Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Pomalé PC/odpojuje připojení/někdy se hlásil sám bez hesla.

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
csw*
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 16 kvě 2010 12:53

Pomalé PC/odpojuje připojení/někdy se hlásil sám bez hesla.

#1 Příspěvek od csw* »

Logfile of random's system information tool 1.07 (written by random/random)
Run by Thomas at 2010-09-23 22:09:17
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 23 GB (13%) free of 179 GB
Total RAM: 3070 MB (60% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:09:58, on 23-9-10
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18943)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Logitech\SetPoint\LBTWiz.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\Thomas\Documents\Utility\Krtecek\krtecek.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Media Player\wmplayer.exe
K:\RSIT.exe
C:\Program Files\trend micro\Thomas.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - .DEFAULT User Startup: CCC.lnk = ? (User 'Default user')
O4 - Startup: CCC.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Připojit cíl vazby k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Připojit k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O16 - DPF: Garmin Communicator Plug-In - https://my.garmin.com/static/m/cab/2.8. ... ontrol.CAB
O16 - DPF: {672EE252-D813-4F5E-81BB-5DD163DD4FA5} (Active602XMLFiller Control) - https://www.mojedatovaschranka.cz/stati ... b?3,14,8,0
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Služba Google Update (gupdate1ca012fde4d2990) (gupdate1ca012fde4d2990) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 13635 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1359515326-673433840-379764564-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1359515326-673433840-379764564-1000UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2008-01-10 2403392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-07-10 668656]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
CBrowserHelperObject Object - C:\PROGRA~1\GOOGLE~1\BAE.dll [2006-06-23 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-01-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2008-01-10 2403392]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832]
"Kernel and Hardware Abstraction Layer"=C:\Windows\KHALMNPR.EXE [2008-02-29 76304]
"AdobeAAMUpdater-1.0"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
"AdobeCS5ServiceManager"=C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-07-22 402432]
"SwitchBoard"=C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"Adobe Acrobat Speed Launcher"=C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [2010-06-19 38840]
""= []
"Acrobat Assistant 8.0"=C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [2010-06-19 640440]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-03-18 421888]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2010-07-21 141608]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2010-09-07 2838912]
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []
""= []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"=C:\Program Files\RocketDock\RocketDock.exe [2007-09-02 495616]
"AdobeBridge"= []
"ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2008-10-24 206112]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlackBerryAutoUpdate]
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe [2009-10-30 623960]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-05-14 30192]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe [2008-10-01 133104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
C:\Program Files\Google\Google Talk\googletalk.exe [2007-01-01 3739648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MarketingTools]
C:\Program Files\Sony\Marketing Tools\MarketingTools.exe [2008-01-10 36864]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
C:\Program Files\Picasa2\PicasaMediaDetector.exe [2008-02-26 443968]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Program Files\uTorrent\uTorrent.exe [2010-06-18 322352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
C:\PROGRA~1\Logitech\DESKTO~1\8876480\Program\LOGITE~1.EXE [2008-09-29 67128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QLink.lnk]
C:\PROGRA~1\UTAX_TA\CD1316~1\CD1316~1\QLINK.exe [2007-05-01 1779712]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Thomas^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^BlackBerry Desktop Manager.lnk]
C:\PROGRA~1\RESEAR~1\BLACKB~1\DESKTO~1.EXE [2009-10-30 1799512]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe

C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
CCC.lnk - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\VESWinlogon]
C:\Windows\system32\VESWinlogon.dll [2007-08-15 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
"NoDriveAutoRun"=255
"HonorAutoRunSetting"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fed76339-8e65-11dd-a48f-001dba3b0a80}]
shell\AutoRun\command - H:\LaunchU3.exe -a


======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 months======

2010-09-20 17:51:17 ----D---- C:\Program Files\Common Files\Brother
2010-09-20 17:50:58 ----D---- C:\Program Files\Brother
2010-09-20 16:50:39 ----D---- C:\Users\Thomas\AppData\Roaming\Brother
2010-09-20 14:13:06 ----A---- C:\Windows\system32\PT21M.DLL
2010-09-20 14:13:06 ----A---- C:\Windows\system32\PT21L.INI
2010-09-20 14:13:06 ----A---- C:\Windows\system32\PT21L.DLL
2010-09-20 14:13:06 ----A---- C:\Windows\system32\PT21F.DLL
2010-09-15 11:13:05 ----A---- C:\Windows\system32\usp10.dll
2010-09-15 11:13:03 ----A---- C:\Windows\system32\spoolsv.exe
2010-09-15 11:13:00 ----A---- C:\Windows\system32\MP4SDECD.DLL
2010-09-15 11:12:56 ----A---- C:\Windows\system32\inetcomm.dll
2010-09-11 21:00:23 ----A---- C:\Windows\system32\aswBoot.exe
2010-09-04 19:26:21 ----D---- C:\Users\Thomas\AppData\Roaming\esmska
2010-09-04 19:26:18 ----HD---- C:\Program Files\InstallJammer Registry
2010-09-04 19:26:03 ----D---- C:\Program Files\Esmska

======List of files/folders modified in the last 1 months======

2010-09-23 22:09:34 ----D---- C:\Windows\temp
2010-09-23 22:09:22 ----D---- C:\Program Files\trend micro
2010-09-23 22:08:20 ----D---- C:\Windows\Minidump
2010-09-23 22:08:20 ----D---- C:\Windows\Debug
2010-09-23 22:08:20 ----D---- C:\Windows
2010-09-23 22:06:18 ----D---- C:\Windows\System32
2010-09-23 22:06:18 ----D---- C:\Windows\inf
2010-09-23 22:06:18 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-09-23 22:01:59 ----D---- C:\Users\Thomas\AppData\Roaming\Skype
2010-09-23 20:01:31 ----D---- C:\Windows\Tasks
2010-09-21 21:11:57 ----SHD---- C:\System Volume Information
2010-09-20 17:51:40 ----SHD---- C:\Windows\Installer
2010-09-20 17:51:40 ----HD---- C:\Program Files\InstallShield Installation Information
2010-09-20 17:51:25 ----RSD---- C:\Windows\Fonts
2010-09-20 17:51:17 ----D---- C:\Program Files\Common Files
2010-09-20 17:50:58 ----RD---- C:\Program Files
2010-09-20 17:30:05 ----D---- C:\Windows\system32\catroot
2010-09-20 17:27:28 ----D---- C:\Windows\system32\catroot2
2010-09-20 17:03:15 ----D---- C:\Windows\Prefetch
2010-09-19 09:51:24 ----D---- C:\Program Files\Google
2010-09-19 09:21:16 ----D---- C:\Users\Thomas\AppData\Roaming\Canon
2010-09-18 16:22:33 ----SD---- C:\Users\Thomas\AppData\Roaming\Microsoft
2010-09-17 10:29:42 ----D---- C:\Program Files\Mozilla Firefox
2010-09-16 12:48:05 ----D---- C:\Users\Thomas\AppData\Roaming\ICQ
2010-09-16 07:50:53 ----D---- C:\Users\Thomas\AppData\Roaming\uTorrent
2010-09-16 00:28:14 ----D---- C:\Windows\winsxs
2010-09-16 00:27:40 ----D---- C:\ProgramData\Microsoft Help
2010-09-16 00:19:48 ----A---- C:\Windows\system32\mrt.exe
2010-09-16 00:19:28 ----D---- C:\Program Files\Windows Mail
2010-09-15 11:19:47 ----D---- C:\ProgramData\CanonIJPLM
2010-09-11 21:00:55 ----D---- C:\Windows\system32\drivers
2010-09-11 21:00:04 ----D---- C:\ProgramData\Alwil Software
2010-09-11 16:29:12 ----D---- C:\Program Files\CCleaner
2010-09-07 17:13:10 ----D---- C:\Program Files\ICQ7.0

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2010-09-07 23376]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2010-09-07 165584]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2010-09-07 46672]
R1 DMICall;Sony DMI Call service; C:\Windows\system32\DRIVERS\DMICall.sys [2007-09-19 10216]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2010-09-07 17744]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2010-09-07 50768]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2007-09-05 12672]
R2 regi;regi; C:\Windows\system32\drivers\regi.sys [2007-04-18 11032]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2007-09-05 8192]
R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect; C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys [2007-10-30 17920]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2007-10-19 2930176]
R3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-19 92160]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-04-11 29696]
R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2007-11-15 81448]
R3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2007-11-15 99880]
R3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2007-11-15 28464]
R3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2007-11-15 17448]
R3 CmBatt;Ovladač baterie Microsoft ACPI Control Method Battery; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-19 14208]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\System32\Drivers\GEARAspiWDM.sys [2009-05-18 26600]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2007-09-05 985600]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2007-09-05 207360]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-04-08 1761696]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2008-02-29 35344]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2008-02-29 36880]
R3 NETw4v32;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-09-19 2222080]
R3 R5U870FLx86;R5U870 UVC Lower Filter ; C:\Windows\System32\Drivers\R5U870FLx86.sys [2007-10-17 73472]
R3 R5U870FUx86;R5U870 UVC Upper Filter ; C:\Windows\System32\Drivers\R5U870FUx86.sys [2007-10-17 43904]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
R3 RimVSerPort;RIM Virtual Serial Port v2; C:\Windows\system32\DRIVERS\RimSerial.sys [2009-01-09 27136]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\Windows\System32\Drivers\RootMdm.sys [2008-01-19 8192]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2007-09-05 84480]
R3 SFEP;Sony Firmware Extension Parser; C:\Windows\system32\DRIVERS\SFEP.sys [2007-08-29 9344]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-03-10 181560]
R3 ti21sony;ti21sony; C:\Windows\system32\drivers\ti21sony.sys [2007-11-16 818688]
R3 usbvideo;R5U870 (UVC) ; C:\Windows\System32\Drivers\usbvideo.sys [2008-01-19 134016]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2007-09-05 659968]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-04-11 507904]
S3 catchme;catchme; \??\C:\Users\Thomas\AppData\Local\Temp\catchme.sys []
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2006-11-02 200704]
S3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\Windows\System32\Drivers\LUsbFilt.Sys [2008-02-29 28944]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2006-11-02 1781760]
S3 RimUsb;zařízení BlackBerry Smartphone; C:\Windows\System32\Drivers\RimUsb.sys [2008-05-20 22784]
S3 TcUsb;TC USB Kernel Driver; C:\Windows\System32\Drivers\tcusb.sys [2007-10-03 47376]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2010-04-19 41984]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2007-05-26 128104]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S4 UIUSys;Conexant Setup API; C:\Windows\system32\DRIVERS\UIUSYS.SYS []
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 602XML Updater;602Updater; C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [2010-04-14 73728]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-06-10 144176]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2007-10-19 610304]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-05-18 345376]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 IJPLMSVC;PIXMA Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2007-04-13 97432]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-05 112152]
R2 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe [2008-05-02 121360]
R2 uCamMonitor;CamMonitor; C:\Program Files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe [2007-10-31 125440]
R2 VAIO Event Service;VAIO Event Service; C:\Program Files\Sony\VAIO Event Service\VESMgr.exe [2007-08-15 182392]
R2 VzCdbSvc;VAIO Entertainment Database Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [2007-08-29 192512]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2007-09-05 386560]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2010-07-21 540968]
R3 Vcsw;VAIO Entertainment UPnP Client Adapter; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [2007-06-28 274432]
S2 CLTNetCnService;Symantec Lic NetConnect service; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon []
S2 gupdate1ca012fde4d2990;Služba Google Update (gupdate1ca012fde4d2990); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-07-10 133104]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-10 190448]
S2 Roxio Upnp Server 9;Roxio Upnp Server 9; C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe [2007-12-06 362992]
S2 RoxLiveShare9;LiveShare P2P Server 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe [2009-04-11 313840]
S2 RoxWatch9;Roxio Hard Drive Watcher 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe [2009-04-11 170480]
S2 VzFw;VAIO Entertainment File Import Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe [2007-08-29 131072]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-06-25 651720]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-05-14 30192]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 MSCSPTISRV;MSCSPTISRV; C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe [2006-12-14 45056]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PACSPTISVR;PACSPTISVR; C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [2006-12-14 57344]
S3 Roxio UPnP Renderer 9;Roxio UPnP Renderer 9; C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe [2007-12-06 88560]
S3 RoxMediaDB9;RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [2009-04-11 1108464]
S3 SPTISRV;Sony SPTI Service; C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe [2006-12-14 69632]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 VAIO Entertainment TV Device Arbitration Service;VAIO Entertainment TV Device Arbitration Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe [2007-06-28 73728]
S3 VAIOMediaPlatform-IntegratedServer-AppServer;VAIO Media Integrated Server; C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe [2007-06-21 2523136]
S3 VAIOMediaPlatform-IntegratedServer-HTTP;VAIO Media Integrated Server (HTTP); C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe [2007-06-21 397312]
S3 VAIOMediaPlatform-IntegratedServer-UPnP;VAIO Media Integrated Server (UPnP); C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [2007-06-21 1089536]
S3 VAIOMediaPlatform-Mobile-Gateway;VAIO Media Gateway Server; C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe [2007-06-21 499712]
S3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection; C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe [2007-01-11 745472]
S3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP); C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe [2007-06-21 397312]
S3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP); C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [2007-06-21 1089536]
S3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager; C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2007-09-29 292128]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pomalé PC/odpojuje připojení/někdy se hlásil sám bez hes

#2 Příspěvek od motji »

Hezké dopoledne :)

:arrow: Spusťte combofix podle tohoto návodu
http://www.bleepingcomputer.com/combofi ... t-combofix
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

csw*
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 16 kvě 2010 12:53

Re: Pomalé PC/odpojuje připojení/někdy se hlásil sám bez hes

#3 Příspěvek od csw* »

Kontrola systému souboru na K:
Systém souboru je typu FAT32.

Nektery z disku vyzaduje kontrolu konzistence. Kontrolu disku
muzete stornovat, durazne vsak doporucujeme kontrolu provést.
Systém nyní zkontroluje disk.
Sériové císlo svazku je 00D7-9ABE
Systém Windows zkontroloval systém souboru a nezjistil zádné
potíze.

250839040 bajtu celkem
2048 bajtu v 1 skrytych souborech
2048 bajtu v 1 slozkách.
11862016 bajtu v 8 souborech.
Volné místo na disku: 238970880 bajtu

2048 bajtu v kazdé alokacní jednotce
122480 alokacních jednotek na disku celkem.
116685 volnych alokacních jednotek



Tak dělám defragmentaci přes JkDefrag.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pomalé PC/odpojuje připojení/někdy se hlásil sám bez hes

#4 Příspěvek od motji »

Jednotka K je nějaký disk?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

csw*
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 16 kvě 2010 12:53

Re: Pomalé PC/odpojuje připojení/někdy se hlásil sám bez hes

#5 Příspěvek od csw* »

Takže to asi není ten log:/

Combofix se na konci seknul a připravoval ten log strašně dlouho, tak jsem ho killnul, protože 15 min. by mělo stačit ne?;)

csw*
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 16 kvě 2010 12:53

Re: Pomalé PC/odpojuje připojení/někdy se hlásil sám bez hes

#6 Příspěvek od csw* »

ComboFix 10-09-23.01 - Thomas á 24-09-10 17:40:31.4.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3070.2039 [GMT 2:00]
Spuštěný z: c:\users\Thomas\Desktop\cokoliv.com.exe
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Thomas\Error.log
.
---- Předchozí spuštění -------
.
c:\users\Thomas\AppData\Local\Microsoft\Windows\Temporary Internet Files\WDICT32.INI

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-08-24 do 2010-09-24 )))))))))))))))))))))))))))))))
.

2010-09-24 15:58 . 2010-09-24 15:58 -------- d-----w- c:\users\Thomas\AppData\Local\temp
2010-09-24 15:58 . 2010-09-24 15:58 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-09-24 15:58 . 2010-09-24 15:58 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-09-20 15:51 . 2010-09-20 15:51 -------- d-----w- c:\program files\Common Files\Brother
2010-09-20 15:50 . 2010-09-20 15:50 -------- d-----w- c:\program files\Brother
2010-09-20 14:50 . 2010-09-20 15:14 -------- d-----w- c:\users\Thomas\AppData\Roaming\Brother
2010-09-20 12:13 . 2010-02-05 06:53 43520 ----a-w- c:\windows\system32\PT21L.DLL
2010-09-20 12:13 . 2007-04-16 04:23 57344 ----a-w- c:\windows\system32\PT21F.DLL
2010-09-20 12:13 . 2007-01-16 12:09 10240 ----a-w- c:\windows\system32\PT21M.DLL
2010-09-16 09:56 . 2010-09-12 16:04 58368 ----a-w- c:\users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\mx0vhi3g.default\extensions\{88836b34-ff60-42d0-a684-e58683fcc4b9}\components\FFExternalAlert.dll
2010-09-16 09:56 . 2010-09-12 16:04 101376 ----a-w- c:\users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\mx0vhi3g.default\extensions\{88836b34-ff60-42d0-a684-e58683fcc4b9}\components\RadioWMPCore.dll
2010-09-16 09:56 . 2010-09-05 14:42 58368 ----a-w- c:\users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\mx0vhi3g.default\extensions\engine@conduit.com\components\FFExternalAlert.dll
2010-09-16 09:56 . 2010-09-05 14:42 101376 ----a-w- c:\users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\mx0vhi3g.default\extensions\engine@conduit.com\components\RadioWMPCore.dll
2010-09-15 09:13 . 2010-04-16 16:46 502272 ----a-w- c:\windows\system32\usp10.dll
2010-09-15 09:13 . 2010-08-17 14:11 128000 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-15 09:13 . 2010-04-05 17:02 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2010-09-15 09:12 . 2010-05-27 20:08 739328 ----a-w- c:\windows\system32\inetcomm.dll
2010-09-11 19:00 . 2010-09-07 14:52 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-09-11 19:00 . 2010-09-07 14:47 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-09-11 19:00 . 2010-09-07 14:47 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-09-11 19:00 . 2010-09-07 14:52 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-09-11 19:00 . 2010-09-07 14:47 50768 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-09-11 19:00 . 2010-09-07 15:12 38848 ----a-w- c:\windows\avastSS.scr
2010-09-11 19:00 . 2010-09-07 15:11 167592 ----a-w- c:\windows\system32\aswBoot.exe
2010-09-04 17:26 . 2010-09-04 18:22 -------- d-----w- c:\users\Thomas\AppData\Roaming\esmska
2010-09-04 17:26 . 2010-09-04 17:26 -------- d--h--w- c:\program files\InstallJammer Registry
2010-09-04 17:26 . 2010-09-04 17:41 -------- d-----w- c:\program files\Esmska

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-24 15:37 . 2008-01-09 17:39 602092 ----a-w- c:\windows\system32\perfh005.dat
2010-09-24 15:37 . 2008-01-09 17:39 116204 ----a-w- c:\windows\system32\perfc005.dat
2010-09-24 15:28 . 2008-01-09 19:24 1641 ----a-w- c:\windows\bthservsdp.dat
2010-09-24 09:11 . 2008-09-29 19:34 -------- d-----w- c:\users\Thomas\AppData\Roaming\Skype
2010-09-23 20:09 . 2010-05-16 12:34 -------- d-----w- c:\program files\trend micro
2010-09-20 15:52 . 2008-09-29 14:23 262344 ----a-w- c:\users\Thomas\AppData\Local\GDIPFONTCACHEV1.DAT
2010-09-20 15:51 . 2008-01-09 19:35 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-19 07:51 . 2008-01-09 19:17 -------- d-----w- c:\program files\Google
2010-09-19 07:21 . 2009-01-14 08:09 -------- d-----w- c:\users\Thomas\AppData\Roaming\Canon
2010-09-16 10:48 . 2008-09-29 19:36 -------- d-----w- c:\users\Thomas\AppData\Roaming\ICQ
2010-09-16 05:50 . 2009-03-20 20:18 -------- d-----w- c:\users\Thomas\AppData\Roaming\uTorrent
2010-09-15 22:27 . 2008-01-09 22:15 -------- d-----w- c:\programdata\Microsoft Help
2010-09-15 22:19 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-09-15 09:19 . 2009-12-18 20:29 -------- d-----w- c:\programdata\CanonIJPLM
2010-09-11 19:00 . 2010-05-20 22:30 -------- d-----w- c:\programdata\Alwil Software
2010-09-11 14:29 . 2010-05-20 22:12 -------- d-----w- c:\program files\CCleaner
2010-09-07 15:13 . 2010-01-29 12:53 -------- d-----w- c:\program files\ICQ7.0
2010-08-23 10:29 . 2010-06-23 11:32 -------- d-----w- c:\users\Thomas\AppData\Roaming\602XML
2010-08-22 18:40 . 2010-08-22 18:39 -------- d-----w- c:\program files\iTunes
2010-08-22 18:39 . 2010-08-22 18:39 -------- d-----w- c:\program files\iPod
2010-08-22 18:39 . 2009-11-23 14:39 -------- d-----w- c:\program files\Common Files\Apple
2010-08-22 18:25 . 2010-08-22 18:24 -------- d-----w- c:\program files\QuickTime
2010-08-22 18:22 . 2010-08-22 18:22 -------- d-----w- c:\program files\Apple Software Update
2010-08-11 15:13 . 2009-02-04 14:02 -------- d-----w- c:\users\Thomas\AppData\Roaming\FileZilla
2010-07-27 17:06 . 2010-07-27 16:42 -------- d-----w- c:\program files\The KMPlayer
2010-07-21 14:30 . 2010-07-21 14:30 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
2010-05-14 20:12 . 2008-12-16 07:37 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2008-10-24 206112]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-22 402432]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2010-06-19 38840]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2010-06-19 640440]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 443968]

c:\users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
CCC.lnk - c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2007-6-1 49152]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-10-30 748072]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-10-30 805392]

c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
CCC.lnk - c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2007-6-1 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2007-08-15 04:05 98304 ----a-w- c:\windows\System32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\SPYWAR~1\sp_rsdel.exe \??\c:\progra~2\SPYWAR~1\sp_rsdel.dat

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QLink.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\QLink.lnk
backup=c:\windows\pss\QLink.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Thomas^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^BlackBerry Desktop Manager.lnk]
path=c:\users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BlackBerry Desktop Manager.lnk
backup=c:\windows\pss\BlackBerry Desktop Manager.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlackBerryAutoUpdate]
2009-10-30 19:43 623960 ----a-w- c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2010-05-14 20:12 30192 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2008-10-01 21:25 133104 ----atw- c:\users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
2007-01-01 21:22 3739648 ----a-w- c:\program files\Google\Google Talk\googletalk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MarketingTools]
2008-01-09 22:32 36864 ----a-w- c:\program files\Sony\Marketing Tools\MarketingTools.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
2008-02-26 01:23 443968 ----a-w- c:\program files\Picasa2\PicasaMediaDetector.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2010-06-18 19:16 322352 ----a-w- c:\program files\uTorrent\uTorrent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-19 07:38 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1359515326-673433840-379764564-1000]
"EnableNotificationsRef"=dword:00000001

R2 gupdate1ca012fde4d2990;Služba Google Update (gupdate1ca012fde4d2990);c:\program files\Google\Update\GoogleUpdate.exe [2009-07-10 133104]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2007-11-15 28464]
R3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-05-14 30192]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;c:\program files\Sony\VAIO Media Integrated Server\UCLS.exe [2007-01-10 745472]
R3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);c:\program files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe [2007-06-20 397312]
R3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);c:\program files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [2007-06-20 1089536]
R3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2007-09-29 292128]
S1 aswSP;aswSP; [x]
S2 602XML Updater;602Updater;c:\program files\Common Files\soft602\602updsvc\602updsvc.exe [2010-04-14 73728]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-09-07 50768]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-18 11032]
S2 uCamMonitor;CamMonitor;c:\program files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe [2007-10-31 125440]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys [2007-10-30 17920]
S3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\system32\Drivers\R5U870FLx86.sys [2007-10-17 73472]
S3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\system32\Drivers\R5U870FUx86.sys [2007-10-17 43904]
S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\DRIVERS\SFEP.sys [2007-08-29 9344]
S3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2007-11-16 818688]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'

2010-09-24 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-01-09 07:26]

2010-09-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-10 07:27]

2010-09-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-10 07:27]

2010-09-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1359515326-673433840-379764564-1000Core.job
- c:\users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe [2008-10-01 21:25]

2010-09-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1359515326-673433840-379764564-1000UA.job
- c:\users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe [2008-10-01 21:25]
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/static/m/cab/2.8.3/GarminAxControl.CAB
DPF: {672EE252-D813-4F5E-81BB-5DD163DD4FA5} - hxxps://www.mojedatovaschranka.cz/static/pages/ ... b?3,14,8,0
FF - ProfilePath - c:\users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\mx0vhi3g.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/
FF - component: c:\users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\mx0vhi3g.default\extensions\{88836b34-ff60-42d0-a684-e58683fcc4b9}\components\FFExternalAlert.dll
FF - component: c:\users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\mx0vhi3g.default\extensions\{88836b34-ff60-42d0-a684-e58683fcc4b9}\components\RadioWMPCore.dll
FF - component: c:\users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\mx0vhi3g.default\extensions\engine@conduit.com\components\FFExternalAlert.dll
FF - component: c:\users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\mx0vhi3g.default\extensions\engine@conduit.com\components\RadioWMPCore.dll
FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1636.7222\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npfiller.dll
FF - plugin: c:\program files\Picasa2\npPicasa3.dll
FF - plugin: c:\users\Thomas\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKCU-Run-AdobeBridge - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-24 17:58
Windows 6.0.6002 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Celkový čas: 2010-09-24 18:07:38
ComboFix-quarantined-files.txt 2010-09-24 16:07
ComboFix2.txt 2010-05-17 09:05
ComboFix3.txt 2010-05-16 23:50

Před spuštěním: Volných bajtů: 39 453 425 664
Po spuštění: Volných bajtů: 39 395 090 432

- - End Of File - - 856BF80673E6477B1F413465C94E97BD

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pomalé PC/odpojuje připojení/někdy se hlásil sám bez hes

#7 Příspěvek od motji »

Někdy mu to trvá déle :) .
Co je jednotka K?
Jak to vypadá s počítačem?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

csw*
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 16 kvě 2010 12:53

Re: Pomalé PC/odpojuje připojení/někdy se hlásil sám bez hes

#8 Příspěvek od csw* »

K je USB klíč. PC celkem ok, jen ta síť vypadává více než obvykle. Jestli to nevypadá na nějaký problém, tak to mohlo být způsobeno nedostatkem paměti na HDD (15GB).

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pomalé PC/odpojuje připojení/někdy se hlásil sám bez hes

#9 Příspěvek od motji »

:arrow: Stahněte z mého podpisu AVPTOOl http://www.viry.cz/forum/viewtopic.php?f=29&t=58179

-Podle návodu nainstalujte a proveďte sken
-co najde nechejte léčit, mazat
-sken může trvat několik hodin
-vložte zde log z výsledky
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

csw*
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 16 kvě 2010 12:53

Re: Pomalé PC/odpojuje připojení/někdy se hlásil sám bez hes

#10 Příspěvek od csw* »

Autoscan: stopped 15 hours ago (events: 61, objects: 904380, time: 06:33:13)
30-9-10 18:23:14 Task started
30-9-10 20:36:23 Detected: HEUR:Trojan.Win32.Generic C:\Qoobox\Quarantine\C\Users\Thomas\AppData\Roaming\sdra64.exe.vir
30-9-10 20:36:23 Detected: Worm.Win32.Pinit.lk C:\Qoobox\Quarantine\C\Windows\System32\cooper.mine.vir
30-9-10 20:36:25 Detected: Trojan.Win32.Vilsel.aesw C:\Qoobox\Quarantine\C\lsass.exe.vir
30-9-10 20:53:46 Deleted: Worm.Win32.Pinit.lk C:\Qoobox\Quarantine\C\Windows\System32\cooper.mine.vir
30-9-10 20:53:46 Detected: Worm.Win32.Pinit.mh C:\Qoobox\Quarantine\C\Windows\System32\nmklo.dll.vir
30-9-10 20:54:34 Deleted: Trojan.Win32.Vilsel.aesw C:\Qoobox\Quarantine\C\lsass.exe.vir
30-9-10 20:55:14 Deleted: Worm.Win32.Pinit.mh C:\Qoobox\Quarantine\C\Windows\System32\nmklo.dll.vir
30-9-10 20:55:38 Deleted: HEUR:Trojan.Win32.Generic C:\Qoobox\Quarantine\C\Users\Thomas\AppData\Roaming\sdra64.exe.vir
30-9-10 21:16:26 Processing error C:\Users\Thomas\Local Settings\Microsoft\Outlook\Outlook.pst Read error
1-10-10 0:33:10 Detected: Trojan.Win32.Buzus.ebks C:\_OTL\MovedFiles\05172010_010433\C_RECYCLER\S-1-5-21-5394953386-0610143787-811536984-0373\mgrls32.exe
1-10-10 0:33:10 Detected: Trojan.Win32.Vilsel.aesw C:\_OTL\MovedFiles\05172010_010433\C_Users\Thomas\AppData\Local\Temp\nrktcvy.exe
1-10-10 0:33:11 Detected: Trojan.Win32.Buzus.ebks C:\_OTL\CSW.zip/05172010_010433/C_RECYCLER/S-1-5-21-5394953386-0610143787-811536984-0373/mgrls32.exe
1-10-10 0:33:30 Deleted: Trojan.Win32.Buzus.ebks C:\_OTL\MovedFiles\05172010_010433\C_RECYCLER\S-1-5-21-5394953386-0610143787-811536984-0373\mgrls32.exe
1-10-10 0:33:34 Deleted: Trojan.Win32.Buzus.ebks C:\_OTL\CSW.zip/05172010_010433/C_RECYCLER/S-1-5-21-5394953386-0610143787-811536984-0373/mgrls32.exe
1-10-10 0:33:37 Detected: Backdoor.Win32.VB.lvn C:\_OTL\CSW.zip/05172010_010433/C_Users/Thomas/AppData/Local/Temp/b8n8nse.exe/UPX
1-10-10 0:33:41 Deleted: Backdoor.Win32.VB.lvn C:\_OTL\CSW.zip/05172010_010433/C_Users/Thomas/AppData/Local/Temp/b8n8nse.exe
1-10-10 0:33:41 Detected: Trojan.Win32.Vilsel.aesw C:\_OTL\CSW.zip/05172010_010433/C_Users/Thomas/AppData/Local/Temp/nrktcvy.exe
1-10-10 0:33:43 Deleted: Trojan.Win32.Vilsel.aesw C:\_OTL\CSW.zip/05172010_010433/C_Users/Thomas/AppData/Local/Temp/nrktcvy.exe
1-10-10 0:33:45 Detected: Trojan-Downloader.Win32.Agent.delf C:\_OTL\CSW.zip/05172010_010433/C_Windows/System32/msxsltsso.dll
1-10-10 0:33:47 Deleted: Trojan-Downloader.Win32.Agent.delf C:\_OTL\CSW.zip/05172010_010433/C_Windows/System32/msxsltsso.dll
1-10-10 0:33:50 Detected: Trojan.Win32.VBKrypt.auq C:\_OTL\CSW.zip/05172010_010433/C_Windows/wndrive32.exe
1-10-10 0:33:51 Deleted: Trojan.Win32.VBKrypt.auq C:\_OTL\CSW.zip/05172010_010433/C_Windows/wndrive32.exe
1-10-10 0:34:33 Detected: Trojan.Win32.Vilsel.aesw C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R27PMY9.zip/Quarantine/C/lsass.exe.vir
1-10-10 0:34:57 Detected: Trojan.Win32.Vilsel.aesw C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R6RWB2G.zip/Quarantine/C/lsass.exe.vir
1-10-10 0:35:33 Deleted: Trojan.Win32.Vilsel.aesw C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R27PMY9.zip/Quarantine/C/lsass.exe.vir
1-10-10 0:35:40 Deleted: Trojan.Win32.Vilsel.aesw C:\_OTL\MovedFiles\05172010_010433\C_Users\Thomas\AppData\Local\Temp\nrktcvy.exe
1-10-10 0:36:05 Detected: Trojan.Win32.Vilsel.aesw C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R6OSD12\Quarantine\C\lsass.exe.vir
1-10-10 0:36:10 Detected: HEUR:Trojan.Win32.Generic C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R6OSD12\Quarantine\C\Users\Thomas\AppData\Roaming\sdra64.exe.vir
1-10-10 0:36:41 Detected: Worm.Win32.Pinit.lk C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R6OSD12\Quarantine\C\Windows\System32\cooper.mine.vir
1-10-10 0:37:47 Deleted: Trojan.Win32.Vilsel.aesw C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R6RWB2G.zip/Quarantine/C/lsass.exe.vir
1-10-10 0:38:06 Deleted: HEUR:Trojan.Win32.Generic C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R6OSD12\Quarantine\C\Users\Thomas\AppData\Roaming\sdra64.exe.vir
1-10-10 0:38:07 Detected: Worm.Win32.Pinit.mh C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R6OSD12\Quarantine\C\Windows\System32\nmklo.dll.vir
1-10-10 0:38:30 Deleted: Worm.Win32.Pinit.lk C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R6OSD12\Quarantine\C\Windows\System32\cooper.mine.vir
1-10-10 0:38:44 Detected: Trojan.Win32.Vilsel.aesw C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$RGPQNGE\Quarantine\C\lsass.exe.vir
1-10-10 0:39:09 Deleted: Trojan.Win32.Vilsel.aesw C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R6OSD12\Quarantine\C\lsass.exe.vir
1-10-10 0:39:24 Deleted: Worm.Win32.Pinit.mh C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R6OSD12\Quarantine\C\Windows\System32\nmklo.dll.vir
1-10-10 0:39:27 Detected: HEUR:Trojan.Win32.Generic C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$RGPQNGE\Quarantine\C\Users\Thomas\AppData\Roaming\sdra64.exe.vir
1-10-10 0:39:42 Detected: Worm.Win32.Pinit.lk C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$RGPQNGE\Quarantine\C\Windows\System32\cooper.mine.vir
1-10-10 0:39:57 Deleted: Trojan.Win32.Vilsel.aesw C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$RGPQNGE\Quarantine\C\lsass.exe.vir
1-10-10 0:39:58 Detected: Worm.Win32.Pinit.mh C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$RGPQNGE\Quarantine\C\Windows\System32\nmklo.dll.vir
1-10-10 0:40:28 Detected: HEUR:Trojan.Win32.Generic C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R27PMY9.zip/Quarantine/C/Users/Thomas/AppData/Roaming/sdra64.exe.vir
1-10-10 0:40:28 Deleted: HEUR:Trojan.Win32.Generic C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$RGPQNGE\Quarantine\C\Users\Thomas\AppData\Roaming\sdra64.exe.vir
1-10-10 0:40:42 Detected: Trojan.Win32.Buzus.ebks C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\G\RECYCLER\autorun.exe.UsbFix
1-10-10 0:40:43 Deleted: HEUR:Trojan.Win32.Generic C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R27PMY9.zip/Quarantine/C/Users/Thomas/AppData/Roaming/sdra64.exe.vir
1-10-10 0:40:47 Detected: Worm.Win32.Pinit.lk C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R27PMY9.zip/Quarantine/C/Windows/System32/cooper.mine.vir
1-10-10 0:41:00 Deleted: Worm.Win32.Pinit.lk C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R27PMY9.zip/Quarantine/C/Windows/System32/cooper.mine.vir
1-10-10 0:41:06 Deleted: Worm.Win32.Pinit.lk C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$RGPQNGE\Quarantine\C\Windows\System32\cooper.mine.vir
1-10-10 0:41:08 Detected: HEUR:Trojan.Win32.Generic C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R6RWB2G.zip/Quarantine/C/Users/Thomas/AppData/Roaming/sdra64.exe.vir
1-10-10 0:41:10 Detected: Worm.Win32.Pinit.mh C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R27PMY9.zip/Quarantine/C/Windows/System32/nmklo.dll.vir
1-10-10 0:41:12 Deleted: HEUR:Trojan.Win32.Generic C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R6RWB2G.zip/Quarantine/C/Users/Thomas/AppData/Roaming/sdra64.exe.vir
1-10-10 0:41:18 Deleted: Worm.Win32.Pinit.mh C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R27PMY9.zip/Quarantine/C/Windows/System32/nmklo.dll.vir
1-10-10 0:41:25 Detected: Worm.Win32.Pinit.lk C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R6RWB2G.zip/Quarantine/C/Windows/System32/cooper.mine.vir
1-10-10 0:41:33 Deleted: Worm.Win32.Pinit.lk C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R6RWB2G.zip/Quarantine/C/Windows/System32/cooper.mine.vir
1-10-10 0:41:36 Deleted: Worm.Win32.Pinit.mh C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$RGPQNGE\Quarantine\C\Windows\System32\nmklo.dll.vir
1-10-10 0:41:37 Detected: Trojan.Win32.Buzus.ebks C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\I\RECYCLER\autorun.exe.UsbFix
1-10-10 0:41:43 Detected: Worm.Win32.Pinit.mh C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R6RWB2G.zip/Quarantine/C/Windows/System32/nmklo.dll.vir
1-10-10 0:41:48 Deleted: Worm.Win32.Pinit.mh C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\C\$RECYCLE.BIN\S-1-5-21-1359515326-673433840-379764564-1000.UsbFix\$R6RWB2G.zip/Quarantine/C/Windows/System32/nmklo.dll.vir
1-10-10 0:42:09 Deleted: Trojan.Win32.Buzus.ebks C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\G\RECYCLER\autorun.exe.UsbFix
1-10-10 0:42:41 Deleted: Trojan.Win32.Buzus.ebks C:\_OTL\MovedFiles\05192010_011638\C_UsbFix\Quarantine\I\RECYCLER\autorun.exe.UsbFix
1-10-10 0:56:27 Task stopped


Vše možno smazat. Niz z toho zipu mi chybět nebude;)

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pomalé PC/odpojuje připojení/někdy se hlásil sám bez hes

#11 Příspěvek od motji »

Avptool měl vše smazat. Jinak se dívám, že tam máte ještě karanténu OTL , starou pár měsíců :D .
Jak to vypadá s počítačem?



:arrow: Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:

ComboFix /Uninstall

-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.


***********


:arrow: Stáhněte T-Cleaner
http://sweb.cz/Marinus/T-Cleaner.exe

-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir



***********


:arrow: Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

Obrázekzáložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

Obrázekzáložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy :arrow: ok :arrow: zavřít

Obrázek Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.

Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.


***********



:arrow: Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech



***********

:arrow: Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět