
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
počítač se často vypíná
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
počítač se často vypíná
DObrý den,
poslední dobou se mi často vypíná počítač. vypadá to asi na nějakou nekalost.
POsílám log z RSIT:
Logfile of random's system information tool 1.08 (written by random/random)
Run by vasek at 2011-02-19 14:47:32
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 20 GB (26%) free of 76 GB
Total RAM: 447 MB (24% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:48:09, on 19.2.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Documents and Settings\LocalService\Data aplikací\Microsoft\cessemma.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\HPQ\One-Touch\OneTouch.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\WINDOWS\system32\cessemma.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\TEMP\kfwyhpuu01501515.tmp
C:\WINDOWS\TEMP\vbzoap03BEB32E.tmp
C:\DOCUME~1\vasek\LOCALS~1\Temp\kfwyhpuu01501515.tmp
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\DOCUME~1\vasek\LOCALS~1\Temp\vbzoap03BEB32E.tmp
C:\WINDOWS\system32\cessemma.exe
C:\DOCUME~1\vasek\LOCALS~1\Temp\kfwyhpuu01501515.tmp
C:\DOCUME~1\vasek\LOCALS~1\Temp\vbzoap03BEB32E.tmp
C:\DOCUME~1\vasek\LOCALS~1\Temp\881.exe
C:\DOCUME~1\vasek\LOCALS~1\Temp\197.exe
C:\Documents and Settings\vasek\Plocha\RSIT.exe
C:\Program Files\trend micro\vasek.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\vasek\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\vasek\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [zoummoh] C:\WINDOWS\system32\lydazoug.exe
O4 - HKLM\..\Run: [biquoottaf] C:\WINDOWS\system32\padofou.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Infium] "C:\Program Files\QIP 2010\qip.exe" /autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: 00juepz.exe
O4 - Startup: 01niknj.exe
O4 - Startup: 0xfkwhr.exe
O4 - Startup: 1huobrz.exe
O4 - Startup: 1tbozpu.exe
O4 - Startup: 1vsubrz.exe
O4 - Startup: 55gcfvg.exe
O4 - Startup: 5qnlhil.exe
O4 - Startup: 5ysbpjs.exe
O4 - Startup: cfgm55uix.exe
O4 - Startup: emhpksj55.exe
O4 - Startup: fjgifh00n.exe
O4 - Startup: fvuq55csvx.exe
O4 - Startup: gnnygtf0.exe
O4 - Startup: hegdfc01h.exe
O4 - Startup: ixlqks55c.exe
O4 - Startup: jrluoxra.exe
O4 - Startup: k55eiliexve.exe
O4 - Startup: laow55amln.exe
O4 - Startup: lvg01bjemh.exe
O4 - Startup: nbwezhb00.exe
O4 - Startup: nyitd001n.exe
O4 - Startup: ojpa01jikn.exe
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: pyy56kdjuq.exe
O4 - Startup: rakzd00zw.exe
O4 - Startup: rcmxhss5.exe
O4 - Startup: rks55iatre.exe
O4 - Startup: smx5suvdyg.exe
O4 - Startup: stngcv56o.exe
O4 - Startup: teizj0mvp.exe
O4 - Startup: uixlqqj56.exe
O4 - Startup: vpysbfsc.exe
O4 - Startup: wghn00bpk.exe
O4 - Startup: x55egnreofh.exe
O4 - Startup: y55mkvxeyhb.exe
O4 - Startup: yvxet56ix.exe
O4 - Startup: zicfheqv.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: SmartLinkService (a7yya77di) - Google Inc. - C:\WINDOWS\system32\divin.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: BsHelpCS (iflpyug9f2yytal8) - Unknown owner - C:\WINDOWS\system32\vouciby.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 9402 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Documents and Settings\vasek\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2010-11-24 150400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-01-04 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-01-04 79648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2003-05-22 110592]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2003-05-22 610304]
"ATIModeChange"=C:\WINDOWS\system32\Ati2mdxx.exe [2002-08-16 28672]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2002-08-14 290816]
"Cpqset"=C:\Program Files\HPQ\Default Settings\cpqset.exe [2003-10-05 196670]
"Display Settings"=C:\Program Files\HPQ\Notebook Utilities\hptasks.exe [2002-08-15 45056]
"AdaptecDirectCD"=C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe [2003-03-26 684032]
"QuickTime Task"=E:\Program Files\QuickTime\QTTask.exe -atboottime []
"CARPService"=C:\WINDOWS\system32\carpserv.exe [2003-04-15 4608]
"QT4HPOT"=C:\Program Files\HPQ\One-Touch\OneTouch.EXE [2003-03-13 106496]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"zoummoh"=C:\WINDOWS\system32\lydazoug.exe []
"biquoottaf"=C:\WINDOWS\system32\padofou.exe [2011-02-19 245760]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Infium"=C:\Program Files\QIP 2010\qip.exe [2010-11-24 5853056]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-12-03 14944136]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění
00juepz.exe
01niknj.exe
0xfkwhr.exe
1huobrz.exe
1tbozpu.exe
1vsubrz.exe
55gcfvg.exe
5qnlhil.exe
5ysbpjs.exe
cfgm55uix.exe
emhpksj55.exe
fjgifh00n.exe
fvuq55csvx.exe
gnnygtf0.exe
hegdfc01h.exe
ixlqks55c.exe
jrluoxra.exe
k55eiliexve.exe
laow55amln.exe
lvg01bjemh.exe
nbwezhb00.exe
nyitd001n.exe
ojpa01jikn.exe
OpenOffice.org 3.2.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe
pyy56kdjuq.exe
rakzd00zw.exe
rcmxhss5.exe
rks55iatre.exe
smx5suvdyg.exe
stngcv56o.exe
teizj0mvp.exe
uixlqqj56.exe
vpysbfsc.exe
wghn00bpk.exe
x55egnreofh.exe
y55mkvxeyhb.exe
yvxet56ix.exe
zicfheqv.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Winamp\winamp.exe"="C:\Program Files\Winamp\winamp.exe:*:Enabled:Winamp"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"C:\Documents and Settings\vasek\Local Settings\Temp\Resources\KMSKG\Keygen.exe"="C:\Documents and Settings\vasek\Local Settings\Temp\Resources\KMSKG\Keygen.exe:*:Enabled:Keygen"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2011-02-19 14:45:57 ----A---- C:\WINDOWS\system32\divin.exe
2011-02-19 14:40:50 ----A---- C:\WINDOWS\system32\drivers\xybmxyqqc.sys
2011-02-19 14:38:13 ----A---- C:\WINDOWS\system32\drivers\tntxrruw.sys
2011-02-19 13:25:00 ----A---- C:\WINDOWS\system32\cessemma.exe
2011-02-16 06:36:30 ----A---- C:\WINDOWS\system32\pubusoojad.exe
2011-02-16 06:14:39 ----A---- C:\WINDOWS\system32\drivers\kddppngq.sys
2011-02-16 06:14:14 ----AH---- C:\Documents and Settings\vasek\Data aplikací\fLFGjmeheC.txt
2011-02-12 17:32:11 ----AH---- C:\Documents and Settings\vasek\Data aplikací\CmI1eJ1FIL.txt
2011-02-12 17:32:04 ----A---- C:\WINDOWS\system32\padofou.exe
2011-02-10 18:28:53 ----D---- C:\Program Files\Officy
2011-02-09 19:11:13 ----D---- C:\ado
2011-02-08 18:13:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\MiKTeX
2011-02-08 17:03:04 ----D---- C:\Program Files\MiKTeX 2.8
2011-02-02 11:00:17 ----D---- C:\Documents and Settings\vasek\Data aplikací\gtk-2.0
2011-02-02 10:58:50 ----D---- C:\Documents and Settings\vasek\Data aplikací\gretl
2011-02-02 10:57:28 ----D---- C:\Program Files\gretl
2011-01-30 10:28:53 ----D---- C:\Documents and Settings\vasek\Data aplikací\Stata10
======List of files/folders modified in the last 1 months======
2011-02-19 14:47:50 ----D---- C:\WINDOWS\Temp
2011-02-19 14:47:42 ----D---- C:\Program Files\trend micro
2011-02-19 14:46:30 ----D---- C:\Documents and Settings\vasek\Data aplikací\Skype
2011-02-19 14:46:14 ----D---- C:\WINDOWS\system32
2011-02-19 14:45:59 ----D---- C:\Program Files\Mozilla Firefox
2011-02-19 14:45:48 ----D---- C:\Program Files\QIP 2010
2011-02-19 14:44:54 ----D---- C:\WINDOWS\Minidump
2011-02-19 14:44:54 ----D---- C:\WINDOWS
2011-02-19 14:41:01 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-02-19 14:40:56 ----D---- C:\WINDOWS\system32\drivers
2011-02-19 14:40:52 ----D---- C:\WINDOWS\system32\CatRoot2
2011-02-19 13:02:41 ----D---- C:\Documents and Settings\vasek\Data aplikací\skypePM
2011-02-18 15:58:21 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-02-17 18:36:57 ----D---- C:\WINDOWS\Prefetch
2011-02-16 07:21:06 ----RSHD---- C:\RECYCLER
2011-02-10 18:28:56 ----RD---- C:\Program Files
2011-02-01 11:18:37 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2011-01-26 23:00:49 ----SD---- C:\Documents and Settings\vasek\Data aplikací\Microsoft
2011-01-25 09:51:51 ----D---- C:\Music
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\System32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys [2009-04-28 9072]
R1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2009-04-28 9200]
R1 cdudf_xp;cdudf_xp; C:\WINDOWS\system32\drivers\cdudf_xp.sys [2003-03-26 241280]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 pwd_2k;pwd_2k; C:\WINDOWS\system32\drivers\pwd_2k.sys [2003-03-26 144250]
R1 UdfReadr_xp;UdfReadr_xp; C:\WINDOWS\system32\drivers\UdfReadr_xp.sys [2003-03-26 206464]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.9.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2010-12-25 21275]
R2 irda;Protokol IrDA; C:\WINDOWS\System32\DRIVERS\irda.sys [2008-04-13 88192]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2003-04-15 9855]
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2005-12-28 13568]
R2 StreamDispatcher;StreamDispatcher; C:\WINDOWS\system32\DRIVERS\strmdisp.sys [2003-04-15 34224]
R3 ALiIRDA;ALi Infrared Device Driver; C:\WINDOWS\System32\DRIVERS\aliirda.sys [2001-12-17 26112]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\System32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2002-08-16 471168]
R3 BCM43XX;Broadcom 802.11 OneDriver; C:\WINDOWS\System32\DRIVERS\bcmwl5.sys [2003-10-01 254208]
R3 CALIAUD;Conexant AMC 3D ENVIRONMENTAL AUDIO; C:\WINDOWS\system32\drivers\caliaud.sys [2002-11-05 291328]
R3 CALIHALA;CALIHALA; C:\WINDOWS\system32\drivers\calihal.sys [2002-11-05 244608]
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver; C:\WINDOWS\System32\Drivers\DKbFltr.SYS [2002-10-16 14543]
R3 DP83815;National Semiconductor Corp. DP83815/816 NDIS 5.0 Miniport Driver; C:\WINDOWS\System32\DRIVERS\DP83815.SYS [2003-07-17 28280]
R3 HPCI;HP Configuration Interface; C:\WINDOWS\System32\DRIVERS\hpci.sys [2002-07-17 14504]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSF_DP.sys [2003-04-15 1171616]
R3 HSFHWALI;HSFHWALI; C:\WINDOWS\system32\DRIVERS\HSFHWALI.sys [2003-04-15 153380]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\System32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\System32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\System32\DRIVERS\SynTP.sys [2003-05-22 273072]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2003-04-15 594960]
S0 kddppngq;kddppngq; C:\WINDOWS\system32\drivers\kddppngq.sys []
S3 aliadwdm;Ovladač WDM urychlovače zpracování zvuku ALi; C:\WINDOWS\system32\drivers\ac97ali.sys [2002-08-29 231552]
S3 Bridge;Most MAC; C:\WINDOWS\System32\DRIVERS\bridge.sys [2008-04-13 71552]
S3 BridgeMP;Miniport mostu MAC; C:\WINDOWS\System32\DRIVERS\bridge.sys [2008-04-13 71552]
S3 dvd_2K;dvd_2K; C:\WINDOWS\system32\drivers\dvd_2K.sys [2003-03-26 25930]
S3 FA312;NETGEAR FA330/FA312/FA311 Fast Ethernet Adapter Driver; C:\WINDOWS\System32\DRIVERS\FA312nd5.sys [2001-08-17 16074]
S3 mmc_2K;mmc_2K; C:\WINDOWS\system32\drivers\mmc_2K.sys [2003-03-26 30662]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2005-12-28 114753]
R2 HPConfig;HP Configuration Interface Service; C:\WINDOWS\system32\HPConfig.exe [2002-08-15 151552]
R2 HPWirelessMgr;HPWirelessMgr; C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe [2003-07-28 53248]
R2 Irmon;Sledování infračerveného přenosu; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-01-04 153376]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2005-12-28 217164]
R2 S24EventMonitor;Intel(R) PROSet/Wireless Service; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2005-12-28 540745]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R2 WLTRYSVC;WLTRYSVC; C:\WINDOWS\System32\WLTRYSVC.EXE [2003-10-01 45056]
S2 a7yya77di;SmartLinkService; C:\WINDOWS\system32\divin.exe [2011-02-19 245760]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-01-01 135664]
S2 iflpyug9f2yytal8;BsHelpCS; C:\WINDOWS\system32\vouciby.exe []
-----------------EOF-----------------
poslední dobou se mi často vypíná počítač. vypadá to asi na nějakou nekalost.
POsílám log z RSIT:
Logfile of random's system information tool 1.08 (written by random/random)
Run by vasek at 2011-02-19 14:47:32
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 20 GB (26%) free of 76 GB
Total RAM: 447 MB (24% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:48:09, on 19.2.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Documents and Settings\LocalService\Data aplikací\Microsoft\cessemma.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\HPQ\One-Touch\OneTouch.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\WINDOWS\system32\cessemma.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\TEMP\kfwyhpuu01501515.tmp
C:\WINDOWS\TEMP\vbzoap03BEB32E.tmp
C:\DOCUME~1\vasek\LOCALS~1\Temp\kfwyhpuu01501515.tmp
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\DOCUME~1\vasek\LOCALS~1\Temp\vbzoap03BEB32E.tmp
C:\WINDOWS\system32\cessemma.exe
C:\DOCUME~1\vasek\LOCALS~1\Temp\kfwyhpuu01501515.tmp
C:\DOCUME~1\vasek\LOCALS~1\Temp\vbzoap03BEB32E.tmp
C:\DOCUME~1\vasek\LOCALS~1\Temp\881.exe
C:\DOCUME~1\vasek\LOCALS~1\Temp\197.exe
C:\Documents and Settings\vasek\Plocha\RSIT.exe
C:\Program Files\trend micro\vasek.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\vasek\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\vasek\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [zoummoh] C:\WINDOWS\system32\lydazoug.exe
O4 - HKLM\..\Run: [biquoottaf] C:\WINDOWS\system32\padofou.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Infium] "C:\Program Files\QIP 2010\qip.exe" /autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: 00juepz.exe
O4 - Startup: 01niknj.exe
O4 - Startup: 0xfkwhr.exe
O4 - Startup: 1huobrz.exe
O4 - Startup: 1tbozpu.exe
O4 - Startup: 1vsubrz.exe
O4 - Startup: 55gcfvg.exe
O4 - Startup: 5qnlhil.exe
O4 - Startup: 5ysbpjs.exe
O4 - Startup: cfgm55uix.exe
O4 - Startup: emhpksj55.exe
O4 - Startup: fjgifh00n.exe
O4 - Startup: fvuq55csvx.exe
O4 - Startup: gnnygtf0.exe
O4 - Startup: hegdfc01h.exe
O4 - Startup: ixlqks55c.exe
O4 - Startup: jrluoxra.exe
O4 - Startup: k55eiliexve.exe
O4 - Startup: laow55amln.exe
O4 - Startup: lvg01bjemh.exe
O4 - Startup: nbwezhb00.exe
O4 - Startup: nyitd001n.exe
O4 - Startup: ojpa01jikn.exe
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: pyy56kdjuq.exe
O4 - Startup: rakzd00zw.exe
O4 - Startup: rcmxhss5.exe
O4 - Startup: rks55iatre.exe
O4 - Startup: smx5suvdyg.exe
O4 - Startup: stngcv56o.exe
O4 - Startup: teizj0mvp.exe
O4 - Startup: uixlqqj56.exe
O4 - Startup: vpysbfsc.exe
O4 - Startup: wghn00bpk.exe
O4 - Startup: x55egnreofh.exe
O4 - Startup: y55mkvxeyhb.exe
O4 - Startup: yvxet56ix.exe
O4 - Startup: zicfheqv.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: SmartLinkService (a7yya77di) - Google Inc. - C:\WINDOWS\system32\divin.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: BsHelpCS (iflpyug9f2yytal8) - Unknown owner - C:\WINDOWS\system32\vouciby.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 9402 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Documents and Settings\vasek\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2010-11-24 150400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-01-04 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-01-04 79648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2003-05-22 110592]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2003-05-22 610304]
"ATIModeChange"=C:\WINDOWS\system32\Ati2mdxx.exe [2002-08-16 28672]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2002-08-14 290816]
"Cpqset"=C:\Program Files\HPQ\Default Settings\cpqset.exe [2003-10-05 196670]
"Display Settings"=C:\Program Files\HPQ\Notebook Utilities\hptasks.exe [2002-08-15 45056]
"AdaptecDirectCD"=C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe [2003-03-26 684032]
"QuickTime Task"=E:\Program Files\QuickTime\QTTask.exe -atboottime []
"CARPService"=C:\WINDOWS\system32\carpserv.exe [2003-04-15 4608]
"QT4HPOT"=C:\Program Files\HPQ\One-Touch\OneTouch.EXE [2003-03-13 106496]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"zoummoh"=C:\WINDOWS\system32\lydazoug.exe []
"biquoottaf"=C:\WINDOWS\system32\padofou.exe [2011-02-19 245760]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Infium"=C:\Program Files\QIP 2010\qip.exe [2010-11-24 5853056]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-12-03 14944136]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění
00juepz.exe
01niknj.exe
0xfkwhr.exe
1huobrz.exe
1tbozpu.exe
1vsubrz.exe
55gcfvg.exe
5qnlhil.exe
5ysbpjs.exe
cfgm55uix.exe
emhpksj55.exe
fjgifh00n.exe
fvuq55csvx.exe
gnnygtf0.exe
hegdfc01h.exe
ixlqks55c.exe
jrluoxra.exe
k55eiliexve.exe
laow55amln.exe
lvg01bjemh.exe
nbwezhb00.exe
nyitd001n.exe
ojpa01jikn.exe
OpenOffice.org 3.2.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe
pyy56kdjuq.exe
rakzd00zw.exe
rcmxhss5.exe
rks55iatre.exe
smx5suvdyg.exe
stngcv56o.exe
teizj0mvp.exe
uixlqqj56.exe
vpysbfsc.exe
wghn00bpk.exe
x55egnreofh.exe
y55mkvxeyhb.exe
yvxet56ix.exe
zicfheqv.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Winamp\winamp.exe"="C:\Program Files\Winamp\winamp.exe:*:Enabled:Winamp"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"C:\Documents and Settings\vasek\Local Settings\Temp\Resources\KMSKG\Keygen.exe"="C:\Documents and Settings\vasek\Local Settings\Temp\Resources\KMSKG\Keygen.exe:*:Enabled:Keygen"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2011-02-19 14:45:57 ----A---- C:\WINDOWS\system32\divin.exe
2011-02-19 14:40:50 ----A---- C:\WINDOWS\system32\drivers\xybmxyqqc.sys
2011-02-19 14:38:13 ----A---- C:\WINDOWS\system32\drivers\tntxrruw.sys
2011-02-19 13:25:00 ----A---- C:\WINDOWS\system32\cessemma.exe
2011-02-16 06:36:30 ----A---- C:\WINDOWS\system32\pubusoojad.exe
2011-02-16 06:14:39 ----A---- C:\WINDOWS\system32\drivers\kddppngq.sys
2011-02-16 06:14:14 ----AH---- C:\Documents and Settings\vasek\Data aplikací\fLFGjmeheC.txt
2011-02-12 17:32:11 ----AH---- C:\Documents and Settings\vasek\Data aplikací\CmI1eJ1FIL.txt
2011-02-12 17:32:04 ----A---- C:\WINDOWS\system32\padofou.exe
2011-02-10 18:28:53 ----D---- C:\Program Files\Officy
2011-02-09 19:11:13 ----D---- C:\ado
2011-02-08 18:13:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\MiKTeX
2011-02-08 17:03:04 ----D---- C:\Program Files\MiKTeX 2.8
2011-02-02 11:00:17 ----D---- C:\Documents and Settings\vasek\Data aplikací\gtk-2.0
2011-02-02 10:58:50 ----D---- C:\Documents and Settings\vasek\Data aplikací\gretl
2011-02-02 10:57:28 ----D---- C:\Program Files\gretl
2011-01-30 10:28:53 ----D---- C:\Documents and Settings\vasek\Data aplikací\Stata10
======List of files/folders modified in the last 1 months======
2011-02-19 14:47:50 ----D---- C:\WINDOWS\Temp
2011-02-19 14:47:42 ----D---- C:\Program Files\trend micro
2011-02-19 14:46:30 ----D---- C:\Documents and Settings\vasek\Data aplikací\Skype
2011-02-19 14:46:14 ----D---- C:\WINDOWS\system32
2011-02-19 14:45:59 ----D---- C:\Program Files\Mozilla Firefox
2011-02-19 14:45:48 ----D---- C:\Program Files\QIP 2010
2011-02-19 14:44:54 ----D---- C:\WINDOWS\Minidump
2011-02-19 14:44:54 ----D---- C:\WINDOWS
2011-02-19 14:41:01 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-02-19 14:40:56 ----D---- C:\WINDOWS\system32\drivers
2011-02-19 14:40:52 ----D---- C:\WINDOWS\system32\CatRoot2
2011-02-19 13:02:41 ----D---- C:\Documents and Settings\vasek\Data aplikací\skypePM
2011-02-18 15:58:21 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-02-17 18:36:57 ----D---- C:\WINDOWS\Prefetch
2011-02-16 07:21:06 ----RSHD---- C:\RECYCLER
2011-02-10 18:28:56 ----RD---- C:\Program Files
2011-02-01 11:18:37 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2011-01-26 23:00:49 ----SD---- C:\Documents and Settings\vasek\Data aplikací\Microsoft
2011-01-25 09:51:51 ----D---- C:\Music
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\System32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys [2009-04-28 9072]
R1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2009-04-28 9200]
R1 cdudf_xp;cdudf_xp; C:\WINDOWS\system32\drivers\cdudf_xp.sys [2003-03-26 241280]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 pwd_2k;pwd_2k; C:\WINDOWS\system32\drivers\pwd_2k.sys [2003-03-26 144250]
R1 UdfReadr_xp;UdfReadr_xp; C:\WINDOWS\system32\drivers\UdfReadr_xp.sys [2003-03-26 206464]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.9.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2010-12-25 21275]
R2 irda;Protokol IrDA; C:\WINDOWS\System32\DRIVERS\irda.sys [2008-04-13 88192]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2003-04-15 9855]
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2005-12-28 13568]
R2 StreamDispatcher;StreamDispatcher; C:\WINDOWS\system32\DRIVERS\strmdisp.sys [2003-04-15 34224]
R3 ALiIRDA;ALi Infrared Device Driver; C:\WINDOWS\System32\DRIVERS\aliirda.sys [2001-12-17 26112]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\System32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2002-08-16 471168]
R3 BCM43XX;Broadcom 802.11 OneDriver; C:\WINDOWS\System32\DRIVERS\bcmwl5.sys [2003-10-01 254208]
R3 CALIAUD;Conexant AMC 3D ENVIRONMENTAL AUDIO; C:\WINDOWS\system32\drivers\caliaud.sys [2002-11-05 291328]
R3 CALIHALA;CALIHALA; C:\WINDOWS\system32\drivers\calihal.sys [2002-11-05 244608]
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver; C:\WINDOWS\System32\Drivers\DKbFltr.SYS [2002-10-16 14543]
R3 DP83815;National Semiconductor Corp. DP83815/816 NDIS 5.0 Miniport Driver; C:\WINDOWS\System32\DRIVERS\DP83815.SYS [2003-07-17 28280]
R3 HPCI;HP Configuration Interface; C:\WINDOWS\System32\DRIVERS\hpci.sys [2002-07-17 14504]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSF_DP.sys [2003-04-15 1171616]
R3 HSFHWALI;HSFHWALI; C:\WINDOWS\system32\DRIVERS\HSFHWALI.sys [2003-04-15 153380]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\System32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\System32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\System32\DRIVERS\SynTP.sys [2003-05-22 273072]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2003-04-15 594960]
S0 kddppngq;kddppngq; C:\WINDOWS\system32\drivers\kddppngq.sys []
S3 aliadwdm;Ovladač WDM urychlovače zpracování zvuku ALi; C:\WINDOWS\system32\drivers\ac97ali.sys [2002-08-29 231552]
S3 Bridge;Most MAC; C:\WINDOWS\System32\DRIVERS\bridge.sys [2008-04-13 71552]
S3 BridgeMP;Miniport mostu MAC; C:\WINDOWS\System32\DRIVERS\bridge.sys [2008-04-13 71552]
S3 dvd_2K;dvd_2K; C:\WINDOWS\system32\drivers\dvd_2K.sys [2003-03-26 25930]
S3 FA312;NETGEAR FA330/FA312/FA311 Fast Ethernet Adapter Driver; C:\WINDOWS\System32\DRIVERS\FA312nd5.sys [2001-08-17 16074]
S3 mmc_2K;mmc_2K; C:\WINDOWS\system32\drivers\mmc_2K.sys [2003-03-26 30662]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2005-12-28 114753]
R2 HPConfig;HP Configuration Interface Service; C:\WINDOWS\system32\HPConfig.exe [2002-08-15 151552]
R2 HPWirelessMgr;HPWirelessMgr; C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe [2003-07-28 53248]
R2 Irmon;Sledování infračerveného přenosu; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-01-04 153376]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2005-12-28 217164]
R2 S24EventMonitor;Intel(R) PROSet/Wireless Service; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2005-12-28 540745]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R2 WLTRYSVC;WLTRYSVC; C:\WINDOWS\System32\WLTRYSVC.EXE [2003-10-01 45056]
S2 a7yya77di;SmartLinkService; C:\WINDOWS\system32\divin.exe [2011-02-19 245760]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-01-01 135664]
S2 iflpyug9f2yytal8;BsHelpCS; C:\WINDOWS\system32\vouciby.exe []
-----------------EOF-----------------
Re: počítač se často vypíná
Zdravim a pekny den preji
Mate tam celou zoo i s babkou pokladni
Spustte HJT a provedeme fixnuti polozek
Stahnete OTM (viz muj podpis)




- HJT najdete zde C:\Program Files\trend micro\vasek.exe
- Otevre se Vam okno, kliknete na Do a system scan only
- V dalsim okne najdete radky které jsem Vam vypsal nize, vedle nich je ctverecek, do ktereho udelate zatrzitko
- R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\vasek\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll - Kliknete na Fix checked (vlevo dole)
- HJT se Vas zepta zda opravdu ANO, s tim souhlasite a je hotovo

- Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
- Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
Kód: Vybrat vše
:reg [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"=- "zoummoh"=- "biquoottaf"=- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Skype"=- "MSMSGS"=- [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "C:\Documents and Settings\vasek\Local Settings\Temp\Resources\KMSKG\Keygen.exe"=- :services BsHelpCS iflpyug9f2yytal8 a7yya77di :files C:\WINDOWS\system32\divin.exe C:\WINDOWS\system32\drivers\xybmxyqqc.sys C:\WINDOWS\system32\drivers\tntxrruw.sys C:\WINDOWS\system32\cessemma.exe C:\WINDOWS\system32\pubusoojad.exe C:\WINDOWS\system32\drivers\kddppngq.sys C:\Documents and Settings\vasek\Local Settings\Temp\Resources\KMSKG C:\Documents and Settings\vasek\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Synchronizer.lnk C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\*.exe C:\WINDOWS\TEMP\kfwyhpuu01501515.tmp C:\WINDOWS\TEMP\vbzoap03BEB32E.tmp C:\DOCUME~1\vasek\LOCALS~1\Temp\kfwyhpuu01501515.tmp :\WINDOWS\system32\cessemma.exe C:\DOCUME~1\vasek\LOCALS~1\Temp\kfwyhpuu01501515.tmp C:\DOCUME~1\vasek\LOCALS~1\Temp\vbzoap03BEB32E.tmp C:\DOCUME~1\vasek\LOCALS~1\Temp\881.exe C:\DOCUME~1\vasek\LOCALS~1\Temp\197.exe C:\WINDOWS\TEMP %windir%\system32\*.tmp.dll /s %windir%\system32\SET*.tmp /s %windir%\*.tmp /s :commands [RESETHOSTS] [EMPTYTEMP] [EMPTYFLASH]
- Kliknete na cervene tlacitko MoveIt!
- Budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles, obsah sem vlozte
Re: počítač se často vypíná
Zde je log:
All processes killed
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\zoummoh deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\biquoottaf deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Skype deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\MSMSGS deleted successfully.
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\Documents and Settings\vasek\Local Settings\Temp\Resources\KMSKG\Keygen.exe deleted successfully.
========== SERVICES/DRIVERS ==========
Error: No service named BsHelpCS was found to stop!
Service\Driver key BsHelpCS not found.
Service iflpyug9f2yytal8 stopped successfully!
Service iflpyug9f2yytal8 deleted successfully!
Service a7yya77di stopped successfully!
Service a7yya77di deleted successfully!
========== FILES ==========
C:\WINDOWS\system32\divin.exe moved successfully.
File move failed. C:\WINDOWS\system32\drivers\xybmxyqqc.sys scheduled to be moved on reboot.
C:\WINDOWS\system32\drivers\tntxrruw.sys moved successfully.
C:\WINDOWS\system32\cessemma.exe moved successfully.
C:\WINDOWS\system32\pubusoojad.exe moved successfully.
C:\WINDOWS\system32\drivers\kddppngq.sys moved successfully.
C:\Documents and Settings\vasek\Local Settings\Temp\Resources\KMSKG folder moved successfully.
C:\Documents and Settings\vasek\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Synchronizer.lnk moved successfully.
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\00juepz.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\01niknj.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\0xfkwhr.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\1huobrz.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\1tbozpu.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\1vsubrz.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\55gcfvg.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\5qnlhil.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\5ysbpjs.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\cfgm55uix.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\emhpksj55.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\emhpksm55.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\fjgifh00n.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\fvuq55csvx.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\gnnygtf0.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\hegdfc01h.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\idlgod55a.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\ixlqks55c.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\jrluoxra.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\k55eiliexve.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\laow55amln.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\lvg01bjemh.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\nbwezhb00.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\nyitd001n.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\ojpa01jikn.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\pyy56kdjuq.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\rakzd00zw.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\rcmxhss5.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\rks55iatre.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\smx5suvdyg.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\stngcv56o.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\teizj0mvp.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\uixlqqj56.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\vpysbfsc.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\wghn00bpk.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\x55egnreofh.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\y55mkvxeyhb.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\yvxet56ix.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\zicfheqv.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\zv00hpksnvp.exe moved successfully.
C:\WINDOWS\TEMP\kfwyhpuu01501515.tmp moved successfully.
C:\WINDOWS\TEMP\vbzoap03BEB32E.tmp moved successfully.
C:\DOCUME~1\vasek\LOCALS~1\Temp\kfwyhpuu01501515.tmp moved successfully.
Error: Unable to interpret <:\WINDOWS\system32\cessemma.exe> in the current context!
Error: Unable to interpret <C:\DOCUME~1\vasek\LOCALS~1\Temp\kfwyhpuu01501515.tmp> in the current context!
Error: Unable to interpret <C:\DOCUME~1\vasek\LOCALS~1\Temp\vbzoap03BEB32E.tmp> in the current context!
Error: Unable to interpret <C:\DOCUME~1\vasek\LOCALS~1\Temp\881.exe> in the current context!
Error: Unable to interpret <C:\DOCUME~1\vasek\LOCALS~1\Temp\197.exe> in the current context!
Error: Unable to interpret <C:\WINDOWS\TEMP> in the current context!
Error: Unable to interpret <%windir%\system32\*.tmp.dll /s> in the current context!
Error: Unable to interpret <%windir%\system32\SET*.tmp /s> in the current context!
Error: Unable to interpret <%windir%\*.tmp /s> in the current context!
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 1087696 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: vasek
->Temp folder emptied: 1877112401 bytes
->Temporary Internet Files folder emptied: 33237739 bytes
->Java cache emptied: 1931608 bytes
->FireFox cache emptied: 55070736 bytes
->Google Chrome cache emptied: 7913597 bytes
->Flash cache emptied: 25502 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1139202 bytes
%systemroot%\System32 .tmp files removed: 2504 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 5041048 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 40400 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 1 891,00 mb
OTM by OldTimer - Version 3.1.17.2 log created on 02192011_171626
Files moved on Reboot...
File move failed. C:\WINDOWS\system32\drivers\xybmxyqqc.sys scheduled to be moved on reboot.
Registry entries deleted on Reboot...
All processes killed
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\zoummoh deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\biquoottaf deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Skype deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\MSMSGS deleted successfully.
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\Documents and Settings\vasek\Local Settings\Temp\Resources\KMSKG\Keygen.exe deleted successfully.
========== SERVICES/DRIVERS ==========
Error: No service named BsHelpCS was found to stop!
Service\Driver key BsHelpCS not found.
Service iflpyug9f2yytal8 stopped successfully!
Service iflpyug9f2yytal8 deleted successfully!
Service a7yya77di stopped successfully!
Service a7yya77di deleted successfully!
========== FILES ==========
C:\WINDOWS\system32\divin.exe moved successfully.
File move failed. C:\WINDOWS\system32\drivers\xybmxyqqc.sys scheduled to be moved on reboot.
C:\WINDOWS\system32\drivers\tntxrruw.sys moved successfully.
C:\WINDOWS\system32\cessemma.exe moved successfully.
C:\WINDOWS\system32\pubusoojad.exe moved successfully.
C:\WINDOWS\system32\drivers\kddppngq.sys moved successfully.
C:\Documents and Settings\vasek\Local Settings\Temp\Resources\KMSKG folder moved successfully.
C:\Documents and Settings\vasek\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Synchronizer.lnk moved successfully.
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\00juepz.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\01niknj.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\0xfkwhr.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\1huobrz.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\1tbozpu.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\1vsubrz.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\55gcfvg.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\5qnlhil.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\5ysbpjs.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\cfgm55uix.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\emhpksj55.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\emhpksm55.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\fjgifh00n.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\fvuq55csvx.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\gnnygtf0.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\hegdfc01h.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\idlgod55a.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\ixlqks55c.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\jrluoxra.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\k55eiliexve.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\laow55amln.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\lvg01bjemh.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\nbwezhb00.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\nyitd001n.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\ojpa01jikn.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\pyy56kdjuq.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\rakzd00zw.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\rcmxhss5.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\rks55iatre.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\smx5suvdyg.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\stngcv56o.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\teizj0mvp.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\uixlqqj56.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\vpysbfsc.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\wghn00bpk.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\x55egnreofh.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\y55mkvxeyhb.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\yvxet56ix.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\zicfheqv.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\zv00hpksnvp.exe moved successfully.
C:\WINDOWS\TEMP\kfwyhpuu01501515.tmp moved successfully.
C:\WINDOWS\TEMP\vbzoap03BEB32E.tmp moved successfully.
C:\DOCUME~1\vasek\LOCALS~1\Temp\kfwyhpuu01501515.tmp moved successfully.
Error: Unable to interpret <:\WINDOWS\system32\cessemma.exe> in the current context!
Error: Unable to interpret <C:\DOCUME~1\vasek\LOCALS~1\Temp\kfwyhpuu01501515.tmp> in the current context!
Error: Unable to interpret <C:\DOCUME~1\vasek\LOCALS~1\Temp\vbzoap03BEB32E.tmp> in the current context!
Error: Unable to interpret <C:\DOCUME~1\vasek\LOCALS~1\Temp\881.exe> in the current context!
Error: Unable to interpret <C:\DOCUME~1\vasek\LOCALS~1\Temp\197.exe> in the current context!
Error: Unable to interpret <C:\WINDOWS\TEMP> in the current context!
Error: Unable to interpret <%windir%\system32\*.tmp.dll /s> in the current context!
Error: Unable to interpret <%windir%\system32\SET*.tmp /s> in the current context!
Error: Unable to interpret <%windir%\*.tmp /s> in the current context!
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 1087696 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: vasek
->Temp folder emptied: 1877112401 bytes
->Temporary Internet Files folder emptied: 33237739 bytes
->Java cache emptied: 1931608 bytes
->FireFox cache emptied: 55070736 bytes
->Google Chrome cache emptied: 7913597 bytes
->Flash cache emptied: 25502 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1139202 bytes
%systemroot%\System32 .tmp files removed: 2504 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 5041048 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 40400 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 1 891,00 mb
OTM by OldTimer - Version 3.1.17.2 log created on 02192011_171626
Files moved on Reboot...
File move failed. C:\WINDOWS\system32\drivers\xybmxyqqc.sys scheduled to be moved on reboot.
Registry entries deleted on Reboot...
Re: počítač se často vypíná
Tak ted pouzijem trosku tezsi kalibr
PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK

- Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
- Pokud mate Win XP spustte pod uctem Spravce\Administratora
- Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
- Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
- Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
- Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
- Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
- Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
- Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
Re: počítač se často vypíná
Tady je log z COmbofixu.
ComboFix 11-02-19.02 - vasek 19.02.2011 17:35:54.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.447.202 [GMT 1:00]
Spuštěný z: c:\documents and settings\vasek\Dokumenty\Downloads\ComboFix.exe
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\vasek\LOCALS~1\Temp\kfwyhpuu01501515.tmp
c:\docume~1\vasek\LOCALS~1\Temp\vbzoap03BEB32E.tmp
c:\documents and settings\LocalService\Data aplikací\Microsoft\cessemma.exe
c:\documents and settings\LocalService\Data aplikací\Microsoft\divin.exe
c:\documents and settings\LocalService\Data aplikací\Microsoft\lydazoug.exe
c:\documents and settings\LocalService\Data aplikací\Microsoft\padofou.exe
c:\documents and settings\LocalService\Data aplikací\Microsoft\pubusoojad.exe
c:\documents and settings\LocalService\Data aplikací\Microsoft\vouciby.exe
c:\documents and settings\vasek\fxmdk.exe
c:\documents and settings\vasek\Local Settings\Temp\kfwyhpuu01501515.tmp
c:\documents and settings\vasek\Local Settings\Temp\vbzoap03BEB32E.tmp
c:\recycler\S-1-5-21-0402442840-1596461924-253656365-2919\djwi2kcew.exe
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-19 do 2011-02-19 )))))))))))))))))))))))))))))))
.
2011-02-19 16:49 . 2011-02-19 16:19 245760 ----a-w- c:\windows\system32\divin.exe
2011-02-19 16:20 . 2011-02-19 16:19 245760 ----a-w- c:\documents and settings\LocalService\Data aplikací\Microsoft\padofou.exe
2011-02-19 16:19 . 2011-02-19 16:19 245760 ----a-w- c:\windows\system32\cessemma.exe
2011-02-19 16:16 . 2011-02-19 16:16 -------- d-----w- C:\_OTM
2011-02-19 13:40 . 2011-02-19 16:49 738304 ----a-w- c:\windows\system32\drivers\xybmxyqqc.sys
2011-02-18 14:51 . 2011-02-18 14:51 -------- d-----w- c:\documents and settings\vasek\Local Settings\Data aplikací\WinZip
2011-02-12 16:32 . 2011-02-19 16:19 245760 ----a-w- c:\windows\system32\padofou.exe
2011-02-10 17:28 . 2011-02-10 17:29 -------- d-----w- c:\program files\Officy
2011-02-09 18:11 . 2011-02-09 18:11 -------- d-----w- C:\ado
2011-02-08 17:13 . 2011-02-08 17:13 -------- d-----w- c:\documents and settings\All Users\Data aplikací\MiKTeX
2011-02-08 16:03 . 2011-02-08 16:53 -------- d-----w- c:\program files\MiKTeX 2.8
2011-02-02 10:00 . 2011-02-09 16:53 -------- d-----w- c:\documents and settings\vasek\Data aplikací\gtk-2.0
2011-02-02 09:58 . 2011-02-12 09:51 -------- d-----w- c:\documents and settings\vasek\Data aplikací\gretl
2011-02-02 09:57 . 2011-02-02 09:57 -------- d-----w- c:\program files\gretl
2011-01-30 09:28 . 2011-01-30 09:28 -------- d-----w- c:\documents and settings\vasek\Data aplikací\Stata10
2011-01-26 22:00 . 2011-01-26 22:00 -------- d-----w- c:\documents and settings\vasek\Local Settings\Data aplikací\Identities
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-04 21:10 . 2011-01-04 21:11 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-01-04 21:10 . 2011-01-04 21:11 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-12-31 21:38 . 2010-12-31 21:39 737280 ----a-w- c:\windows\iun6002.exe
2010-12-25 12:31 . 2010-12-25 12:31 21275 ----a-w- c:\windows\system32\drivers\AegisP.sys
2010-12-20 17:09 . 2010-12-26 20:30 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 17:08 . 2010-12-26 20:30 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2008-02-02 10:19 . 2010-12-31 21:40 67696 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-02-02 10:19 . 2010-12-31 21:40 54376 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-02-02 10:19 . 2010-12-31 21:40 34952 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-02-02 10:19 . 2010-12-31 21:40 46720 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2008-02-02 10:19 . 2010-12-31 21:40 172144 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Infium"="c:\program files\QIP 2010\qip.exe" [2010-11-24 5853056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-05-22 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-05-22 610304]
"ATIModeChange"="Ati2mdxx.exe" [2002-08-15 28672]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2002-08-14 290816]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2003-10-05 196670]
"Display Settings"="c:\program files\HPQ\Notebook Utilities\hptasks.exe" [2002-08-15 45056]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2003-03-26 684032]
"CARPService"="carpserv.exe" [2003-04-15 4608]
"QT4HPOT"="c:\program files\HPQ\One-Touch\OneTouch.EXE" [2003-03-13 106496]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"biquoottaf"="c:\windows\system32\padofou.exe" [2011-02-19 245760]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"biquoottaf"="c:\documents and settings\LocalService\Data aplikací\Microsoft\padofou.exe" [2011-02-19 245760]
c:\documents and settings\vasek\Nabˇdka Start\Programy\Po spuçtŘnˇ\
55umbzm.exe [2011-2-19 42496]
abo01psozf.exe [2011-2-19 43008]
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-6-7 1195520]
ubo01psozf.exe [2011-2-19 43008]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Winamp\\winamp.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
R3 ALiIRDA;ALi Infrared Device Driver;c:\windows\system32\drivers\aliirda.sys [30.7.2010 3:47 26112]
R3 CALIAUD;Conexant AMC 3D ENVIRONMENTAL AUDIO;c:\windows\system32\drivers\caliaud.sys [30.7.2010 3:46 291328]
R3 CALIHALA;CALIHALA;c:\windows\system32\drivers\calihal.sys [30.7.2010 3:46 244608]
R3 DP83815;National Semiconductor Corp. DP83815/816 NDIS 5.0 Miniport Driver;c:\windows\system32\drivers\DP83815.sys [17.7.2003 2:01 28280]
S0 kddppngq;kddppngq; [x]
S2 a7yya77di;SmartLinkService;c:\windows\system32\divin.exe [19.2.2011 17:49 245760]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1.1.2011 16:54 135664]
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - A7YYA77DI
*Deregistered* - xybmxyqqc
.
.
------- Doplňkový sken -------
.
uSearchAssistant = hxxp://search.qip.ru/ie
FF - ProfilePath - c:\documents and settings\vasek\Data aplikací\Mozilla\Firefox\Profiles\do2b6c5q.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://google.com/
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-19 17:49
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????3?7?7?6??????? ???B???????????????B? ??????
skenování skrytých souborů ...
c:\windows\system32\divin.exe 245760 bytes executable
sken byl úspešně dokončen
skryté soubory: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\xybmxyqqc]
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\system32\HPConfig.exe
c:\program files\HPQ\Notebook Utilities\HPWirelessMgr.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\wdfmgr.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\windows\system32\wscntfy.exe
c:\windows\System32\wbem\wmiapsrv.exe
c:\documents and settings\LocalService\Data aplikací\Microsoft\cessemma.exe
c:\windows\system32\carpserv.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\windows\TEMP\vbzoap03BEB32E.tmp
c:\docume~1\vasek\LOCALS~1\Temp\kfwyhpuu01501515.tmp
c:\docume~1\vasek\LOCALS~1\Temp\vbzoap03BEB32E.tmp
.
**************************************************************************
.
Celkový čas: 2011-02-19 17:54:55 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-02-19 16:54
Před spuštěním: Volných bajtů: 23 844 401 152
Po spuštění: Volných bajtů: 23 788 695 552
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
- - End Of File - - CF96654C9A742C6BB1F65B9F2E083389
ComboFix 11-02-19.02 - vasek 19.02.2011 17:35:54.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.447.202 [GMT 1:00]
Spuštěný z: c:\documents and settings\vasek\Dokumenty\Downloads\ComboFix.exe
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\vasek\LOCALS~1\Temp\kfwyhpuu01501515.tmp
c:\docume~1\vasek\LOCALS~1\Temp\vbzoap03BEB32E.tmp
c:\documents and settings\LocalService\Data aplikací\Microsoft\cessemma.exe
c:\documents and settings\LocalService\Data aplikací\Microsoft\divin.exe
c:\documents and settings\LocalService\Data aplikací\Microsoft\lydazoug.exe
c:\documents and settings\LocalService\Data aplikací\Microsoft\padofou.exe
c:\documents and settings\LocalService\Data aplikací\Microsoft\pubusoojad.exe
c:\documents and settings\LocalService\Data aplikací\Microsoft\vouciby.exe
c:\documents and settings\vasek\fxmdk.exe
c:\documents and settings\vasek\Local Settings\Temp\kfwyhpuu01501515.tmp
c:\documents and settings\vasek\Local Settings\Temp\vbzoap03BEB32E.tmp
c:\recycler\S-1-5-21-0402442840-1596461924-253656365-2919\djwi2kcew.exe
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-19 do 2011-02-19 )))))))))))))))))))))))))))))))
.
2011-02-19 16:49 . 2011-02-19 16:19 245760 ----a-w- c:\windows\system32\divin.exe
2011-02-19 16:20 . 2011-02-19 16:19 245760 ----a-w- c:\documents and settings\LocalService\Data aplikací\Microsoft\padofou.exe
2011-02-19 16:19 . 2011-02-19 16:19 245760 ----a-w- c:\windows\system32\cessemma.exe
2011-02-19 16:16 . 2011-02-19 16:16 -------- d-----w- C:\_OTM
2011-02-19 13:40 . 2011-02-19 16:49 738304 ----a-w- c:\windows\system32\drivers\xybmxyqqc.sys
2011-02-18 14:51 . 2011-02-18 14:51 -------- d-----w- c:\documents and settings\vasek\Local Settings\Data aplikací\WinZip
2011-02-12 16:32 . 2011-02-19 16:19 245760 ----a-w- c:\windows\system32\padofou.exe
2011-02-10 17:28 . 2011-02-10 17:29 -------- d-----w- c:\program files\Officy
2011-02-09 18:11 . 2011-02-09 18:11 -------- d-----w- C:\ado
2011-02-08 17:13 . 2011-02-08 17:13 -------- d-----w- c:\documents and settings\All Users\Data aplikací\MiKTeX
2011-02-08 16:03 . 2011-02-08 16:53 -------- d-----w- c:\program files\MiKTeX 2.8
2011-02-02 10:00 . 2011-02-09 16:53 -------- d-----w- c:\documents and settings\vasek\Data aplikací\gtk-2.0
2011-02-02 09:58 . 2011-02-12 09:51 -------- d-----w- c:\documents and settings\vasek\Data aplikací\gretl
2011-02-02 09:57 . 2011-02-02 09:57 -------- d-----w- c:\program files\gretl
2011-01-30 09:28 . 2011-01-30 09:28 -------- d-----w- c:\documents and settings\vasek\Data aplikací\Stata10
2011-01-26 22:00 . 2011-01-26 22:00 -------- d-----w- c:\documents and settings\vasek\Local Settings\Data aplikací\Identities
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-04 21:10 . 2011-01-04 21:11 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-01-04 21:10 . 2011-01-04 21:11 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-12-31 21:38 . 2010-12-31 21:39 737280 ----a-w- c:\windows\iun6002.exe
2010-12-25 12:31 . 2010-12-25 12:31 21275 ----a-w- c:\windows\system32\drivers\AegisP.sys
2010-12-20 17:09 . 2010-12-26 20:30 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 17:08 . 2010-12-26 20:30 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2008-02-02 10:19 . 2010-12-31 21:40 67696 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-02-02 10:19 . 2010-12-31 21:40 54376 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-02-02 10:19 . 2010-12-31 21:40 34952 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-02-02 10:19 . 2010-12-31 21:40 46720 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2008-02-02 10:19 . 2010-12-31 21:40 172144 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Infium"="c:\program files\QIP 2010\qip.exe" [2010-11-24 5853056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-05-22 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-05-22 610304]
"ATIModeChange"="Ati2mdxx.exe" [2002-08-15 28672]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2002-08-14 290816]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2003-10-05 196670]
"Display Settings"="c:\program files\HPQ\Notebook Utilities\hptasks.exe" [2002-08-15 45056]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2003-03-26 684032]
"CARPService"="carpserv.exe" [2003-04-15 4608]
"QT4HPOT"="c:\program files\HPQ\One-Touch\OneTouch.EXE" [2003-03-13 106496]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"biquoottaf"="c:\windows\system32\padofou.exe" [2011-02-19 245760]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"biquoottaf"="c:\documents and settings\LocalService\Data aplikací\Microsoft\padofou.exe" [2011-02-19 245760]
c:\documents and settings\vasek\Nabˇdka Start\Programy\Po spuçtŘnˇ\
55umbzm.exe [2011-2-19 42496]
abo01psozf.exe [2011-2-19 43008]
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-6-7 1195520]
ubo01psozf.exe [2011-2-19 43008]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Winamp\\winamp.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
R3 ALiIRDA;ALi Infrared Device Driver;c:\windows\system32\drivers\aliirda.sys [30.7.2010 3:47 26112]
R3 CALIAUD;Conexant AMC 3D ENVIRONMENTAL AUDIO;c:\windows\system32\drivers\caliaud.sys [30.7.2010 3:46 291328]
R3 CALIHALA;CALIHALA;c:\windows\system32\drivers\calihal.sys [30.7.2010 3:46 244608]
R3 DP83815;National Semiconductor Corp. DP83815/816 NDIS 5.0 Miniport Driver;c:\windows\system32\drivers\DP83815.sys [17.7.2003 2:01 28280]
S0 kddppngq;kddppngq; [x]
S2 a7yya77di;SmartLinkService;c:\windows\system32\divin.exe [19.2.2011 17:49 245760]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1.1.2011 16:54 135664]
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - A7YYA77DI
*Deregistered* - xybmxyqqc
.
.
------- Doplňkový sken -------
.
uSearchAssistant = hxxp://search.qip.ru/ie
FF - ProfilePath - c:\documents and settings\vasek\Data aplikací\Mozilla\Firefox\Profiles\do2b6c5q.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://google.com/
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-19 17:49
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????3?7?7?6??????? ???B???????????????B? ??????
skenování skrytých souborů ...
c:\windows\system32\divin.exe 245760 bytes executable
sken byl úspešně dokončen
skryté soubory: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\xybmxyqqc]
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\system32\HPConfig.exe
c:\program files\HPQ\Notebook Utilities\HPWirelessMgr.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\wdfmgr.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\windows\system32\wscntfy.exe
c:\windows\System32\wbem\wmiapsrv.exe
c:\documents and settings\LocalService\Data aplikací\Microsoft\cessemma.exe
c:\windows\system32\carpserv.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\windows\TEMP\vbzoap03BEB32E.tmp
c:\docume~1\vasek\LOCALS~1\Temp\kfwyhpuu01501515.tmp
c:\docume~1\vasek\LOCALS~1\Temp\vbzoap03BEB32E.tmp
.
**************************************************************************
.
Celkový čas: 2011-02-19 17:54:55 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-02-19 16:54
Před spuštěním: Volných bajtů: 23 844 401 152
Po spuštění: Volných bajtů: 23 788 695 552
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
- - End Of File - - CF96654C9A742C6BB1F65B9F2E083389
Re: počítač se často vypíná

- Pokud pouzivate Win Vista ci W7, kliknete na Avenger pravym a dejte Run As Administrator ci Spustit jako spravce
- Po spusteni Vas program upozorni, ze vse co delate, delate na vlastni riziko - Dejte OK
- Po potvrzeni uz na Vas koukne hlavni okno, kam vlozite skript, ktery mate nize
-
Kód: Vybrat vše
Files to delete: c:\windows\system32\divin.exe c:\documents and settings\LocalService\Data aplikací\Microsoft\padofou.exe c:\windows\system32\cessemma.exe c:\windows\system32\drivers\xybmxyqqc.sys c:\windows\system32\padofou.exe Drivers to delete: kddppngq a7yya77di gupdate xybmxyqqc Registry values to delete: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | SunJavaUpdateSched HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | biquoottaf
- Do ctverecku u Scan for rootkits a Automatically disable any rootkits found dejte fajecku
- Nyni uz kliknete na Execute a potvrdte Yes v nasledujicim okne - timto potvrdite spusteni skriptu
- Na otazku Reboot now odpovezte opet OK - timto se PC restartuje
- Po restartu by se mel otevrit poznamkovy blok s logem a jeho obsah vlozte sem. Pokud se tak nestane, naleznete pozadovany dokument v C:\avenger.txt
Re: počítač se často vypíná
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com
Platform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
Error: file "c:\windows\system32\divin.exe" not found!
Deletion of file "c:\windows\system32\divin.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\documents and settings\LocalService\Data aplikací\Microsoft\padofou.exe" not found!
Deletion of file "c:\documents and settings\LocalService\Data aplikací\Microsoft\padofou.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
File "c:\windows\system32\cessemma.exe" deleted successfully.
File "c:\windows\system32\drivers\xybmxyqqc.sys" deleted successfully.
File "c:\windows\system32\padofou.exe" deleted successfully.
Driver "kddppngq" deleted successfully.
Driver "a7yya77di" deleted successfully.
Driver "gupdate" deleted successfully.
Driver "xybmxyqqc" deleted successfully.
Registry value "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|SunJavaUpdateSched" deleted successfully.
Registry value "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|biquoottaf" deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
http://swandog46.geekstogo.com
Platform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
Error: file "c:\windows\system32\divin.exe" not found!
Deletion of file "c:\windows\system32\divin.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "c:\documents and settings\LocalService\Data aplikací\Microsoft\padofou.exe" not found!
Deletion of file "c:\documents and settings\LocalService\Data aplikací\Microsoft\padofou.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
File "c:\windows\system32\cessemma.exe" deleted successfully.
File "c:\windows\system32\drivers\xybmxyqqc.sys" deleted successfully.
File "c:\windows\system32\padofou.exe" deleted successfully.
Driver "kddppngq" deleted successfully.
Driver "a7yya77di" deleted successfully.
Driver "gupdate" deleted successfully.
Driver "xybmxyqqc" deleted successfully.
Registry value "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|SunJavaUpdateSched" deleted successfully.
Registry value "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|biquoottaf" deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
Re: počítač se často vypíná

Kód: Vybrat vše
:files
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\*.exe
:commands
[EMPTYTEMP]
Re: počítač se často vypíná
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: vasek
->Temp folder emptied: 2502766 bytes
->Temporary Internet Files folder emptied: 4788388 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 4540071 bytes
->Google Chrome cache emptied: 7408035 bytes
->Flash cache emptied: 956 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1006284 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 519680 bytes
Total Files Cleaned = 20,00 mb
OTM by OldTimer - Version 3.1.17.2 log created on 02202011_094259
Files moved on Reboot...
Registry entries deleted on Reboot...
->Temporary Internet Files folder emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: vasek
->Temp folder emptied: 2502766 bytes
->Temporary Internet Files folder emptied: 4788388 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 4540071 bytes
->Google Chrome cache emptied: 7408035 bytes
->Flash cache emptied: 956 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1006284 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 519680 bytes
Total Files Cleaned = 20,00 mb
OTM by OldTimer - Version 3.1.17.2 log created on 02202011_094259
Files moved on Reboot...
Registry entries deleted on Reboot...
- cernohous13
- VIP in memoriam
- Příspěvky: 8721
- Registrován: 09 pro 2006 06:19
- Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: počítač se často vypíná
Chybí ti začátek logu - zkus sem dát celý
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
Re: počítač se často vypíná
A, pardon, spatne jsem zkopiroval:
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: vasek
->Temp folder emptied: 2502766 bytes
->Temporary Internet Files folder emptied: 4788388 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 4540071 bytes
->Google Chrome cache emptied: 7408035 bytes
->Flash cache emptied: 956 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1006284 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 519680 bytes
Total Files Cleaned = 20,00 mb
OTM by OldTimer - Version 3.1.17.2 log created on 02202011_094259
Files moved on Reboot...
Registry entries deleted on Reboot...
10:01:43: All processes killed
========== FILES ==========
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\55umbzm.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\abo01psozf.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\ubo01psozf.exe moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: vasek
->Temp folder emptied: 2502766 bytes
->Temporary Internet Files folder emptied: 4788388 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 4540071 bytes
->Google Chrome cache emptied: 7408035 bytes
->Flash cache emptied: 956 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1006284 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 519680 bytes
Total Files Cleaned = 20,00 mb
OTM by OldTimer - Version 3.1.17.2 log created on 02202011_094259
Files moved on Reboot...
Registry entries deleted on Reboot...
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: vasek
->Temp folder emptied: 2502766 bytes
->Temporary Internet Files folder emptied: 4788388 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 4540071 bytes
->Google Chrome cache emptied: 7408035 bytes
->Flash cache emptied: 956 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1006284 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 519680 bytes
Total Files Cleaned = 20,00 mb
OTM by OldTimer - Version 3.1.17.2 log created on 02202011_094259
Files moved on Reboot...
Registry entries deleted on Reboot...
10:01:43: All processes killed
========== FILES ==========
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\55umbzm.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\abo01psozf.exe moved successfully.
C:\Documents and Settings\vasek\Nabídka Start\Programy\Po spuštění\ubo01psozf.exe moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: vasek
->Temp folder emptied: 2502766 bytes
->Temporary Internet Files folder emptied: 4788388 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 4540071 bytes
->Google Chrome cache emptied: 7408035 bytes
->Flash cache emptied: 956 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1006284 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 519680 bytes
Total Files Cleaned = 20,00 mb
OTM by OldTimer - Version 3.1.17.2 log created on 02202011_094259
Files moved on Reboot...
Registry entries deleted on Reboot...
Re: počítač se často vypíná



Re: počítač se často vypíná
pocitac bezi rychlejc nez predtim,nevypina se,ale v procesech jsou furt nektery programy,ktery by tam bejt nemely (nejspis)
Re: počítač se často vypíná
Co mate konkretne namysliskalpik píše:,ale v procesech jsou furt nektery programy,ktery by tam bejt nemely (nejspis)

Re: počítač se často vypíná
bzoap03BRB32E.tmp,zase cesemma.exe, S24EvMon.exe, wuauclt.exe
a take padofou.exe
a take padofou.exe