Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Trapim se trapim a nejde zikvidovat.Prosim,mrkne te mi na to

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
pajikus
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 16 zář 2010 09:04

Trapim se trapim a nejde zikvidovat.Prosim,mrkne te mi na to

#1 Příspěvek od pajikus »

Logfile of random's system information tool 1.08 (written by random/random)
Run by paja at 2010-09-16 10:21:05
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 96 GB (70%) free of 138 GB
Total RAM: 1014 MB (46% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:21:11, on 16.9.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\totalcmd\TOTALCMD.EXE
c:\Program Files\ICQ6.5\ICQ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ping.exe
E:\RSIT.exe
C:\Program Files\trend micro\paja.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.atlas.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\pchealth\helpctr\System\panels\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\pchealth\helpctr\System\panels\blank.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkID=178591
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [HybridTM_A] C:\Program Files\HybridTM_IR(A)\RC620_A.exe
O4 - HKLM\..\Run: [HKLM] C:\WINDOWS\system32\install\svchost.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [HKCU] C:\WINDOWS\system32\install\svchost.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acer VCM.lnk = ?
O4 - Global Startup: TMMonitor.lnk = C:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (file missing)
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (file missing)
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {888078C6-70B2-4F88-8EE7-1F50DDEA6120} (CeWe Color AG & Co. OHG Control) - https://as.photoprintit.de/ips-opdata/a ... oader6.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - (no file)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 7799 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\User_Feed_Synchronization-{A46FDBE0-98BB-4409-8AF3-AF576ACE6C93}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-04 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-08-04 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} -

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AzMixerSel"=C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe [2006-01-25 53248]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2008-02-28 141848]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2008-02-28 166424]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2008-02-28 137752]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2008-04-14 208952]
"MSPY2002"=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [2008-04-14 59392]
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2008-04-14 455168]
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2008-04-14 455168]
"UnlockerAssistant"=C:\Program Files\Unlocker\UnlockerAssistant.exe [2008-05-02 15872]
"TrueImageMonitor.exe"=C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2006-10-19 1183656]
"AcronisTimounterMonitor"=C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [2006-10-19 1958800]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2009-10-27 365560]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"nod32kui"=C:\Program Files\Eset\nod32kui.exe [2010-08-12 917504]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2010-07-28 19557480]
"HybridTM_A"=C:\Program Files\HybridTM_IR(A)\RC620_A.exe []
"HKLM"=C:\WINDOWS\system32\install\svchost.exe [2010-09-15 241664]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"HKCU"=C:\WINDOWS\system32\install\svchost.exe [2010-09-15 241664]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Acer VCM.lnk - C:\Program Files\Acer\Acer VCM\AcerVCM.exe
TMMonitor.lnk - C:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2008-02-15 208896]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Miranda IM\miranda32.exe"="C:\Program Files\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\VoipDiscount.com\VoipDiscount\VoipDiscount.exe"="C:\Program Files\VoipDiscount.com\VoipDiscount\VoipDiscount.exe:*:Enabled:VoipDiscount"
"C:\Program Files\viphone communicator\viphone communicator.exe"="C:\Program Files\viphone communicator\viphone communicator.exe:*:Enabled:viphone communicator"
"C:\Program Files\ArcSoft\TotalMedia 3\TotalMedia.exe"="C:\Program Files\ArcSoft\TotalMedia 3\TotalMedia.exe:LocalSubNet:Enabled:ArcSoft TotalMedia 3"
"C:\Program Files\BitLord\BitLord.exe"="C:\Program Files\BitLord\BitLord.exe:*:Enabled:BitLord"
"C:\Program Files\Java\jre6\launch4j-tmp\frd.exe"="C:\Program Files\Java\jre6\launch4j-tmp\frd.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Free SMTP Server\localsrv.exe"="C:\Program Files\Free SMTP Server\localsrv.exe:*:Enabled:localsrv"
"C:\Program Files\TightVNC\WinVNC.exe"="C:\Program Files\TightVNC\WinVNC.exe:*:Enabled:TightVNC Win32 Server"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======File associations======

.js - open - %SystemRoot%\System32\CScript.exe "%1" %*
.vbs - open - %SystemRoot%\System32\CScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2010-09-16 09:43:14 ----D---- C:\rsit
2010-09-16 09:43:14 ----D---- C:\Program Files\trend micro
2010-09-15 17:59:13 ----A---- C:\WINDOWS\system32\pwNative.exe
2010-09-15 17:59:12 ----N---- C:\WINDOWS\system32\pwdspio.sys
2010-09-15 17:59:12 ----N---- C:\WINDOWS\system32\pwdrvio.sys
2010-09-15 17:43:59 ----ASH---- C:\hiberfil.sys
2010-09-15 14:11:55 ----RASH---- C:\MSDOS.SYS
2010-09-15 14:11:55 ----RASH---- C:\IO.SYS
2010-09-15 13:51:58 ----D---- C:\stazene
2010-09-15 13:20:39 ----A---- C:\WINDOWS\system32\MbrFix.exe
2010-09-15 09:52:10 ----A---- C:\WINDOWS\ntbtlog.txt
2010-09-15 08:30:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2259922$
2010-09-15 08:30:31 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2010-09-15 08:30:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2010-09-15 08:30:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2121546$
2010-09-15 08:30:07 ----HDC---- C:\WINDOWS\$NtUninstallKB982802$
2010-09-15 08:29:59 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2010-09-15 08:27:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2141007$
2010-09-15 08:23:47 ----D---- C:\WINDOWS\$hf_mig$
2010-09-13 11:41:05 ----A---- C:\WINDOWS\system32\javaws.exe
2010-09-13 11:41:05 ----A---- C:\WINDOWS\system32\javaw.exe
2010-09-13 11:41:05 ----A---- C:\WINDOWS\system32\java.exe
2010-09-11 17:26:07 ----A---- C:\Program Files\ZaznamZvuku.exe
2010-09-11 14:57:02 ----D---- C:\Documents and Settings\All Users\Data aplikací\NCH Swift Sound
2010-09-11 14:56:18 ----D---- C:\Documents and Settings\paja\Data aplikací\NCH Swift Sound
2010-09-09 11:33:19 ----D---- C:\WINDOWS\Temp
2010-09-09 11:33:04 ----HD---- C:\Program Files\InstallShield Installation Information
2010-09-08 18:18:11 ----D---- C:\Intel
2010-08-24 11:39:10 ----D---- C:\Documents and Settings\paja\Data aplikací\Devices
2010-08-22 10:23:35 ----D---- C:\WINDOWS\SHELLNEW
2010-08-22 10:23:23 ----D---- C:\Program Files\Microsoft Office
2010-08-17 17:07:12 ----D---- C:\Program Files\AIDA32 - Enterprise System Information
2010-08-17 16:56:50 ----D---- C:\Documents and Settings\paja\Data aplikací\Broad Intelligence
2010-08-17 16:55:21 ----D---- C:\Program Files\MediaCoder

======List of files/folders modified in the last 1 months======

2010-09-16 10:07:32 ----D---- C:\WINDOWS\Prefetch
2010-09-16 09:43:14 ----RD---- C:\Program Files
2010-09-15 18:11:02 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2010-09-15 18:09:17 ----AD---- C:\WINDOWS\system32
2010-09-15 18:01:54 ----SH---- C:\boot.ini
2010-09-15 15:54:18 ----SHD---- C:\WINDOWS\Installer
2010-09-15 15:54:12 ----AD---- C:\WINDOWS\system32\drivers
2010-09-15 15:30:56 ----D---- C:\Program Files\Common Files
2010-09-15 15:28:22 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-09-15 15:14:30 ----D---- C:\WINDOWS
2010-09-15 14:36:42 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-09-15 12:53:43 ----RSHD---- C:\WINDOWS\system32\install
2010-09-15 12:25:42 ----D---- C:\Documents and Settings\All Users\Data aplikací\RFA_Backups
2010-09-15 10:50:21 ----A---- C:\WINDOWS\k-mania.Ini
2010-09-15 09:52:27 ----D---- C:\Documents and Settings
2010-09-15 09:25:42 ----SHD---- C:\System Volume Information
2010-09-15 09:25:42 ----D---- C:\WINDOWS\system32\Restore
2010-09-15 09:12:14 ----D---- C:\WINDOWS\WinSxS
2010-09-15 08:30:42 ----HD---- C:\WINDOWS\inf
2010-09-15 08:30:34 ----A---- C:\WINDOWS\imsins.BAK
2010-09-15 08:30:33 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-09-15 08:27:31 ----A---- C:\WINDOWS\system32\MRT.exe
2010-09-15 08:23:47 ----D---- C:\WINDOWS\system32\CatRoot2
2010-09-14 13:37:34 ----SD---- C:\Documents and Settings\paja\Data aplikací\Microsoft
2010-09-13 11:41:01 ----D---- C:\Program Files\Java
2010-09-11 17:16:14 ----A---- C:\WINDOWS\win.ini
2010-09-11 15:49:10 ----SD---- C:\WINDOWS\Tasks
2010-09-10 08:39:53 ----D---- C:\WINDOWS\Network Diagnostic
2010-09-09 11:38:37 ----D---- C:\WINDOWS\system32\RTCOM
2010-09-09 11:33:11 ----D---- C:\WINDOWS\system32\Atheros_L1e
2010-08-23 09:53:11 ----D---- C:\Documents and Settings\paja\Data aplikací\ICQ
2010-08-22 12:46:19 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-08-22 11:05:14 ----RSD---- C:\WINDOWS\Fonts
2010-08-22 10:24:25 ----A---- C:\WINDOWS\ODBC.INI
2010-08-22 10:24:13 ----RSD---- C:\WINDOWS\assembly
2010-08-22 10:23:41 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-08-22 10:20:22 ----D---- C:\WINDOWS\system
2010-08-17 15:17:06 ----A---- C:\WINDOWS\system32\spoolsv.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-14 42368]
R0 agpCPQ;Filtr Compaq sběrnice AGP; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2008-04-14 44928]
R0 alim1541;Filtr ALI sběrnice AGP; C:\WINDOWS\system32\DRIVERS\alim1541.sys [2008-04-14 42752]
R0 amdagp;Ovladač filtru AMD portu AGP; C:\WINDOWS\system32\DRIVERS\amdagp.sys [2008-04-14 43008]
R0 cbidf;cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [2008-04-14 13952]
R0 iaStor;Intel AHCI Controller; C:\WINDOWS\system32\drivers\iaStor.sys [2010-01-08 331288]
R0 sisagp;Filtr SIS sběrnice AGP ; C:\WINDOWS\system32\DRIVERS\sisagp.sys [2008-04-14 40960]
R0 snapman;Acronis Snapshots Manager; C:\WINDOWS\system32\DRIVERS\snapman.sys [2010-07-01 114048]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-07-01 722416]
R0 timounter;Acronis True Image Backup Archive Explorer; C:\WINDOWS\system32\DRIVERS\timntr.sys [2010-07-01 395744]
R0 viaagp;Filtr VIA sběrnice AGP ; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2008-04-14 42240]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032]
R2 AMON;AMON; \??\C:\WINDOWS\system32\drivers\amon.sys []
R2 tifsfilter;Acronis True Image FS Filter; C:\WINDOWS\system32\DRIVERS\tifsfilt.sys [2010-07-01 39264]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 AR5416;Atheros AR5008 Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\athw.sys [2010-01-06 1596768]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2008-02-15 5854752]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2010-07-28 6108776]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-14 121984]
S1 DritekPortIO;Dritek General Port I/O; C:\WINDOWS\system32\drivers\DritekPortIO.sys []
S3 a075bi13;a075bi13; C:\WINDOWS\system32\drivers\a075bi13.sys []
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 CrystalSysInfo;CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys []
S3 int15.sys;int15.sys; C:\WINDOWS\system32\drivers\int15.sys.sys []
S3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l1e51x86.sys [2010-03-19 46632]
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 MPE;Filtr MPE BDA; C:\WINDOWS\system32\DRIVERS\MPE.sys [2008-04-14 15232]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 pwdrvio;pwdrvio; \??\C:\WINDOWS\system32\pwdrvio.sys []
S3 pwdspio;pwdspio; \??\C:\WINDOWS\system32\pwdspio.sys []
S3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader; C:\WINDOWS\System32\Drivers\RTS5121.sys [2008-11-21 160256]
S3 Rts516xIR;Realtek IR Driver; C:\WINDOWS\system32\DRIVERS\Rts516xIR.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 TridDev;USB Hybrid TV Device (TM6000); C:\WINDOWS\system32\DRIVERS\Triddev.sys [2005-04-26 3584]
S3 TridVid;USB Hybrid TV Receiver (TM6000); C:\WINDOWS\system32\DRIVERS\TridVid.sys [2006-04-04 189568]
S3 USBCCID;Realtek Smartcard Reader Driver; C:\WINDOWS\system32\DRIVERS\Rts5161ccid.sys []
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2009-10-27 660504]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2010-01-08 354840]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-07-17 153376]
R2 NOD32krn;NOD32 Kernel Service; C:\Program Files\Eset\nod32krn.exe [2010-08-12 495616]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 268288]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Trapim se trapim a nejde zikvidovat.Prosim,mrkne te mi n

#2 Příspěvek od vyosek »

Zdravim a pekne dopoledne preji :)

:arrow: Havet tam je, jen co je pravda :arcisit:

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Vložte do PC vsechny USB klice (flash disky, ext.disky apod.)
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

pajikus
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 16 zář 2010 09:04

Re: Trapim se trapim a nejde zikvidovat.Prosim,mrkne te mi n

#3 Příspěvek od pajikus »

tak combofix domakal,jen se mi nepodarilo zlikvidovat nod32 uplne.
ale zadny problem nenastal
tak vypis:

ComboFix 10-09-15.01 - paja 16.09.2010 10:52:17.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1014.623 [GMT 2:00]
Spuštěný z: c:\stazene\ComboFix.exe
AV: Eset NOD32 Antivirus 2.50 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Rezidentní štít AV je zapnutý

.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\paja\Data aplikací\Desktopicon
c:\documents and settings\paja\Data aplikací\Desktopicon\eBayShortcuts.exe
c:\documents and settings\paja\Data aplikací\logs.dat
c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
c:\windows\system32\install\Svchost.exe

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-08-16 do 2010-09-16 )))))))))))))))))))))))))))))))
.

2010-09-16 07:43 . 2010-09-16 08:21 -------- d-----w- c:\program files\trend micro
2010-09-16 07:43 . 2010-09-16 07:43 -------- d-----w- C:\rsit
2010-09-15 15:59 . 2010-04-09 11:16 535624 ----a-w- c:\windows\system32\pwNative.exe
2010-09-15 15:59 . 2010-04-09 11:16 16472 ------w- c:\windows\system32\pwdrvio.sys
2010-09-15 15:59 . 2010-04-09 11:16 11104 ------w- c:\windows\system32\pwdspio.sys
2010-09-15 11:51 . 2010-09-16 08:37 -------- d-----w- C:\stazene
2010-09-15 11:20 . 2010-09-15 11:17 58368 ----a-w- c:\windows\system32\MbrFix.exe
2010-09-15 06:23 . 2010-09-15 06:30 -------- d-----w- c:\windows\$hf_mig$
2010-09-11 15:26 . 2010-06-16 18:19 386560 ----a-w- c:\program files\ZaznamZvuku.exe
2010-09-09 09:33 . 2010-09-15 13:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-08 16:18 . 2010-09-08 16:18 -------- d-----w- C:\Intel
2010-08-22 10:39 . 2010-08-22 10:39 -------- d-----w- c:\documents and settings\paja\.jenny
2010-08-22 08:23 . 2010-08-22 08:23 -------- d-----w- c:\windows\SHELLNEW
2010-08-17 15:07 . 2010-08-17 15:07 -------- d-----w- c:\program files\AIDA32 - Enterprise System Information
2010-08-17 14:55 . 2010-08-17 14:58 -------- d-----w- c:\program files\MediaCoder
2010-08-17 12:08 . 2010-08-17 12:08 -------- d-sh--w- c:\documents and settings\paja\PrivacIE
2010-08-17 12:08 . 2010-08-17 12:08 -------- d-sh--w- c:\documents and settings\paja\IECompatCache
2010-08-17 12:08 . 2010-08-17 12:08 -------- d-sh--w- c:\documents and settings\paja\IETldCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-15 12:36 . 2009-01-22 11:15 79086 ----a-w- c:\windows\system32\perfc005.dat
2010-09-15 12:36 . 2009-01-22 11:15 430582 ----a-w- c:\windows\system32\perfh005.dat
2010-09-15 09:52 . 2010-09-15 09:52 0 ----a-w- c:\documents and settings\LocalService\exp2E0.tmp
2010-09-14 09:31 . 2010-09-14 09:31 0 ----a-w- c:\documents and settings\LocalService\exp950.tmp
2010-09-13 09:41 . 2010-07-04 15:31 -------- d-----w- c:\program files\Java
2010-09-13 09:26 . 2010-09-13 09:26 0 ----a-w- c:\documents and settings\LocalService\exp304.tmp
2010-09-12 08:55 . 2010-09-12 08:55 0 ----a-w- c:\documents and settings\LocalService\exp339.tmp
2010-09-11 08:13 . 2010-09-11 08:13 0 ----a-w- c:\documents and settings\LocalService\exp5A1.tmp
2010-09-10 07:37 . 2010-09-10 07:37 0 ----a-w- c:\documents and settings\LocalService\exp192.tmp
2010-09-09 07:22 . 2010-09-09 07:22 0 ----a-w- c:\documents and settings\LocalService\exp1F6.tmp
2010-09-08 06:40 . 2010-09-08 06:40 0 ----a-w- c:\documents and settings\LocalService\exp13E.tmp
2010-09-07 06:25 . 2010-09-07 06:25 0 ----a-w- c:\documents and settings\LocalService\exp376.tmp
2010-09-06 06:12 . 2010-09-06 06:12 0 ----a-w- c:\documents and settings\LocalService\exp26E.tmp
2010-09-04 17:34 . 2010-09-04 17:34 0 ----a-w- c:\documents and settings\LocalService\expDF.tmp
2010-09-03 13:55 . 2010-09-03 13:55 0 ----a-w- c:\documents and settings\LocalService\exp16B.tmp
2010-09-01 14:27 . 2010-09-01 14:27 0 ----a-w- c:\documents and settings\LocalService\exp3B8.tmp
2010-08-31 13:37 . 2010-08-31 13:37 0 ----a-w- c:\documents and settings\LocalService\exp477.tmp
2010-08-30 12:53 . 2010-08-30 12:53 0 ----a-w- c:\documents and settings\LocalService\expDA.tmp
2010-08-29 11:45 . 2010-08-29 11:45 0 ----a-w- c:\documents and settings\LocalService\exp799.tmp
2010-08-28 11:15 . 2010-08-28 11:15 0 ----a-w- c:\documents and settings\LocalService\expFF.tmp
2010-08-27 10:35 . 2010-08-27 10:35 0 ----a-w- c:\documents and settings\LocalService\exp451.tmp
2010-08-26 09:58 . 2010-08-26 09:58 0 ----a-w- c:\documents and settings\LocalService\exp497.tmp
2010-08-24 19:06 . 2010-08-24 19:06 0 ----a-w- c:\documents and settings\LocalService\exp24.tmp
2010-08-23 09:51 . 2010-08-23 09:51 0 ----a-w- c:\documents and settings\LocalService\exp2B1.tmp
2010-08-22 09:18 . 2010-08-22 09:18 0 ----a-w- c:\documents and settings\LocalService\exp5A9.tmp
2010-08-21 08:20 . 2010-08-21 08:20 0 ----a-w- c:\documents and settings\LocalService\exp12.tmp
2010-08-19 16:23 . 2010-08-19 16:23 0 ----a-w- c:\documents and settings\LocalService\exp11F8.tmp
2010-08-18 15:30 . 2010-08-18 15:30 0 ----a-w- c:\documents and settings\LocalService\exp12E0.tmp
2010-08-17 15:28 . 2010-08-17 15:28 0 ----a-w- c:\documents and settings\LocalService\exp14BF.tmp
2010-08-17 13:17 . 2009-01-22 11:15 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 15:06 . 2010-08-16 15:06 0 ----a-w- c:\documents and settings\LocalService\expF19.tmp
2010-08-15 14:37 . 2010-08-15 14:37 0 ----a-w- c:\documents and settings\LocalService\expDD8.tmp
2010-08-14 15:40 . 2010-07-01 13:09 -------- d-----w- c:\program files\viphone communicator
2010-08-14 14:10 . 2010-08-14 14:10 0 ----a-w- c:\documents and settings\LocalService\exp8D9.tmp
2010-08-13 13:32 . 2010-08-13 13:32 0 ----a-w- c:\documents and settings\LocalService\exp90.tmp
2010-08-13 13:04 . 2010-08-13 13:04 -------- d-----w- c:\program files\xat.com JPEG Optimizer
2010-08-13 12:20 . 2010-07-01 10:39 -------- d-----w- c:\program files\TightVNC
2010-08-12 13:04 . 2010-08-12 12:48 -------- d-----w- c:\program files\ESET
2010-08-12 12:51 . 2010-08-12 12:51 0 ----a-w- c:\documents and settings\LocalService\exp3.tmp
2010-08-12 12:48 . 2010-07-29 11:15 270336 ----a-w- c:\windows\system32\imon.dll
2010-08-12 12:48 . 2010-07-29 11:15 502208 ----a-w- c:\windows\system32\drivers\amon.sys
2010-08-10 09:15 . 2010-08-10 08:50 -------- d-----w- c:\program files\pebuilder3110a
2010-08-08 07:57 . 2010-08-08 07:57 -------- d-----w- c:\program files\MSXML 6.0
2010-08-03 16:08 . 2010-07-04 15:28 -------- d-----w- c:\program files\FreeRapid-0.83
2010-07-30 16:14 . 2010-07-30 16:13 -------- d-----w- c:\program files\Kleptomania
2010-07-30 08:25 . 2010-07-30 08:15 733827072 ----a-w- c:\documents and settings\LocalService\HTT9EC.tmp
2010-07-30 08:25 . 2010-07-30 08:04 825281048 ----a-w- c:\documents and settings\LocalService\HTT913.tmp
2010-07-28 16:27 . 2009-01-22 03:22 84584 ----a-w- c:\windows\SOUNDMAN.EXE
2010-07-28 16:27 . 2009-01-22 03:22 359016 ----a-w- c:\windows\vncutil.exe
2010-07-28 16:27 . 2009-01-22 03:22 1833576 ----a-w- c:\windows\SkyTel.exe
2010-07-28 16:27 . 2009-01-22 03:22 1489512 ----a-w- c:\windows\RtlUpd.exe
2010-07-28 16:27 . 2009-01-22 03:22 9721960 ----a-w- c:\windows\RTLCPL.EXE
2010-07-28 16:27 . 2009-01-22 03:22 6108776 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
2010-07-28 16:27 . 2009-01-22 03:22 53864 ----a-w- c:\windows\system32\RtkCoInstXP.dll
2010-07-28 16:27 . 2009-01-22 03:22 129640 ----a-w- c:\windows\RtkAudioService.exe
2010-07-28 16:27 . 2009-01-22 03:22 19557480 ----a-w- c:\windows\RTHDCPL.EXE
2010-07-28 16:27 . 2009-01-22 03:22 2180712 ----a-w- c:\windows\MicCal.exe
2010-07-28 16:27 . 2009-01-22 03:22 64104 ----a-w- c:\windows\ALCMTR.EXE
2010-07-28 16:27 . 2009-01-22 03:22 2815592 ----a-w- c:\windows\ALCWZRD.EXE
2010-07-27 11:54 . 2009-01-22 03:22 1251944 ----a-w- c:\windows\RtlExUpd.dll
2010-07-25 15:27 . 2009-01-22 02:30 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-07-25 15:27 . 2009-01-22 02:30 2378 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-07-25 14:35 . 2010-07-25 14:21 -------- d-----w- c:\program files\AVS4YOU
2010-07-25 14:23 . 2010-07-25 14:22 -------- d-----w- c:\program files\Common Files\AVSMedia
2010-07-22 15:46 . 2009-01-22 11:15 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 06:19 . 2008-05-05 05:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
2010-07-18 14:46 . 2010-07-18 14:46 73970 ----a-w- c:\program files\lang_cz_cz.xml
2010-07-17 03:00 . 2010-07-04 15:31 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-01 16:31 . 2010-07-01 16:31 722416 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-07-01 13:47 . 2010-07-01 11:15 1243680 ----a-w- c:\windows\system32\AutoPartNt.exe
2010-07-01 11:14 . 2009-01-22 02:30 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2010-07-01 10:59 . 2010-07-01 10:59 395744 ----a-w- c:\windows\system32\drivers\timntr.sys
2010-07-01 10:59 . 2010-07-01 10:59 39264 ----a-w- c:\windows\system32\drivers\tifsfilt.sys
2010-07-01 10:59 . 2010-07-01 10:59 114048 ----a-w- c:\windows\system32\drivers\snapman.sys
2010-06-30 12:33 . 2009-01-22 11:15 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-28 08:00 . 2010-07-01 13:53 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-06-25 10:39 . 2008-09-09 10:51 2252 ----a-w- c:\windows\CLEANUP.CMD
2010-06-24 12:27 . 2009-01-22 11:15 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 09:02 . 2009-01-22 11:15 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2009-01-22 11:15 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-18 17:47 . 2009-01-22 11:15 293376 ----a-w- c:\windows\system32\winsrv.dll
2009-03-09 18:09 . 2010-07-01 14:14 37376 ----a-w- c:\program files\win32whois.exe
2009-03-09 18:09 . 2010-07-01 14:13 204800 ----a-w- c:\program files\Restoration.exe
2009-03-09 18:09 . 2010-07-01 14:12 6790400 ----a-w- c:\program files\Foxit Reader.exe
2007-08-18 08:28 . 2010-07-01 12:51 4316160 ----a-w- c:\program files\mplayerc.exe
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AzMixerSel"="c:\program files\Realtek\Audio\Drivers\AzMixerSel.exe" [2006-01-25 53248]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2006-10-19 1183656]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2006-10-19 1958800]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2009-10-27 365560]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2010-08-12 917504]
"RTHDCPL"="RTHDCPL.EXE" [2010-07-28 19557480]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Miranda IM\\miranda32.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\VoipDiscount.com\\VoipDiscount\\VoipDiscount.exe"=
"c:\\Program Files\\viphone communicator\\viphone communicator.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\frd.exe"=
"c:\\Program Files\\TightVNC\\WinVNC.exe"=

S2 gupdate;Služba Google Update (gupdate); [x]
S2 RS_Service;Raw Socket Service; [x]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [22.1.2009 5:22 1691480]
S3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [15.9.2010 17:59 16472]
S3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [15.9.2010 17:59 11104]
S3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [22.1.2009 5:24 160256]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
S3 TridDev;USB Hybrid TV Device (TM6000);c:\windows\system32\drivers\Triddev.sys [7.4.2006 12:54 3584]
S3 TridVid;USB Hybrid TV Receiver (TM6000);c:\windows\system32\drivers\TridVid.sys [7.4.2006 12:54 189568]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [1.7.2010 18:31 722416]
.
Obsah adresáře 'Naplánované úlohy'

2010-09-16 c:\windows\Tasks\User_Feed_Synchronization-{A46FDBE0-98BB-4409-8AF3-AF576ACE6C93}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\pchealth\helpctr\System\panels\blank.htm
uStart Page = hxxp://www.atlas.cz/
mLocal Page = c:\windows\pchealth\helpctr\System\panels\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: WikiKomentáře Google...
LSP: imon.dll
DPF: {888078C6-70B2-4F88-8EE7-1F50DDEA6120} - hxxps://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKLM-Run-HybridTM_A - c:\program files\HybridTM_IR(A)\RC620_A.exe
SafeBoot-mcmscsvc
SafeBoot-MCODS
ActiveSetup-{6C27YN54-S7M6-KTE4-GXK3-CAN1M6121255} - c:\windows\system32\install\svchost.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-16 10:57
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'lsass.exe'(736)
c:\windows\system32\relog_ap.dll
c:\windows\system32\imon.dll
c:\program files\Eset\pr_imon.dll
.
Celkový čas: 2010-09-16 10:59:16
ComboFix-quarantined-files.txt 2010-09-16 08:59

Před spuštěním: Volných bajtů: 100 902 653 952
Po spuštění: Volných bajtů: 101 091 196 928

WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - E4A83503DE1091C07534BF063114C5A9

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Trapim se trapim a nejde zikvidovat.Prosim,mrkne te mi n

#4 Příspěvek od vyosek »

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "UnlockerAssistant"=-
    "SunJavaUpdateSched"=-
    
    Driver::
    RS_Service
    gupdate
    
    DDS::
    uLocal Page = c:\windows\pchealth\helpctr\System\panels\blank.htm
    mLocal Page = c:\windows\pchealth\helpctr\System\panels\blank.htm
    
    RegLock::
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

pajikus
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 16 zář 2010 09:04

Re: Trapim se trapim a nejde zikvidovat.Prosim,mrkne te mi n

#5 Příspěvek od pajikus »

Moc diky,kazdopadne ja sem dobrej.

ComboFix 10-09-15.01 - paja 16.09.2010 12:54:56.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1014.615 [GMT 2:00]
Spuštěný z: c:\documents and settings\paja\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\stazene\CFScript.txt
AV: Eset NOD32 Antivirus 2.50 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Rezidentní štít AV je zapnutý

.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_GUPDATE
-------\Legacy_RS_SERVICE
-------\Service_gupdate
-------\Service_RS_Service


((((((((((((((((((((((((( Soubory vytvořené od 2010-08-16 do 2010-09-16 )))))))))))))))))))))))))))))))
.

2010-09-16 07:43 . 2010-09-16 08:21 -------- d-----w- c:\program files\trend micro
2010-09-16 07:43 . 2010-09-16 07:43 -------- d-----w- C:\rsit
2010-09-15 15:59 . 2010-04-09 11:16 535624 ----a-w- c:\windows\system32\pwNative.exe
2010-09-15 15:59 . 2010-04-09 11:16 16472 ------w- c:\windows\system32\pwdrvio.sys
2010-09-15 15:59 . 2010-04-09 11:16 11104 ------w- c:\windows\system32\pwdspio.sys
2010-09-15 11:51 . 2010-09-16 10:54 -------- d-----w- C:\stazene
2010-09-15 11:20 . 2010-09-15 11:17 58368 ----a-w- c:\windows\system32\MbrFix.exe
2010-09-15 06:23 . 2010-09-15 06:30 -------- d-----w- c:\windows\$hf_mig$
2010-09-11 15:26 . 2010-06-16 18:19 386560 ----a-w- c:\program files\ZaznamZvuku.exe
2010-09-09 09:33 . 2010-09-15 13:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-08 16:18 . 2010-09-08 16:18 -------- d-----w- C:\Intel
2010-08-22 10:39 . 2010-08-22 10:39 -------- d-----w- c:\documents and settings\paja\.jenny
2010-08-22 08:23 . 2010-08-22 08:23 -------- d-----w- c:\windows\SHELLNEW
2010-08-17 15:07 . 2010-08-17 15:07 -------- d-----w- c:\program files\AIDA32 - Enterprise System Information
2010-08-17 14:55 . 2010-08-17 14:58 -------- d-----w- c:\program files\MediaCoder
2010-08-17 12:08 . 2010-08-17 12:08 -------- d-sh--w- c:\documents and settings\paja\PrivacIE
2010-08-17 12:08 . 2010-08-17 12:08 -------- d-sh--w- c:\documents and settings\paja\IECompatCache
2010-08-17 12:08 . 2010-08-17 12:08 -------- d-sh--w- c:\documents and settings\paja\IETldCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-16 10:12 . 2010-09-16 10:12 0 ----a-w- c:\documents and settings\LocalService\exp16.tmp
2010-09-15 12:36 . 2009-01-22 11:15 79086 ----a-w- c:\windows\system32\perfc005.dat
2010-09-15 12:36 . 2009-01-22 11:15 430582 ----a-w- c:\windows\system32\perfh005.dat
2010-09-15 09:52 . 2010-09-15 09:52 0 ----a-w- c:\documents and settings\LocalService\exp2E0.tmp
2010-09-14 09:31 . 2010-09-14 09:31 0 ----a-w- c:\documents and settings\LocalService\exp950.tmp
2010-09-13 09:41 . 2010-07-04 15:31 -------- d-----w- c:\program files\Java
2010-09-13 09:26 . 2010-09-13 09:26 0 ----a-w- c:\documents and settings\LocalService\exp304.tmp
2010-09-12 08:55 . 2010-09-12 08:55 0 ----a-w- c:\documents and settings\LocalService\exp339.tmp
2010-09-11 08:13 . 2010-09-11 08:13 0 ----a-w- c:\documents and settings\LocalService\exp5A1.tmp
2010-09-10 07:37 . 2010-09-10 07:37 0 ----a-w- c:\documents and settings\LocalService\exp192.tmp
2010-09-09 07:22 . 2010-09-09 07:22 0 ----a-w- c:\documents and settings\LocalService\exp1F6.tmp
2010-09-08 06:40 . 2010-09-08 06:40 0 ----a-w- c:\documents and settings\LocalService\exp13E.tmp
2010-09-07 06:25 . 2010-09-07 06:25 0 ----a-w- c:\documents and settings\LocalService\exp376.tmp
2010-09-06 06:12 . 2010-09-06 06:12 0 ----a-w- c:\documents and settings\LocalService\exp26E.tmp
2010-09-04 17:34 . 2010-09-04 17:34 0 ----a-w- c:\documents and settings\LocalService\expDF.tmp
2010-09-03 13:55 . 2010-09-03 13:55 0 ----a-w- c:\documents and settings\LocalService\exp16B.tmp
2010-09-01 14:27 . 2010-09-01 14:27 0 ----a-w- c:\documents and settings\LocalService\exp3B8.tmp
2010-08-31 13:37 . 2010-08-31 13:37 0 ----a-w- c:\documents and settings\LocalService\exp477.tmp
2010-08-30 12:53 . 2010-08-30 12:53 0 ----a-w- c:\documents and settings\LocalService\expDA.tmp
2010-08-29 11:45 . 2010-08-29 11:45 0 ----a-w- c:\documents and settings\LocalService\exp799.tmp
2010-08-28 11:15 . 2010-08-28 11:15 0 ----a-w- c:\documents and settings\LocalService\expFF.tmp
2010-08-27 10:35 . 2010-08-27 10:35 0 ----a-w- c:\documents and settings\LocalService\exp451.tmp
2010-08-26 09:58 . 2010-08-26 09:58 0 ----a-w- c:\documents and settings\LocalService\exp497.tmp
2010-08-24 19:06 . 2010-08-24 19:06 0 ----a-w- c:\documents and settings\LocalService\exp24.tmp
2010-08-23 09:51 . 2010-08-23 09:51 0 ----a-w- c:\documents and settings\LocalService\exp2B1.tmp
2010-08-22 09:18 . 2010-08-22 09:18 0 ----a-w- c:\documents and settings\LocalService\exp5A9.tmp
2010-08-21 08:20 . 2010-08-21 08:20 0 ----a-w- c:\documents and settings\LocalService\exp12.tmp
2010-08-19 16:23 . 2010-08-19 16:23 0 ----a-w- c:\documents and settings\LocalService\exp11F8.tmp
2010-08-18 15:30 . 2010-08-18 15:30 0 ----a-w- c:\documents and settings\LocalService\exp12E0.tmp
2010-08-17 15:28 . 2010-08-17 15:28 0 ----a-w- c:\documents and settings\LocalService\exp14BF.tmp
2010-08-17 13:17 . 2009-01-22 11:15 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 15:06 . 2010-08-16 15:06 0 ----a-w- c:\documents and settings\LocalService\expF19.tmp
2010-08-15 14:37 . 2010-08-15 14:37 0 ----a-w- c:\documents and settings\LocalService\expDD8.tmp
2010-08-14 15:40 . 2010-07-01 13:09 -------- d-----w- c:\program files\viphone communicator
2010-08-14 14:10 . 2010-08-14 14:10 0 ----a-w- c:\documents and settings\LocalService\exp8D9.tmp
2010-08-13 13:32 . 2010-08-13 13:32 0 ----a-w- c:\documents and settings\LocalService\exp90.tmp
2010-08-13 13:04 . 2010-08-13 13:04 -------- d-----w- c:\program files\xat.com JPEG Optimizer
2010-08-13 12:20 . 2010-07-01 10:39 -------- d-----w- c:\program files\TightVNC
2010-08-12 13:04 . 2010-08-12 12:48 -------- d-----w- c:\program files\ESET
2010-08-12 12:51 . 2010-08-12 12:51 0 ----a-w- c:\documents and settings\LocalService\exp3.tmp
2010-08-12 12:48 . 2010-07-29 11:15 270336 ----a-w- c:\windows\system32\imon.dll
2010-08-12 12:48 . 2010-07-29 11:15 502208 ----a-w- c:\windows\system32\drivers\amon.sys
2010-08-10 09:15 . 2010-08-10 08:50 -------- d-----w- c:\program files\pebuilder3110a
2010-08-08 07:57 . 2010-08-08 07:57 -------- d-----w- c:\program files\MSXML 6.0
2010-08-03 16:08 . 2010-07-04 15:28 -------- d-----w- c:\program files\FreeRapid-0.83
2010-07-30 16:14 . 2010-07-30 16:13 -------- d-----w- c:\program files\Kleptomania
2010-07-30 08:25 . 2010-07-30 08:15 733827072 ----a-w- c:\documents and settings\LocalService\HTT9EC.tmp
2010-07-30 08:25 . 2010-07-30 08:04 825281048 ----a-w- c:\documents and settings\LocalService\HTT913.tmp
2010-07-28 16:27 . 2009-01-22 03:22 84584 ----a-w- c:\windows\SOUNDMAN.EXE
2010-07-28 16:27 . 2009-01-22 03:22 359016 ----a-w- c:\windows\vncutil.exe
2010-07-28 16:27 . 2009-01-22 03:22 1833576 ----a-w- c:\windows\SkyTel.exe
2010-07-28 16:27 . 2009-01-22 03:22 1489512 ----a-w- c:\windows\RtlUpd.exe
2010-07-28 16:27 . 2009-01-22 03:22 9721960 ----a-w- c:\windows\RTLCPL.EXE
2010-07-28 16:27 . 2009-01-22 03:22 6108776 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
2010-07-28 16:27 . 2009-01-22 03:22 53864 ----a-w- c:\windows\system32\RtkCoInstXP.dll
2010-07-28 16:27 . 2009-01-22 03:22 129640 ----a-w- c:\windows\RtkAudioService.exe
2010-07-28 16:27 . 2009-01-22 03:22 19557480 ----a-w- c:\windows\RTHDCPL.EXE
2010-07-28 16:27 . 2009-01-22 03:22 2180712 ----a-w- c:\windows\MicCal.exe
2010-07-28 16:27 . 2009-01-22 03:22 64104 ----a-w- c:\windows\ALCMTR.EXE
2010-07-28 16:27 . 2009-01-22 03:22 2815592 ----a-w- c:\windows\ALCWZRD.EXE
2010-07-27 11:54 . 2009-01-22 03:22 1251944 ----a-w- c:\windows\RtlExUpd.dll
2010-07-25 15:27 . 2009-01-22 02:30 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-07-25 15:27 . 2009-01-22 02:30 2378 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-07-25 14:35 . 2010-07-25 14:21 -------- d-----w- c:\program files\AVS4YOU
2010-07-25 14:23 . 2010-07-25 14:22 -------- d-----w- c:\program files\Common Files\AVSMedia
2010-07-22 15:46 . 2009-01-22 11:15 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 06:19 . 2008-05-05 05:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
2010-07-18 14:46 . 2010-07-18 14:46 73970 ----a-w- c:\program files\lang_cz_cz.xml
2010-07-17 03:00 . 2010-07-04 15:31 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-01 16:31 . 2010-07-01 16:31 722416 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-07-01 13:47 . 2010-07-01 11:15 1243680 ----a-w- c:\windows\system32\AutoPartNt.exe
2010-07-01 11:14 . 2009-01-22 02:30 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2010-07-01 10:59 . 2010-07-01 10:59 395744 ----a-w- c:\windows\system32\drivers\timntr.sys
2010-07-01 10:59 . 2010-07-01 10:59 39264 ----a-w- c:\windows\system32\drivers\tifsfilt.sys
2010-07-01 10:59 . 2010-07-01 10:59 114048 ----a-w- c:\windows\system32\drivers\snapman.sys
2010-06-30 12:33 . 2009-01-22 11:15 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-28 08:00 . 2010-07-01 13:53 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-06-25 10:39 . 2008-09-09 10:51 2252 ----a-w- c:\windows\CLEANUP.CMD
2010-06-24 12:27 . 2009-01-22 11:15 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 09:02 . 2009-01-22 11:15 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2009-01-22 11:15 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-18 17:47 . 2009-01-22 11:15 293376 ----a-w- c:\windows\system32\winsrv.dll
2009-03-09 18:09 . 2010-07-01 14:14 37376 ----a-w- c:\program files\win32whois.exe
2009-03-09 18:09 . 2010-07-01 14:13 204800 ----a-w- c:\program files\Restoration.exe
2009-03-09 18:09 . 2010-07-01 14:12 6790400 ----a-w- c:\program files\Foxit Reader.exe
2007-08-18 08:28 . 2010-07-01 12:51 4316160 ----a-w- c:\program files\mplayerc.exe
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AzMixerSel"="c:\program files\Realtek\Audio\Drivers\AzMixerSel.exe" [2006-01-25 53248]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2006-10-19 1183656]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2006-10-19 1958800]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2009-10-27 365560]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2010-08-12 917504]
"RTHDCPL"="RTHDCPL.EXE" [2010-07-28 19557480]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Miranda IM\\miranda32.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\VoipDiscount.com\\VoipDiscount\\VoipDiscount.exe"=
"c:\\Program Files\\viphone communicator\\viphone communicator.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\frd.exe"=
"c:\\Program Files\\TightVNC\\WinVNC.exe"=

S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [22.1.2009 5:22 1691480]
S3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [15.9.2010 17:59 16472]
S3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [15.9.2010 17:59 11104]
S3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [22.1.2009 5:24 160256]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
S3 TridDev;USB Hybrid TV Device (TM6000);c:\windows\system32\drivers\Triddev.sys [7.4.2006 12:54 3584]
S3 TridVid;USB Hybrid TV Receiver (TM6000);c:\windows\system32\drivers\TridVid.sys [7.4.2006 12:54 189568]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [1.7.2010 18:31 722416]
.
Obsah adresáře 'Naplánované úlohy'

2010-09-16 c:\windows\Tasks\User_Feed_Synchronization-{A46FDBE0-98BB-4409-8AF3-AF576ACE6C93}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.atlas.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: WikiKomentáře Google...
LSP: imon.dll
DPF: {888078C6-70B2-4F88-8EE7-1F50DDEA6120} - hxxps://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-16 13:01
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'lsass.exe'(740)
c:\windows\system32\relog_ap.dll
c:\windows\system32\imon.dll
c:\program files\Eset\pr_imon.dll

- - - - - - - > 'explorer.exe'(3640)
c:\windows\system32\webcheck.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Eset\nod32krn.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\RTHDCPL.EXE
c:\program files\ArcSoft\TotalMedia 3\TMMonitor.exe
.
**************************************************************************
.
Celkový čas: 2010-09-16 13:04:25 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-09-16 11:04

Před spuštěním: Volných bajtů: 101 115 330 560
Po spuštění: Volných bajtů: 101 069 496 320

- - End Of File - - FABBABDB2DD4DE26313A08243628B644

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Trapim se trapim a nejde zikvidovat.Prosim,mrkne te mi n

#6 Příspěvek od vyosek »

:arrow: Stahnete OTM (viz muj podpis)
  • Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
  • Kód: Vybrat vše

    :files
    c:\documents and settings\LocalService\exp*.tmp
    c:\documents and settings\LocalService\HTT9EC.tmp
    c:\documents and settings\LocalService\HTT913.tmp
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp /s
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
  • Kliknete na cervene tlacitko MoveIt!
  • Sem pote dejte obsah okna Results (pod zelenou carou)
  • Pokud budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles
:arrow: Napiste jak se chova PC
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

pajikus
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 16 zář 2010 09:04

Re: Trapim se trapim a nejde zikvidovat.Prosim,mrkne te mi n

#7 Příspěvek od pajikus »

toz tu je

All processes killed
========== FILES ==========
c:\documents and settings\LocalService\exp11F8.tmp moved successfully.
c:\documents and settings\LocalService\exp12.tmp moved successfully.
c:\documents and settings\LocalService\exp12E0.tmp moved successfully.
c:\documents and settings\LocalService\exp13E.tmp moved successfully.
c:\documents and settings\LocalService\exp14BF.tmp moved successfully.
c:\documents and settings\LocalService\exp16.tmp moved successfully.
c:\documents and settings\LocalService\exp16B.tmp moved successfully.
c:\documents and settings\LocalService\exp192.tmp moved successfully.
c:\documents and settings\LocalService\exp1F6.tmp moved successfully.
c:\documents and settings\LocalService\exp24.tmp moved successfully.
c:\documents and settings\LocalService\exp26E.tmp moved successfully.
c:\documents and settings\LocalService\exp2B1.tmp moved successfully.
c:\documents and settings\LocalService\exp2E0.tmp moved successfully.
c:\documents and settings\LocalService\exp3.tmp moved successfully.
c:\documents and settings\LocalService\exp304.tmp moved successfully.
c:\documents and settings\LocalService\exp339.tmp moved successfully.
c:\documents and settings\LocalService\exp376.tmp moved successfully.
c:\documents and settings\LocalService\exp3B8.tmp moved successfully.
c:\documents and settings\LocalService\exp451.tmp moved successfully.
c:\documents and settings\LocalService\exp477.tmp moved successfully.
c:\documents and settings\LocalService\exp497.tmp moved successfully.
c:\documents and settings\LocalService\exp5A1.tmp moved successfully.
c:\documents and settings\LocalService\exp5A9.tmp moved successfully.
c:\documents and settings\LocalService\exp799.tmp moved successfully.
c:\documents and settings\LocalService\exp8D9.tmp moved successfully.
c:\documents and settings\LocalService\exp90.tmp moved successfully.
c:\documents and settings\LocalService\exp950.tmp moved successfully.
c:\documents and settings\LocalService\expDA.tmp moved successfully.
c:\documents and settings\LocalService\expDD8.tmp moved successfully.
c:\documents and settings\LocalService\expDF.tmp moved successfully.
c:\documents and settings\LocalService\expF19.tmp moved successfully.
c:\documents and settings\LocalService\expFF.tmp moved successfully.
c:\documents and settings\LocalService\HTT9EC.tmp moved successfully.
c:\documents and settings\LocalService\HTT913.tmp moved successfully.
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP104.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP13.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP169.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1D1.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1DF.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP204.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP225.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP243.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP26F.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2AB.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2FD.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP345.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP4C0.tmp folder moved successfully.
C:\WINDOWS\system32\CONFIG.TMP moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 75 bytes

User: All Users

User: Default User
->Temp folder emptied: 55391936 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 75 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32835 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: paja
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 8510518 bytes
->Java cache emptied: 1987855 bytes
->Flash cache emptied: 22647 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33438 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 63,00 mb


[EMPTYFLASH]

User: Administrator
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Flash cache emptied: 0 bytes

User: LocalService

User: NetworkService

User: paja
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0,00 mb

Restore points cleared and new OTL Restore Point set!

OTL by OldTimer - Version 3.2.12.1 log created on 09162010_143831

Files\Folders moved on Reboot...
C:\Documents and Settings\paja\Local Settings\Temporary Internet Files\Content.IE5\TDP4NQLM\afr[1].htm moved successfully.
C:\Documents and Settings\paja\Local Settings\Temporary Internet Files\Content.IE5\EIZ27IYZ\viewtopic[1].htm moved successfully.
C:\Documents and Settings\paja\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
C:\Documents and Settings\paja\Local Settings\Temporary Internet Files\SuggestedSites.dat moved successfully.

Registry entries deleted on Reboot...

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Trapim se trapim a nejde zikvidovat.Prosim,mrkne te mi n

#8 Příspěvek od vyosek »

Fajn, jak se chova PC :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

pajikus
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 16 zář 2010 09:04

Re: Trapim se trapim a nejde zikvidovat.Prosim,mrkne te mi n

#9 Příspěvek od pajikus »

v pohode,diky moc.
ani jsem netusil,kolik toho tam je.a to mam nod32,njn,nejde vsechno.....
diky moc

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Trapim se trapim a nejde zikvidovat.Prosim,mrkne te mi n

#10 Příspěvek od vyosek »

Ani ten nejlepsi antivir Vas neochrani pokud nepouzivate pri surfovani rozum a krmite si PC crackam...

:arrow: Odinstalujte Combofix
  • Start - Spustit (nebo pouzijte klavesobou zkratku Win+R)
  • Napiste ComboFix /Uninstall
  • Stisknete Enter
  • Tohle smaze Combofix a jeho slozky
:arrow: T-Cleaner http://sweb.cz/Marinus/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner (viz muj podpis), pri instalaci dejte fajfku pryc u yahoo toolbaru
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za 14 dni

:arrow: Havet se usadila v bodech obnoveni - smazte je dle navodu kolegy riffa http://www.viry.cz/forum/viewtopic.php?f=11&t=47040

:arrow: Vlozte novy log ze RSITu
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

pajikus
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 16 zář 2010 09:04

Re: Trapim se trapim a nejde zikvidovat.Prosim,mrkne te mi n

#11 Příspěvek od pajikus »

Logfile of random's system information tool 1.08 (written by random/random)
Run by paja at 2010-09-16 17:22:07
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 99 GB (71%) free of 138 GB
Total RAM: 1014 MB (59% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:22:16, on 16.9.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\totalcmd\TOTALCMD.EXE
C:\stazene\RSIT.exe
C:\Program Files\trend micro\paja.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.atlas.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkID=178591
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acer VCM.lnk = ?
O4 - Global Startup: TMMonitor.lnk = C:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (file missing)
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (file missing)
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {888078C6-70B2-4F88-8EE7-1F50DDEA6120} (CeWe Color AG & Co. OHG Control) - https://as.photoprintit.de/ips-opdata/a ... oader6.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - (no file)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 6880 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\User_Feed_Synchronization-{A46FDBE0-98BB-4409-8AF3-AF576ACE6C93}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-04 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-08-04 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} -

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AzMixerSel"=C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe [2006-01-25 53248]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2008-02-28 141848]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2008-02-28 166424]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2008-02-28 137752]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2008-04-14 208952]
"MSPY2002"=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [2008-04-14 59392]
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2008-04-14 455168]
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2008-04-14 455168]
"TrueImageMonitor.exe"=C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2006-10-19 1183656]
"AcronisTimounterMonitor"=C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [2006-10-19 1958800]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2009-10-27 365560]
"nod32kui"=C:\Program Files\Eset\nod32kui.exe [2010-08-12 917504]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2010-07-28 19557480]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Acer VCM.lnk - C:\Program Files\Acer\Acer VCM\AcerVCM.exe
TMMonitor.lnk - C:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2008-02-15 208896]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Miranda IM\miranda32.exe"="C:\Program Files\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\VoipDiscount.com\VoipDiscount\VoipDiscount.exe"="C:\Program Files\VoipDiscount.com\VoipDiscount\VoipDiscount.exe:*:Enabled:VoipDiscount"
"C:\Program Files\viphone communicator\viphone communicator.exe"="C:\Program Files\viphone communicator\viphone communicator.exe:*:Enabled:viphone communicator"
"C:\Program Files\ArcSoft\TotalMedia 3\TotalMedia.exe"="C:\Program Files\ArcSoft\TotalMedia 3\TotalMedia.exe:LocalSubNet:Enabled:ArcSoft TotalMedia 3"
"C:\Program Files\BitLord\BitLord.exe"="C:\Program Files\BitLord\BitLord.exe:*:Enabled:BitLord"
"C:\Program Files\Java\jre6\launch4j-tmp\frd.exe"="C:\Program Files\Java\jre6\launch4j-tmp\frd.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\TightVNC\WinVNC.exe"="C:\Program Files\TightVNC\WinVNC.exe:*:Enabled:TightVNC Win32 Server"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2010-09-16 17:22:07 ----D---- C:\rsit
2010-09-16 17:19:46 ----D---- C:\Program Files\CCleaner
2010-09-16 16:57:37 ----D---- C:\WINDOWS\Minidump
2010-09-16 13:57:28 ----SHD---- C:\RECYCLER
2010-09-16 13:04:28 ----D---- C:\WINDOWS\temp
2010-09-16 10:51:15 ----RASHD---- C:\cmdcons
2010-09-16 09:43:14 ----D---- C:\Program Files\trend micro
2010-09-15 17:59:13 ----A---- C:\WINDOWS\system32\pwNative.exe
2010-09-15 17:59:12 ----N---- C:\WINDOWS\system32\pwdspio.sys
2010-09-15 17:59:12 ----N---- C:\WINDOWS\system32\pwdrvio.sys
2010-09-15 17:43:59 ----ASH---- C:\hiberfil.sys
2010-09-15 13:51:58 ----D---- C:\stazene
2010-09-15 13:20:39 ----A---- C:\WINDOWS\system32\MbrFix.exe
2010-09-15 08:30:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2259922$
2010-09-15 08:30:31 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2010-09-15 08:30:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2010-09-15 08:30:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2121546$
2010-09-15 08:30:07 ----HDC---- C:\WINDOWS\$NtUninstallKB982802$
2010-09-15 08:29:59 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2010-09-15 08:27:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2141007$
2010-09-15 08:23:47 ----D---- C:\WINDOWS\$hf_mig$
2010-09-13 11:41:05 ----A---- C:\WINDOWS\system32\javaws.exe
2010-09-13 11:41:05 ----A---- C:\WINDOWS\system32\javaw.exe
2010-09-13 11:41:05 ----A---- C:\WINDOWS\system32\java.exe
2010-09-11 17:26:07 ----A---- C:\Program Files\ZaznamZvuku.exe
2010-09-11 14:57:02 ----D---- C:\Documents and Settings\All Users\Data aplikací\NCH Swift Sound
2010-09-11 14:56:18 ----D---- C:\Documents and Settings\paja\Data aplikací\NCH Swift Sound
2010-09-09 11:33:04 ----HD---- C:\Program Files\InstallShield Installation Information
2010-08-24 11:39:10 ----D---- C:\Documents and Settings\paja\Data aplikací\Devices
2010-08-22 10:23:35 ----D---- C:\WINDOWS\SHELLNEW
2010-08-22 10:23:23 ----D---- C:\Program Files\Microsoft Office
2010-08-17 17:07:12 ----D---- C:\Program Files\AIDA32 - Enterprise System Information
2010-08-17 16:56:50 ----D---- C:\Documents and Settings\paja\Data aplikací\Broad Intelligence
2010-08-17 16:55:21 ----D---- C:\Program Files\MediaCoder

======List of files/folders modified in the last 1 months======

2010-09-16 17:20:33 ----D---- C:\WINDOWS\Debug
2010-09-16 17:20:33 ----D---- C:\WINDOWS
2010-09-16 17:19:46 ----RD---- C:\Program Files
2010-09-16 17:14:28 ----D---- C:\WINDOWS\system32\Restore
2010-09-16 17:14:28 ----D---- C:\WINDOWS\Prefetch
2010-09-16 17:10:12 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-09-16 17:09:47 ----AD---- C:\WINDOWS\system32
2010-09-16 17:09:45 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-09-16 16:54:09 ----D---- C:\WINDOWS\system32\CatRoot2
2010-09-16 16:54:01 ----AD---- C:\WINDOWS\system32\drivers
2010-09-16 14:38:50 ----SHD---- C:\System Volume Information
2010-09-16 14:38:34 ----D---- C:\WINDOWS\system32\drivers\etc
2010-09-16 13:02:00 ----A---- C:\WINDOWS\system.ini
2010-09-16 13:00:20 ----D---- C:\WINDOWS\system32\config
2010-09-16 12:57:36 ----D---- C:\WINDOWS\AppPatch
2010-09-16 12:57:35 ----D---- C:\Program Files\Common Files
2010-09-16 12:43:53 ----D---- C:\paja
2010-09-16 10:56:27 ----RSHD---- C:\WINDOWS\system32\install
2010-09-16 10:51:22 ----RASH---- C:\boot.ini
2010-09-15 18:11:02 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2010-09-15 15:54:18 ----SHD---- C:\WINDOWS\Installer
2010-09-15 12:25:42 ----D---- C:\Documents and Settings\All Users\Data aplikací\RFA_Backups
2010-09-15 10:50:21 ----A---- C:\WINDOWS\k-mania.Ini
2010-09-15 09:52:27 ----D---- C:\Documents and Settings
2010-09-15 09:12:14 ----D---- C:\WINDOWS\WinSxS
2010-09-15 08:30:42 ----HD---- C:\WINDOWS\inf
2010-09-15 08:30:33 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-09-15 08:27:31 ----A---- C:\WINDOWS\system32\MRT.exe
2010-09-14 13:37:34 ----SD---- C:\Documents and Settings\paja\Data aplikací\Microsoft
2010-09-13 11:41:01 ----D---- C:\Program Files\Java
2010-09-11 17:16:14 ----A---- C:\WINDOWS\win.ini
2010-09-11 15:49:10 ----SD---- C:\WINDOWS\Tasks
2010-09-10 08:39:53 ----D---- C:\WINDOWS\Network Diagnostic
2010-09-09 11:38:37 ----D---- C:\WINDOWS\system32\RTCOM
2010-09-09 11:33:11 ----D---- C:\WINDOWS\system32\Atheros_L1e
2010-08-23 09:53:11 ----D---- C:\Documents and Settings\paja\Data aplikací\ICQ
2010-08-22 12:46:19 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-08-22 11:05:14 ----RSD---- C:\WINDOWS\Fonts
2010-08-22 10:24:25 ----A---- C:\WINDOWS\ODBC.INI
2010-08-22 10:24:13 ----RSD---- C:\WINDOWS\assembly
2010-08-22 10:23:41 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-08-22 10:20:22 ----D---- C:\WINDOWS\system
2010-08-17 15:17:06 ----A---- C:\WINDOWS\system32\spoolsv.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-14 42368]
R0 agpCPQ;Filtr Compaq sběrnice AGP; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2008-04-14 44928]
R0 alim1541;Filtr ALI sběrnice AGP; C:\WINDOWS\system32\DRIVERS\alim1541.sys [2008-04-14 42752]
R0 amdagp;Ovladač filtru AMD portu AGP; C:\WINDOWS\system32\DRIVERS\amdagp.sys [2008-04-14 43008]
R0 cbidf;cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [2008-04-14 13952]
R0 iaStor;Intel AHCI Controller; C:\WINDOWS\system32\drivers\iaStor.sys [2010-01-08 331288]
R0 sisagp;Filtr SIS sběrnice AGP ; C:\WINDOWS\system32\DRIVERS\sisagp.sys [2008-04-14 40960]
R0 snapman;Acronis Snapshots Manager; C:\WINDOWS\system32\DRIVERS\snapman.sys [2010-07-01 114048]
R0 timounter;Acronis True Image Backup Archive Explorer; C:\WINDOWS\system32\DRIVERS\timntr.sys [2010-07-01 395744]
R0 viaagp;Filtr VIA sběrnice AGP ; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2008-04-14 42240]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032]
R2 AMON;AMON; \??\C:\WINDOWS\system32\drivers\amon.sys []
R2 tifsfilter;Acronis True Image FS Filter; C:\WINDOWS\system32\DRIVERS\tifsfilt.sys [2010-07-01 39264]
R3 AR5416;Atheros AR5008 Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\athw.sys [2010-01-06 1596768]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2008-02-15 5854752]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2010-07-28 6108776]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-14 121984]
S1 DritekPortIO;Dritek General Port I/O; C:\WINDOWS\system32\drivers\DritekPortIO.sys []
S3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 CrystalSysInfo;CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys []
S3 int15.sys;int15.sys; C:\WINDOWS\system32\drivers\int15.sys.sys []
S3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l1e51x86.sys [2010-03-19 46632]
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 MPE;Filtr MPE BDA; C:\WINDOWS\system32\DRIVERS\MPE.sys [2008-04-14 15232]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 pwdrvio;pwdrvio; \??\C:\WINDOWS\system32\pwdrvio.sys []
S3 pwdspio;pwdspio; \??\C:\WINDOWS\system32\pwdspio.sys []
S3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader; C:\WINDOWS\System32\Drivers\RTS5121.sys [2008-11-21 160256]
S3 Rts516xIR;Realtek IR Driver; C:\WINDOWS\system32\DRIVERS\Rts516xIR.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 TridDev;USB Hybrid TV Device (TM6000); C:\WINDOWS\system32\DRIVERS\Triddev.sys [2005-04-26 3584]
S3 TridVid;USB Hybrid TV Receiver (TM6000); C:\WINDOWS\system32\DRIVERS\TridVid.sys [2006-04-04 189568]
S3 USBCCID;Realtek Smartcard Reader Driver; C:\WINDOWS\system32\DRIVERS\Rts5161ccid.sys []
S3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-07-01 722416]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2009-10-27 660504]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2010-01-08 354840]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-07-17 153376]
R2 NOD32krn;NOD32 Kernel Service; C:\Program Files\Eset\nod32krn.exe [2010-08-12 495616]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 268288]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Trapim se trapim a nejde zikvidovat.Prosim,mrkne te mi n

#12 Příspěvek od vyosek »

:arrow: Kliknete na Start a pote Spustit, pripadne pouzijte klavesou zkratku Win+R
  • Vyskoci na Vas okenko, do ktereho zkopirujte text nize
  • Kód: Vybrat vše

    services.msc
  • Kliknete na OK
  • Najdete sluzby nize
  • Java Quick Starter
  • U kazde provedte toto
    • Klik na ni pravym mysidlem a zvolit Vlastnosti
    • Nyní klik na Zastavit
    • Typ spousteni nastavit na Zakazano
    • Potvrdte kliknutim na OK
:arrow: Otevrete si poznamkovy blok
  • Start->spustit->notepad
  • Vlozte text nize
  • Kód: Vybrat vše

    Windows Registry Editor Version 5.00
    
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{2318C2B1-4965-11d4-9B18-009027A5CD4F}"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{2670000A-7350-4f3c-8081-5663EE0C6C49}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype4com]
  • Soubor ulozte jako oprava.reg
  • Pri ukladani dejte ulozit jako typ Vsechny soubory (nastevni je uvedeno na obrazku nize)
  • Obrázek
  • Zavrit notepad a spustit dvojklikem oprava.reg
  • Pripadny dotaz na zmenu registru potvrdte
  • Okno jen problikne a opravi regsitry - soubor muzete smazat
:arrow: Z logu je patrno, ze nepouzivate firewall - doporucuji doinstalovat :arrow: Jinak log vypada cisty :wink:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

pajikus
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 16 zář 2010 09:04

Re: Trapim se trapim a nejde zikvidovat.Prosim,mrkne te mi n

#13 Příspěvek od pajikus »

nainstalovano kerio
snad bude pokoj
diky moooooc
pavel

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Trapim se trapim a nejde zikvidovat.Prosim,mrkne te mi n

#14 Příspěvek od vyosek »

Nemate zac, rad jsem pomohl :) Zase nekdy Obrázek
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět