder emptied: 27192 bytes
->Temporary Internet Files folder emptied: 33170 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 848921 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 49635 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 220,00 mb
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
OTM by OldTimer - Version 3.1.15.0 log created on 08082010_215910
Files moved on Reboot...
C:\WINDOWS\temp\Perflib_Perfdata_61c.dat moved successfully.
Registry entries deleted on Reboot...
Nerobievalo to, napriek malej pamäti. Nijaký nový program som nenainštaloval.
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\reset deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: Mapo
->Temp folder emptied: 20693544 bytes
->Temporary Internet Files folder emptied: 124856306 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 83847372 bytes
->Flash cache emptied: 7875 bytes
User: NetworkService
->Temp folder emptied: 27192 bytes
->Temporary Internet Files folder emptied: 33170 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 848921 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 49635 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 220,00 mb
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
OTM by OldTimer - Version 3.1.15.0 log created on 08082010_215910
Files moved on Reboot...
C:\WINDOWS\temp\Perflib_Perfdata_61c.dat moved successfully.
Registry entries deleted on Reboot...
Re: Prosím o kontrolu logu
Ovladace na grafiku mate aktualni?
Co ta gefragmentace,mate barvy v prehledu pouze modrou,zelenou a bilou?
Vycistete pc Ccleanerem.
Vzdy nejprve Analyzovat a pak Spustit Cleaner.2x po sobe.
Windows-odskrtnout historii a historii automatickeho vyplnovani formularu - prisel byste o historii navstivenych stranek a o ulozena hesla ve formularich
(je to sice z pohledu zabezpeceni spatne,ale aspon pak uzivatel nenadava,kam ze mu to zmizelo
)
Aplikace-u prohlizecu internetu odskrtnout Historii internetu.
Registry-nechat vse zaskrtle,Hledej problemy,Opravit vybrane problemy
(nechat ho udelat zalohu-ta je ulozena v Dokumentech-DULEZITE).
Taktez 2x-3x po sobe.
Stahnete GMER , rozbalte a spustte
probehne sken, po jehoz ukonceni na vas vyskoci vysledky
pote kliknete na Save a ulozite tak log, jehoz obsah sem vlozte
pote dle tohoto navodu
absolvujte druhy sken a opet obsah logu sem.
Co ta gefragmentace,mate barvy v prehledu pouze modrou,zelenou a bilou?

Vzdy nejprve Analyzovat a pak Spustit Cleaner.2x po sobe.
Windows-odskrtnout historii a historii automatickeho vyplnovani formularu - prisel byste o historii navstivenych stranek a o ulozena hesla ve formularich
(je to sice z pohledu zabezpeceni spatne,ale aspon pak uzivatel nenadava,kam ze mu to zmizelo

Aplikace-u prohlizecu internetu odskrtnout Historii internetu.
Registry-nechat vse zaskrtle,Hledej problemy,Opravit vybrane problemy
(nechat ho udelat zalohu-ta je ulozena v Dokumentech-DULEZITE).
Taktez 2x-3x po sobe.

probehne sken, po jehoz ukonceni na vas vyskoci vysledky
pote kliknete na Save a ulozite tak log, jehoz obsah sem vlozte
pote dle tohoto navodu
absolvujte druhy sken a opet obsah logu sem.
Autoruns + HitmanPro + UPM + Avenger + GMER + OTM + AVPTool + RSIT + RootRepeal
________________________________________________________________________________________
AKTUALIZOVANY ANTIVIR A PERSONALNI FIREWALL JSOU DVE NEZBYTNE OCHRANNE KOMPONENTY KAZDEHO PC,PRIPOJENEHO DO INTERNETU!!!
ZALOHOVANIM OSOBNICH DAT O NE NEPRIJDETE V PRIPADE FATALNICH PROBLEMU SE SOFTWAREM I HARDWAREM!!
NEPOUZIVEJTE COMBOFIX NA VLASTNI PEST, POUZE, POKUD K TOMU BUDETE VYZVANI.PRI NESPRAVNE MANIPULACI S NIM MUZE DOJIT K ZNEFUNKCNENI SYSTEMU!


___________________________________________________________
----------------------earl@forum.viry.cz-----------------------
________________________________________________________________________________________







___________________________________________________________
----------------------earl@forum.viry.cz-----------------------
Re: Prosím o kontrolu logu
Zdravím, dnes to nechám tak ako to je, po nočnom "oddychu" to vyzerá zatiaľ oveľa lepšie, teda by som povedal, prakticky ako predtým. Ak by sa tie príznaky znovu objavili, tak budem robiť ďalšie kroky ako píšete. Ale tú aktualizáciu grafiky si overím. Ozvem sa, ĎAKUJEM ZATIAĽ.
P.S. Defragmentoval som asi 10x a zostalo dosť červenej.
P.S. Defragmentoval som asi 10x a zostalo dosť červenej.
Re: Prosím o kontrolu logu
Takze to bude chtit presunout urcite mnozstvi dat na externi medium (HDD,DVD-RW,apod...),nasledne je smazat a provest znovu defrag,dokud toP.S. Defragmentoval som asi 10x a zostalo dosť červenej.
nebude v trochu rozumnem stavu.
Silna fragmentace je jeden z hlavnich duvodu,proc je pc tak pomale.
A jinak nemate zac.
Autoruns + HitmanPro + UPM + Avenger + GMER + OTM + AVPTool + RSIT + RootRepeal
________________________________________________________________________________________
AKTUALIZOVANY ANTIVIR A PERSONALNI FIREWALL JSOU DVE NEZBYTNE OCHRANNE KOMPONENTY KAZDEHO PC,PRIPOJENEHO DO INTERNETU!!!
ZALOHOVANIM OSOBNICH DAT O NE NEPRIJDETE V PRIPADE FATALNICH PROBLEMU SE SOFTWAREM I HARDWAREM!!
NEPOUZIVEJTE COMBOFIX NA VLASTNI PEST, POUZE, POKUD K TOMU BUDETE VYZVANI.PRI NESPRAVNE MANIPULACI S NIM MUZE DOJIT K ZNEFUNKCNENI SYSTEMU!


___________________________________________________________
----------------------earl@forum.viry.cz-----------------------
________________________________________________________________________________________







___________________________________________________________
----------------------earl@forum.viry.cz-----------------------
Re: Prosím o kontrolu logu
Prechválil som to, je to také isté. Grafika je v poriadku, log malý z "gmer-u" som uložil, ale veľký po skoro dvoch hodinách mi uložiť neišiel, že sa nedá otvoriť document & setting. Musel som ho resetnúť, pretože mi nič neišlo otvoriť, ak budem mať nervy ešte raz ho skúsim. Ale najprv s pozriem na tú dfrg.
Ale je, každá pomoc je dobrá.
Ď.
Tu je malý gmer
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-08-09 18:37:33
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Mapo\LOCALS~1\Temp\uwpdyaod.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Ip epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Udp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\RawIp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
Tu je ten druhý
---- EOF - GMER 1.0.15 ----GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-09 21:02:57
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Mapo\LOCALS~1\Temp\uwpdyaod.sys
---- System - GMER 1.0.15 ----
SSDT 813E9580 ZwAssignProcessToJobObject
SSDT 813EA100 ZwDebugActiveProcess
SSDT 813E9B30 ZwDuplicateObject
SSDT 813E8CC0 ZwOpenProcess
SSDT 813E8FC0 ZwOpenThread
SSDT 813E99C0 ZwProtectVirtualMemory
SSDT 813E9860 ZwSetContextThread
SSDT 813E96E0 ZwSetInformationThread
SSDT 813E6700 ZwSetSecurityObject
SSDT 813E9420 ZwSuspendProcess
SSDT 813E92C0 ZwSuspendThread
SSDT 813E8E50 ZwTerminateProcess
SSDT 813E9150 ZwTerminateThread
SSDT 813E9F50 ZwWriteVirtualMemory
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\ESET\ESET Smart Security\ekrn.exe[868] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 4 Bytes [C2, 04, 00, 00]
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Ip epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Udp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\RawIp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
---- Registry - GMER 1.0.15 ----
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{23852600-B6DB-30E0-2819-8EF19DC15296}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E409A471-0A64-0EDF-9324-EFCE5AF7BDF9}
---- EOF - GMER 1.0.15 ----
Ale je, každá pomoc je dobrá.
Ď.
Tu je malý gmer
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-08-09 18:37:33
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Mapo\LOCALS~1\Temp\uwpdyaod.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Ip epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Udp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\RawIp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
Tu je ten druhý
---- EOF - GMER 1.0.15 ----GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-09 21:02:57
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Mapo\LOCALS~1\Temp\uwpdyaod.sys
---- System - GMER 1.0.15 ----
SSDT 813E9580 ZwAssignProcessToJobObject
SSDT 813EA100 ZwDebugActiveProcess
SSDT 813E9B30 ZwDuplicateObject
SSDT 813E8CC0 ZwOpenProcess
SSDT 813E8FC0 ZwOpenThread
SSDT 813E99C0 ZwProtectVirtualMemory
SSDT 813E9860 ZwSetContextThread
SSDT 813E96E0 ZwSetInformationThread
SSDT 813E6700 ZwSetSecurityObject
SSDT 813E9420 ZwSuspendProcess
SSDT 813E92C0 ZwSuspendThread
SSDT 813E8E50 ZwTerminateProcess
SSDT 813E9150 ZwTerminateThread
SSDT 813E9F50 ZwWriteVirtualMemory
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\ESET\ESET Smart Security\ekrn.exe[868] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 4 Bytes [C2, 04, 00, 00]
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Ip epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Udp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\RawIp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
---- Registry - GMER 1.0.15 ----
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{23852600-B6DB-30E0-2819-8EF19DC15296}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E409A471-0A64-0EDF-9324-EFCE5AF7BDF9}
---- EOF - GMER 1.0.15 ----
- Přílohy
-
- píše že netreba defragmentovat.JPG
- (243.02 KiB) Staženo 158 x
Re: Prosím o kontrolu logu

Neverte vzdy tomu,co Windows pisou,leckdy jsou informace od informacniho systemu nepresne a zavadejici.
Stav fragmentace by mel vypadat alespon takto -

Takze opakovane defragmentovat,dokud pc nebude rychlejsi.
Pokud StartupLite nezabral,je tu vykonnejsi moznost:

Po prvnim spusteni po dokonceni nabehu zaklepnete fajfku na zalozce Options u polozky Hide Microsoft Entries
a zavrete a spustte znovu.
Pote zkontrolujte vsechny polozky,spoustejici se po startu a pomalu zacnete s
omezovanim jejich poctu.
Tim docilite minimalniho poctu polozek spoustenych po startu Windows.
Je treba ovsem upozornit,ze to nejsou jen programy,ale i ruzne knihovny,ovladace apod.,takze
je treba zvlastni obezretnosti,pri zakazovani.
Autoruns + HitmanPro + UPM + Avenger + GMER + OTM + AVPTool + RSIT + RootRepeal
________________________________________________________________________________________
AKTUALIZOVANY ANTIVIR A PERSONALNI FIREWALL JSOU DVE NEZBYTNE OCHRANNE KOMPONENTY KAZDEHO PC,PRIPOJENEHO DO INTERNETU!!!
ZALOHOVANIM OSOBNICH DAT O NE NEPRIJDETE V PRIPADE FATALNICH PROBLEMU SE SOFTWAREM I HARDWAREM!!
NEPOUZIVEJTE COMBOFIX NA VLASTNI PEST, POUZE, POKUD K TOMU BUDETE VYZVANI.PRI NESPRAVNE MANIPULACI S NIM MUZE DOJIT K ZNEFUNKCNENI SYSTEMU!


___________________________________________________________
----------------------earl@forum.viry.cz-----------------------
________________________________________________________________________________________







___________________________________________________________
----------------------earl@forum.viry.cz-----------------------
Re: Prosím o kontrolu logu
Prosím o vysvetlenie, mám tam v options zatrhnutú fajku u Hide "Windows Entries"
dobre rozumiem,ak si myslím, že treba dať fajku na "Hide Microsoft a Windows Entries?
Ďakujem, ale radšej sa opýtam.
dobre rozumiem,ak si myslím, že treba dať fajku na "Hide Microsoft a Windows Entries?
Ďakujem, ale radšej sa opýtam.
Re: Prosím o kontrolu logu
Presne tak.Hide Microsoft a Windows Entries
Autoruns + HitmanPro + UPM + Avenger + GMER + OTM + AVPTool + RSIT + RootRepeal
________________________________________________________________________________________
AKTUALIZOVANY ANTIVIR A PERSONALNI FIREWALL JSOU DVE NEZBYTNE OCHRANNE KOMPONENTY KAZDEHO PC,PRIPOJENEHO DO INTERNETU!!!
ZALOHOVANIM OSOBNICH DAT O NE NEPRIJDETE V PRIPADE FATALNICH PROBLEMU SE SOFTWAREM I HARDWAREM!!
NEPOUZIVEJTE COMBOFIX NA VLASTNI PEST, POUZE, POKUD K TOMU BUDETE VYZVANI.PRI NESPRAVNE MANIPULACI S NIM MUZE DOJIT K ZNEFUNKCNENI SYSTEMU!


___________________________________________________________
----------------------earl@forum.viry.cz-----------------------
________________________________________________________________________________________







___________________________________________________________
----------------------earl@forum.viry.cz-----------------------
Re: Prosím o kontrolu logu
Zdravím, tak s tým veru neviem čo mám urobiť
Ráno som urobil dfrg. so Smart Defrag-om a potom ešte windowsáckym, už je výsledok omnoho lepší, ale keď som teraz pustil PC na obrazovke sa objavilo hlásenie že, "Činnosť systému bola obnovená po závažnej chybe", prikladám screen. Tomu nerozumiem.
Ešte otázka, v Správcovi úloh beží svchost.exe System 3x, Local service 2x, Network service 2x, je to v poriadku?
Ďakujem za radu.

Ráno som urobil dfrg. so Smart Defrag-om a potom ešte windowsáckym, už je výsledok omnoho lepší, ale keď som teraz pustil PC na obrazovke sa objavilo hlásenie že, "Činnosť systému bola obnovená po závažnej chybe", prikladám screen. Tomu nerozumiem.

Ešte otázka, v Správcovi úloh beží svchost.exe System 3x, Local service 2x, Network service 2x, je to v poriadku?
Ďakujem za radu.
Re: Prosím o kontrolu logu
Pri dalsim spusteni by se jiz chyba nemela objevit.
Stahnete OTC
spustte a klepnete na CleanUp.

Vycistete pc Ccleanerem.
Vzdy nejprve Analyzovat a pak Spustit Cleaner.2x po sobe.
Windows-odskrtnout historii a historii automatickeho vyplnovani formularu - prisel byste o historii navstivenych stranek a o ulozena hesla ve formularich
(je to sice z pohledu zabezpeceni spatne,ale aspon pak uzivatel nenadava,kam ze mu to zmizelo
)
Aplikace-u prohlizecu internetu odskrtnout Historii internetu.
Registry-nechat vse zaskrtle,Hledej problemy,Opravit vybrane problemy
(nechat ho udelat zalohu-ta je ulozena v Dokumentech-DULEZITE).
Taktez 2x-3x po sobe.
A hotovo.

spustte a klepnete na CleanUp.


Vzdy nejprve Analyzovat a pak Spustit Cleaner.2x po sobe.
Windows-odskrtnout historii a historii automatickeho vyplnovani formularu - prisel byste o historii navstivenych stranek a o ulozena hesla ve formularich
(je to sice z pohledu zabezpeceni spatne,ale aspon pak uzivatel nenadava,kam ze mu to zmizelo

Aplikace-u prohlizecu internetu odskrtnout Historii internetu.
Registry-nechat vse zaskrtle,Hledej problemy,Opravit vybrane problemy
(nechat ho udelat zalohu-ta je ulozena v Dokumentech-DULEZITE).
Taktez 2x-3x po sobe.
A hotovo.
Autoruns + HitmanPro + UPM + Avenger + GMER + OTM + AVPTool + RSIT + RootRepeal
________________________________________________________________________________________
AKTUALIZOVANY ANTIVIR A PERSONALNI FIREWALL JSOU DVE NEZBYTNE OCHRANNE KOMPONENTY KAZDEHO PC,PRIPOJENEHO DO INTERNETU!!!
ZALOHOVANIM OSOBNICH DAT O NE NEPRIJDETE V PRIPADE FATALNICH PROBLEMU SE SOFTWAREM I HARDWAREM!!
NEPOUZIVEJTE COMBOFIX NA VLASTNI PEST, POUZE, POKUD K TOMU BUDETE VYZVANI.PRI NESPRAVNE MANIPULACI S NIM MUZE DOJIT K ZNEFUNKCNENI SYSTEMU!


___________________________________________________________
----------------------earl@forum.viry.cz-----------------------
________________________________________________________________________________________







___________________________________________________________
----------------------earl@forum.viry.cz-----------------------
Re: Prosím o kontrolu logu
Vykonané podľa návodu, " OTC "vyzerá to dobre.
S tým "autorunsom" na to si netrúfam niečo mazať.
Problém z tou lenivosťou PC je mi už jasný. Spôsobuje to ESS pri aktualizácii a pri kontrole OS či je aktualizovaný, pokiaľ toto neurobí je procesor vyťažený skoro na maximum a stránkovanie tak isto, podľa Správcu súborov. Zastavil som kontrolu OS v ESS a ide ako predtým.
P.S. Myslím, že možno tento problém uzavrieť.
Ďakujem za poradu, ak budem mať nejaké nejasnosti, opäť sa ozvem.

S tým "autorunsom" na to si netrúfam niečo mazať.
Problém z tou lenivosťou PC je mi už jasný. Spôsobuje to ESS pri aktualizácii a pri kontrole OS či je aktualizovaný, pokiaľ toto neurobí je procesor vyťažený skoro na maximum a stránkovanie tak isto, podľa Správcu súborov. Zastavil som kontrolu OS v ESS a ide ako predtým.
P.S. Myslím, že možno tento problém uzavrieť.
Ďakujem za poradu, ak budem mať nejaké nejasnosti, opäť sa ozvem.

Re: Prosím o kontrolu logu
Nemate zac,od toho jsme tu. 

Autoruns + HitmanPro + UPM + Avenger + GMER + OTM + AVPTool + RSIT + RootRepeal
________________________________________________________________________________________
AKTUALIZOVANY ANTIVIR A PERSONALNI FIREWALL JSOU DVE NEZBYTNE OCHRANNE KOMPONENTY KAZDEHO PC,PRIPOJENEHO DO INTERNETU!!!
ZALOHOVANIM OSOBNICH DAT O NE NEPRIJDETE V PRIPADE FATALNICH PROBLEMU SE SOFTWAREM I HARDWAREM!!
NEPOUZIVEJTE COMBOFIX NA VLASTNI PEST, POUZE, POKUD K TOMU BUDETE VYZVANI.PRI NESPRAVNE MANIPULACI S NIM MUZE DOJIT K ZNEFUNKCNENI SYSTEMU!


___________________________________________________________
----------------------earl@forum.viry.cz-----------------------
________________________________________________________________________________________







___________________________________________________________
----------------------earl@forum.viry.cz-----------------------