Kamarádovo PC, nejde naistalovat ani AV

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
Perseus
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 24 Led 2007 12:21
Kontaktovat uživatele:

Re: Kamarádovo PC, nejde naistalovat ani AV

#16 Příspěvek od Perseus »

Musím už pracovně někam jít. K tomuto PC se dostanu zítra od 16 hodin do večera. Postnu log... Děkuji moc!

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Kamarádovo PC, nejde naistalovat ani AV

#17 Příspěvek od vyosek »

Hlavni je, ze havet je pryc...uz jen docistime, uklidime a bude klid :wink:

Zitra tu budu taky, neboj :D Pekny zbytek vikendu :turned:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Perseus
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 24 Led 2007 12:21
Kontaktovat uživatele:

Re: Kamarádovo PC, nejde naistalovat ani AV

#18 Příspěvek od Perseus »

Dostal jsem se k PC až teď.

Log z CF se mi ukládá do C:\ComboFix\ComboFix.txt

ComboFix 10-12-04.01 - xx 06.12.2010 20:09:48.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1022.644 [GMT 1:00]
Spuštěný z: C:\Documents and Settings\xx\Plocha\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Předchozí spuštění -------
.
c:\windows\system32\CleanMFT32.exe
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\Norton Security Scan for Administrator.job

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-06 do 2010-12-06 )))))))))))))))))))))))))))))))
.

2010-12-06 19:02:37 . 2010-12-06 19:02:37 -------- d--h--w- C:\WINDOWS\PIF
2010-12-05 13:39:00 . 2010-12-05 13:46:57 -------- d-----w- C:\Beruska.com
2010-12-05 13:19:45 . 2010-12-05 13:19:45 -------- d-----w- C:\_OTM
2010-12-05 12:01:52 . 2010-12-05 12:01:55 -------- d-----w- C:\rsit
2010-12-05 12:01:52 . 2010-12-05 12:01:52 -------- d-----w- C:\Program Files\trend micro
2010-12-04 14:39:05 . 2008-04-14 03:21:42 21504 -c--a-w- C:\WINDOWS\system32\dllcache\hidserv.dll
2010-12-04 14:39:05 . 2008-04-14 03:21:42 21504 ----a-w- C:\WINDOWS\system32\hidserv.dll
2010-12-04 13:22:15 . 2010-12-04 13:22:19 -------- d-----w- C:\Documents and Settings\Administrator
2010-12-04 13:18:18 . 2010-12-04 13:18:18 -------- d-----w- C:\8dc749fb77e1e8cb09441bdc0983
2010-12-04 13:15:29 . 2010-12-04 13:15:29 -------- d-----w- C:\73bebd2db4bdfbb4b4fcc8df
2010-11-29 15:11:27 . 2010-11-29 15:11:27 869376 ----a-w- C:\Documents and Settings\xx\Local Settings\Data aplikací\71815.exe
2010-11-14 15:14:24 . 2008-09-17 20:17:48 658432 ----a-w- C:\WINDOWS\system32\MSCOMCT2.OCX
2010-11-14 15:14:24 . 2008-04-02 14:54:20 1101824 ----a-w- C:\WINDOWS\system32\UniBox210.ocx
2010-11-14 15:14:24 . 2008-04-02 14:53:50 212992 ----a-w- C:\WINDOWS\system32\UniBoxVB12.ocx
2010-11-14 15:14:24 . 2008-04-02 14:53:36 880640 ----a-w- C:\WINDOWS\system32\UniBox10.ocx
2010-11-14 15:14:24 . 2004-03-08 23:00:00 1081616 ----a-w- C:\WINDOWS\system32\MSCOMCTL.OCX
2010-11-14 15:14:22 . 2010-11-14 15:14:24 -------- d-----w- C:\Program Files\Common Files\PC Tools
2010-11-14 15:14:21 . 2010-11-26 20:12:28 -------- d---a-w- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 10:23:38 . 2004-08-18 12:00:00 974848 ----a-w- C:\WINDOWS\system32\mfc42u.dll
2010-09-18 06:53:37 . 2004-08-18 12:00:00 974848 ----a-w- C:\WINDOWS\system32\mfc42.dll
2010-09-18 06:53:37 . 2004-08-18 12:00:00 954368 ----a-w- C:\WINDOWS\system32\mfc40.dll
2010-09-18 06:53:37 . 2004-08-18 12:00:00 953856 ----a-w- C:\WINDOWS\system32\mfc40u.dll
2010-09-09 13:34:29 . 2004-08-18 12:00:00 832512 ----a-w- C:\WINDOWS\system32\wininet.dll
2010-09-09 13:34:28 . 2004-08-18 12:00:00 1830912 ------w- C:\WINDOWS\system32\inetcpl.cpl
2010-09-09 13:34:27 . 2004-08-18 12:00:00 78336 ----a-w- C:\WINDOWS\system32\ieencode.dll
2010-09-09 13:34:26 . 2004-08-18 12:00:00 17408 ------w- C:\WINDOWS\system32\corpol.dll
2010-09-08 15:57:57 . 2004-08-18 12:00:00 389120 ----a-w- C:\WINDOWS\system32\html.iec
2009-10-05 19:50:30 . 2007-12-24 22:40:56 67688 ----a-w- C:\Program Files\mozilla firefox\components\jar50.dll
2009-10-05 19:50:30 . 2007-12-24 22:40:56 54368 ----a-w- C:\Program Files\mozilla firefox\components\jsd3250.dll
2009-10-05 19:50:31 . 2007-12-24 22:40:56 34944 ----a-w- C:\Program Files\mozilla firefox\components\myspell.dll
2009-10-05 19:50:31 . 2007-12-24 22:40:57 46712 ----a-w- C:\Program Files\mozilla firefox\components\spellchk.dll
2009-10-05 19:50:31 . 2007-12-24 22:40:57 172136 ----a-w- C:\Program Files\mozilla firefox\components\xpinstal.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ICQ"="C:\Program Files\ICQ6\ICQ.exe" [2008-09-01 15:08:21 173304]
"AutoStartNPSAgent"="C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2009-01-08 07:55:56 98304]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-10 17:46:18 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-21 06:49:20 16126464]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 20:34:40 49152]
"NPSStartup"="" [BU]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 03:22:17 15360]

C:\Documents and Settings\All Users.WINDOWS\Nabˇdka Start\Programy\Po spuçtŘnˇ\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\Program Files\\Ubisoft\\Crytek\\Far Cry\\Bin32\\FarCry.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Ubisoft\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"C:\\hry\\Instinkt\\instinct.exe"=
"C:\\Program Files\\Xplosiv\\SOF PLATINUM\\SoF.exe"=
"C:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"C:\\Program Files\\MotoGP2\\motogp2.exe"=
"C:\\Program Files\\Boiling Point - Cesta do pekel\\XENUS.EXE"=
"C:\\Program Files\\Techland\\Xpand Rally\\xpandrally.exe"=
"C:\\Program Files\\Metin2_TESTER\\metin2.bin"=
"C:\\Program Files\\Samsung\\Samsung New PC Studio\\npsasvr.exe"=
"C:\\Program Files\\Samsung\\Samsung New PC Studio\\npsvsvr.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"C:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Launcher.exe"=
"C:\\Program Files\\Cenega Czech\\VIETCONG\\vietcong.exe"=
"C:\\Program Files\\Electronic Arts\\Medal of Honor Airborne\\UnrealEngine3\\Binaries\\MOHA.exe"=

R2 FsUsbExService;FsUsbExService;C:\WINDOWS\system32\FsUsbExService.Exe [15.7.2009 14:01:17 233472]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe [14.11.2010 16:14:24 583640]
R3 FsUsbExDisk;FsUsbExDisk;C:\WINDOWS\system32\FsUsbExDisk.Sys [15.7.2009 14:01:17 36608]
S2 gupdate;Služba Google Update (gupdate);C:\Program Files\Google\Update\GoogleUpdate.exe [2.8.2010 13:07:40 135664]

--- Ostatní služby/ovladače v paměti ---

*NewlyCreated* - FSUSBEXDISK

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Obsah adresáře 'Naplánované úlohy'

2010-11-28 C:\WINDOWS\Tasks\Norton Security Scan for xx.job
- C:\Program Files\Norton Security Scan\Norton Security Scan\Engine\2.7.0.52\Nss.exe [2009-12-11 17:01:35 . 2010-09-03 04:32:54]

2010-11-26 C:\WINDOWS\Tasks\RMSchedule.job
- C:\Program Files\Registry Mechanic\RegMech.exe [2010-11-14 15:14:24 . 2010-08-05 07:46:14]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: WikiKomentáře Google... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
FF - ProfilePath - C:\Documents and Settings\xx\Data aplikací\Mozilla\Firefox\Profiles\salleaoj.default\
FF - component: C:\Documents and Settings\xx\Data aplikací\Mozilla\Firefox\Profiles\salleaoj.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: C:\Program Files\Mozilla Firefox\components\xpinstal.dll
FF - component: C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

WebBrowser-{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - (no file)

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Kamarádovo PC, nejde naistalovat ani AV

#19 Příspěvek od vyosek »

Tohle neni ono :o Mel by se jmenovat ComboFix2.txt a v hlavicce by melo byt Command switches used :: c:\documents and settings\doma\Desktop\CFScript.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Perseus
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 24 Led 2007 12:21
Kontaktovat uživatele:

Re: Kamarádovo PC, nejde naistalovat ani AV

#20 Příspěvek od Perseus »

Tak tohle jsem našel ve složce Qoobox

ComboFix 10-12-04.01 - Administrator 05.12.2010 14:39:42.2.2 - x86 NETWORK
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1022.734 [GMT 1:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\Beruska.com.exe

VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Předchozí spuštění -------
.
C:\autoexec.exe
c:\documents and settings\All Users.WINDOWS\Nabídka Start\Programy\Seekmo\Reset Cursor.lnk
c:\documents and settings\All Users.WINDOWS\Nabídka Start\Programy\Seekmo\Seekmo Customer Support Center.lnk
c:\documents and settings\All Users.WINDOWS\Nabídka Start\Programy\Seekmo\Seekmo Uninstall Instructions.lnk
c:\documents and settings\All Users.WINDOWS\Nabídka Start\Programy\Seekmo\Weather.lnk
c:\documents and settings\xx\Data aplikací\SystemProc\lsass.exe
c:\documents and settings\xx\Data aplikací\WeatherDPA\Weather\WeatherStartup.xml
c:\documents and settings\xx\Plocha\Internet Explorer.lnk
c:\program files\Mozilla Firefox\components\npclntax.xpt
c:\program files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content\timer.xul
c:\program files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf
c:\program files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
c:\program files\ShoppingReport\Uninst.exe
c:\windows\system32\AutoRun.inf
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\wpcap.dll

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NPF
-------\Service_NPF


((((((((((((((((((((((((( Soubory vytvořené od 2010-11-05 do 2010-12-05 )))))))))))))))))))))))))))))))
.

2010-12-05 13:19 . 2010-12-05 13:19 -------- d-----w- C:\_OTM
2010-12-05 12:01 . 2010-12-05 12:01 -------- d-----w- C:\rsit
2010-12-05 12:01 . 2010-12-05 12:01 -------- d-----w- c:\program files\trend micro
2010-12-04 14:39 . 2008-04-14 03:21 21504 -c--a-w- c:\windows\system32\dllcache\hidserv.dll
2010-12-04 14:39 . 2008-04-14 03:21 21504 ----a-w- c:\windows\system32\hidserv.dll
2010-12-04 13:22 . 2010-12-04 13:22 -------- d-----w- c:\documents and settings\Administrator
2010-12-04 13:18 . 2010-12-04 13:18 -------- d-----w- C:\8dc749fb77e1e8cb09441bdc0983
2010-12-04 13:15 . 2010-12-04 13:15 -------- d-----w- C:\73bebd2db4bdfbb4b4fcc8df
2010-11-29 15:11 . 2010-11-29 15:11 869376 ----a-w- c:\documents and settings\xx\Local Settings\Data aplikací\71815.exe
2010-11-14 15:14 . 2010-08-05 07:46 37336 ----a-w- c:\windows\system32\CleanMFT32.exe
2010-11-14 15:14 . 2008-09-17 20:17 658432 ----a-w- c:\windows\system32\MSCOMCT2.OCX
2010-11-14 15:14 . 2008-04-02 14:54 1101824 ----a-w- c:\windows\system32\UniBox210.ocx
2010-11-14 15:14 . 2008-04-02 14:53 212992 ----a-w- c:\windows\system32\UniBoxVB12.ocx
2010-11-14 15:14 . 2008-04-02 14:53 880640 ----a-w- c:\windows\system32\UniBox10.ocx
2010-11-14 15:14 . 2004-03-08 23:00 1081616 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2010-11-14 15:14 . 2010-11-14 15:14 -------- d-----w- c:\program files\Common Files\PC Tools
2010-11-14 15:14 . 2010-11-26 20:12 -------- d---a-w- c:\documents and settings\All Users.WINDOWS\Data aplikací\TEMP

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 10:23 . 2004-08-18 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2004-08-18 12:00 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2004-08-18 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2004-08-18 12:00 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-09 13:34 . 2004-08-18 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-09-09 13:34 . 2004-08-18 12:00 1830912 ------w- c:\windows\system32\inetcpl.cpl
2010-09-09 13:34 . 2004-08-18 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-09-09 13:34 . 2004-08-18 12:00 17408 ------w- c:\windows\system32\corpol.dll
2010-09-08 15:57 . 2004-08-18 12:00 389120 ----a-w- c:\windows\system32\html.iec
2009-10-05 19:50 . 2007-12-24 22:40 67688 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2009-10-05 19:50 . 2007-12-24 22:40 54368 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2009-10-05 19:50 . 2007-12-24 22:40 34944 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2009-10-05 19:50 . 2007-12-24 22:40 46712 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2009-10-05 19:50 . 2007-12-24 22:40 172136 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-21 16126464]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"NPSStartup"="" [BU]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users.WINDOWS\Nabˇdka Start\Programy\Po spuçtŘnˇ\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ6\\ICQ.exe"=
"c:\\Program Files\\Ubisoft\\Crytek\\Far Cry\\Bin32\\FarCry.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Ubisoft\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"c:\\hry\\Instinkt\\instinct.exe"=
"c:\\Program Files\\Xplosiv\\SOF PLATINUM\\SoF.exe"=
"c:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"c:\\Program Files\\MotoGP2\\motogp2.exe"=
"c:\\Program Files\\Boiling Point - Cesta do pekel\\XENUS.EXE"=
"c:\\Program Files\\Techland\\Xpand Rally\\xpandrally.exe"=
"c:\\Program Files\\Metin2_TESTER\\metin2.bin"=
"c:\\Program Files\\Samsung\\Samsung New PC Studio\\npsasvr.exe"=
"c:\\Program Files\\Samsung\\Samsung New PC Studio\\npsvsvr.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Launcher.exe"=
"c:\\Program Files\\Cenega Czech\\VIETCONG\\vietcong.exe"=
"c:\\Program Files\\Electronic Arts\\Medal of Honor Airborne\\UnrealEngine3\\Binaries\\MOHA.exe"=

S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [15.7.2009 14:01 233472]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2.8.2010 13:07 135664]
S2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [14.11.2010 16:14 583640]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [15.7.2009 14:01 36608]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Obsah adresáře 'Naplánované úlohy'

2010-12-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-02 12:07]

2010-12-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-02 12:07]

2010-12-04 c:\windows\Tasks\Norton Security Scan for Administrator.job
- c:\program files\Norton Security Scan\Norton Security Scan\Engine\2.7.0.52\Nss.exe [2009-12-11 04:32]

2010-11-28 c:\windows\Tasks\Norton Security Scan for xx.job
- c:\program files\Norton Security Scan\Norton Security Scan\Engine\2.7.0.52\Nss.exe [2009-12-11 04:32]

2010-11-26 c:\windows\Tasks\RMSchedule.job
- c:\program files\Registry Mechanic\RegMech.exe [2010-11-14 07:46]
.
.
------- Doplňkový sken -------
.
FF - ProfilePath - c:\documents and settings\xx\Data aplikací\Mozilla\Firefox\Profiles\salleaoj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.atlas.cz/?from=icqhp
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - component: c:\documents and settings\xx\Data aplikací\Mozilla\Firefox\Profiles\salleaoj.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

AddRemove-HijackThis - c:\documents and settings\Administrator\Plocha\HijackThis.exe



**************************************************************************
skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory:

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(604)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(660)
c:\windows\system32\vorbis.dll
c:\windows\system32\ogg.dll

- - - - - - - > 'explorer.exe'(1424)
c:\windows\system32\vorbis.dll
c:\windows\system32\ogg.dll
.
Celkový čas: 2010-12-05 14:46:54
ComboFix-quarantined-files.txt 2010-12-05 13:46

Před spuštěním: Volných bajtů: 37 841 215 488
Po spuštění: Volných bajtů: 37 786 079 232

- - End Of File - - 5A61EFB4E67C331A343CEC0FB2825CD2

Perseus
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 24 Led 2007 12:21
Kontaktovat uživatele:

Re: Kamarádovo PC, nejde naistalovat ani AV

#21 Příspěvek od Perseus »

Ten je taky špatnej, tento log u jsem jednou postnul. Ten poslední 3 nikde nemám ...


Edit:
našel jsem ještě tento...

Collect::
c:\documents and settings\xx\Local Settings\Data aplikací\71815.exe
c:\windows\system32\CleanMFT32.exe

File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\Norton Security Scan for Administrator.job
2010-11-28 c:\windows\Tasks\Norton Security Scan for xx.job
2010-11-26 c:\windows\Tasks\RMSchedule.job

Firefox::
FF - ProfilePath - c:\documents and settings\xx\Data aplikací\Mozilla\Firefox\Profiles\salleaoj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.atlas.cz/?from=icqhp
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_result ... id=afex&q=

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Kamarádovo PC, nejde naistalovat ani AV

#22 Příspěvek od vyosek »

:arrow: Pro jistotu jeste udelame jeden krok, at overime ze je havet fuc

:arrow: Stahnete OTM (viz muj podpis)
  • Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
  • Kód: Vybrat vše

    :files
    c:\documents and settings\xx\Local Settings\Data aplikací\71815.exe
    c:\windows\system32\CleanMFT32.exe
    c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    c:\windows\Tasks\Norton Security Scan for Administrator.job
    c:\windows\Tasks\Norton Security Scan for xx.job
    c:\windows\Tasks\RMSchedule.job
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp /s
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
  • Kliknete na cervene tlacitko MoveIt!
  • Budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles, obsah sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Perseus
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 24 Led 2007 12:21
Kontaktovat uživatele:

Re: Kamarádovo PC, nejde naistalovat ani AV

#23 Příspěvek od Perseus »

All processes killed
========== FILES ==========
c:\documents and settings\xx\Local Settings\Data aplikací\71815.exe moved successfully.
File/Folder c:\windows\system32\CleanMFT32.exe not found.
File/Folder c:\windows\Tasks\GoogleUpdateTaskMachineCore.job not found.
File/Folder c:\windows\Tasks\GoogleUpdateTaskMachineUA.job not found.
File/Folder c:\windows\Tasks\Norton Security Scan for Administrator.job not found.
c:\windows\Tasks\Norton Security Scan for xx.job moved successfully.
c:\windows\Tasks\RMSchedule.job moved successfully.
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->FireFox cache emptied: 0 bytes

User: All Users

User: All Users.WINDOWS

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User.WINDOWS
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: NetworkService.NT AUTHORITY
->Temp folder emptied: 6848 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Pítrs
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: xx
->Temp folder emptied: 667271 bytes
->Temporary Internet Files folder emptied: 35378559 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 560 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 53341 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 359 bytes

Total Files Cleaned = 34,00 mb


OTM by OldTimer - Version 3.1.17.2 log created on 12062010_210839

Files moved on Reboot...

Registry entries deleted on Reboot...

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Kamarádovo PC, nejde naistalovat ani AV

#24 Příspěvek od vyosek »

Tak OTM dokoncilo co CF zacal...

:arrow: Odinstalujte Combofix
  • Prejmenujte ComboFix (Berusku) na Uninstall
  • Spustte Uninstall
  • Tohle smaze Combofix a jeho slozky
:arrow: T-Cleaner http://sweb.cz/Marinus/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner (viz muj podpis)
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za 14 dni

:arrow: Dejte novy log z RSIT a napiste jak se chova PC
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Perseus
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 24 Led 2007 12:21
Kontaktovat uživatele:

Re: Kamarádovo PC, nejde naistalovat ani AV

#25 Příspěvek od Perseus »

Děkuji moc počítač šlape jak hodinky. Pošlu slíbený donate.
Posílám RSIT log

Logfile of random's system information tool 1.08 (written by random/random)
Run by xx at 2010-12-07 18:58:14
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 37 GB (24%) free of 153 GB
Total RAM: 1022 MB (54% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:58:26, on 7.12.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\FsUsbExService.Exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\ICQ6\ICQ.exe
C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\xx\Plocha\RSIT.exe
C:\Program Files\trend micro\xx.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6\ICQ.exe" silent
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
O9 - Extra button: Kniha klipů HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Chytrý výběr - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - Unknown owner - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe

--
End of file - 6595 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\MpIdleTask.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{451439B8-D1B6-44F7-88C1-7678839657B4}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll [2007-03-02 1298024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
HP Print Clips - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [2007-03-02 177768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll [2003-05-11 50376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-10-28 297648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE84A6AA-A333-4B92-B276-C11E2212E4FE}]
CPrintEnhancer Object - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll [2006-12-15 599472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll [2010-10-28 843832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-10-28 297648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-03-21 16126464]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-03-11 49152]
"NPSStartup"= []
"MSSE"=c:\Program Files\Microsoft Security Essentials\msseces.exe [2010-09-15 1094224]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ICQ"=C:\Program Files\ICQ6\ICQ.exe [2008-09-01 173304]
"AutoStartNPSAgent"=C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [2009-01-08 98304]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-04-10 68856]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Po spuštění
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2010-02-11 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"NoDriveAutoRun"=67108863

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ6\ICQ.exe"="C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Ubisoft\Crytek\Far Cry\Bin32\FarCry.exe"="C:\Program Files\Ubisoft\Crytek\Far Cry\Bin32\FarCry.exe:*:Disabled:Far Cry"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Ubisoft\Splinter Cell Pandora Tomorrow\pandora.exe"="C:\Program Files\Ubisoft\Splinter Cell Pandora Tomorrow\pandora.exe:*:Enabled:pandora"
"C:\hry\Instinkt\instinct.exe"="C:\hry\Instinkt\instinct.exe:*:Enabled:ds2main"
"C:\Program Files\Xplosiv\SOF PLATINUM\SoF.exe"="C:\Program Files\Xplosiv\SOF PLATINUM\SoF.exe:*:Disabled:SoF"
"C:\Program Files\GameSpy Arcade\Aphex.exe"="C:\Program Files\GameSpy Arcade\Aphex.exe:*:Enabled:GameSpy Arcade"
"C:\Program Files\MotoGP2\motogp2.exe"="C:\Program Files\MotoGP2\motogp2.exe:*:Disabled:motogp2"
"C:\Program Files\Boiling Point - Cesta do pekel\XENUS.EXE"="C:\Program Files\Boiling Point - Cesta do pekel\XENUS.EXE:*:Disabled:XENUS"
"C:\Program Files\Techland\Xpand Rally\xpandrally.exe"="C:\Program Files\Techland\Xpand Rally\xpandrally.exe:*:Enabled:XpandRally"
"C:\Program Files\Metin2_TESTER\metin2.bin"="C:\Program Files\Metin2_TESTER\metin2.bin:*:Enabled:metin2"
"C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe"="C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server"
"C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe"="C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Game.exe"="C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Game.exe:*:Enabled:Tom Clancy's Rainbow Six Vegas 2"
"C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Launcher.exe"="C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Launcher.exe:*:Enabled:Tom Clancy's Rainbow Six Vegas 2 Update"
"C:\Program Files\Cenega Czech\VIETCONG\vietcong.exe"="C:\Program Files\Cenega Czech\VIETCONG\vietcong.exe:*:Disabled:vietcong"
"C:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe"="C:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe:*:Enabled:Medal of Honor Airborne"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-12-07 18:57:51 ----D---- C:\rsit
2010-12-07 18:57:51 ----D---- C:\Program Files\trend micro
2010-12-07 18:53:48 ----D---- C:\Program Files\CCleaner
2010-12-06 21:04:25 ----D---- C:\Documents and Settings\xx\Data aplikací\vlc
2010-12-06 21:03:27 ----D---- C:\Program Files\VideoLAN
2010-12-06 20:46:31 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2010-12-06 20:42:29 ----D---- C:\WINDOWS\ie8updates
2010-12-06 20:38:32 ----HDC---- C:\WINDOWS\ie8
2010-12-06 20:29:56 ----D---- C:\Program Files\Microsoft Security Essentials
2010-12-06 20:20:03 ----SHD---- C:\RECYCLER
2010-12-06 20:14:31 ----D---- C:\WINDOWS\temp
2010-12-06 20:06:14 ----A---- C:\Boot.bak
2010-12-06 20:06:07 ----RASHD---- C:\cmdcons
2010-12-06 20:02:37 ----HD---- C:\WINDOWS\PIF
2010-12-05 15:07:23 ----D---- C:\Beruska.com6008B
2010-12-05 14:39:00 ----D---- C:\Beruska.com
2010-12-05 11:41:24 ----SHD---- C:\WINDOWS\CSC
2010-12-04 15:39:05 ----A---- C:\WINDOWS\system32\hidserv.dll
2010-12-04 14:18:18 ----D---- C:\8dc749fb77e1e8cb09441bdc0983
2010-12-04 14:15:29 ----D---- C:\73bebd2db4bdfbb4b4fcc8df
2010-11-14 16:14:22 ----D---- C:\Program Files\Common Files\PC Tools
2010-11-14 16:14:21 ----D---- C:\Program Files\Registry Mechanic
2010-11-14 16:14:21 ----AD---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP

======List of files/folders modified in the last 1 months======

2010-12-07 18:57:51 ----RD---- C:\Program Files
2010-12-07 18:55:49 ----D---- C:\WINDOWS\Debug
2010-12-07 18:55:49 ----D---- C:\WINDOWS
2010-12-07 18:54:38 ----SD---- C:\WINDOWS\Tasks
2010-12-07 18:50:49 ----D---- C:\WINDOWS\system32\CatRoot2
2010-12-07 18:47:59 ----D---- C:\WINDOWS\system32
2010-12-07 18:47:34 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-12-07 18:46:52 ----D---- C:\WINDOWS\Minidump
2010-12-07 18:46:21 ----D---- C:\WINDOWS\Prefetch
2010-12-07 18:41:58 ----D---- C:\Program Files\Mozilla Firefox
2010-12-07 18:40:20 ----HD---- C:\WINDOWS\inf
2010-12-07 18:40:18 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-12-07 18:40:16 ----HD---- C:\WINDOWS\$hf_mig$
2010-12-07 18:39:26 ----SHD---- C:\System Volume Information
2010-12-07 18:39:26 ----D---- C:\WINDOWS\system32\Restore
2010-12-06 21:08:55 ----D---- C:\WINDOWS\system32\drivers\etc
2010-12-06 20:44:35 ----D---- C:\WINDOWS\system32\cs-cz
2010-12-06 20:44:35 ----D---- C:\WINDOWS\Media
2010-12-06 20:44:35 ----D---- C:\WINDOWS\Help
2010-12-06 20:44:35 ----D---- C:\Program Files\Internet Explorer
2010-12-06 20:38:02 ----SHD---- C:\WINDOWS\Installer
2010-12-06 20:38:00 ----D---- C:\Config.Msi
2010-12-06 20:36:23 ----D---- C:\WINDOWS\system32\drivers
2010-12-06 20:30:00 ----SD---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Microsoft
2010-12-06 20:14:43 ----A---- C:\WINDOWS\system.ini
2010-12-06 20:12:13 ----D---- C:\WINDOWS\AppPatch
2010-12-06 20:12:05 ----D---- C:\Program Files\Common Files
2010-12-06 20:06:14 ----RASH---- C:\boot.ini
2010-12-05 13:47:59 ----D---- C:\WINDOWS\system32\config
2010-12-04 14:24:50 ----D---- C:\Program Files\Common Files\Symantec Shared
2010-12-04 14:22:15 ----D---- C:\Documents and Settings
2010-12-04 14:14:33 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\SeekmoSA
2010-11-18 20:03:03 ----D---- C:\Program Files\Mořské dobrodružství
2010-11-11 15:57:22 ----A---- C:\WINDOWS\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 prohlp02;StarForce Protection Helper Driver v2; C:\WINDOWS\System32\drivers\prohlp02.sys [2004-09-03 115680]
R0 prosync1;StarForce Protection Synchronization Driver v1; C:\WINDOWS\System32\drivers\prosync1.sys [2004-07-19 7040]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-04-23 36624]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2005-05-17 50176]
R0 sfhlp01;StarForce Protection Helper Driver; C:\WINDOWS\System32\drivers\sfhlp01.sys [2003-12-01 4832]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2005-05-16 6656]
R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:\WINDOWS\System32\drivers\sfsync02.sys [2005-05-16 19968]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\WINDOWS\System32\drivers\sfvfs02.sys [2005-06-27 66560]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-06-18 43008]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2010-03-25 151216]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2004-09-03 54368]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2010-02-11 3565056]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\WINDOWS\system32\FsUsbExDisk.SYS []
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-03-26 4395008]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2006-08-15 83200]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\WINDOWS\system32\drivers\WmBEnum.sys [2004-04-14 10144]
R3 WmXlCore;Logitech WingMan Translation Layer Driver; C:\WINDOWS\system32\drivers\WmXlCore.sys [2004-04-14 44064]
S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\sscdbus.sys [2008-02-22 87936]
S3 sscdmdfl;SAMSUNG Mobile Modem Filter; C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys [2008-02-22 14976]
S3 sscdmdm;SAMSUNG Mobile Modem Drivers; C:\WINDOWS\system32\DRIVERS\sscdmdm.sys [2008-02-22 114304]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 WmFilter;Logitech WingMan HID Filter Driver; C:\WINDOWS\system32\drivers\WmFilter.sys [2004-04-14 21280]
S3 WmVirHid;Logitech Virtual Hid Device Driver; C:\WINDOWS\system32\drivers\WmVirHid.sys [2004-04-14 5600]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2010-02-11 602112]
R2 FsUsbExService;FsUsbExService; C:\WINDOWS\system32\FsUsbExService.Exe [2009-01-08 233472]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2010-03-25 17904]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service; C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe [2010-08-05 583640]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-11-09 66872]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2009-11-09 107832]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2010-02-10 593920]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-08-02 135664]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-08-02 182768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]

-----------------EOF-----------------

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Kamarádovo PC, nejde naistalovat ani AV

#26 Příspěvek od vyosek »

Log vypada v poradku :wink:

Za podporu fora jeste jednou dekuji :clapping:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět