
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
pomale nabyhani windows
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
pomale nabyhani windows
zdravim mel jsem v pc dost haveti ale porad mi nabihaji windows stylem najede pozadi a po asi 5 minutach zahraje melodii a jde s tim neco delat. Uz si s tim nevim rady. log z rsit
Logfile of random's system information tool 1.08 (written by random/random)
Run by xxx at 2011-02-03 10:23:38
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 63 GB (82%) free of 76 GB
Total RAM: 503 MB (46% free)
HijackThis download failed
======Scheduled tasks folder======
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Smapp"=C:\Program Files\Analog Devices\SoundMAX\SMTray.exe [2003-07-30 143360]
"LogMeIn GUI"=C:\Program Files\LogMeIn\x86\LogMeInSystray.exe [2010-05-31 63048]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2004-11-02 32768]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\system32\hkcmd.exe [2007-01-13 163840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\system32\igfxtray.exe [2007-01-13 131072]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
C:\Documents and Settings\xxx\weejqdq.exe \u []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\WINDOWS\system32\igfxpers.exe [2007-01-13 135168]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0bxss6e.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\0bxss6e.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0ggbssn.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\0ggbssn.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0tpkk6w.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\0tpkk6w.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^9a1wssn.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\9a1wssn.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^arhhxd60.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\arhhxd60.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^bssneezqqlc.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\bssneezqqlc.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^bxss6ee6.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\bxss6ee6.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^cxoojaav.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\cxoojaav.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^dzpplbbx.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\dzpplbbx.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^dzpplbbxnn.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\dzpplbbxnn.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^lm70njee6q.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\lm70njee6q.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^neezqqlccxo.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\neezqqlccxo.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^nii6uu6gg.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\nii6uu6gg.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^qmmhyytkkf.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\qmmhyytkkf.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rm0dy0pk0r.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\rm0dy0pk0r.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rm1ieezqql.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\rm1ieezqql.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rw86i81ufg.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\rw86i81ufg.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^s6ee6qq6.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\s6ee6qq6.exe []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-01-13 204800]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LMIinit]
C:\WINDOWS\system32\LMIinit.dll [2010-12-16 87424]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Documents and Settings\xxx\Plocha\facebook-pic00005267(2).exe"="c:\windows\nvsvc32.exe:*:Enabled:NVIDIA driver monitor"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2011-02-03 10:16:36 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2011-02-03 10:16:36 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2011-02-03 10:06:54 ----RA---- C:\WINDOWS\system32\drivers\SbFw.sys
2011-02-03 10:06:54 ----A---- C:\WINDOWS\system32\drivers\SbFwIm.sys
2011-02-03 10:06:50 ----D---- C:\Program Files\Sunbelt Software
2011-02-03 10:03:40 ----SHD---- C:\RECYCLER
2011-02-03 10:03:30 ----D---- C:\Program Files\CCleaner
2011-02-03 09:18:56 ----D---- C:\Documents and Settings\xxx\Data aplikací\Malwarebytes
2011-02-03 09:18:49 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2011-02-03 09:18:49 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011-02-03 09:18:46 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-02-03 09:18:46 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2011-02-03 08:57:10 ----D---- C:\rsit
2011-02-03 08:57:10 ----D---- C:\Program Files\trend micro
2011-02-02 14:34:05 ----D---- C:\WINDOWS\temp
2011-02-02 14:34:04 ----A---- C:\ComboFix.txt
2011-02-02 14:22:32 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2011-02-02 14:22:32 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2011-02-02 14:22:31 ----A---- C:\WINDOWS\system32\drivers\aswmon2.sys
2011-02-02 14:22:31 ----A---- C:\WINDOWS\system32\drivers\aswmon.sys
2011-02-02 14:22:31 ----A---- C:\WINDOWS\system32\drivers\aavmker4.sys
2011-02-02 14:22:28 ----A---- C:\WINDOWS\system32\MSVCR71.dll
2011-02-02 14:22:28 ----A---- C:\WINDOWS\system32\MSVCP71.dll
2011-02-02 14:22:28 ----A---- C:\WINDOWS\system32\MFC71.dll
2011-02-02 14:22:28 ----A---- C:\WINDOWS\system32\aswBoot.exe
2011-02-02 14:04:48 ----A---- C:\Boot.bak
2011-02-02 14:04:45 ----RASHD---- C:\cmdcons
2011-02-02 14:02:50 ----A---- C:\WINDOWS\zip.exe
2011-02-02 14:02:50 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-02-02 14:02:50 ----A---- C:\WINDOWS\SWSC.exe
2011-02-02 14:02:50 ----A---- C:\WINDOWS\SWREG.exe
2011-02-02 14:02:50 ----A---- C:\WINDOWS\sed.exe
2011-02-02 14:02:50 ----A---- C:\WINDOWS\PEV.exe
2011-02-02 14:02:50 ----A---- C:\WINDOWS\NIRCMD.exe
2011-02-02 14:02:50 ----A---- C:\WINDOWS\MBR.exe
2011-02-02 14:02:50 ----A---- C:\WINDOWS\grep.exe
2011-02-02 13:56:24 ----AH---- C:\Documents and Settings\xxx\Data aplikací\HhdFJl61DD.txt
2011-02-02 13:52:04 ----D---- C:\WINDOWS\ERDNT
2011-02-02 13:51:57 ----D---- C:\Qoobox
2011-02-02 13:44:52 ----A---- C:\WINDOWS\system32\drivers\pcszsglm.sys
2011-02-02 13:41:05 ----D---- C:\WINDOWS\pss
2011-02-02 13:37:41 ----A---- C:\WINDOWS\system32\drivers\yyzyv.sys
2011-01-29 14:01:10 ----A---- C:\WINDOWS\system32\drivers\lbrtfdc.sys
2011-01-29 14:01:09 ----A---- C:\WINDOWS\system32\drivers\i2omgmt.sys
2011-01-29 14:01:08 ----A---- C:\WINDOWS\system32\drivers\changer.sys
2011-01-27 08:03:39 ----AH---- C:\Documents and Settings\xxx\Data aplikací\n1cLg8mgHL.txt
2011-01-27 08:03:36 ----A---- C:\m23w.exe
2011-01-05 16:30:00 ----A---- C:\WINDOWS\ODBC.INI
2011-01-05 16:29:52 ----A---- C:\WINDOWS\system32\mdimon.dll
2011-01-05 16:29:02 ----D---- C:\Program Files\Microsoft.NET
2011-01-05 16:28:27 ----D---- C:\Program Files\Common Files\DESIGNER
2011-01-05 16:28:06 ----D---- C:\WINDOWS\SHELLNEW
2011-01-05 16:28:02 ----D---- C:\Program Files\Microsoft Office
2011-01-05 16:26:31 ----RD---- C:\MSOCache
2011-01-05 16:25:51 ----D---- C:\Documents and Settings\xxx\Data aplikací\WinRAR
2011-01-05 16:13:37 ----D---- C:\Program Files\WinRAR
2011-01-05 16:05:33 ----D---- C:\WINDOWS\system32\appmgmt
======List of files/folders modified in the last 1 months======
2011-02-03 10:16:36 ----D---- C:\WINDOWS\system32\drivers
2011-02-03 10:16:12 ----D---- C:\WINDOWS\system32
2011-02-03 10:10:11 ----D---- C:\WINDOWS
2011-02-03 10:07:48 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-02-03 10:07:02 ----SHD---- C:\WINDOWS\Installer
2011-02-03 10:06:57 ----HD---- C:\WINDOWS\inf
2011-02-03 10:06:55 ----D---- C:\WINDOWS\system32\CatRoot2
2011-02-03 10:06:50 ----RD---- C:\Program Files
2011-02-03 10:03:40 ----D---- C:\WINDOWS\Minidump
2011-02-03 10:03:40 ----D---- C:\WINDOWS\Debug
2011-02-03 08:53:59 ----D---- C:\WINDOWS\Prefetch
2011-02-03 08:52:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\LogMeIn
2011-02-02 14:32:31 ----A---- C:\WINDOWS\system.ini
2011-02-02 14:30:57 ----D---- C:\WINDOWS\AppPatch
2011-02-02 14:30:54 ----D---- C:\Program Files\Common Files
2011-02-02 14:26:45 ----D---- C:\WINDOWS\system32\config
2011-02-02 14:22:26 ----D---- C:\Program Files\Alwil Software
2011-02-02 14:08:22 ----D---- C:\WINDOWS\system32\drivers\etc
2011-02-02 14:04:49 ----RASH---- C:\boot.ini
2011-02-02 13:47:44 ----A---- C:\WINDOWS\win.ini
2011-02-02 13:33:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2011-01-29 14:01:30 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-01-27 15:45:56 ----D---- C:\Program Files\Ask.com
2011-01-25 22:38:43 ----RSD---- C:\WINDOWS\Fonts
2011-01-13 17:19:09 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-01-06 20:33:51 ----SD---- C:\Documents and Settings\xxx\Data aplikací\Microsoft
2011-01-05 16:29:08 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-01-05 16:28:08 ----D---- C:\Program Files\Common Files\System
2011-01-05 16:28:02 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-01-05 16:28:02 ----D---- C:\WINDOWS\pchealth
2011-01-05 16:26:35 ----D---- C:\WINDOWS\system
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-17 39936]
R1 SbFw;SbFw; C:\WINDOWS\system32\drivers\SbFw.sys [2008-10-31 270888]
R1 sbhips;Sunbelt HIPS Driver; C:\WINDOWS\system32\drivers\sbhips.sys [2008-06-21 66600]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2004-08-04 8832]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-11-25 94160]
R2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files\LogMeIn\x86\RaInfo.sys []
R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\WINDOWS\system32\drivers\LMIRfsDriver.sys []
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2003-10-23 100384]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2008-07-25 176640]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-01-13 5672032]
R3 lmimirr;lmimirr; C:\WINDOWS\system32\DRIVERS\lmimirr.sys [2010-05-31 10144]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport; C:\WINDOWS\system32\DRIVERS\sbfwim.sys [2008-06-21 65576]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2004-04-15 612416]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
S3 catchme;catchme; \??\C:\DOCUME~1\xxx\LOCALS~1\Temp\catchme.sys []
S3 cdnvorme;cdnvorme; \??\C:\WINDOWS\System32\Drivers\cdnvorme.sys []
S3 gayhjmem;gayhjmem; \??\C:\WINDOWS\System32\Drivers\gayhjmem.sys []
S3 hzigaoxl;hzigaoxl; \??\C:\WINDOWS\System32\Drivers\hzigaoxl.sys []
S3 jnckoxip;jnckoxip; \??\C:\WINDOWS\System32\Drivers\jnckoxip.sys []
S3 msyktsat;msyktsat; \??\C:\WINDOWS\System32\Drivers\msyktsat.sys []
S3 nwhpnlbd;nwhpnlbd; \??\C:\WINDOWS\System32\Drivers\nwhpnlbd.sys []
S3 pcszsglm;pcszsglm; \??\C:\WINDOWS\System32\Drivers\pcszsglm.sys []
S3 tzxhyhiz;tzxhyhiz; \??\C:\WINDOWS\System32\Drivers\tzxhyhiz.sys []
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S4 LMIRfsClientNP;LMIRfsClientNP; C:\WINDOWS\system32\drivers\LMIRfsClientNP.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe [2010-12-16 374152]
R2 LMIMaint;LogMeIn Maintenance Service; C:\Program Files\LogMeIn\x86\RaMaint.exe [2010-12-16 136584]
R2 LogMeIn;LogMeIn; C:\Program Files\LogMeIn\x86\LogMeIn.exe [2010-12-16 390528]
R2 SbPF.Launcher;SbPF.Launcher; C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [2008-10-31 95528]
R2 SoundMAX Agent Service (default);SoundMAX Agent Service; C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [2002-09-20 45056]
R2 SPF4;Sunbelt Personal Firewall 4; C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [2008-10-31 1365288]
S3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-06-11 136120]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
-----------------EOF-----------------
Logfile of random's system information tool 1.08 (written by random/random)
Run by xxx at 2011-02-03 10:23:38
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 63 GB (82%) free of 76 GB
Total RAM: 503 MB (46% free)
HijackThis download failed
======Scheduled tasks folder======
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Smapp"=C:\Program Files\Analog Devices\SoundMAX\SMTray.exe [2003-07-30 143360]
"LogMeIn GUI"=C:\Program Files\LogMeIn\x86\LogMeInSystray.exe [2010-05-31 63048]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2004-11-02 32768]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\system32\hkcmd.exe [2007-01-13 163840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\system32\igfxtray.exe [2007-01-13 131072]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
C:\Documents and Settings\xxx\weejqdq.exe \u []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\WINDOWS\system32\igfxpers.exe [2007-01-13 135168]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0bxss6e.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\0bxss6e.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0ggbssn.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\0ggbssn.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0tpkk6w.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\0tpkk6w.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^9a1wssn.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\9a1wssn.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^arhhxd60.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\arhhxd60.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^bssneezqqlc.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\bssneezqqlc.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^bxss6ee6.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\bxss6ee6.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^cxoojaav.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\cxoojaav.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^dzpplbbx.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\dzpplbbx.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^dzpplbbxnn.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\dzpplbbxnn.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^lm70njee6q.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\lm70njee6q.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^neezqqlccxo.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\neezqqlccxo.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^nii6uu6gg.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\nii6uu6gg.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^qmmhyytkkf.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\qmmhyytkkf.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rm0dy0pk0r.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\rm0dy0pk0r.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rm1ieezqql.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\rm1ieezqql.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rw86i81ufg.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\rw86i81ufg.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^s6ee6qq6.exe]
C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\s6ee6qq6.exe []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-01-13 204800]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LMIinit]
C:\WINDOWS\system32\LMIinit.dll [2010-12-16 87424]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Documents and Settings\xxx\Plocha\facebook-pic00005267(2).exe"="c:\windows\nvsvc32.exe:*:Enabled:NVIDIA driver monitor"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2011-02-03 10:16:36 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2011-02-03 10:16:36 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2011-02-03 10:06:54 ----RA---- C:\WINDOWS\system32\drivers\SbFw.sys
2011-02-03 10:06:54 ----A---- C:\WINDOWS\system32\drivers\SbFwIm.sys
2011-02-03 10:06:50 ----D---- C:\Program Files\Sunbelt Software
2011-02-03 10:03:40 ----SHD---- C:\RECYCLER
2011-02-03 10:03:30 ----D---- C:\Program Files\CCleaner
2011-02-03 09:18:56 ----D---- C:\Documents and Settings\xxx\Data aplikací\Malwarebytes
2011-02-03 09:18:49 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2011-02-03 09:18:49 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011-02-03 09:18:46 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-02-03 09:18:46 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2011-02-03 08:57:10 ----D---- C:\rsit
2011-02-03 08:57:10 ----D---- C:\Program Files\trend micro
2011-02-02 14:34:05 ----D---- C:\WINDOWS\temp
2011-02-02 14:34:04 ----A---- C:\ComboFix.txt
2011-02-02 14:22:32 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2011-02-02 14:22:32 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2011-02-02 14:22:31 ----A---- C:\WINDOWS\system32\drivers\aswmon2.sys
2011-02-02 14:22:31 ----A---- C:\WINDOWS\system32\drivers\aswmon.sys
2011-02-02 14:22:31 ----A---- C:\WINDOWS\system32\drivers\aavmker4.sys
2011-02-02 14:22:28 ----A---- C:\WINDOWS\system32\MSVCR71.dll
2011-02-02 14:22:28 ----A---- C:\WINDOWS\system32\MSVCP71.dll
2011-02-02 14:22:28 ----A---- C:\WINDOWS\system32\MFC71.dll
2011-02-02 14:22:28 ----A---- C:\WINDOWS\system32\aswBoot.exe
2011-02-02 14:04:48 ----A---- C:\Boot.bak
2011-02-02 14:04:45 ----RASHD---- C:\cmdcons
2011-02-02 14:02:50 ----A---- C:\WINDOWS\zip.exe
2011-02-02 14:02:50 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-02-02 14:02:50 ----A---- C:\WINDOWS\SWSC.exe
2011-02-02 14:02:50 ----A---- C:\WINDOWS\SWREG.exe
2011-02-02 14:02:50 ----A---- C:\WINDOWS\sed.exe
2011-02-02 14:02:50 ----A---- C:\WINDOWS\PEV.exe
2011-02-02 14:02:50 ----A---- C:\WINDOWS\NIRCMD.exe
2011-02-02 14:02:50 ----A---- C:\WINDOWS\MBR.exe
2011-02-02 14:02:50 ----A---- C:\WINDOWS\grep.exe
2011-02-02 13:56:24 ----AH---- C:\Documents and Settings\xxx\Data aplikací\HhdFJl61DD.txt
2011-02-02 13:52:04 ----D---- C:\WINDOWS\ERDNT
2011-02-02 13:51:57 ----D---- C:\Qoobox
2011-02-02 13:44:52 ----A---- C:\WINDOWS\system32\drivers\pcszsglm.sys
2011-02-02 13:41:05 ----D---- C:\WINDOWS\pss
2011-02-02 13:37:41 ----A---- C:\WINDOWS\system32\drivers\yyzyv.sys
2011-01-29 14:01:10 ----A---- C:\WINDOWS\system32\drivers\lbrtfdc.sys
2011-01-29 14:01:09 ----A---- C:\WINDOWS\system32\drivers\i2omgmt.sys
2011-01-29 14:01:08 ----A---- C:\WINDOWS\system32\drivers\changer.sys
2011-01-27 08:03:39 ----AH---- C:\Documents and Settings\xxx\Data aplikací\n1cLg8mgHL.txt
2011-01-27 08:03:36 ----A---- C:\m23w.exe
2011-01-05 16:30:00 ----A---- C:\WINDOWS\ODBC.INI
2011-01-05 16:29:52 ----A---- C:\WINDOWS\system32\mdimon.dll
2011-01-05 16:29:02 ----D---- C:\Program Files\Microsoft.NET
2011-01-05 16:28:27 ----D---- C:\Program Files\Common Files\DESIGNER
2011-01-05 16:28:06 ----D---- C:\WINDOWS\SHELLNEW
2011-01-05 16:28:02 ----D---- C:\Program Files\Microsoft Office
2011-01-05 16:26:31 ----RD---- C:\MSOCache
2011-01-05 16:25:51 ----D---- C:\Documents and Settings\xxx\Data aplikací\WinRAR
2011-01-05 16:13:37 ----D---- C:\Program Files\WinRAR
2011-01-05 16:05:33 ----D---- C:\WINDOWS\system32\appmgmt
======List of files/folders modified in the last 1 months======
2011-02-03 10:16:36 ----D---- C:\WINDOWS\system32\drivers
2011-02-03 10:16:12 ----D---- C:\WINDOWS\system32
2011-02-03 10:10:11 ----D---- C:\WINDOWS
2011-02-03 10:07:48 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-02-03 10:07:02 ----SHD---- C:\WINDOWS\Installer
2011-02-03 10:06:57 ----HD---- C:\WINDOWS\inf
2011-02-03 10:06:55 ----D---- C:\WINDOWS\system32\CatRoot2
2011-02-03 10:06:50 ----RD---- C:\Program Files
2011-02-03 10:03:40 ----D---- C:\WINDOWS\Minidump
2011-02-03 10:03:40 ----D---- C:\WINDOWS\Debug
2011-02-03 08:53:59 ----D---- C:\WINDOWS\Prefetch
2011-02-03 08:52:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\LogMeIn
2011-02-02 14:32:31 ----A---- C:\WINDOWS\system.ini
2011-02-02 14:30:57 ----D---- C:\WINDOWS\AppPatch
2011-02-02 14:30:54 ----D---- C:\Program Files\Common Files
2011-02-02 14:26:45 ----D---- C:\WINDOWS\system32\config
2011-02-02 14:22:26 ----D---- C:\Program Files\Alwil Software
2011-02-02 14:08:22 ----D---- C:\WINDOWS\system32\drivers\etc
2011-02-02 14:04:49 ----RASH---- C:\boot.ini
2011-02-02 13:47:44 ----A---- C:\WINDOWS\win.ini
2011-02-02 13:33:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2011-01-29 14:01:30 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-01-27 15:45:56 ----D---- C:\Program Files\Ask.com
2011-01-25 22:38:43 ----RSD---- C:\WINDOWS\Fonts
2011-01-13 17:19:09 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-01-06 20:33:51 ----SD---- C:\Documents and Settings\xxx\Data aplikací\Microsoft
2011-01-05 16:29:08 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-01-05 16:28:08 ----D---- C:\Program Files\Common Files\System
2011-01-05 16:28:02 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-01-05 16:28:02 ----D---- C:\WINDOWS\pchealth
2011-01-05 16:26:35 ----D---- C:\WINDOWS\system
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-17 39936]
R1 SbFw;SbFw; C:\WINDOWS\system32\drivers\SbFw.sys [2008-10-31 270888]
R1 sbhips;Sunbelt HIPS Driver; C:\WINDOWS\system32\drivers\sbhips.sys [2008-06-21 66600]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2004-08-04 8832]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-11-25 94160]
R2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files\LogMeIn\x86\RaInfo.sys []
R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\WINDOWS\system32\drivers\LMIRfsDriver.sys []
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2003-10-23 100384]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2008-07-25 176640]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-01-13 5672032]
R3 lmimirr;lmimirr; C:\WINDOWS\system32\DRIVERS\lmimirr.sys [2010-05-31 10144]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport; C:\WINDOWS\system32\DRIVERS\sbfwim.sys [2008-06-21 65576]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2004-04-15 612416]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
S3 catchme;catchme; \??\C:\DOCUME~1\xxx\LOCALS~1\Temp\catchme.sys []
S3 cdnvorme;cdnvorme; \??\C:\WINDOWS\System32\Drivers\cdnvorme.sys []
S3 gayhjmem;gayhjmem; \??\C:\WINDOWS\System32\Drivers\gayhjmem.sys []
S3 hzigaoxl;hzigaoxl; \??\C:\WINDOWS\System32\Drivers\hzigaoxl.sys []
S3 jnckoxip;jnckoxip; \??\C:\WINDOWS\System32\Drivers\jnckoxip.sys []
S3 msyktsat;msyktsat; \??\C:\WINDOWS\System32\Drivers\msyktsat.sys []
S3 nwhpnlbd;nwhpnlbd; \??\C:\WINDOWS\System32\Drivers\nwhpnlbd.sys []
S3 pcszsglm;pcszsglm; \??\C:\WINDOWS\System32\Drivers\pcszsglm.sys []
S3 tzxhyhiz;tzxhyhiz; \??\C:\WINDOWS\System32\Drivers\tzxhyhiz.sys []
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S4 LMIRfsClientNP;LMIRfsClientNP; C:\WINDOWS\system32\drivers\LMIRfsClientNP.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe [2010-12-16 374152]
R2 LMIMaint;LogMeIn Maintenance Service; C:\Program Files\LogMeIn\x86\RaMaint.exe [2010-12-16 136584]
R2 LogMeIn;LogMeIn; C:\Program Files\LogMeIn\x86\LogMeIn.exe [2010-12-16 390528]
R2 SbPF.Launcher;SbPF.Launcher; C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [2008-10-31 95528]
R2 SoundMAX Agent Service (default);SoundMAX Agent Service; C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [2002-09-20 45056]
R2 SPF4;Sunbelt Personal Firewall 4; C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [2008-10-31 1365288]
S3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-06-11 136120]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
-----------------EOF-----------------
Re: pomale nabyhani windows
Zdravim a pekny den preji
Ten vcerejsi ComboFix jste delal na pokyn nejakeho Radce
Byl jeho log dolusten a vysten pomoci skriptu
Nebo jste si jej jen tak sam od sebe pustil
Nebezpeci CFka
Poprosim tedy o log z CFka, je ulozen v c:\combofix.txt






- Je urcen primarne pro radce - jeho svevolnym pouzitim ztracite narok na podporu
- Maze stopy po haveti, takze v logu z RSIT neni nic videt
- Jeho log je treba dolustit, jelikoz neumi smazat vse - to ovsem tezko zvladnete pokud k tomu nejste vyskolen
- CF muze mit bug = sunda Vam system, pokud nevite kam co uklada, jak co obnovit, mate system v kytkam a ceka Vas reinstal
- CF taky bohuzel prozatim nekontroluje nektere dulezite knihovny (napr. hal.dll) - ty treba mazou nektere typy haveti (napr. angela) - smaze Vam po restartu hal.dll = nenajede Vam system a jste o radek vyse = reinstal

Re: pomale nabyhani windows
pustil jsem to a myslel ze to pomuze
log z CF
ComboFix 11-01-31.02 - xxx 02.02.2011 14:28:40.3.2 - x86 MINIMAL
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.503.399 [GMT 1:00]
Spuštěný z: c:\documents and settings\xxx\Plocha\ComboFix.exe
AV: avast! antivirus 4.6.763 [VPS 0611-0] *Enabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-02 do 2011-02-02 )))))))))))))))))))))))))))))))
.
2011-02-02 13:22 . 2006-01-27 23:03 16352 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-02-02 13:22 . 2006-01-27 23:02 36176 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-02-02 13:22 . 2006-01-27 23:05 85760 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-02-02 13:22 . 2006-01-27 23:04 83968 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-02-02 13:22 . 2006-01-27 23:00 24240 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-02-02 13:22 . 2006-01-27 22:38 503296 ----a-w- c:\windows\system32\aswBoot.exe
2011-02-02 13:22 . 2006-01-27 22:30 90112 ----a-w- c:\windows\system32\AVASTSS.scr
2011-02-02 13:22 . 2004-01-09 09:13 380928 ----a-w- c:\windows\system32\actskin4.ocx
2011-02-02 13:22 . 2003-03-18 20:20 1060864 ----a-w- c:\windows\system32\MFC71.dll
2011-02-02 13:22 . 2003-03-18 19:14 499712 ----a-w- c:\windows\system32\MSVCP71.dll
2011-02-02 13:22 . 2003-02-21 03:42 348160 ----a-w- c:\windows\system32\MSVCR71.dll
2011-02-02 12:44 . 2011-02-02 12:44 40128 ----a-w- c:\windows\system32\drivers\pcszsglm.sys
2011-02-02 12:37 . 2011-02-02 13:32 737280 ----a-w- c:\windows\system32\drivers\yyzyv.sys
2011-01-29 13:01 . 2004-08-03 21:59 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2011-01-29 13:01 . 2004-08-03 21:59 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2011-01-29 13:01 . 2004-08-03 22:00 8192 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys
2011-01-29 13:01 . 2004-08-03 22:00 8192 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2011-01-29 13:01 . 2004-08-03 22:00 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2011-01-29 13:01 . 2004-08-03 22:00 8192 ----a-w- c:\windows\system32\drivers\changer.sys
2011-01-27 07:03 . 2011-01-27 07:03 163840 --sh--r- c:\documents and settings\xxx\Data aplikací\juzjf.exe
2011-01-27 07:03 . 2011-01-27 07:03 163840 ----a-w- C:\m23w.exe
2011-01-05 15:29 . 2003-06-19 00:31 18944 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\mdippr.dll
2011-01-05 15:29 . 2003-06-19 00:31 17920 ----a-w- c:\windows\system32\mdimon.dll
2011-01-05 15:29 . 2011-01-05 15:29 -------- d-----w- c:\program files\Microsoft.NET
2011-01-05 15:28 . 2011-01-05 15:29 -------- d-----w- c:\windows\SHELLNEW
2011-01-05 15:26 . 2011-01-05 15:26 -------- d-----r- C:\MSOCache
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-16 19:59 . 2010-10-05 07:15 83360 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2010-12-16 19:59 . 2010-10-05 07:15 53632 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2010-12-16 19:59 . 2010-10-05 07:15 29568 ----a-w- c:\windows\system32\LMIport.dll
2010-12-16 19:59 . 2010-10-05 07:15 87424 ----a-w- c:\windows\system32\LMIinit.dll
2010-11-20 20:34 . 2010-11-20 14:48 779368262 ----a-w- c:\windows\java\trustlib\addins\Nová složka\Sindicate.exe
2010-11-20 16:59 . 2010-11-20 16:59 207360 ----a-w- c:\windows\java\trustlib\addins\Nová složka\mr_bean.exe
2010-11-20 16:58 . 2010-11-20 16:58 34176 ----a-w- c:\windows\java\trustlib\addins\Nová složka\voda.exe
2010-11-20 16:57 . 2010-11-20 16:57 282624 ----a-w- c:\windows\java\trustlib\addins\Nová složka\po_poziti_alkoholu.exe
2010-11-20 16:56 . 2010-11-20 16:56 123904 ----a-w- c:\windows\java\trustlib\addins\Nová složka\krb.exe
2010-11-20 16:51 . 2010-11-20 16:51 40976 ----a-w- c:\windows\java\trustlib\addins\Nová složka\load.exe
2010-11-20 16:49 . 2010-11-20 16:49 1002622 ----a-w- c:\windows\java\trustlib\addins\Nová složka\vytvor_si_sefa.exe
2010-11-20 16:47 . 2010-11-20 16:47 341331 ----a-w- c:\windows\java\trustlib\addins\Nová složka\potrapte_rybu.exe
2010-11-20 16:45 . 2010-11-20 16:45 37984 ----a-w- c:\windows\java\trustlib\addins\Nová složka\tv.exe
2010-11-20 16:43 . 2010-11-20 16:43 94208 ----a-w- c:\windows\java\trustlib\addins\Nová složka\foceni_monitorem.exe
2010-11-20 16:42 . 2010-11-20 16:42 142336 ----a-w- c:\windows\java\trustlib\addins\Nová složka\winmine.exe
2010-11-20 16:40 . 2010-11-20 16:40 333848 ----a-w- c:\windows\java\trustlib\addins\Nová složka\inspekce_disku.exe
2010-11-20 16:39 . 2010-11-20 16:39 365616 ----a-w- c:\windows\java\trustlib\addins\Nová složka\pobihajici_pomeranc.exe
2010-11-20 16:38 . 2010-11-20 16:38 163927 ----a-w- c:\windows\java\trustlib\addins\Nová složka\poradne_oplachnuty_monitor.exe
2010-11-20 15:49 . 2010-11-20 15:44 14259704 ----a-w- c:\windows\java\trustlib\addins\Nová složka\picasa38cz-setup.exe
.
------- Sigcheck -------
[-] 2008-01-22 . 21DC51B6D100B4C7691D07ECF3807444 . 1548288 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="c:\program files\Analog Devices\SoundMAX\SMTray.exe" [2003-07-30 143360]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2010-05-31 63048]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
c:\documents and settings\xxx\Nabˇdka Start\Programy\Po spuçtŘnˇ\
0bxss6e.exe [2011-1-31 40448]
0ggbssn.exe [2011-2-2 43520]
0tpkk6w.exe [2011-2-1 43520]
0yytkkf.exe [2011-2-2 43520]
1cyytkk.exe [2011-2-2 43520]
2dyy6kk.exe [2011-2-2 40448]
9a1wssn.exe [2011-2-2 43520]
9s1okkf.exe [2011-2-2 40448]
arhhxd60.exe [2011-1-30 43520]
bssneezqqlc.exe [2011-2-2 40448]
bxss6ee6.exe [2011-2-2 43520]
cxoojaav.exe [2011-2-1 43520]
dzpplbbx.exe [2011-2-1 43520]
dzpplbbxnn.exe [2011-1-31 43520]
lm70njee6q.exe [2011-1-31 43520]
m6yy6kk6.exe [2011-2-2 40448]
neezqqlccxo.exe [2011-1-31 40448]
nii6uu6gg.exe [2011-2-1 43520]
qmmhyytkkf.exe [2011-2-2 40448]
rm0dy0pk0r.exe [2011-1-30 40448]
rm1ieezqql.exe [2011-2-2 43520]
rw86i81ufg.exe [2011-1-30 43520]
s6ee6qq6.exe [2011-1-31 40448]
w9s1okkfww.exe [2011-2-2 43520]
wssneezqql.exe [2011-2-2 43520]
xxtjjfvvrhh.exe [2011-2-2 40448]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2010-12-16 19:59 87424 ----a-w- c:\windows\system32\LMIinit.dll
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0bxss6e.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\0bxss6e.exe
backup=c:\windows\pss\0bxss6e.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0ggbssn.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\0ggbssn.exe
backup=c:\windows\pss\0ggbssn.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0tpkk6w.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\0tpkk6w.exe
backup=c:\windows\pss\0tpkk6w.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^9a1wssn.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\9a1wssn.exe
backup=c:\windows\pss\9a1wssn.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^arhhxd60.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\arhhxd60.exe
backup=c:\windows\pss\arhhxd60.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^bssneezqqlc.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\bssneezqqlc.exe
backup=c:\windows\pss\bssneezqqlc.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^bxss6ee6.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\bxss6ee6.exe
backup=c:\windows\pss\bxss6ee6.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^cxoojaav.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\cxoojaav.exe
backup=c:\windows\pss\cxoojaav.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^dzpplbbx.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\dzpplbbx.exe
backup=c:\windows\pss\dzpplbbx.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^dzpplbbxnn.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\dzpplbbxnn.exe
backup=c:\windows\pss\dzpplbbxnn.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^lm70njee6q.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\lm70njee6q.exe
backup=c:\windows\pss\lm70njee6q.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^neezqqlccxo.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\neezqqlccxo.exe
backup=c:\windows\pss\neezqqlccxo.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^nii6uu6gg.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\nii6uu6gg.exe
backup=c:\windows\pss\nii6uu6gg.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^qmmhyytkkf.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\qmmhyytkkf.exe
backup=c:\windows\pss\qmmhyytkkf.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rm0dy0pk0r.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\rm0dy0pk0r.exe
backup=c:\windows\pss\rm0dy0pk0r.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rm1ieezqql.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\rm1ieezqql.exe
backup=c:\windows\pss\rm1ieezqql.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rw86i81ufg.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\rw86i81ufg.exe
backup=c:\windows\pss\rw86i81ufg.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^s6ee6qq6.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\s6ee6qq6.exe
backup=c:\windows\pss\s6ee6qq6.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
c:\documents and settings\xxx\weejqdq.exe \u [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2007-01-13 08:47 163840 ----a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2007-01-13 08:47 131072 ----a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2007-01-13 08:46 135168 ----a-w- c:\windows\system32\igfxpers.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\xxx\\Plocha\\facebook-pic00005267(2).exe"= c:\\windows\\nvsvc32.exe
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [27.9.2010 13:47 374152]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [31.5.2010 10:31 12856]
S3 cdnvorme;cdnvorme;\??\c:\windows\System32\Drivers\cdnvorme.sys --> c:\windows\System32\Drivers\cdnvorme.sys [?]
S3 gayhjmem;gayhjmem;\??\c:\windows\System32\Drivers\gayhjmem.sys --> c:\windows\System32\Drivers\gayhjmem.sys [?]
S3 hzigaoxl;hzigaoxl;\??\c:\windows\System32\Drivers\hzigaoxl.sys --> c:\windows\System32\Drivers\hzigaoxl.sys [?]
S3 jnckoxip;jnckoxip;\??\c:\windows\System32\Drivers\jnckoxip.sys --> c:\windows\System32\Drivers\jnckoxip.sys [?]
S3 msyktsat;msyktsat;\??\c:\windows\System32\Drivers\msyktsat.sys --> c:\windows\System32\Drivers\msyktsat.sys [?]
S3 nwhpnlbd;nwhpnlbd;\??\c:\windows\System32\Drivers\nwhpnlbd.sys --> c:\windows\System32\Drivers\nwhpnlbd.sys [?]
S3 pcszsglm;pcszsglm;c:\windows\system32\drivers\pcszsglm.sys [2.2.2011 13:44 40128]
S3 tzxhyhiz;tzxhyhiz;\??\c:\windows\System32\Drivers\tzxhyhiz.sys --> c:\windows\System32\Drivers\tzxhyhiz.sys [?]
--- Ostatní služby/ovladače v paměti ---
*Deregistered* - yyzyv
.
Obsah adresáře 'Naplánované úlohy'
2011-02-02 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-02-04 14:50]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\xxx\Data aplikací\Mozilla\Firefox\Profiles\3f0ytt0f.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-02 14:32
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\yyzyv]
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(252)
c:\windows\system32\LMIinit.dll
.
Celkový čas: 2011-02-02 14:34:03
ComboFix-quarantined-files.txt 2011-02-02 13:34
ComboFix2.txt 2011-02-02 13:20
ComboFix3.txt 2011-02-02 13:09
Před spuštěním: Volných bajtů: 66 013 462 528
Po spuštění: Volných bajtů: 66 006 196 224
- - End Of File - - 602D654C2C4A3DF576101F5C89130A0D

log z CF
ComboFix 11-01-31.02 - xxx 02.02.2011 14:28:40.3.2 - x86 MINIMAL
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.503.399 [GMT 1:00]
Spuštěný z: c:\documents and settings\xxx\Plocha\ComboFix.exe
AV: avast! antivirus 4.6.763 [VPS 0611-0] *Enabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-02 do 2011-02-02 )))))))))))))))))))))))))))))))
.
2011-02-02 13:22 . 2006-01-27 23:03 16352 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-02-02 13:22 . 2006-01-27 23:02 36176 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-02-02 13:22 . 2006-01-27 23:05 85760 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-02-02 13:22 . 2006-01-27 23:04 83968 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-02-02 13:22 . 2006-01-27 23:00 24240 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-02-02 13:22 . 2006-01-27 22:38 503296 ----a-w- c:\windows\system32\aswBoot.exe
2011-02-02 13:22 . 2006-01-27 22:30 90112 ----a-w- c:\windows\system32\AVASTSS.scr
2011-02-02 13:22 . 2004-01-09 09:13 380928 ----a-w- c:\windows\system32\actskin4.ocx
2011-02-02 13:22 . 2003-03-18 20:20 1060864 ----a-w- c:\windows\system32\MFC71.dll
2011-02-02 13:22 . 2003-03-18 19:14 499712 ----a-w- c:\windows\system32\MSVCP71.dll
2011-02-02 13:22 . 2003-02-21 03:42 348160 ----a-w- c:\windows\system32\MSVCR71.dll
2011-02-02 12:44 . 2011-02-02 12:44 40128 ----a-w- c:\windows\system32\drivers\pcszsglm.sys
2011-02-02 12:37 . 2011-02-02 13:32 737280 ----a-w- c:\windows\system32\drivers\yyzyv.sys
2011-01-29 13:01 . 2004-08-03 21:59 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2011-01-29 13:01 . 2004-08-03 21:59 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2011-01-29 13:01 . 2004-08-03 22:00 8192 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys
2011-01-29 13:01 . 2004-08-03 22:00 8192 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2011-01-29 13:01 . 2004-08-03 22:00 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2011-01-29 13:01 . 2004-08-03 22:00 8192 ----a-w- c:\windows\system32\drivers\changer.sys
2011-01-27 07:03 . 2011-01-27 07:03 163840 --sh--r- c:\documents and settings\xxx\Data aplikací\juzjf.exe
2011-01-27 07:03 . 2011-01-27 07:03 163840 ----a-w- C:\m23w.exe
2011-01-05 15:29 . 2003-06-19 00:31 18944 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\mdippr.dll
2011-01-05 15:29 . 2003-06-19 00:31 17920 ----a-w- c:\windows\system32\mdimon.dll
2011-01-05 15:29 . 2011-01-05 15:29 -------- d-----w- c:\program files\Microsoft.NET
2011-01-05 15:28 . 2011-01-05 15:29 -------- d-----w- c:\windows\SHELLNEW
2011-01-05 15:26 . 2011-01-05 15:26 -------- d-----r- C:\MSOCache
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-16 19:59 . 2010-10-05 07:15 83360 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2010-12-16 19:59 . 2010-10-05 07:15 53632 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2010-12-16 19:59 . 2010-10-05 07:15 29568 ----a-w- c:\windows\system32\LMIport.dll
2010-12-16 19:59 . 2010-10-05 07:15 87424 ----a-w- c:\windows\system32\LMIinit.dll
2010-11-20 20:34 . 2010-11-20 14:48 779368262 ----a-w- c:\windows\java\trustlib\addins\Nová složka\Sindicate.exe
2010-11-20 16:59 . 2010-11-20 16:59 207360 ----a-w- c:\windows\java\trustlib\addins\Nová složka\mr_bean.exe
2010-11-20 16:58 . 2010-11-20 16:58 34176 ----a-w- c:\windows\java\trustlib\addins\Nová složka\voda.exe
2010-11-20 16:57 . 2010-11-20 16:57 282624 ----a-w- c:\windows\java\trustlib\addins\Nová složka\po_poziti_alkoholu.exe
2010-11-20 16:56 . 2010-11-20 16:56 123904 ----a-w- c:\windows\java\trustlib\addins\Nová složka\krb.exe
2010-11-20 16:51 . 2010-11-20 16:51 40976 ----a-w- c:\windows\java\trustlib\addins\Nová složka\load.exe
2010-11-20 16:49 . 2010-11-20 16:49 1002622 ----a-w- c:\windows\java\trustlib\addins\Nová složka\vytvor_si_sefa.exe
2010-11-20 16:47 . 2010-11-20 16:47 341331 ----a-w- c:\windows\java\trustlib\addins\Nová složka\potrapte_rybu.exe
2010-11-20 16:45 . 2010-11-20 16:45 37984 ----a-w- c:\windows\java\trustlib\addins\Nová složka\tv.exe
2010-11-20 16:43 . 2010-11-20 16:43 94208 ----a-w- c:\windows\java\trustlib\addins\Nová složka\foceni_monitorem.exe
2010-11-20 16:42 . 2010-11-20 16:42 142336 ----a-w- c:\windows\java\trustlib\addins\Nová složka\winmine.exe
2010-11-20 16:40 . 2010-11-20 16:40 333848 ----a-w- c:\windows\java\trustlib\addins\Nová složka\inspekce_disku.exe
2010-11-20 16:39 . 2010-11-20 16:39 365616 ----a-w- c:\windows\java\trustlib\addins\Nová složka\pobihajici_pomeranc.exe
2010-11-20 16:38 . 2010-11-20 16:38 163927 ----a-w- c:\windows\java\trustlib\addins\Nová složka\poradne_oplachnuty_monitor.exe
2010-11-20 15:49 . 2010-11-20 15:44 14259704 ----a-w- c:\windows\java\trustlib\addins\Nová složka\picasa38cz-setup.exe
.
------- Sigcheck -------
[-] 2008-01-22 . 21DC51B6D100B4C7691D07ECF3807444 . 1548288 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="c:\program files\Analog Devices\SoundMAX\SMTray.exe" [2003-07-30 143360]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2010-05-31 63048]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
c:\documents and settings\xxx\Nabˇdka Start\Programy\Po spuçtŘnˇ\
0bxss6e.exe [2011-1-31 40448]
0ggbssn.exe [2011-2-2 43520]
0tpkk6w.exe [2011-2-1 43520]
0yytkkf.exe [2011-2-2 43520]
1cyytkk.exe [2011-2-2 43520]
2dyy6kk.exe [2011-2-2 40448]
9a1wssn.exe [2011-2-2 43520]
9s1okkf.exe [2011-2-2 40448]
arhhxd60.exe [2011-1-30 43520]
bssneezqqlc.exe [2011-2-2 40448]
bxss6ee6.exe [2011-2-2 43520]
cxoojaav.exe [2011-2-1 43520]
dzpplbbx.exe [2011-2-1 43520]
dzpplbbxnn.exe [2011-1-31 43520]
lm70njee6q.exe [2011-1-31 43520]
m6yy6kk6.exe [2011-2-2 40448]
neezqqlccxo.exe [2011-1-31 40448]
nii6uu6gg.exe [2011-2-1 43520]
qmmhyytkkf.exe [2011-2-2 40448]
rm0dy0pk0r.exe [2011-1-30 40448]
rm1ieezqql.exe [2011-2-2 43520]
rw86i81ufg.exe [2011-1-30 43520]
s6ee6qq6.exe [2011-1-31 40448]
w9s1okkfww.exe [2011-2-2 43520]
wssneezqql.exe [2011-2-2 43520]
xxtjjfvvrhh.exe [2011-2-2 40448]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2010-12-16 19:59 87424 ----a-w- c:\windows\system32\LMIinit.dll
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0bxss6e.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\0bxss6e.exe
backup=c:\windows\pss\0bxss6e.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0ggbssn.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\0ggbssn.exe
backup=c:\windows\pss\0ggbssn.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0tpkk6w.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\0tpkk6w.exe
backup=c:\windows\pss\0tpkk6w.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^9a1wssn.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\9a1wssn.exe
backup=c:\windows\pss\9a1wssn.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^arhhxd60.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\arhhxd60.exe
backup=c:\windows\pss\arhhxd60.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^bssneezqqlc.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\bssneezqqlc.exe
backup=c:\windows\pss\bssneezqqlc.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^bxss6ee6.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\bxss6ee6.exe
backup=c:\windows\pss\bxss6ee6.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^cxoojaav.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\cxoojaav.exe
backup=c:\windows\pss\cxoojaav.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^dzpplbbx.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\dzpplbbx.exe
backup=c:\windows\pss\dzpplbbx.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^dzpplbbxnn.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\dzpplbbxnn.exe
backup=c:\windows\pss\dzpplbbxnn.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^lm70njee6q.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\lm70njee6q.exe
backup=c:\windows\pss\lm70njee6q.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^neezqqlccxo.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\neezqqlccxo.exe
backup=c:\windows\pss\neezqqlccxo.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^nii6uu6gg.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\nii6uu6gg.exe
backup=c:\windows\pss\nii6uu6gg.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^qmmhyytkkf.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\qmmhyytkkf.exe
backup=c:\windows\pss\qmmhyytkkf.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rm0dy0pk0r.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\rm0dy0pk0r.exe
backup=c:\windows\pss\rm0dy0pk0r.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rm1ieezqql.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\rm1ieezqql.exe
backup=c:\windows\pss\rm1ieezqql.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rw86i81ufg.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\rw86i81ufg.exe
backup=c:\windows\pss\rw86i81ufg.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^s6ee6qq6.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\s6ee6qq6.exe
backup=c:\windows\pss\s6ee6qq6.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
c:\documents and settings\xxx\weejqdq.exe \u [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2007-01-13 08:47 163840 ----a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2007-01-13 08:47 131072 ----a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2007-01-13 08:46 135168 ----a-w- c:\windows\system32\igfxpers.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\xxx\\Plocha\\facebook-pic00005267(2).exe"= c:\\windows\\nvsvc32.exe
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [27.9.2010 13:47 374152]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [31.5.2010 10:31 12856]
S3 cdnvorme;cdnvorme;\??\c:\windows\System32\Drivers\cdnvorme.sys --> c:\windows\System32\Drivers\cdnvorme.sys [?]
S3 gayhjmem;gayhjmem;\??\c:\windows\System32\Drivers\gayhjmem.sys --> c:\windows\System32\Drivers\gayhjmem.sys [?]
S3 hzigaoxl;hzigaoxl;\??\c:\windows\System32\Drivers\hzigaoxl.sys --> c:\windows\System32\Drivers\hzigaoxl.sys [?]
S3 jnckoxip;jnckoxip;\??\c:\windows\System32\Drivers\jnckoxip.sys --> c:\windows\System32\Drivers\jnckoxip.sys [?]
S3 msyktsat;msyktsat;\??\c:\windows\System32\Drivers\msyktsat.sys --> c:\windows\System32\Drivers\msyktsat.sys [?]
S3 nwhpnlbd;nwhpnlbd;\??\c:\windows\System32\Drivers\nwhpnlbd.sys --> c:\windows\System32\Drivers\nwhpnlbd.sys [?]
S3 pcszsglm;pcszsglm;c:\windows\system32\drivers\pcszsglm.sys [2.2.2011 13:44 40128]
S3 tzxhyhiz;tzxhyhiz;\??\c:\windows\System32\Drivers\tzxhyhiz.sys --> c:\windows\System32\Drivers\tzxhyhiz.sys [?]
--- Ostatní služby/ovladače v paměti ---
*Deregistered* - yyzyv
.
Obsah adresáře 'Naplánované úlohy'
2011-02-02 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-02-04 14:50]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\xxx\Data aplikací\Mozilla\Firefox\Profiles\3f0ytt0f.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-02 14:32
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\yyzyv]
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(252)
c:\windows\system32\LMIinit.dll
.
Celkový čas: 2011-02-02 14:34:03
ComboFix-quarantined-files.txt 2011-02-02 13:34
ComboFix2.txt 2011-02-02 13:20
ComboFix3.txt 2011-02-02 13:09
Před spuštěním: Volných bajtů: 66 013 462 528
Po spuštění: Volných bajtů: 66 006 196 224
- - End Of File - - 602D654C2C4A3DF576101F5C89130A0D
Re: pomale nabyhani windows



Re: pomale nabyhani windows
Hotovo doufam ze to bude stacit a omluva za neznalost
Re: pomale nabyhani windows



- Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
- Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
Kód: Vybrat vše
:reg [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0bxss6e.exe] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0ggbssn.exe] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0tpkk6w.exe] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^9a1wssn.exe] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^arhhxd60.exe] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^bssneezqqlc.exe] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^bxss6ee6.exe] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^cxoojaav.exe] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^dzpplbbx.exe] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^dzpplbbxnn.exe] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^lm70njee6q.exe] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^neezqqlccxo.exe] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^nii6uu6gg.exe] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^qmmhyytkkf.exe] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rm0dy0pk0r.exe] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rm1ieezqql.exe] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rw86i81ufg.exe] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^s6ee6qq6.exe] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig] :files C:\Documents and Settings\xxx\weejqdq.exe c:\documents and settings\xxx\Data aplikací\juzjf.exe C:\m23w.exe C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\*.exe %windir%\system32\*.tmp.dll /s %windir%\system32\SET*.tmp /s %windir%\*.tmp /s :commands [RESETHOSTS] [EMPTYTEMP] [EMPTYFLASH]
- Kliknete na cervene tlacitko MoveIt!
- Budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles, obsah sem vlozte

- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
KillAll:: Driver:: cdnvorme gayhjmem hzigaoxl jnckoxip msyktsat nwhpnlbd pcszsglm tzxhyhiz yyzyv File:: c:\windows\System32\Drivers\cdnvorme.sys c:\windows\System32\Drivers\gayhjmem.sys c:\windows\System32\Drivers\hzigaoxl.sys c:\windows\System32\Drivers\jnckoxip.sys c:\windows\System32\Drivers\msyktsat.sys c:\windows\System32\Drivers\nwhpnlbd.sys c:\windows\system32\drivers\pcszsglm.sys c:\windows\System32\Drivers\tzxhyhiz.sys c:\windows\Tasks\Scheduled Update for Ask Toolbar.job c:\\Documents and Settings\\xxx\\Plocha\\facebook-pic00005267(2).exe "c:\\Documents and Settings\\xxx\\Plocha\\facebook-pic00005267.exe c:\\windows\\nvsvc32.exe DDS:: uDefault_Search_URL = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s Folder:: c:\program files\Ask.com c:\recycler\S-1-5-21-1474344014-3360588721-216412361-5572 Registry:: [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\Documents and Settings\\xxx\\Plocha\\facebook-pic00005267(2).exe"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RemoteControl"=- "Adobe Reader Speed Launcher"=- "Adobe ARM"=-
- Ulozte vytvoreny TXT jako CFScript.txt
- Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
- Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte

Re: pomale nabyhani windows
tak pokud staci combofix tak tady to je 
ComboFix 11-01-31.02 - xxx 03.02.2011 10:55:17.4.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.503.249 [GMT 1:00]
Spuštěný z: c:\documents and settings\xxx\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\xxx\Plocha\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 110203-1] *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Sunbelt Personal Firewall *Enabled* {82B1150E-9B37-49FC-83EB-D52197D900D0}
FILE ::
"c:\\Documents and Settings\\xxx\\Plocha\\facebook-pic00005267(2).exe"
"c:\\Documents and Settings\\xxx\\Plocha\\facebook-pic00005267.exe"
"c:\\windows\\nvsvc32.exe"
"c:\windows\System32\Drivers\cdnvorme.sys"
"c:\windows\System32\Drivers\gayhjmem.sys"
"c:\windows\System32\Drivers\hzigaoxl.sys"
"c:\windows\System32\Drivers\jnckoxip.sys"
"c:\windows\System32\Drivers\msyktsat.sys"
"c:\windows\System32\Drivers\nwhpnlbd.sys"
"c:\windows\system32\drivers\pcszsglm.sys"
"c:\windows\System32\Drivers\tzxhyhiz.sys"
"c:\windows\Tasks\Scheduled Update for Ask Toolbar.job"
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\\Documents and Settings\\xxx\\Plocha\\facebook-pic00005267(2).exe
c:\program files\Ask.com
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\UpdateTask.exe
c:\windows\system32\drivers\pcszsglm.sys
c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_YYZYV
-------\Service_cdnvorme
-------\Service_gayhjmem
-------\Service_hzigaoxl
-------\Service_jnckoxip
-------\Service_msyktsat
-------\Service_nwhpnlbd
-------\Service_pcszsglm
-------\Service_tzxhyhiz
-------\Service_yyzyv
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-03 do 2011-02-03 )))))))))))))))))))))))))))))))
.
2011-02-03 09:16 . 2009-11-24 23:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-02-03 09:16 . 2009-11-24 23:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-02-03 09:06 . 2008-10-31 06:09 270888 ----a-r- c:\windows\system32\drivers\SbFw.sys
2011-02-03 09:06 . 2008-06-21 03:54 65576 ----a-w- c:\windows\system32\drivers\SbFwIm.sys
2011-02-03 09:06 . 2011-02-03 09:06 -------- d-----w- c:\program files\Sunbelt Software
2011-02-03 09:03 . 2011-02-03 09:03 -------- d-----w- c:\program files\CCleaner
2011-02-03 08:18 . 2011-02-03 08:18 -------- d-----w- c:\documents and settings\xxx\Data aplikací\Malwarebytes
2011-02-03 08:18 . 2011-02-03 08:18 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-02-03 08:18 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-03 08:18 . 2011-02-03 08:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-02-03 08:18 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-03 07:57 . 2011-02-03 07:57 -------- d-----w- C:\rsit
2011-02-03 07:57 . 2011-02-03 07:57 -------- d-----w- c:\program files\trend micro
2011-02-02 13:22 . 2009-11-24 23:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-02-02 13:22 . 2009-11-24 23:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-02-02 13:22 . 2009-11-24 23:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-02-02 13:22 . 2009-11-24 23:50 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-02-02 13:22 . 2009-11-24 23:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-02-02 13:22 . 2009-11-24 23:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2011-02-02 13:22 . 2009-11-24 23:47 97480 ----a-w- c:\windows\system32\AVASTSS.scr
2011-02-02 13:22 . 2004-01-09 09:13 380928 ----a-w- c:\windows\system32\actskin4.ocx
2011-02-02 13:22 . 2003-03-18 20:20 1060864 ----a-w- c:\windows\system32\MFC71.dll
2011-02-02 13:22 . 2003-03-18 19:14 499712 ----a-w- c:\windows\system32\MSVCP71.dll
2011-02-02 13:22 . 2003-02-21 03:42 348160 ----a-w- c:\windows\system32\MSVCR71.dll
2011-02-02 12:37 . 2011-02-03 10:01 737280 ----a-w- c:\windows\system32\drivers\yyzyv.sys
2011-01-29 13:01 . 2004-08-03 21:59 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2011-01-29 13:01 . 2004-08-03 21:59 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2011-01-29 13:01 . 2004-08-03 22:00 8192 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys
2011-01-29 13:01 . 2004-08-03 22:00 8192 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2011-01-29 13:01 . 2004-08-03 22:00 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2011-01-29 13:01 . 2004-08-03 22:00 8192 ----a-w- c:\windows\system32\drivers\changer.sys
2011-01-27 07:03 . 2011-01-27 07:03 163840 ----a-w- C:\m23w.exe
2011-01-05 15:29 . 2003-06-19 00:31 18944 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\mdippr.dll
2011-01-05 15:29 . 2003-06-19 00:31 17920 ----a-w- c:\windows\system32\mdimon.dll
2011-01-05 15:29 . 2011-01-05 15:29 -------- d-----w- c:\program files\Microsoft.NET
2011-01-05 15:28 . 2011-01-05 15:29 -------- d-----w- c:\windows\SHELLNEW
2011-01-05 15:26 . 2011-01-05 15:26 -------- d-----r- C:\MSOCache
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-16 19:59 . 2010-10-05 07:15 83360 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2010-12-16 19:59 . 2010-10-05 07:15 53632 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2010-12-16 19:59 . 2010-10-05 07:15 29568 ----a-w- c:\windows\system32\LMIport.dll
2010-12-16 19:59 . 2010-10-05 07:15 87424 ----a-w- c:\windows\system32\LMIinit.dll
2010-11-20 20:34 . 2010-11-20 14:48 779368262 ----a-w- c:\windows\java\trustlib\addins\Nová složka\Sindicate.exe
2010-11-20 16:59 . 2010-11-20 16:59 207360 ----a-w- c:\windows\java\trustlib\addins\Nová složka\mr_bean.exe
2010-11-20 16:58 . 2010-11-20 16:58 34176 ----a-w- c:\windows\java\trustlib\addins\Nová složka\voda.exe
2010-11-20 16:57 . 2010-11-20 16:57 282624 ----a-w- c:\windows\java\trustlib\addins\Nová složka\po_poziti_alkoholu.exe
2010-11-20 16:56 . 2010-11-20 16:56 123904 ----a-w- c:\windows\java\trustlib\addins\Nová složka\krb.exe
2010-11-20 16:51 . 2010-11-20 16:51 40976 ----a-w- c:\windows\java\trustlib\addins\Nová složka\load.exe
2010-11-20 16:49 . 2010-11-20 16:49 1002622 ----a-w- c:\windows\java\trustlib\addins\Nová složka\vytvor_si_sefa.exe
2010-11-20 16:47 . 2010-11-20 16:47 341331 ----a-w- c:\windows\java\trustlib\addins\Nová složka\potrapte_rybu.exe
2010-11-20 16:45 . 2010-11-20 16:45 37984 ----a-w- c:\windows\java\trustlib\addins\Nová složka\tv.exe
2010-11-20 16:43 . 2010-11-20 16:43 94208 ----a-w- c:\windows\java\trustlib\addins\Nová složka\foceni_monitorem.exe
2010-11-20 16:42 . 2010-11-20 16:42 142336 ----a-w- c:\windows\java\trustlib\addins\Nová složka\winmine.exe
2010-11-20 16:40 . 2010-11-20 16:40 333848 ----a-w- c:\windows\java\trustlib\addins\Nová složka\inspekce_disku.exe
2010-11-20 16:39 . 2010-11-20 16:39 365616 ----a-w- c:\windows\java\trustlib\addins\Nová složka\pobihajici_pomeranc.exe
2010-11-20 16:38 . 2010-11-20 16:38 163927 ----a-w- c:\windows\java\trustlib\addins\Nová složka\poradne_oplachnuty_monitor.exe
2010-11-20 15:49 . 2010-11-20 15:44 14259704 ----a-w- c:\windows\java\trustlib\addins\Nová složka\picasa38cz-setup.exe
.
------- Sigcheck -------
[-] 2008-01-22 . 21DC51B6D100B4C7691D07ECF3807444 . 1548288 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2011-02-02_13.08.28 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-02-03 09:22 . 2011-02-03 09:22 16384 c:\windows\temp\Perflib_Perfdata_708.dat
+ 2011-02-03 10:02 . 2011-02-03 10:02 16384 c:\windows\temp\Perflib_Perfdata_66c.dat
+ 2008-06-21 03:54 . 2008-06-21 03:54 66600 c:\windows\system32\drivers\sbhips.sys
+ 2011-02-03 09:07 . 2011-02-03 09:07 57344 c:\windows\Installer\{82B1150E-9B37-49FC-83EB-D52197D900D0}\NewShortcut4_C665E66BE8EF49DBB30B81BB5E60462C.exe
+ 2011-02-03 09:07 . 2011-02-03 09:07 18718 c:\windows\Installer\{82B1150E-9B37-49FC-83EB-D52197D900D0}\NewShortcut1_E659E0EE10E649B7869660F38D0EB174.exe
+ 2011-02-03 09:07 . 2011-02-03 09:07 18718 c:\windows\Installer\{82B1150E-9B37-49FC-83EB-D52197D900D0}\ARPPRODUCTICON.exe
+ 2011-02-02 12:33 . 2011-02-03 09:03 262144 c:\windows\system32\config\systemprofile\NtUser.dat
- 2011-02-02 12:33 . 2011-02-02 12:33 262144 c:\windows\system32\config\systemprofile\NtUser.dat
+ 2011-02-03 09:07 . 2011-02-03 09:07 481280 c:\windows\Installer\a1ddb.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="c:\program files\Analog Devices\SoundMAX\SMTray.exe" [2003-07-30 143360]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2010-05-31 63048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2010-12-16 19:59 87424 ----a-w- c:\windows\system32\LMIinit.dll
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0bxss6e.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\0bxss6e.exe
backup=c:\windows\pss\0bxss6e.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0ggbssn.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\0ggbssn.exe
backup=c:\windows\pss\0ggbssn.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0tpkk6w.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\0tpkk6w.exe
backup=c:\windows\pss\0tpkk6w.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^9a1wssn.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\9a1wssn.exe
backup=c:\windows\pss\9a1wssn.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^arhhxd60.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\arhhxd60.exe
backup=c:\windows\pss\arhhxd60.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^bssneezqqlc.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\bssneezqqlc.exe
backup=c:\windows\pss\bssneezqqlc.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^bxss6ee6.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\bxss6ee6.exe
backup=c:\windows\pss\bxss6ee6.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^cxoojaav.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\cxoojaav.exe
backup=c:\windows\pss\cxoojaav.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^dzpplbbx.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\dzpplbbx.exe
backup=c:\windows\pss\dzpplbbx.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^dzpplbbxnn.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\dzpplbbxnn.exe
backup=c:\windows\pss\dzpplbbxnn.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^lm70njee6q.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\lm70njee6q.exe
backup=c:\windows\pss\lm70njee6q.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^neezqqlccxo.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\neezqqlccxo.exe
backup=c:\windows\pss\neezqqlccxo.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^nii6uu6gg.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\nii6uu6gg.exe
backup=c:\windows\pss\nii6uu6gg.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^qmmhyytkkf.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\qmmhyytkkf.exe
backup=c:\windows\pss\qmmhyytkkf.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rm0dy0pk0r.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\rm0dy0pk0r.exe
backup=c:\windows\pss\rm0dy0pk0r.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rm1ieezqql.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\rm1ieezqql.exe
backup=c:\windows\pss\rm1ieezqql.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rw86i81ufg.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\rw86i81ufg.exe
backup=c:\windows\pss\rw86i81ufg.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^s6ee6qq6.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\s6ee6qq6.exe
backup=c:\windows\pss\s6ee6qq6.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
c:\documents and settings\xxx\weejqdq.exe \u [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2007-01-13 08:47 163840 ----a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2007-01-13 08:47 131072 ----a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2007-01-13 08:46 135168 ----a-w- c:\windows\system32\igfxpers.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [3.2.2011 10:16 114768]
R1 SbFw;SbFw;c:\windows\system32\drivers\SbFw.sys [3.2.2011 10:06 270888]
R1 sbhips;Sunbelt HIPS Driver;c:\windows\system32\drivers\sbhips.sys [21.6.2008 4:54 66600]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [3.2.2011 10:16 20560]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [27.9.2010 13:47 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [31.5.2010 10:31 12856]
R2 SbPF.Launcher;SbPF.Launcher;c:\program files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [31.10.2008 7:24 95528]
R2 SPF4;Sunbelt Personal Firewall 4;c:\program files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [31.10.2008 7:24 1365288]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\system32\drivers\SbFwIm.sys [3.2.2011 10:06 65576]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\xxx\Data aplikací\Mozilla\Firefox\Profiles\3f0ytt0f.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-03 11:03
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(944)
c:\windows\system32\LMIinit.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\LogMeIn\x86\RaMaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\Sunbelt Software\Personal Firewall\SbPFCl.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2011-02-03 11:05:11 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-02-03 10:05
ComboFix2.txt 2011-02-02 13:34
ComboFix3.txt 2011-02-02 13:20
ComboFix4.txt 2011-02-02 13:09
Před spuštěním: Volných bajtů: 65 812 103 168
Po spuštění: Volných bajtů: 65 804 812 288
- - End Of File - - B4DA18AC39A4A95CB903D4E09DB94F51

ComboFix 11-01-31.02 - xxx 03.02.2011 10:55:17.4.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.503.249 [GMT 1:00]
Spuštěný z: c:\documents and settings\xxx\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\xxx\Plocha\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 110203-1] *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Sunbelt Personal Firewall *Enabled* {82B1150E-9B37-49FC-83EB-D52197D900D0}
FILE ::
"c:\\Documents and Settings\\xxx\\Plocha\\facebook-pic00005267(2).exe"
"c:\\Documents and Settings\\xxx\\Plocha\\facebook-pic00005267.exe"
"c:\\windows\\nvsvc32.exe"
"c:\windows\System32\Drivers\cdnvorme.sys"
"c:\windows\System32\Drivers\gayhjmem.sys"
"c:\windows\System32\Drivers\hzigaoxl.sys"
"c:\windows\System32\Drivers\jnckoxip.sys"
"c:\windows\System32\Drivers\msyktsat.sys"
"c:\windows\System32\Drivers\nwhpnlbd.sys"
"c:\windows\system32\drivers\pcszsglm.sys"
"c:\windows\System32\Drivers\tzxhyhiz.sys"
"c:\windows\Tasks\Scheduled Update for Ask Toolbar.job"
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\\Documents and Settings\\xxx\\Plocha\\facebook-pic00005267(2).exe
c:\program files\Ask.com
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\UpdateTask.exe
c:\windows\system32\drivers\pcszsglm.sys
c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_YYZYV
-------\Service_cdnvorme
-------\Service_gayhjmem
-------\Service_hzigaoxl
-------\Service_jnckoxip
-------\Service_msyktsat
-------\Service_nwhpnlbd
-------\Service_pcszsglm
-------\Service_tzxhyhiz
-------\Service_yyzyv
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-03 do 2011-02-03 )))))))))))))))))))))))))))))))
.
2011-02-03 09:16 . 2009-11-24 23:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-02-03 09:16 . 2009-11-24 23:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-02-03 09:06 . 2008-10-31 06:09 270888 ----a-r- c:\windows\system32\drivers\SbFw.sys
2011-02-03 09:06 . 2008-06-21 03:54 65576 ----a-w- c:\windows\system32\drivers\SbFwIm.sys
2011-02-03 09:06 . 2011-02-03 09:06 -------- d-----w- c:\program files\Sunbelt Software
2011-02-03 09:03 . 2011-02-03 09:03 -------- d-----w- c:\program files\CCleaner
2011-02-03 08:18 . 2011-02-03 08:18 -------- d-----w- c:\documents and settings\xxx\Data aplikací\Malwarebytes
2011-02-03 08:18 . 2011-02-03 08:18 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-02-03 08:18 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-03 08:18 . 2011-02-03 08:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-02-03 08:18 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-03 07:57 . 2011-02-03 07:57 -------- d-----w- C:\rsit
2011-02-03 07:57 . 2011-02-03 07:57 -------- d-----w- c:\program files\trend micro
2011-02-02 13:22 . 2009-11-24 23:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-02-02 13:22 . 2009-11-24 23:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-02-02 13:22 . 2009-11-24 23:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-02-02 13:22 . 2009-11-24 23:50 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-02-02 13:22 . 2009-11-24 23:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-02-02 13:22 . 2009-11-24 23:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2011-02-02 13:22 . 2009-11-24 23:47 97480 ----a-w- c:\windows\system32\AVASTSS.scr
2011-02-02 13:22 . 2004-01-09 09:13 380928 ----a-w- c:\windows\system32\actskin4.ocx
2011-02-02 13:22 . 2003-03-18 20:20 1060864 ----a-w- c:\windows\system32\MFC71.dll
2011-02-02 13:22 . 2003-03-18 19:14 499712 ----a-w- c:\windows\system32\MSVCP71.dll
2011-02-02 13:22 . 2003-02-21 03:42 348160 ----a-w- c:\windows\system32\MSVCR71.dll
2011-02-02 12:37 . 2011-02-03 10:01 737280 ----a-w- c:\windows\system32\drivers\yyzyv.sys
2011-01-29 13:01 . 2004-08-03 21:59 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2011-01-29 13:01 . 2004-08-03 21:59 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2011-01-29 13:01 . 2004-08-03 22:00 8192 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys
2011-01-29 13:01 . 2004-08-03 22:00 8192 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2011-01-29 13:01 . 2004-08-03 22:00 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2011-01-29 13:01 . 2004-08-03 22:00 8192 ----a-w- c:\windows\system32\drivers\changer.sys
2011-01-27 07:03 . 2011-01-27 07:03 163840 ----a-w- C:\m23w.exe
2011-01-05 15:29 . 2003-06-19 00:31 18944 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\mdippr.dll
2011-01-05 15:29 . 2003-06-19 00:31 17920 ----a-w- c:\windows\system32\mdimon.dll
2011-01-05 15:29 . 2011-01-05 15:29 -------- d-----w- c:\program files\Microsoft.NET
2011-01-05 15:28 . 2011-01-05 15:29 -------- d-----w- c:\windows\SHELLNEW
2011-01-05 15:26 . 2011-01-05 15:26 -------- d-----r- C:\MSOCache
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-16 19:59 . 2010-10-05 07:15 83360 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2010-12-16 19:59 . 2010-10-05 07:15 53632 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2010-12-16 19:59 . 2010-10-05 07:15 29568 ----a-w- c:\windows\system32\LMIport.dll
2010-12-16 19:59 . 2010-10-05 07:15 87424 ----a-w- c:\windows\system32\LMIinit.dll
2010-11-20 20:34 . 2010-11-20 14:48 779368262 ----a-w- c:\windows\java\trustlib\addins\Nová složka\Sindicate.exe
2010-11-20 16:59 . 2010-11-20 16:59 207360 ----a-w- c:\windows\java\trustlib\addins\Nová složka\mr_bean.exe
2010-11-20 16:58 . 2010-11-20 16:58 34176 ----a-w- c:\windows\java\trustlib\addins\Nová složka\voda.exe
2010-11-20 16:57 . 2010-11-20 16:57 282624 ----a-w- c:\windows\java\trustlib\addins\Nová složka\po_poziti_alkoholu.exe
2010-11-20 16:56 . 2010-11-20 16:56 123904 ----a-w- c:\windows\java\trustlib\addins\Nová složka\krb.exe
2010-11-20 16:51 . 2010-11-20 16:51 40976 ----a-w- c:\windows\java\trustlib\addins\Nová složka\load.exe
2010-11-20 16:49 . 2010-11-20 16:49 1002622 ----a-w- c:\windows\java\trustlib\addins\Nová složka\vytvor_si_sefa.exe
2010-11-20 16:47 . 2010-11-20 16:47 341331 ----a-w- c:\windows\java\trustlib\addins\Nová složka\potrapte_rybu.exe
2010-11-20 16:45 . 2010-11-20 16:45 37984 ----a-w- c:\windows\java\trustlib\addins\Nová složka\tv.exe
2010-11-20 16:43 . 2010-11-20 16:43 94208 ----a-w- c:\windows\java\trustlib\addins\Nová složka\foceni_monitorem.exe
2010-11-20 16:42 . 2010-11-20 16:42 142336 ----a-w- c:\windows\java\trustlib\addins\Nová složka\winmine.exe
2010-11-20 16:40 . 2010-11-20 16:40 333848 ----a-w- c:\windows\java\trustlib\addins\Nová složka\inspekce_disku.exe
2010-11-20 16:39 . 2010-11-20 16:39 365616 ----a-w- c:\windows\java\trustlib\addins\Nová složka\pobihajici_pomeranc.exe
2010-11-20 16:38 . 2010-11-20 16:38 163927 ----a-w- c:\windows\java\trustlib\addins\Nová složka\poradne_oplachnuty_monitor.exe
2010-11-20 15:49 . 2010-11-20 15:44 14259704 ----a-w- c:\windows\java\trustlib\addins\Nová složka\picasa38cz-setup.exe
.
------- Sigcheck -------
[-] 2008-01-22 . 21DC51B6D100B4C7691D07ECF3807444 . 1548288 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2011-02-02_13.08.28 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-02-03 09:22 . 2011-02-03 09:22 16384 c:\windows\temp\Perflib_Perfdata_708.dat
+ 2011-02-03 10:02 . 2011-02-03 10:02 16384 c:\windows\temp\Perflib_Perfdata_66c.dat
+ 2008-06-21 03:54 . 2008-06-21 03:54 66600 c:\windows\system32\drivers\sbhips.sys
+ 2011-02-03 09:07 . 2011-02-03 09:07 57344 c:\windows\Installer\{82B1150E-9B37-49FC-83EB-D52197D900D0}\NewShortcut4_C665E66BE8EF49DBB30B81BB5E60462C.exe
+ 2011-02-03 09:07 . 2011-02-03 09:07 18718 c:\windows\Installer\{82B1150E-9B37-49FC-83EB-D52197D900D0}\NewShortcut1_E659E0EE10E649B7869660F38D0EB174.exe
+ 2011-02-03 09:07 . 2011-02-03 09:07 18718 c:\windows\Installer\{82B1150E-9B37-49FC-83EB-D52197D900D0}\ARPPRODUCTICON.exe
+ 2011-02-02 12:33 . 2011-02-03 09:03 262144 c:\windows\system32\config\systemprofile\NtUser.dat
- 2011-02-02 12:33 . 2011-02-02 12:33 262144 c:\windows\system32\config\systemprofile\NtUser.dat
+ 2011-02-03 09:07 . 2011-02-03 09:07 481280 c:\windows\Installer\a1ddb.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="c:\program files\Analog Devices\SoundMAX\SMTray.exe" [2003-07-30 143360]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2010-05-31 63048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2010-12-16 19:59 87424 ----a-w- c:\windows\system32\LMIinit.dll
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0bxss6e.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\0bxss6e.exe
backup=c:\windows\pss\0bxss6e.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0ggbssn.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\0ggbssn.exe
backup=c:\windows\pss\0ggbssn.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0tpkk6w.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\0tpkk6w.exe
backup=c:\windows\pss\0tpkk6w.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^9a1wssn.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\9a1wssn.exe
backup=c:\windows\pss\9a1wssn.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^arhhxd60.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\arhhxd60.exe
backup=c:\windows\pss\arhhxd60.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^bssneezqqlc.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\bssneezqqlc.exe
backup=c:\windows\pss\bssneezqqlc.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^bxss6ee6.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\bxss6ee6.exe
backup=c:\windows\pss\bxss6ee6.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^cxoojaav.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\cxoojaav.exe
backup=c:\windows\pss\cxoojaav.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^dzpplbbx.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\dzpplbbx.exe
backup=c:\windows\pss\dzpplbbx.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^dzpplbbxnn.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\dzpplbbxnn.exe
backup=c:\windows\pss\dzpplbbxnn.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^lm70njee6q.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\lm70njee6q.exe
backup=c:\windows\pss\lm70njee6q.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^neezqqlccxo.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\neezqqlccxo.exe
backup=c:\windows\pss\neezqqlccxo.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^nii6uu6gg.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\nii6uu6gg.exe
backup=c:\windows\pss\nii6uu6gg.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^qmmhyytkkf.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\qmmhyytkkf.exe
backup=c:\windows\pss\qmmhyytkkf.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rm0dy0pk0r.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\rm0dy0pk0r.exe
backup=c:\windows\pss\rm0dy0pk0r.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rm1ieezqql.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\rm1ieezqql.exe
backup=c:\windows\pss\rm1ieezqql.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rw86i81ufg.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\rw86i81ufg.exe
backup=c:\windows\pss\rw86i81ufg.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^s6ee6qq6.exe]
path=c:\documents and settings\xxx\Nabídka Start\Programy\Po spuštění\s6ee6qq6.exe
backup=c:\windows\pss\s6ee6qq6.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
c:\documents and settings\xxx\weejqdq.exe \u [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2007-01-13 08:47 163840 ----a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2007-01-13 08:47 131072 ----a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2007-01-13 08:46 135168 ----a-w- c:\windows\system32\igfxpers.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [3.2.2011 10:16 114768]
R1 SbFw;SbFw;c:\windows\system32\drivers\SbFw.sys [3.2.2011 10:06 270888]
R1 sbhips;Sunbelt HIPS Driver;c:\windows\system32\drivers\sbhips.sys [21.6.2008 4:54 66600]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [3.2.2011 10:16 20560]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [27.9.2010 13:47 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [31.5.2010 10:31 12856]
R2 SbPF.Launcher;SbPF.Launcher;c:\program files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [31.10.2008 7:24 95528]
R2 SPF4;Sunbelt Personal Firewall 4;c:\program files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [31.10.2008 7:24 1365288]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\system32\drivers\SbFwIm.sys [3.2.2011 10:06 65576]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\xxx\Data aplikací\Mozilla\Firefox\Profiles\3f0ytt0f.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-03 11:03
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(944)
c:\windows\system32\LMIinit.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\LogMeIn\x86\RaMaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\Sunbelt Software\Personal Firewall\SbPFCl.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2011-02-03 11:05:11 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-02-03 10:05
ComboFix2.txt 2011-02-02 13:34
ComboFix3.txt 2011-02-02 13:20
ComboFix4.txt 2011-02-02 13:09
Před spuštěním: Volných bajtů: 65 812 103 168
Po spuštění: Volných bajtů: 65 804 812 288
- - End Of File - - B4DA18AC39A4A95CB903D4E09DB94F51
Re: pomale nabyhani windows
Nestaci, ja ten navod pro OTM nepsal jen tak pro nic za nic
Takze jej prosim provedte 


Re: pomale nabyhani windows
log OTM je se me zacaly sekat windows kdyz chci jit do disku C tak jsem musel vytahnout log v nouzovem rezimu ani to nastartovani v posledni funkci konfiguraci nepomohlo
All processes killed
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0bxss6e.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0ggbssn.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0tpkk6w.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^9a1wssn.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^arhhxd60.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^bssneezqqlc.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^bxss6ee6.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^cxoojaav.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^dzpplbbx.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^dzpplbbxnn.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^lm70njee6q.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^neezqqlccxo.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^nii6uu6gg.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^qmmhyytkkf.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rm0dy0pk0r.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rm1ieezqql.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rw86i81ufg.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^s6ee6qq6.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig\ deleted successfully.
========== FILES ==========
File/Folder C:\Documents and Settings\xxx\weejqdq.exe not found.
File/Folder c:\documents and settings\xxx\Data aplikací\juzjf.exe not found.
C:\m23w.exe moved successfully.
File/Folder C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\*.exe not found.
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
C:\WINDOWS\system32\CONFIG.TMP moved successfully.
C:\WINDOWS\temp\JET6F82.tmp moved successfully.
File move failed. C:\WINDOWS\temp\JET6F92.tmp scheduled to be moved on reboot.
C:\WINDOWS\temp\JET706D.tmp moved successfully.
File move failed. C:\WINDOWS\temp\JET70BB.tmp scheduled to be moved on reboot.
C:\WINDOWS\temp\JET8BE4.tmp moved successfully.
C:\WINDOWS\temp\JET8DC8.tmp moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: LogMeInRemoteUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes
User: xxx
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->FireFox cache emptied: 56839407 bytes
->Flash cache emptied: 2049 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 49152 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 54,00 mb
OTM by OldTimer - Version 3.1.17.2 log created on 02032011_111547
All processes killed
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0bxss6e.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0ggbssn.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^0tpkk6w.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^9a1wssn.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^arhhxd60.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^bssneezqqlc.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^bxss6ee6.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^cxoojaav.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^dzpplbbx.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^dzpplbbxnn.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^lm70njee6q.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^neezqqlccxo.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^nii6uu6gg.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^qmmhyytkkf.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rm0dy0pk0r.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rm1ieezqql.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^rw86i81ufg.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^xxx^Nabídka Start^Programy^Po spuštění^s6ee6qq6.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig\ deleted successfully.
========== FILES ==========
File/Folder C:\Documents and Settings\xxx\weejqdq.exe not found.
File/Folder c:\documents and settings\xxx\Data aplikací\juzjf.exe not found.
C:\m23w.exe moved successfully.
File/Folder C:\Documents and Settings\xxx\Nabídka Start\Programy\Po spuštění\*.exe not found.
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
C:\WINDOWS\system32\CONFIG.TMP moved successfully.
C:\WINDOWS\temp\JET6F82.tmp moved successfully.
File move failed. C:\WINDOWS\temp\JET6F92.tmp scheduled to be moved on reboot.
C:\WINDOWS\temp\JET706D.tmp moved successfully.
File move failed. C:\WINDOWS\temp\JET70BB.tmp scheduled to be moved on reboot.
C:\WINDOWS\temp\JET8BE4.tmp moved successfully.
C:\WINDOWS\temp\JET8DC8.tmp moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: LogMeInRemoteUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes
User: xxx
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->FireFox cache emptied: 56839407 bytes
->Flash cache emptied: 2049 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 49152 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 54,00 mb
OTM by OldTimer - Version 3.1.17.2 log created on 02032011_111547
Re: pomale nabyhani windows


Re: pomale nabyhani windows
tak kdyz neco spustim tak se po chvilce sekne a za chvilku teprve zahraje znelka windows a vse funguje normalne, tak nevim
Re: pomale nabyhani windows



- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte

Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy
Re: pomale nabyhani windows
na plose je jen par ikon s combofix atd, udelal jsem vse podle navodu ale koukam ze se mi nespusti antivir
Re: pomale nabyhani windows



Re: pomale nabyhani windows
tak to nepomohlo porad to po stratu na neco ceka ale na co ? to je otazka, uz nevim co by se spoustelo po stratu