Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosim o kontrolu logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
00Inferno00
1. Stupeň Varování
Příspěvky: 55
Registrován: 25 říj 2007 18:38
Bydliště: Dolní BenešoVW
Kontaktovat uživatele:

Prosim o kontrolu logu

#1 Příspěvek od 00Inferno00 »

PC se obcas samovolně vypne/restartuje, ale nejspíš se přehřívá(overclocknute)
log:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Jan at 2011-03-27 10:43:26
Systém Microsoft Windows XP Professional Service Pack 3
System drive D: has 17 GB (7%) free of 238 GB
Total RAM: 3327 MB (82% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:43:32, on 27.3.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\F-Secure\Common\FSM32.EXE
D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
D:\Program Files\Winamp\winampa.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
D:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\Program Files\PowerISO\PWRISOVM.EXE
D:\Program Files\Analog Devices\Core\smax4pnp.exe
D:\Program Files\Analog Devices\SoundMAX\Smax4.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Logitech\Profiler\lwemon.exe
D:\Documents and Settings\Jan\Data aplikací\QipGuard\QipGuard.exe
E:\ZALOHA1\ALOHA\O.C\Core Temp.exe
D:\Program Files\Microsoft ActiveSync\Wcescomm.exe
D:\Program Files\uTorrent\uTorrent.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
D:\PROGRA~1\MI3AA1~1\rapimgr.exe
E:\ZALOHA1\SpeedFan\speedfan.exe
D:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
D:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
D:\Program Files\F-Secure\Common\FSMA32.EXE
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\F-Secure\Common\FSHDLL32.EXE
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Program Files\F-Secure\Common\FNRB32.EXE
D:\Program Files\F-Secure\Common\FIH32.EXE
D:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
D:\Program Files\F-Secure\Anti-Virus\fssm32.exe
D:\WINDOWS\system32\wbem\wmiapsrv.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\F-Secure\Anti-Virus\fsav32.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Mozilla Firefox\plugin-container.exe
D:\Documents and Settings\Jan\Plocha\RSIT.exe
D:\Program Files\trend micro\Jan.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://getii.com/7z
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - D:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - D:\Documents and Settings\Jan\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - D:\Program Files\uTorrentBar\tbuTor.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - D:\Program Files\ConduitEngine\ConduitEngine.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: QIPBHO - {95289393-33EA-4F8D-B952-483415B9C955} - D:\Documents and Settings\Jan\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - D:\Program Files\uTorrentBar\tbuTor.dll
O2 - BHO: LitmusBHO - {C6867EB7-8350-4856-877F-93CF8AE3DC9C} - D:\Program Files\F-Secure\NRS\iescript\baselitmus.dll
O2 - BHO: Search-Results Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - D:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Browsing Protection Toolbar - {265EEE8E-3228-44D3-AEA5-F7FDF5860049} - D:\Program Files\F-Secure\NRS\iescript\baselitmus.dll
O3 - Toolbar: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - D:\Program Files\uTorrentBar\tbuTor.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - D:\Program Files\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: Search-Results Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - D:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] D:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] D:\WINDOWS\system32\xRaidSetup.exe boot
O4 - HKLM\..\Run: [F-Secure Manager] "D:\Program Files\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "D:\Program Files\F-Secure\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [StartCCC] "D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] D:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [NBKeyScan] "D:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] D:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "D:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Start WingMan Profiler] "D:\Program Files\Logitech\Profiler\lwemon.exe" /noui
O4 - HKCU\..\Run: [QIP Internet Guardian] D:\Documents and Settings\Jan\Data aplikací\QipGuard\QipGuard.exe /p
O4 - HKCU\..\Run: [Core Temp] E:\ZALOHA1\ALOHA\O.C\Core Temp.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [uTorrent] "D:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "D:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Zástupce - speedfan.exe.lnk = E:\ZALOHA1\SpeedFan\speedfan.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{4FE42FBC-A8C6-4C80-AF62-CF7D532108D9}: NameServer = 212.71.150.16,82.209.19.226
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - Unknown owner - D:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
O23 - Service: Služba F-Secure Network Request Broker (F-Secure Network Request Broker) - F-Secure Corporation - D:\Program Files\F-Secure\Common\FNRB32.EXE
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - D:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - D:\Program Files\F-Secure\Common\FSMA32.EXE
O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - D:\Program Files\F-Secure\ORSP Client\fsorsp.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 10217 bytes

======Scheduled tasks folder======

D:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - D:\Program Files\ConduitEngine\ConduitEngine.dll [2010-12-09 3911776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - D:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]
QIPBHO Class - D:\Documents and Settings\Jan\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2011-02-01 141184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
uTorrentBar Toolbar - D:\Program Files\uTorrentBar\tbuTor.dll [2010-12-09 3911776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C6867EB7-8350-4856-877F-93CF8AE3DC9C}]
Browsing Protection Class - D:\Program Files\F-Secure\NRS\iescript\baselitmus.dll [2011-02-08 544440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Search-Results Toolbar - D:\Program Files\Ask.com\GenericAskToolbar.dll [2010-09-29 1435112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-02-03 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-02-03 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{265EEE8E-3228-44D3-AEA5-F7FDF5860049} - Browsing Protection Toolbar - D:\Program Files\F-Secure\NRS\iescript\baselitmus.dll [2011-02-08 544440]
{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - uTorrentBar Toolbar - D:\Program Files\uTorrentBar\tbuTor.dll [2010-12-09 3911776]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - D:\Program Files\ConduitEngine\ConduitEngine.dll [2010-12-09 3911776]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Search-Results Toolbar - D:\Program Files\Ask.com\GenericAskToolbar.dll [2010-09-29 1435112]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"=D:\WINDOWS\RaidTool\xInsIDE.exe [2007-03-20 36864]
"36X Raid Configurer"=D:\WINDOWS\system32\xRaidSetup.exe [2007-03-21 1953792]
"F-Secure Manager"=D:\Program Files\F-Secure\Common\FSM32.EXE [2010-03-26 301744]
"F-Secure TNB"=D:\Program Files\F-Secure\FSGUI\TNBUtil.exe [2010-03-26 1653424]
"GrooveMonitor"=D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"StartCCC"=D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-02-11 61440]
"WinampAgent"=D:\Program Files\Winamp\winampa.exe [2007-08-22 39424]
"SunJavaUpdateSched"=D:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-10-29 249064]
"PWRISOVM.EXE"=D:\Program Files\PowerISO\PWRISOVM.EXE [2010-04-12 180224]
"NBKeyScan"=D:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe []
"SoundMAXPnP"=D:\Program Files\Analog Devices\Core\smax4pnp.exe [2006-12-18 868352]
"SoundMAX"=D:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2006-07-13 729088]
"KernelFaultCheck"=D:\WINDOWS\system32\dumprep 0 -k []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=D:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Start WingMan Profiler"=D:\Program Files\Logitech\Profiler\lwemon.exe [2005-04-18 73728]
"QIP Internet Guardian"=D:\Documents and Settings\Jan\Data aplikací\QipGuard\QipGuard.exe [2011-02-01 187776]
"Core Temp"=E:\ZALOHA1\ALOHA\O.C\Core Temp.exe [2009-05-29 260624]
"H/PC Connection Agent"=D:\Program Files\Microsoft ActiveSync\Wcescomm.exe [2006-11-13 1289000]
"uTorrent"=D:\Program Files\uTorrent\uTorrent.exe [2011-02-20 396152]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=D:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe []

D:\Documents and Settings\Jan\Nabídka Start\Programy\Po spuštění
Zástupce - speedfan.exe.lnk - E:\ZALOHA1\SpeedFan\speedfan.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
D:\WINDOWS\system32\Ati2evxx.dll [2010-02-11 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
D:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=D:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\Codemasters\GRID\GRID.exe"="D:\Program Files\Codemasters\GRID\GRID.exe:*:Enabled:GRID"
"D:\Program Files\uTorrent\uTorrent.exe"="D:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"D:\Program Files\Microsoft ActiveSync\rapimgr.exe"="D:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"D:\Program Files\Microsoft ActiveSync\wcescomm.exe"="D:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"D:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="D:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"D:\Program Files\Codemasters\DiRT2\dirt2_game.exe"="D:\Program Files\Codemasters\DiRT2\dirt2_game.exe:*:Enabled:DiRT2"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\Microsoft ActiveSync\rapimgr.exe"="D:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"D:\Program Files\Microsoft ActiveSync\wcescomm.exe"="D:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"D:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="D:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger="

======List of files/folders created in the last 1 months======

2011-03-27 10:43:26 ----D---- D:\rsit
2011-03-27 10:43:26 ----D---- D:\Program Files\trend micro
2011-03-27 00:14:29 ----A---- D:\WINDOWS\ntbtlog.txt
2011-03-26 21:31:03 ----HD---- D:\WINDOWS\system32\GroupPolicy
2011-03-26 00:50:49 ----D---- D:\WINDOWS\system32\NtmsData
2011-03-26 00:36:09 ----RA---- D:\WINDOWS\system32\tmp181.tmp
2011-03-26 00:36:09 ----RA---- D:\WINDOWS\system32\tmp180.tmp
2011-03-26 00:26:00 ----D---- D:\WINDOWS\system32\xlive
2011-03-26 00:26:00 ----D---- D:\Program Files\Microsoft Games for Windows - LIVE
2011-03-26 00:25:18 ----RA---- D:\WINDOWS\system32\tmp10C.tmp
2011-03-26 00:25:18 ----RA---- D:\WINDOWS\system32\tmp10B.tmp
2011-03-25 20:40:06 ----D---- D:\Program Files\Free YouTube Downloader Converter
2011-03-24 23:32:26 ----D---- D:\Documents and Settings\All Users\Data aplikací\Electronic Arts
2011-03-24 22:21:20 ----D---- D:\Program Files\Ask.com
2011-03-24 22:21:11 ----D---- D:\Program Files\7-Zip
2011-03-24 21:28:19 ----A---- D:\WINDOWS\system32\XAudio2_6.dll
2011-03-24 21:28:19 ----A---- D:\WINDOWS\system32\XAPOFX1_4.dll
2011-03-24 21:28:18 ----A---- D:\WINDOWS\system32\xactengine3_6.dll
2011-03-24 21:28:17 ----A---- D:\WINDOWS\system32\X3DAudio1_7.dll
2011-03-24 21:28:16 ----A---- D:\WINDOWS\system32\XAudio2_5.dll
2011-03-24 21:28:15 ----A---- D:\WINDOWS\system32\xactengine3_5.dll
2011-03-24 21:28:14 ----A---- D:\WINDOWS\system32\D3DCompiler_42.dll
2011-03-24 21:28:13 ----A---- D:\WINDOWS\system32\d3dcsx_42.dll
2011-03-24 21:28:12 ----A---- D:\WINDOWS\system32\d3dx11_42.dll
2011-03-24 21:28:11 ----A---- D:\WINDOWS\system32\d3dx10_42.dll
2011-03-24 21:28:10 ----A---- D:\WINDOWS\system32\D3DX9_42.dll
2011-03-24 07:57:59 ----HDC---- D:\WINDOWS\$NtUninstallKB2524375$
2011-03-23 23:09:58 ----D---- D:\WINDOWS\system32\appmgmt
2011-03-23 17:55:37 ----A---- D:\WINDOWS\system32\mkl_vml_p4.dll
2011-03-23 17:55:36 ----A---- D:\WINDOWS\system32\mkl_vml_p3.dll
2011-03-23 17:55:36 ----A---- D:\WINDOWS\system32\mkl_vml_def.dll
2011-03-23 17:55:35 ----A---- D:\WINDOWS\system32\mkl_p4.dll
2011-03-23 17:55:34 ----A---- D:\WINDOWS\system32\mkl_p3.dll
2011-03-23 17:55:33 ----A---- D:\WINDOWS\system32\mkl_lapack64.dll
2011-03-23 17:55:31 ----A---- D:\WINDOWS\system32\mkl_lapack32.dll
2011-03-23 17:55:29 ----A---- D:\WINDOWS\system32\mkl_def.dll
2011-03-23 17:55:29 ----A---- D:\WINDOWS\system32\libguide40.dll
2011-03-23 17:55:28 ----A---- D:\WINDOWS\system32\rapture3d_oal.dll
2011-03-23 17:55:25 ----D---- D:\Program Files\BRS
2011-03-23 15:18:35 ----D---- D:\Program Files\Feneris
2011-03-23 12:59:07 ----D---- D:\Program Files\Micro DVD Player
2011-03-23 00:37:45 ----D---- D:\Program Files\Earth 3D Screensaver
2011-03-22 23:50:19 ----D---- D:\Program Files\3Planesoft Screensaver Manager
2011-03-22 23:50:19 ----D---- D:\Documents and Settings\All Users\Data aplikací\3Planesoft
2011-03-22 23:50:00 ----D---- D:\Program Files\The One Ring 3D Screensaver
2011-03-22 23:45:39 ----A---- D:\WINDOWS\LOTR_Orcs.exe
2011-03-22 23:42:14 ----A---- D:\WINDOWS\LOTR Dark Rider.exe
2011-03-22 23:40:11 ----A---- D:\WINDOWS\mickey32.dll
2011-03-22 23:40:11 ----A---- D:\WINDOWS\LOTR Eye of Sauron.exe
2011-03-22 19:08:00 ----D---- D:\Program Files\Microsoft Games
2011-03-22 15:49:37 ----HD---- D:\WINDOWS\PIF
2011-03-22 10:28:15 ----A---- D:\WINDOWS\Q3version.ini
2011-03-22 10:28:08 ----D---- D:\Program Files\Quake III Arena
2011-03-22 10:27:09 ----D---- D:\Quake III Arena
2011-03-20 20:10:51 ----RA---- D:\WINDOWS\system32\drivers\senfilt.sys
2011-03-20 20:10:51 ----RA---- D:\WINDOWS\system32\drivers\aeaudio.sys
2011-03-20 20:10:50 ----RA---- D:\WINDOWS\system32\drivers\ADIHdAud.sys
2011-03-20 20:10:37 ----N---- D:\WINDOWS\system32\wdmioctl.dll
2011-03-20 20:10:36 ----N---- D:\WINDOWS\system32\SMMedia.dll
2011-03-20 20:10:32 ----N---- D:\WINDOWS\system32\DSndUp.exe
2011-03-20 20:10:32 ----D---- D:\Program Files\Analog Devices
2011-03-20 20:10:31 ----N---- D:\WINDOWS\system32\CleanUp.exe
2011-03-20 20:10:01 ----A---- D:\WINDOWS\Ascd_tmp.ini
2011-03-20 19:52:41 ----D---- D:\swsetup
2011-03-20 19:38:17 ----D---- D:\Documents and Settings\All Users\Data aplikací\PC Drivers HeadQuarters
2011-03-20 19:05:59 ----A---- D:\WINDOWS\AS_Debug.txt
2011-03-20 18:18:16 ----D---- D:\Documents and Settings\Jan\Data aplikací\InstallShield
2011-03-20 10:48:44 ----D---- D:\Program Files\Ubisoft
2011-03-20 09:35:41 ----A---- D:\WINDOWS\Qiii.INI
2011-03-20 09:30:39 ----A---- D:\WINDOWS\NeroDigital.ini
2011-03-20 08:54:46 ----D---- D:\Program Files\MSXML 4.0
2011-03-19 19:53:26 ----A---- D:\WINDOWS\system32\MsiExec.exe.log
2011-03-19 19:47:35 ----D---- D:\Documents and Settings\Jan\Data aplikací\U3
2011-03-19 19:08:43 ----D---- D:\Documents and Settings\Jan\Data aplikací\F-Secure
2011-03-16 20:28:21 ----D---- D:\Program Files\18 Wheels of Steel Haulin
2011-03-16 16:17:46 ----HDC---- D:\WINDOWS\$NtUninstallKB971029$
2011-03-13 14:52:44 ----A---- D:\WINDOWS\treeskp.sys
2011-03-12 14:16:01 ----A---- D:\WINDOWS\IE4 Error Log.txt
2011-03-09 21:05:05 ----HDC---- D:\WINDOWS\$NtUninstallKB2479943$
2011-03-09 21:03:50 ----HDC---- D:\WINDOWS\$NtUninstallKB2481109$
2011-03-09 16:17:19 ----D---- D:\Documents and Settings\All Users\Data aplikací\ACD Systems
2011-03-09 16:17:13 ----D---- D:\Program Files\Common Files\ACD Systems
2011-03-09 16:17:13 ----D---- D:\Program Files\ACD Systems
2011-03-06 14:21:45 ----A---- D:\WINDOWS\doom3.ini
2011-03-06 14:20:52 ----D---- D:\Program Files\Doom 3
2011-03-06 10:09:02 ----A---- D:\WINDOWS\system32\D3DX9_41.dll
2011-03-06 10:09:02 ----A---- D:\WINDOWS\system32\d3dx10_41.dll
2011-03-06 10:09:02 ----A---- D:\WINDOWS\system32\D3DCompiler_41.dll
2011-03-06 10:09:01 ----A---- D:\WINDOWS\system32\XAudio2_4.dll
2011-03-06 10:09:01 ----A---- D:\WINDOWS\system32\XAPOFX1_3.dll
2011-03-06 10:09:01 ----A---- D:\WINDOWS\system32\xactengine3_4.dll
2011-03-06 10:09:01 ----A---- D:\WINDOWS\system32\X3DAudio1_6.dll
2011-03-06 10:09:00 ----A---- D:\WINDOWS\system32\d3dx10_40.dll
2011-03-06 10:09:00 ----A---- D:\WINDOWS\system32\D3DCompiler_40.dll
2011-03-06 10:08:59 ----A---- D:\WINDOWS\system32\XAudio2_3.dll
2011-03-06 10:08:59 ----A---- D:\WINDOWS\system32\XAPOFX1_2.dll
2011-03-06 10:08:58 ----A---- D:\WINDOWS\system32\xactengine3_3.dll
2011-03-06 10:08:58 ----A---- D:\WINDOWS\system32\X3DAudio1_5.dll
2011-03-06 10:08:57 ----A---- D:\WINDOWS\system32\XAudio2_2.dll
2011-03-06 10:08:57 ----A---- D:\WINDOWS\system32\XAPOFX1_1.dll
2011-03-06 10:08:57 ----A---- D:\WINDOWS\system32\xactengine3_2.dll
2011-03-06 10:08:56 ----A---- D:\WINDOWS\system32\d3dx10_39.dll
2011-03-06 10:08:56 ----A---- D:\WINDOWS\system32\D3DCompiler_39.dll
2011-03-06 10:08:55 ----A---- D:\WINDOWS\system32\XAudio2_1.dll
2011-03-06 10:08:55 ----A---- D:\WINDOWS\system32\XAPOFX1_0.dll
2011-03-06 10:08:55 ----A---- D:\WINDOWS\system32\D3DX9_39.dll
2011-03-06 10:08:54 ----A---- D:\WINDOWS\system32\xactengine3_1.dll
2011-03-06 10:08:54 ----A---- D:\WINDOWS\system32\X3DAudio1_4.dll
2011-03-06 10:08:53 ----A---- D:\WINDOWS\system32\D3DX9_38.dll
2011-03-06 10:08:53 ----A---- D:\WINDOWS\system32\d3dx10_38.dll
2011-03-06 10:08:53 ----A---- D:\WINDOWS\system32\D3DCompiler_38.dll
2011-03-06 09:33:24 ----D---- D:\WINDOWS\ASTULogTemp
2011-03-05 18:25:05 ----D---- D:\Program Files\City Interactive
2011-03-02 19:20:40 ----D---- D:\Program Files\EA GAMES
2011-03-02 19:17:07 ----D---- D:\Program Files\Common Files\DirectX
2011-03-02 14:54:13 ----D---- D:\Program Files\Microsoft ActiveSync
2011-03-02 14:03:57 ----D---- D:\WINDOWS\Minidump

======List of files/folders modified in the last 1 months======

2011-03-27 10:43:26 ----RD---- D:\Program Files
2011-03-27 10:43:20 ----D---- D:\Documents and Settings\Jan\Data aplikací\uTorrent
2011-03-27 10:40:09 ----D---- D:\Program Files\QIP 2010
2011-03-27 10:39:14 ----D---- D:\WINDOWS\system32\CatRoot2
2011-03-27 10:39:05 ----D---- D:\WINDOWS\Temp
2011-03-27 10:27:42 ----D---- D:\WINDOWS\Prefetch
2011-03-27 10:26:18 ----D---- D:\WINDOWS
2011-03-27 00:28:17 ----A---- D:\WINDOWS\SchedLgU.Txt
2011-03-26 21:54:48 ----SD---- D:\Documents and Settings\Jan\Data aplikací\Microsoft
2011-03-26 21:31:03 ----D---- D:\WINDOWS\system32
2011-03-26 21:28:56 ----D---- D:\WINDOWS\system32\drivers
2011-03-26 01:13:41 ----D---- D:\Documents and Settings\All Users\Data aplikací\Codemasters
2011-03-26 00:37:12 ----SHD---- D:\WINDOWS\Installer
2011-03-26 00:36:09 ----A---- D:\WINDOWS\system32\wrap_oal.dll
2011-03-26 00:36:09 ----A---- D:\WINDOWS\system32\OpenAL32.dll
2011-03-26 00:36:07 ----HD---- D:\WINDOWS\inf
2011-03-26 00:35:54 ----RSD---- D:\WINDOWS\assembly
2011-03-26 00:35:34 ----D---- D:\WINDOWS\system32\DirectX
2011-03-26 00:26:00 ----SD---- D:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-03-25 23:51:17 ----HD---- D:\Program Files\InstallShield Installation Information
2011-03-25 23:51:17 ----D---- D:\Program Files\Codemasters
2011-03-24 22:57:49 ----D---- D:\Program Files\Electronic Arts
2011-03-24 22:21:27 ----SD---- D:\WINDOWS\Tasks
2011-03-24 12:55:25 ----D---- D:\Program Files\Mozilla Firefox
2011-03-24 09:07:25 ----D---- D:\Program Files\rFactor
2011-03-24 07:57:56 ----HD---- D:\WINDOWS\$hf_mig$
2011-03-24 07:57:49 ----D---- D:\WINDOWS\system32\CatRoot
2011-03-23 23:11:29 ----D---- D:\Program Files\Nero
2011-03-23 23:11:22 ----D---- D:\Program Files\Common Files
2011-03-23 23:09:29 ----D---- D:\Documents and Settings\All Users\Data aplikací\Nero
2011-03-23 10:23:55 ----D---- D:\WINDOWS\system32\wbem
2011-03-23 10:23:52 ----A---- D:\WINDOWS\system32\PerfStringBackup.INI
2011-03-22 23:46:26 ----A---- D:\WINDOWS\system.ini
2011-03-22 21:21:07 ----D---- D:\Documents and Settings\Jan\Data aplikací\PriceGong
2011-03-22 19:35:20 ----D---- D:\WINDOWS\WinSxS
2011-03-22 19:18:08 ----RSD---- D:\WINDOWS\Fonts
2011-03-20 20:11:02 ----RSHDC---- D:\WINDOWS\system32\dllcache
2011-03-20 20:10:56 ----D---- D:\WINDOWS\system
2011-03-20 19:35:36 ----D---- D:\WINDOWS\system32\config
2011-03-19 19:53:48 ----D---- D:\Documents and Settings\Jan\Data aplikací\Nero
2011-03-19 19:52:01 ----D---- D:\WINDOWS\Cursors
2011-03-16 16:17:55 ----A---- D:\WINDOWS\imsins.BAK
2011-03-13 15:22:13 ----D---- D:\Program Files\SpeedFan
2011-03-09 21:04:05 ----D---- D:\WINDOWS\Debug
2011-03-09 21:04:02 ----A---- D:\WINDOWS\system32\MRT.exe
2011-03-09 21:03:27 ----A---- D:\WINDOWS\RTacDbg.txt
2011-03-05 15:40:35 ----D---- D:\Documents and Settings\Jan\Data aplikací\Dream Aquarium
2011-03-02 14:54:16 ----D---- D:\WINDOWS\Help
2011-03-02 14:54:15 ----D---- D:\Program Files\Common Files\Microsoft Shared

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 fsbts;fsbts; D:\WINDOWS\system32\Drivers\fsbts.sys [2011-02-08 42664]
R0 FSFW;F-Secure Firewall Driver; D:\WINDOWS\System32\drivers\fsdfw.sys [2010-03-26 80080]
R0 giveio;giveio; D:\WINDOWS\system32\giveio.sys [1996-04-03 5248]
R0 JGOGO;JMicron Hot-Plug Driver; D:\WINDOWS\system32\DRIVERS\JGOGO.sys [2006-02-07 6912]
R0 JRAID;JRAID; D:\WINDOWS\system32\DRIVERS\jraid.sys [2007-03-24 46208]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI; D:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 PxHelp20;PxHelp20; D:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R0 speedfan;speedfan; D:\WINDOWS\system32\speedfan.sys [2006-09-24 5248]
R1 F-Secure HIPS;F-Secure HIPS Driver; \??\D:\Program Files\F-Secure\HIPS\drivers\fshs.sys []
R1 intelppm;Řadič procesoru Intel; D:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\D:\Program Files\UltraISO\drivers\ISODrive.sys []
R1 kbdhid;Ovladač klávesnice standardu HID; D:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 SCDEmu;SCDEmu; D:\WINDOWS\system32\drivers\SCDEmu.sys [2010-04-12 59388]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.5.0; D:\WINDOWS\system32\DRIVERS\AegisP.sys [2011-02-08 21035]
R2 cpuz135;cpuz135; \??\D:\WINDOWS\system32\drivers\cpuz135_x32.sys []
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; D:\WINDOWS\system32\drivers\ADIHdAud.sys [2007-01-16 293888]
R3 AEAudio;AE Audio Service; D:\WINDOWS\system32\drivers\AEAudio.sys [2006-08-07 93952]
R3 ALSysIO;ALSysIO; \??\D:\DOCUME~1\Jan\LOCALS~1\Temp\ALSysIO.sys []
R3 Arp1394;Protokol 1394 ARP Client; D:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ati2mtag;ati2mtag; D:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2010-02-11 3565056]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper; \??\D:\Program Files\F-Secure\Anti-Virus\minifilter\fsgk.sys []
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; D:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; D:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; D:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; D:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NIC1394;1394 Net Driver; D:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter; D:\WINDOWS\system32\DRIVERS\RTL8187.sys [2006-06-16 176128]
R3 SenFiltService;SenFilt Service; D:\WINDOWS\system32\drivers\Senfilt.sys [2006-03-17 392960]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; D:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; D:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; D:\WINDOWS\system32\drivers\WmBEnum.sys [2005-04-12 10144]
R3 WmFilter;Logitech Gaming HID Filter Driver; D:\WINDOWS\system32\drivers\WmFilter.sys [2005-04-12 22240]
R3 WmHidLo;Logitech Gaming USB Filter Driver; D:\WINDOWS\system32\drivers\WmHidLo.sys [2005-04-12 17632]
R3 WmVirHid;Logitech Virtual Hid Device Driver; D:\WINDOWS\system32\drivers\WmVirHid.sys [2005-04-12 5600]
R3 WmXlCore;Logitech WingMan Translation Layer Driver; D:\WINDOWS\system32\drivers\WmXlCore.sys [2005-04-12 45504]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; D:\WINDOWS\system32\DRIVERS\yk51x86.sys [2007-08-15 265856]
S3 usb_rndisx;Adaptér USB RNDIS; D:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S4 F-Secure Filter;F-Secure File System Filter; \??\D:\Program Files\F-Secure\Anti-Virus\Win2K\FSfilter.sys []
S4 F-Secure Recognizer;F-Secure File System Recognizer; \??\D:\Program Files\F-Secure\Anti-Virus\Win2K\FSrec.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; D:\WINDOWS\system32\Ati2evxx.exe [2010-02-11 602112]
R2 F-Secure Gatekeeper Handler Starter;FSGKHS; D:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe [2010-03-26 219824]
R2 FSMA;F-Secure Management Agent; D:\Program Files\F-Secure\Common\FSMA32.EXE [2010-03-26 187056]
R2 JavaQuickStarterService;Java Quick Starter; D:\Program Files\Java\jre6\bin\jqs.exe [2011-02-02 153376]
R2 MDM;Machine Debug Manager; D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 UMWdf;Windows User Mode Driver Framework; D:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R3 FSDFWD;F-Secure Anti-Virus Firewall Daemon; D:\Program Files\F-Secure\FWES\Program\fsdfwd.exe [2010-03-26 522928]
R3 F-Secure Network Request Broker;Služba F-Secure Network Request Broker; D:\Program Files\F-Secure\Common\FNRB32.EXE [2010-03-26 166576]
R3 FSORSPClient;F-Secure ORSP Client; D:\Program Files\F-Secure\ORSP Client\fsorsp.exe [2011-02-08 63992]
S2 ATI Smart;ATI Smart; D:\WINDOWS\system32\ati2sgag.exe [2010-02-10 593920]
S3 aspnet_state;ASP.NET State Service; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; d:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; d:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; D:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; D:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; d:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------
ASUS ROG Strix G10DK 27L Gray = ASUS PRIME B550M-K, AMD Ryzen7 5800X undervolted, GeForce RTX 3060, 2x Kingston FURY 32GB DDR4 3200MHz CL16 + ASUS ROG STRIX LC II 120 ARGB

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119506
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o kontrolu logu

#2 Příspěvek od Rudy »

Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware
Vídím tam nějaký spyware, který by však neměl být příčinou restartů. Přehřívání zjistíte, pokud si nainstalujete Speedfan: http://www.stahuj.centrum.cz/utility_a_ ... /speedfan/ a budete sledovat teploty komponent. Neměly by trvale překračovat 65°C.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

00Inferno00
1. Stupeň Varování
Příspěvky: 55
Registrován: 25 říj 2007 18:38
Bydliště: Dolní BenešoVW
Kontaktovat uživatele:

Re: Prosim o kontrolu logu

#3 Příspěvek od 00Inferno00 »

Na monitoring teploty CPU pouzivam Core Temp :wink:
ASUS ROG Strix G10DK 27L Gray = ASUS PRIME B550M-K, AMD Ryzen7 5800X undervolted, GeForce RTX 3060, 2x Kingston FURY 32GB DDR4 3200MHz CL16 + ASUS ROG STRIX LC II 120 ARGB

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119506
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o kontrolu logu

#4 Příspěvek od Rudy »

OK. Takže víte, zda se vám přehřívá, či nikoli. Pokud se opravdu přehřívá, máte 2 možnosti:

1. vrátit takt na defaultní hodnotu.
2. Přidat do skříně další (odsávací) ventilátor.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

00Inferno00
1. Stupeň Varování
Příspěvky: 55
Registrován: 25 říj 2007 18:38
Bydliště: Dolní BenešoVW
Kontaktovat uživatele:

Re: Prosim o kontrolu logu

#5 Příspěvek od 00Inferno00 »

Ventilatoru je ve skrini imho dost (i ten odsavaci), hodnotu taktu sem snizil, tak uvidim. Diky :worship:
ASUS ROG Strix G10DK 27L Gray = ASUS PRIME B550M-K, AMD Ryzen7 5800X undervolted, GeForce RTX 3060, 2x Kingston FURY 32GB DDR4 3200MHz CL16 + ASUS ROG STRIX LC II 120 ARGB

00Inferno00
1. Stupeň Varování
Příspěvky: 55
Registrován: 25 říj 2007 18:38
Bydliště: Dolní BenešoVW
Kontaktovat uživatele:

Re: Prosim o kontrolu logu

#6 Příspěvek od 00Inferno00 »

Log ComboFix

ComboFix 11-03-26.01 - Jan 27.03.2011 12:32:49.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3327.2887 [GMT 2:00]
Spuštěný z: d:\documents and settings\Jan\Plocha\ComboFix.exe
AV: F-Secure Client Security 9.01 *Enabled/Updated* {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: F-Secure Client Security 9.01 *Enabled* {D4747503-0346-49EB-9262-997542F79BF4}
.
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
d:\documents and settings\All Users\ntuser.pol
d:\documents and settings\Jan\Data aplikací\ACD Systems\ACDSee\ImageDB.ddf
d:\documents and settings\Jan\Data aplikací\PriceGong
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\1.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\a.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\b.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\c.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\d.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\e.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\f.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\g.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\h.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\i.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\J.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\k.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\l.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\m.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\mru.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\n.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\o.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\p.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\q.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\r.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\s.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\t.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\u.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\v.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\w.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\x.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\y.xml
d:\documents and settings\Jan\Data aplikací\PriceGong\Data\z.xml
d:\program files\FunWebProducts
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-02-27 do 2011-03-27 )))))))))))))))))))))))))))))))
.
.
2011-03-27 08:43 . 2011-03-27 08:43 -------- d-----w- D:\rsit
2011-03-27 08:43 . 2011-03-27 08:43 -------- d-----w- d:\program files\trend micro
2011-03-26 19:31 . 2011-03-26 19:31 -------- d--h--w- d:\windows\system32\GroupPolicy
2011-03-25 22:50 . 2011-03-25 23:02 -------- d-----w- d:\windows\system32\NtmsData
2011-03-25 22:36 . 2009-10-15 11:44 809560 ----a-r- d:\windows\system32\tmp181.tmp
2011-03-25 22:36 . 2009-10-15 11:44 809560 ----a-r- d:\windows\system32\tmp180.tmp
2011-03-25 22:26 . 2011-03-25 22:26 -------- d-----w- d:\program files\Microsoft Games for Windows - LIVE
2011-03-25 22:26 . 2011-03-25 22:26 -------- d-----w- d:\windows\system32\xlive
2011-03-25 22:25 . 2009-10-15 11:44 809560 ----a-r- d:\windows\system32\tmp10C.tmp
2011-03-25 22:25 . 2009-10-15 11:44 809560 ----a-r- d:\windows\system32\tmp10B.tmp
2011-03-25 18:40 . 2011-03-25 18:40 -------- d-----w- d:\program files\Free YouTube Downloader Converter
2011-03-24 21:32 . 2011-03-24 21:32 -------- d-----w- d:\documents and settings\All Users\Data aplikací\Electronic Arts
2011-03-24 20:21 . 2011-03-24 20:21 -------- d-----w- d:\program files\Ask.com
2011-03-24 20:21 . 2011-03-24 20:21 -------- d-----w- d:\program files\7-Zip
2011-03-24 19:28 . 2010-02-04 09:01 74072 ----a-w- d:\windows\system32\XAPOFX1_4.dll
2011-03-24 19:28 . 2010-02-04 09:01 528216 ----a-w- d:\windows\system32\XAudio2_6.dll
2011-03-24 19:28 . 2010-02-04 09:01 238936 ----a-w- d:\windows\system32\xactengine3_6.dll
2011-03-24 19:28 . 2010-02-04 09:01 22360 ----a-w- d:\windows\system32\X3DAudio1_7.dll
2011-03-24 19:28 . 2009-09-04 16:44 515416 ----a-w- d:\windows\system32\XAudio2_5.dll
2011-03-24 19:28 . 2009-09-04 16:44 238936 ----a-w- d:\windows\system32\xactengine3_5.dll
2011-03-24 19:28 . 2009-09-04 16:29 1974616 ----a-w- d:\windows\system32\D3DCompiler_42.dll
2011-03-24 19:28 . 2009-09-04 16:29 5501792 ----a-w- d:\windows\system32\d3dcsx_42.dll
2011-03-24 19:28 . 2009-09-04 16:29 235344 ----a-w- d:\windows\system32\d3dx11_42.dll
2011-03-24 19:28 . 2009-09-04 16:29 453456 ----a-w- d:\windows\system32\d3dx10_42.dll
2011-03-24 19:28 . 2009-09-04 16:29 1892184 ----a-w- d:\windows\system32\D3DX9_42.dll
2011-03-23 15:55 . 2009-07-13 18:04 839680 ----a-w- d:\windows\system32\mkl_vml_p4.dll
2011-03-23 15:55 . 2009-07-13 18:04 532480 ----a-w- d:\windows\system32\mkl_vml_p3.dll
2011-03-23 15:55 . 2009-07-13 18:04 512000 ----a-w- d:\windows\system32\mkl_vml_def.dll
2011-03-23 15:55 . 2009-07-13 18:04 3485696 ----a-w- d:\windows\system32\mkl_p4.dll
2011-03-23 15:55 . 2009-07-13 18:04 2793472 ----a-w- d:\windows\system32\mkl_p3.dll
2011-03-23 15:55 . 2009-07-13 18:04 2125824 ----a-w- d:\windows\system32\mkl_lapack64.dll
2011-03-23 15:55 . 2009-07-13 18:04 2174976 ----a-w- d:\windows\system32\mkl_lapack32.dll
2011-03-23 15:55 . 2009-07-13 18:04 2441216 ----a-w- d:\windows\system32\mkl_def.dll
2011-03-23 15:55 . 2009-07-13 18:04 184320 ----a-w- d:\windows\system32\libguide40.dll
2011-03-23 15:55 . 2009-10-16 10:19 872448 ----a-w- d:\windows\system32\rapture3d_oal.dll
2011-03-23 15:55 . 2011-03-25 22:36 -------- d-----w- d:\program files\BRS
2011-03-23 13:18 . 2011-03-23 13:18 -------- d-----w- d:\program files\Feneris
2011-03-23 10:59 . 2011-03-23 10:59 -------- d-----w- d:\program files\Micro DVD Player
2011-03-22 22:37 . 2010-12-08 14:19 850944 ----a-w- d:\windows\system32\Earth_3D_Screensaver.scr
2011-03-22 22:37 . 2011-03-22 22:37 -------- d-----w- d:\program files\Earth 3D Screensaver
2011-03-22 21:50 . 2011-01-17 18:16 688640 ----a-w- d:\windows\system32\3Planesoft_Screensaver_Manager.scr
2011-03-22 21:50 . 2011-03-22 22:38 -------- d-----w- d:\program files\3Planesoft Screensaver Manager
2011-03-22 21:50 . 2011-03-22 22:38 -------- d-----w- d:\documents and settings\All Users\Data aplikací\3Planesoft
2011-03-22 21:50 . 2010-06-02 13:05 462848 ----a-w- d:\windows\system32\The_One_Ring_3D_Screensaver.scr
2011-03-22 21:50 . 2011-03-22 21:50 -------- d-----w- d:\program files\The One Ring 3D Screensaver
2011-03-22 21:45 . 2011-03-22 21:45 851999 ----a-w- d:\windows\LOTR_Orcs.exe
2011-03-22 21:45 . 2011-03-22 21:45 386848 ----a-w- d:\windows\LOTR_Orcs.scr
2011-03-22 21:42 . 2011-03-22 21:42 649069 ----a-w- d:\windows\LOTR Dark Rider.exe
2011-03-22 21:42 . 2011-03-22 21:42 273304 ----a-w- d:\windows\LOTR Dark Rider.scr
2011-03-22 21:40 . 2011-03-22 21:45 30208 ----a-w- d:\windows\mickey32.dll
2011-03-22 21:40 . 2011-03-22 21:40 514266 ----a-w- d:\windows\LOTR Eye of Sauron.exe
2011-03-22 21:40 . 2011-03-22 21:40 273304 ----a-w- d:\windows\LOTR Eye of Sauron.scr
2011-03-22 17:08 . 2011-03-22 17:08 -------- d-----w- d:\program files\Microsoft Games
2011-03-22 13:49 . 2011-03-22 13:49 -------- d--h--w- d:\windows\PIF
2011-03-22 08:28 . 2011-03-22 08:29 -------- d-----w- d:\program files\Quake III Arena
2011-03-22 08:27 . 2011-03-22 08:27 -------- d-----w- D:\Quake III Arena
2011-03-20 18:10 . 2001-09-19 04:47 765952 ----a-r- d:\windows\system\crlds3d.dll
2011-03-20 18:10 . 2006-08-06 22:57 93952 ----a-r- d:\windows\system32\drivers\aeaudio.sys
2011-03-20 18:10 . 2006-03-17 09:18 392960 ----a-r- d:\windows\system32\drivers\senfilt.sys
2011-03-20 18:10 . 2007-01-16 01:09 293888 ----a-r- d:\windows\system32\drivers\ADIHdAud.sys
2011-03-20 18:10 . 2005-05-04 07:20 53248 ------w- d:\windows\system32\wdmioctl.dll
2011-03-20 18:10 . 2001-09-11 13:20 1285632 ------w- d:\windows\system32\SMMedia.dll
2011-03-20 18:10 . 2011-03-20 18:10 -------- d-----w- d:\program files\Analog Devices
2011-03-20 18:10 . 2006-07-10 13:42 49152 ------w- d:\windows\system32\DSndUp.exe
2011-03-20 18:10 . 2002-04-17 13:05 45056 ------w- d:\windows\system32\CleanUp.exe
2011-03-20 17:52 . 2011-03-20 17:52 -------- d-----w- D:\swsetup
2011-03-20 17:38 . 2011-03-20 17:38 -------- d-----w- d:\documents and settings\All Users\Data aplikací\PC Drivers HeadQuarters
2011-03-20 16:18 . 2011-03-20 16:18 -------- d-----w- d:\documents and settings\Jan\Data aplikací\InstallShield
2011-03-20 08:48 . 2011-03-20 08:48 -------- d-----w- d:\program files\Ubisoft
2011-03-20 06:54 . 2011-03-20 06:54 -------- d-----w- d:\program files\MSXML 4.0
2011-03-19 17:55 . 2011-03-19 17:56 -------- d-----w- d:\documents and settings\Jan\Local Settings\Data aplikací\Ahead
2011-03-19 17:55 . 2011-03-19 17:55 -------- d-----w- d:\documents and settings\Jan\Local Settings\Data aplikací\Nero
2011-03-19 17:47 . 2011-03-25 18:41 -------- d-----w- d:\documents and settings\Jan\Data aplikací\U3
2011-03-19 17:08 . 2011-03-19 17:08 -------- d-----w- d:\documents and settings\Jan\Data aplikací\F-Secure
2011-03-16 18:28 . 2011-03-16 18:28 -------- d-----w- d:\program files\18 Wheels of Steel Haulin
2011-03-13 12:52 . 2011-03-13 12:52 7 ----a-w- d:\windows\treeskp.sys
2011-03-13 12:52 . 2011-03-13 12:52 7 ----a-w- d:\windows\sbacknt.bin
2011-03-12 13:46 . 2004-07-15 23:19 266240 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iscript.dll
2011-03-12 13:46 . 2004-07-15 23:18 172032 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iuser.dll
2011-03-12 13:46 . 2004-07-15 23:20 733184 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iKernel.dll
2011-03-12 13:46 . 2004-07-15 23:20 69715 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\ctor.dll
2011-03-12 13:46 . 2004-07-15 23:18 5632 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\DotNetInstaller.exe
2011-03-12 13:46 . 2011-03-12 13:46 180356 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iGdi.dll
2011-03-12 13:46 . 2011-03-12 13:46 303236 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\setup.dll
2011-03-09 14:17 . 2011-03-09 14:18 -------- d-----w- d:\documents and settings\Jan\Local Settings\Data aplikací\ACD Systems
2011-03-09 14:17 . 2011-03-09 14:17 -------- d-----w- d:\documents and settings\All Users\Data aplikací\ACD Systems
2011-03-09 14:17 . 2011-03-09 14:17 -------- d-----w- d:\program files\Common Files\ACD Systems
2011-03-09 14:17 . 2011-03-09 14:17 -------- d-----w- d:\program files\ACD Systems
2011-03-06 12:20 . 2011-03-06 12:21 -------- d-----w- d:\program files\Doom 3
2011-03-06 08:09 . 2009-03-09 14:27 453456 ----a-w- d:\windows\system32\d3dx10_41.dll
2011-03-06 08:09 . 2009-03-09 14:27 4178264 ----a-w- d:\windows\system32\D3DX9_41.dll
2011-03-06 08:09 . 2009-03-09 14:27 1846632 ----a-w- d:\windows\system32\D3DCompiler_41.dll
2011-03-06 08:09 . 2009-09-04 16:44 69464 ----a-w- d:\windows\system32\XAPOFX1_3.dll
2011-03-06 08:09 . 2009-03-16 13:18 517448 ----a-w- d:\windows\system32\XAudio2_4.dll
2011-03-06 08:09 . 2009-03-16 13:18 235352 ----a-w- d:\windows\system32\xactengine3_4.dll
2011-03-06 08:09 . 2009-03-16 13:18 22360 ----a-w- d:\windows\system32\X3DAudio1_6.dll
2011-03-06 08:09 . 2008-10-15 05:22 452440 ----a-w- d:\windows\system32\d3dx10_40.dll
2011-03-06 08:09 . 2008-10-15 05:22 2036576 ----a-w- d:\windows\system32\D3DCompiler_40.dll
2011-03-06 07:33 . 2011-03-06 07:33 -------- d-----w- d:\windows\ASTULogTemp
2011-03-05 16:25 . 2011-03-05 16:25 -------- d-----w- d:\program files\City Interactive
2011-03-02 17:25 . 2011-03-06 11:43 -------- d-----w- d:\documents and settings\Jan\Local Settings\Data aplikací\NFS Underground 2
2011-03-02 17:20 . 2011-03-02 17:20 -------- d-----w- d:\program files\EA GAMES
2011-03-02 17:17 . 2011-03-02 17:17 -------- d-----w- d:\program files\Common Files\DirectX
2011-03-02 12:54 . 2011-03-20 17:25 -------- d-----w- d:\program files\Microsoft ActiveSync
2011-02-27 18:27 . 2011-03-19 17:53 -------- d-----w- d:\documents and settings\Jan\Data aplikací\Nero
2011-02-27 18:22 . 2011-03-23 21:11 -------- d-----w- d:\program files\Nero
2011-02-27 18:22 . 2011-03-23 21:09 -------- d-----w- d:\documents and settings\All Users\Data aplikací\Nero
2011-02-27 18:15 . 2008-10-15 05:22 4379984 ----a-w- d:\windows\system32\D3DX9_40.dll
2011-02-27 18:15 . 2011-02-27 18:15 -------- d-----w- d:\windows\Logs
2011-02-27 16:21 . 2011-02-27 16:21 -------- d-----w- d:\documents and settings\Jan\Data aplikací\ACD Systems
2011-02-27 16:20 . 2011-02-27 16:20 -------- d-----w- d:\program files\IL-2 Sturmovik 1946
2011-02-27 14:15 . 2001-02-28 10:16 335872 ----a-w- d:\windows\system32\ldf252.dll
2011-02-27 14:15 . 2001-02-28 10:16 126976 ----a-w- d:\windows\system32\lwf214p.dll
2011-02-27 14:15 . 2001-02-28 10:16 144896 ----a-w- d:\windows\system32\Jgdw500.dll
2011-02-27 14:15 . 2001-02-28 10:16 11264 ----a-w- d:\windows\system32\Jgid500.dll
2011-02-27 14:15 . 2001-02-28 10:16 11264 ----a-w- d:\windows\system32\Jgar500.dll
2011-02-27 14:15 . 2001-02-28 10:16 317952 ----a-w- d:\windows\system32\Roboex32.dll
2011-02-27 14:15 . 2001-02-28 10:16 7168 ----a-w- d:\windows\system32\Jgme500.dll
2011-02-27 14:15 . 2001-02-28 10:16 15872 ----a-w- d:\windows\system32\Jgpl500.dll
2011-02-27 14:15 . 2001-02-28 10:16 13312 ----a-w- d:\windows\system32\Jgst500.dll
2011-02-26 14:43 . 2011-02-26 14:43 -------- d-----w- d:\documents and settings\Jan\Local Settings\Data aplikací\Western Digital
2011-02-26 13:30 . 2011-02-26 13:30 -------- d-----w- d:\program files\EACom
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-26 19:28 . 2004-08-03 21:14 361600 ----a-w- d:\windows\system32\drivers\tcpip.sys
2011-03-25 22:36 . 2011-02-20 07:37 445016 ----a-w- d:\windows\system32\wrap_oal.dll
2011-03-25 22:36 . 2011-02-20 07:37 109144 ----a-w- d:\windows\system32\OpenAL32.dll
2011-02-19 12:18 . 2011-02-19 12:18 98304 ----a-w- d:\windows\system32CmdLineExt.dll
2011-02-09 13:53 . 2004-08-17 13:49 270848 ----a-w- d:\windows\system32\sbe.dll
2011-02-09 13:53 . 2004-08-17 13:49 186880 ----a-w- d:\windows\system32\encdec.dll
2011-02-08 18:21 . 2011-02-08 18:03 42664 ----a-w- d:\windows\system32\drivers\fsbts.sys
2011-02-08 17:45 . 2011-02-08 17:45 21035 ----a-w- d:\windows\system32\drivers\AegisP.sys
2011-02-02 20:40 . 2011-02-17 15:13 472808 ----a-w- d:\windows\system32\deployJava1.dll
2011-02-02 18:19 . 2011-02-17 15:13 73728 ----a-w- d:\windows\system32\javacpl.cpl
2011-02-02 07:58 . 2011-02-08 16:20 2067456 ----a-w- d:\windows\system32\mstscax.dll
2011-02-01 09:24 . 2011-02-13 09:22 141184 ----a-w- d:\documents and settings\Jan\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
2011-01-27 11:57 . 2011-02-08 16:20 677888 ----a-w- d:\windows\system32\mstsc.exe
2011-01-24 12:29 . 2011-02-13 11:26 1284712 ----a-w- d:\windows\RtlExUpd.dll
2011-01-21 14:44 . 2004-08-17 13:49 440320 ----a-w- d:\windows\system32\shimgvw.dll
2011-01-19 16:47 . 2011-02-19 18:32 22504 ----a-w- d:\windows\system32\drivers\cpuz135_x32.sys
2011-01-07 14:09 . 2004-08-17 13:48 290048 ----a-w- d:\windows\system32\atmfd.dll
2010-12-31 14:04 . 2004-08-17 13:44 1854976 ----a-w- d:\windows\system32\win32k.sys
.
.
------- Sigcheck -------
.
[-] 2011-03-26 . CBEEBEB899E31EF52B962CB31FC8CA5C . 361600 . . [5.1.2600.5625] . . d:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . d:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . d:\windows\system32\dllcache\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . d:\windows\$NtUninstallKB951748$\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . d:\windows\ServicePackFiles\i386\tcpip.sys
[7] 2004-08-03 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . d:\windows\$NtServicePackUninstall$\tcpip.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "d:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1435112]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "d:\program files\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-12-09 11:51 3911776 ----a-w- d:\program files\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2010-12-09 11:51 3911776 ----a-w- d:\program files\uTorrentBar\tbuTor.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-09-28 22:12 1435112 ----a-w- d:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "d:\program files\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "d:\program files\ConduitEngine\ConduitEngine.dll" [2010-12-09 3911776]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "d:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1435112]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}"= "d:\program files\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Start WingMan Profiler"="d:\program files\Logitech\Profiler\lwemon.exe" [2005-04-18 73728]
"QIP Internet Guardian"="d:\documents and settings\Jan\Data aplikací\QipGuard\QipGuard.exe" [2011-02-01 187776]
"Core Temp"="e:\zaloha1\ALOHA\O.C\Core Temp.exe" [2009-05-29 260624]
"uTorrent"="d:\program files\uTorrent\uTorrent.exe" [2011-02-20 396152]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="d:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"36X Raid Configurer"="d:\windows\system32\xRaidSetup.exe" [2007-03-21 1953792]
"F-Secure Manager"="d:\program files\F-Secure\Common\FSM32.EXE" [2010-03-26 301744]
"F-Secure TNB"="d:\program files\F-Secure\FSGUI\TNBUtil.exe" [2010-03-26 1653424]
"GrooveMonitor"="d:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"StartCCC"="d:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]
"WinampAgent"="d:\program files\Winamp\winampa.exe" [2007-08-22 39424]
"SunJavaUpdateSched"="d:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"PWRISOVM.EXE"="d:\program files\PowerISO\PWRISOVM.EXE" [2010-04-12 180224]
"SoundMAXPnP"="d:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
d:\documents and settings\Jan\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Z stupce - speedfan.exe.lnk - e:\zaloha1\SpeedFan\speedfan.exe [2009-5-27 3287552]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\program files\Microsoft ActiveSync\rapimgr.exe"= d:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"d:\program files\Microsoft ActiveSync\wcescomm.exe"= d:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"d:\program files\Microsoft ActiveSync\WCESMgr.exe"= d:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"d:\\Program Files\\Codemasters\\DiRT2\\dirt2_game.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
.
R0 fsbts;fsbts;d:\windows\system32\drivers\fsbts.sys [8.2.2011 20:03 42664]
R0 FSFW;F-Secure Firewall Driver;d:\windows\system32\drivers\fsdfw.sys [8.2.2011 20:03 80080]
R1 F-Secure HIPS;F-Secure HIPS Driver;d:\program files\F-Secure\HIPS\drivers\fshs.sys [8.2.2011 20:03 68144]
R2 cpuz135;cpuz135;d:\windows\system32\drivers\cpuz135_x32.sys [19.2.2011 20:32 22504]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;d:\program files\F-Secure\Anti-Virus\minifilter\fsgk.sys [8.2.2011 20:03 130728]
R3 FSORSPClient;F-Secure ORSP Client;d:\program files\F-Secure\ORSP Client\fsorsp.exe [8.2.2011 20:03 63992]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;d:\windows\system32\drivers\RTL8187.sys [8.2.2011 19:45 176128]
S3 ALSysIO;ALSysIO;\??\d:\docume~1\Jan\LOCALS~1\Temp\ALSysIO.sys --> d:\docume~1\Jan\LOCALS~1\Temp\ALSysIO.sys [?]
S4 F-Secure Filter;F-Secure File System Filter;d:\program files\F-Secure\Anti-Virus\win2k\fsfilter.sys [8.2.2011 20:03 39856]
S4 F-Secure Recognizer;F-Secure File System Recognizer;d:\program files\F-Secure\Anti-Virus\win2k\fsrec.sys [8.2.2011 20:03 25264]
.
Obsah adresáře 'Naplánované úlohy'
.
2011-03-27 d:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- d:\program files\Ask.com\UpdateTask.exe [2010-09-28 22:12]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://getii.com/7z
IE: E&xportovat do aplikace Microsoft Excel - d:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {4FE42FBC-A8C6-4C80-AF62-CF7D532108D9} = 212.71.150.16,82.209.19.226
FF - ProfilePath - d:\documents and settings\Jan\Data aplikací\Mozilla\Firefox\Profiles\dv83ap4n.default\
FF - prefs.js: browser.search.selectedEngine - Search-Results
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz/
FF - prefs.js: keyword.URL - hxxp://websearch.search-results.com/redirect?client=ff&src=kw&tb=GET-SRS&o=16705&locale=en_ZZ&apn_uid=C28368E0-5448-4FA5-9FE9-260D152E57E5&apn_ptnrs=2R&apn_sauid=FC1FE120-32E2-48CB-9F74-F82A41F5526B&apn_dtid=get001YYCZ&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - d:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - d:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - d:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - d:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - d:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: NASA Night Launch: nasanightlaunch@example.com - %profile%\extensions\nasanightlaunch@example.com
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: QipAuthorizer: {32a1fd71-835e-4b11-8e54-886fda0b4c89} - %profile%\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}
FF - Ext: Foxamp: {F0B24ABB-A42D-4c82-AF2C-3FA6FF27E2C0} - %profile%\extensions\{F0B24ABB-A42D-4c82-AF2C-3FA6FF27E2C0}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - d:\program files\Common Files\Nero\Lib\NMBgMonitor.exe
HKLM-Run-NBKeyScan - d:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
AddRemove-DreamAqua - d:\program files\Dream Aquarium\UnInstall.exe
AddRemove-Electronic Arts Game Updater - c:\program files\EACom\Update\Uninst.isu
AddRemove-IL-2 Sturmovik - 1946 - d:\progra~1\IL-2ST~1\UNWISE.EXE
AddRemove-VirtuaGirlHD - e:\vghd\uninst.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-27 12:41
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-507921405-1004336348-682003330-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:e3,ee,7b,8c,0d,38,a5,32,07,61,76,ed,db,51,bb,46,fb,36,af,a7,67,3f,d4,
63,d6,81,9d,0b,d8,89,d0,6e,3e,be,1d,5a,eb,79,bb,5b,6d,be,2e,cf,a3,ea,46,27,\
"??"=hex:dd,ab,42,a5,75,cb,6c,d1,39,ec,00,6a,ad,10,4d,95
.
[HKEY_USERS\S-1-5-21-507921405-1004336348-682003330-1003\Software\SecuROM\License information*]
"datasecu"=hex:ca,c0,b8,40,ac,4d,b6,de,db,1b,88,f1,a5,31,d4,30,28,56,d8,e5,f1,
19,37,2f,d7,1d,ce,52,b9,d4,cf,86,d8,37,ba,2a,f1,93,ee,b2,7f,fe,39,04,bd,c6,\
"rkeysecu"=hex:0a,8b,e7,68,98,a6,91,bc,e3,2b,0d,69,bc,3c,46,ba
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1048)
d:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2011-03-27 12:42:29
ComboFix-quarantined-files.txt 2011-03-27 10:42
.
Před spuštěním: Volných bajtů: 17 536 561 152
Po spuštění: Volných bajtů: 19 751 452 672
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
.
- - End Of File - - DD29CF5E0481AF9C71A688EDF4B6C98B
ASUS ROG Strix G10DK 27L Gray = ASUS PRIME B550M-K, AMD Ryzen7 5800X undervolted, GeForce RTX 3060, 2x Kingston FURY 32GB DDR4 3200MHz CL16 + ASUS ROG STRIX LC II 120 ARGB

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119506
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o kontrolu logu

#7 Příspěvek od Rudy »

Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:
KillAll::

Collect::
d:\windows\system32\tmp181.tmp
d:\windows\system32\tmp180.tmp
d:\windows\system32\tmp10C.tmp
d:\windows\system32\tmp10B.tmp

Folder::
d:\program files\Ask.com
d:\documents and settings\Jan\Data aplikací\PriceGong

Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"=-
[-HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

00Inferno00
1. Stupeň Varování
Příspěvky: 55
Registrován: 25 říj 2007 18:38
Bydliště: Dolní BenešoVW
Kontaktovat uživatele:

Re: Prosim o kontrolu logu

#8 Příspěvek od 00Inferno00 »

log po dočištění:

ComboFix 11-03-26.02 - Jan 27.03.2011 19:06:50.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3327.2913 [GMT 2:00]
Spuštěný z: d:\documents and settings\Jan\Plocha\ComboFix.exe
Použité ovládací přepínače :: d:\documents and settings\Jan\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
file zipped: d:\windows\system32\tmp10B.tmp
file zipped: d:\windows\system32\tmp10C.tmp
file zipped: d:\windows\system32\tmp180.tmp
file zipped: d:\windows\system32\tmp181.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
d:\program files\Ask.com
d:\program files\Ask.com\cobrand.ico
d:\program files\Ask.com\config.xml
d:\program files\Ask.com\favicon.ico
d:\program files\Ask.com\fv_102.ico
d:\program files\Ask.com\GenericAskToolbar.dll
d:\program files\Ask.com\mupcfg.xml
d:\program files\Ask.com\SaUpdate.exe
d:\program files\Ask.com\UpdateTask.exe
d:\windows\system32\tmp10B.tmp
d:\windows\system32\tmp10C.tmp
d:\windows\system32\tmp180.tmp
d:\windows\system32\tmp181.tmp
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-02-27 do 2011-03-27 )))))))))))))))))))))))))))))))
.
.
2011-03-27 13:58 . 2011-03-27 13:59 -------- d-----w- d:\documents and settings\Jan\Local Settings\Data aplikací\AskToolbar
2011-03-27 13:57 . 2011-03-27 13:57 -------- d-----w- d:\program files\ICQ6Toolbar
2011-03-27 13:57 . 2011-03-27 13:57 -------- d-----w- d:\documents and settings\All Users\Data aplikací\ICQ
2011-03-27 13:39 . 2011-03-27 17:19 -------- d-----w- d:\documents and settings\Jan\Data aplikací\ICQ
2011-03-27 13:35 . 2011-03-27 14:01 -------- d-----w- d:\program files\ICQ7.4
2011-03-27 08:43 . 2011-03-27 08:43 -------- d-----w- D:\rsit
2011-03-27 08:43 . 2011-03-27 08:43 -------- d-----w- d:\program files\trend micro
2011-03-26 19:31 . 2011-03-26 19:31 -------- d--h--w- d:\windows\system32\GroupPolicy
2011-03-25 22:50 . 2011-03-25 23:02 -------- d-----w- d:\windows\system32\NtmsData
2011-03-25 22:26 . 2011-03-25 22:26 -------- d-----w- d:\program files\Microsoft Games for Windows - LIVE
2011-03-25 22:26 . 2011-03-25 22:26 -------- d-----w- d:\windows\system32\xlive
2011-03-25 18:40 . 2011-03-25 18:40 -------- d-----w- d:\program files\Free YouTube Downloader Converter
2011-03-24 21:32 . 2011-03-24 21:32 -------- d-----w- d:\documents and settings\All Users\Data aplikací\Electronic Arts
2011-03-24 20:21 . 2011-03-24 20:21 -------- d-----w- d:\program files\7-Zip
2011-03-24 19:28 . 2010-02-04 09:01 74072 ----a-w- d:\windows\system32\XAPOFX1_4.dll
2011-03-24 19:28 . 2010-02-04 09:01 528216 ----a-w- d:\windows\system32\XAudio2_6.dll
2011-03-24 19:28 . 2010-02-04 09:01 238936 ----a-w- d:\windows\system32\xactengine3_6.dll
2011-03-24 19:28 . 2010-02-04 09:01 22360 ----a-w- d:\windows\system32\X3DAudio1_7.dll
2011-03-24 19:28 . 2009-09-04 16:44 515416 ----a-w- d:\windows\system32\XAudio2_5.dll
2011-03-24 19:28 . 2009-09-04 16:44 238936 ----a-w- d:\windows\system32\xactengine3_5.dll
2011-03-24 19:28 . 2009-09-04 16:29 1974616 ----a-w- d:\windows\system32\D3DCompiler_42.dll
2011-03-24 19:28 . 2009-09-04 16:29 5501792 ----a-w- d:\windows\system32\d3dcsx_42.dll
2011-03-24 19:28 . 2009-09-04 16:29 235344 ----a-w- d:\windows\system32\d3dx11_42.dll
2011-03-24 19:28 . 2009-09-04 16:29 453456 ----a-w- d:\windows\system32\d3dx10_42.dll
2011-03-24 19:28 . 2009-09-04 16:29 1892184 ----a-w- d:\windows\system32\D3DX9_42.dll
2011-03-23 15:55 . 2009-07-13 18:04 839680 ----a-w- d:\windows\system32\mkl_vml_p4.dll
2011-03-23 15:55 . 2009-07-13 18:04 532480 ----a-w- d:\windows\system32\mkl_vml_p3.dll
2011-03-23 15:55 . 2009-07-13 18:04 512000 ----a-w- d:\windows\system32\mkl_vml_def.dll
2011-03-23 15:55 . 2009-07-13 18:04 3485696 ----a-w- d:\windows\system32\mkl_p4.dll
2011-03-23 15:55 . 2009-07-13 18:04 2793472 ----a-w- d:\windows\system32\mkl_p3.dll
2011-03-23 15:55 . 2009-07-13 18:04 2125824 ----a-w- d:\windows\system32\mkl_lapack64.dll
2011-03-23 15:55 . 2009-07-13 18:04 2174976 ----a-w- d:\windows\system32\mkl_lapack32.dll
2011-03-23 15:55 . 2009-07-13 18:04 2441216 ----a-w- d:\windows\system32\mkl_def.dll
2011-03-23 15:55 . 2009-07-13 18:04 184320 ----a-w- d:\windows\system32\libguide40.dll
2011-03-23 15:55 . 2009-10-16 10:19 872448 ----a-w- d:\windows\system32\rapture3d_oal.dll
2011-03-23 15:55 . 2011-03-25 22:36 -------- d-----w- d:\program files\BRS
2011-03-23 13:18 . 2011-03-23 13:18 -------- d-----w- d:\program files\Feneris
2011-03-23 10:59 . 2011-03-23 10:59 -------- d-----w- d:\program files\Micro DVD Player
2011-03-22 22:37 . 2010-12-08 14:19 850944 ----a-w- d:\windows\system32\Earth_3D_Screensaver.scr
2011-03-22 22:37 . 2011-03-22 22:37 -------- d-----w- d:\program files\Earth 3D Screensaver
2011-03-22 21:50 . 2011-01-17 18:16 688640 ----a-w- d:\windows\system32\3Planesoft_Screensaver_Manager.scr
2011-03-22 21:50 . 2011-03-22 22:38 -------- d-----w- d:\program files\3Planesoft Screensaver Manager
2011-03-22 21:50 . 2011-03-22 22:38 -------- d-----w- d:\documents and settings\All Users\Data aplikací\3Planesoft
2011-03-22 21:50 . 2010-06-02 13:05 462848 ----a-w- d:\windows\system32\The_One_Ring_3D_Screensaver.scr
2011-03-22 21:50 . 2011-03-22 21:50 -------- d-----w- d:\program files\The One Ring 3D Screensaver
2011-03-22 21:45 . 2011-03-22 21:45 851999 ----a-w- d:\windows\LOTR_Orcs.exe
2011-03-22 21:45 . 2011-03-22 21:45 386848 ----a-w- d:\windows\LOTR_Orcs.scr
2011-03-22 21:42 . 2011-03-22 21:42 649069 ----a-w- d:\windows\LOTR Dark Rider.exe
2011-03-22 21:42 . 2011-03-22 21:42 273304 ----a-w- d:\windows\LOTR Dark Rider.scr
2011-03-22 21:40 . 2011-03-22 21:45 30208 ----a-w- d:\windows\mickey32.dll
2011-03-22 21:40 . 2011-03-22 21:40 514266 ----a-w- d:\windows\LOTR Eye of Sauron.exe
2011-03-22 21:40 . 2011-03-22 21:40 273304 ----a-w- d:\windows\LOTR Eye of Sauron.scr
2011-03-22 17:08 . 2011-03-22 17:08 -------- d-----w- d:\program files\Microsoft Games
2011-03-22 13:49 . 2011-03-22 13:49 -------- d--h--w- d:\windows\PIF
2011-03-22 08:28 . 2011-03-22 08:29 -------- d-----w- d:\program files\Quake III Arena
2011-03-22 08:27 . 2011-03-22 08:27 -------- d-----w- D:\Quake III Arena
2011-03-20 18:10 . 2001-09-19 04:47 765952 ----a-r- d:\windows\system\crlds3d.dll
2011-03-20 18:10 . 2006-08-06 22:57 93952 ----a-r- d:\windows\system32\drivers\aeaudio.sys
2011-03-20 18:10 . 2006-03-17 09:18 392960 ----a-r- d:\windows\system32\drivers\senfilt.sys
2011-03-20 18:10 . 2007-01-16 01:09 293888 ----a-r- d:\windows\system32\drivers\ADIHdAud.sys
2011-03-20 18:10 . 2005-05-04 07:20 53248 ------w- d:\windows\system32\wdmioctl.dll
2011-03-20 18:10 . 2001-09-11 13:20 1285632 ------w- d:\windows\system32\SMMedia.dll
2011-03-20 18:10 . 2011-03-20 18:10 -------- d-----w- d:\program files\Analog Devices
2011-03-20 18:10 . 2006-07-10 13:42 49152 ------w- d:\windows\system32\DSndUp.exe
2011-03-20 18:10 . 2002-04-17 13:05 45056 ------w- d:\windows\system32\CleanUp.exe
2011-03-20 17:52 . 2011-03-20 17:52 -------- d-----w- D:\swsetup
2011-03-20 17:38 . 2011-03-20 17:38 -------- d-----w- d:\documents and settings\All Users\Data aplikací\PC Drivers HeadQuarters
2011-03-20 16:18 . 2011-03-20 16:18 -------- d-----w- d:\documents and settings\Jan\Data aplikací\InstallShield
2011-03-20 08:48 . 2011-03-20 08:48 -------- d-----w- d:\program files\Ubisoft
2011-03-20 06:54 . 2011-03-20 06:54 -------- d-----w- d:\program files\MSXML 4.0
2011-03-19 17:55 . 2011-03-19 17:56 -------- d-----w- d:\documents and settings\Jan\Local Settings\Data aplikací\Ahead
2011-03-19 17:55 . 2011-03-19 17:55 -------- d-----w- d:\documents and settings\Jan\Local Settings\Data aplikací\Nero
2011-03-19 17:47 . 2011-03-25 18:41 -------- d-----w- d:\documents and settings\Jan\Data aplikací\U3
2011-03-19 17:08 . 2011-03-19 17:08 -------- d-----w- d:\documents and settings\Jan\Data aplikací\F-Secure
2011-03-16 18:28 . 2011-03-16 18:28 -------- d-----w- d:\program files\18 Wheels of Steel Haulin
2011-03-13 12:52 . 2011-03-13 12:52 7 ----a-w- d:\windows\treeskp.sys
2011-03-13 12:52 . 2011-03-13 12:52 7 ----a-w- d:\windows\sbacknt.bin
2011-03-12 13:46 . 2004-07-15 23:19 266240 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iscript.dll
2011-03-12 13:46 . 2004-07-15 23:18 172032 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iuser.dll
2011-03-12 13:46 . 2004-07-15 23:20 733184 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iKernel.dll
2011-03-12 13:46 . 2004-07-15 23:20 69715 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\ctor.dll
2011-03-12 13:46 . 2004-07-15 23:18 5632 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\DotNetInstaller.exe
2011-03-12 13:46 . 2011-03-12 13:46 180356 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iGdi.dll
2011-03-12 13:46 . 2011-03-12 13:46 303236 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\setup.dll
2011-03-09 14:17 . 2011-03-09 14:18 -------- d-----w- d:\documents and settings\Jan\Local Settings\Data aplikací\ACD Systems
2011-03-09 14:17 . 2011-03-09 14:17 -------- d-----w- d:\documents and settings\All Users\Data aplikací\ACD Systems
2011-03-09 14:17 . 2011-03-09 14:17 -------- d-----w- d:\program files\Common Files\ACD Systems
2011-03-09 14:17 . 2011-03-09 14:17 -------- d-----w- d:\program files\ACD Systems
2011-03-06 12:20 . 2011-03-06 12:21 -------- d-----w- d:\program files\Doom 3
2011-03-06 08:09 . 2009-03-09 14:27 453456 ----a-w- d:\windows\system32\d3dx10_41.dll
2011-03-06 08:09 . 2009-03-09 14:27 4178264 ----a-w- d:\windows\system32\D3DX9_41.dll
2011-03-06 08:09 . 2009-03-09 14:27 1846632 ----a-w- d:\windows\system32\D3DCompiler_41.dll
2011-03-06 08:09 . 2009-09-04 16:44 69464 ----a-w- d:\windows\system32\XAPOFX1_3.dll
2011-03-06 08:09 . 2009-03-16 13:18 517448 ----a-w- d:\windows\system32\XAudio2_4.dll
2011-03-06 08:09 . 2009-03-16 13:18 235352 ----a-w- d:\windows\system32\xactengine3_4.dll
2011-03-06 08:09 . 2009-03-16 13:18 22360 ----a-w- d:\windows\system32\X3DAudio1_6.dll
2011-03-06 08:09 . 2008-10-15 05:22 452440 ----a-w- d:\windows\system32\d3dx10_40.dll
2011-03-06 08:09 . 2008-10-15 05:22 2036576 ----a-w- d:\windows\system32\D3DCompiler_40.dll
2011-03-06 07:33 . 2011-03-06 07:33 -------- d-----w- d:\windows\ASTULogTemp
2011-03-05 16:25 . 2011-03-05 16:25 -------- d-----w- d:\program files\City Interactive
2011-03-02 17:25 . 2011-03-06 11:43 -------- d-----w- d:\documents and settings\Jan\Local Settings\Data aplikací\NFS Underground 2
2011-03-02 17:20 . 2011-03-02 17:20 -------- d-----w- d:\program files\EA GAMES
2011-03-02 17:17 . 2011-03-02 17:17 -------- d-----w- d:\program files\Common Files\DirectX
2011-03-02 12:54 . 2011-03-20 17:25 -------- d-----w- d:\program files\Microsoft ActiveSync
2011-02-27 18:27 . 2011-03-19 17:53 -------- d-----w- d:\documents and settings\Jan\Data aplikací\Nero
2011-02-27 18:22 . 2011-03-23 21:11 -------- d-----w- d:\program files\Nero
2011-02-27 18:22 . 2011-03-23 21:09 -------- d-----w- d:\documents and settings\All Users\Data aplikací\Nero
2011-02-27 18:15 . 2008-10-15 05:22 4379984 ----a-w- d:\windows\system32\D3DX9_40.dll
2011-02-27 18:15 . 2011-02-27 18:15 -------- d-----w- d:\windows\Logs
2011-02-27 16:21 . 2011-02-27 16:21 -------- d-----w- d:\documents and settings\Jan\Data aplikací\ACD Systems
2011-02-27 16:20 . 2011-02-27 16:20 -------- d-----w- d:\program files\IL-2 Sturmovik 1946
2011-02-27 14:15 . 2001-02-28 10:16 335872 ----a-w- d:\windows\system32\ldf252.dll
2011-02-27 14:15 . 2001-02-28 10:16 126976 ----a-w- d:\windows\system32\lwf214p.dll
2011-02-27 14:15 . 2001-02-28 10:16 144896 ----a-w- d:\windows\system32\Jgdw500.dll
2011-02-27 14:15 . 2001-02-28 10:16 11264 ----a-w- d:\windows\system32\Jgid500.dll
2011-02-27 14:15 . 2001-02-28 10:16 11264 ----a-w- d:\windows\system32\Jgar500.dll
2011-02-27 14:15 . 2001-02-28 10:16 317952 ----a-w- d:\windows\system32\Roboex32.dll
2011-02-27 14:15 . 2001-02-28 10:16 7168 ----a-w- d:\windows\system32\Jgme500.dll
2011-02-27 14:15 . 2001-02-28 10:16 15872 ----a-w- d:\windows\system32\Jgpl500.dll
2011-02-27 14:15 . 2001-02-28 10:16 13312 ----a-w- d:\windows\system32\Jgst500.dll
2011-02-26 14:43 . 2011-02-26 14:43 -------- d-----w- d:\documents and settings\Jan\Local Settings\Data aplikací\Western Digital
2011-02-26 13:30 . 2011-02-26 13:30 -------- d-----w- d:\program files\EACom
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-26 19:28 . 2004-08-03 21:14 361600 ----a-w- d:\windows\system32\drivers\tcpip.sys
2011-03-25 22:36 . 2011-02-20 07:37 445016 ----a-w- d:\windows\system32\wrap_oal.dll
2011-03-25 22:36 . 2011-02-20 07:37 109144 ----a-w- d:\windows\system32\OpenAL32.dll
2011-02-19 12:18 . 2011-02-19 12:18 98304 ----a-w- d:\windows\system32CmdLineExt.dll
2011-02-09 13:53 . 2004-08-17 13:49 270848 ----a-w- d:\windows\system32\sbe.dll
2011-02-09 13:53 . 2004-08-17 13:49 186880 ----a-w- d:\windows\system32\encdec.dll
2011-02-08 17:45 . 2011-02-08 17:45 21035 ----a-w- d:\windows\system32\drivers\AegisP.sys
2011-02-02 20:40 . 2011-02-17 15:13 472808 ----a-w- d:\windows\system32\deployJava1.dll
2011-02-02 18:19 . 2011-02-17 15:13 73728 ----a-w- d:\windows\system32\javacpl.cpl
2011-02-02 07:58 . 2011-02-08 16:20 2067456 ----a-w- d:\windows\system32\mstscax.dll
2011-02-01 09:24 . 2011-02-13 09:22 141184 ----a-w- d:\documents and settings\Jan\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
2011-01-27 11:57 . 2011-02-08 16:20 677888 ----a-w- d:\windows\system32\mstsc.exe
2011-01-24 12:29 . 2011-02-13 11:26 1284712 ----a-w- d:\windows\RtlExUpd.dll
2011-01-21 14:44 . 2004-08-17 13:49 440320 ----a-w- d:\windows\system32\shimgvw.dll
2011-01-19 16:47 . 2011-02-19 18:32 22504 ----a-w- d:\windows\system32\drivers\cpuz135_x32.sys
2011-01-07 14:09 . 2004-08-17 13:48 290048 ----a-w- d:\windows\system32\atmfd.dll
2010-12-31 14:04 . 2004-08-17 13:44 1854976 ----a-w- d:\windows\system32\win32k.sys
.
.
------- Sigcheck -------
.
[-] 2011-03-26 . CBEEBEB899E31EF52B962CB31FC8CA5C . 361600 . . [5.1.2600.5625] . . d:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . d:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . d:\windows\system32\dllcache\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . d:\windows\$NtUninstallKB951748$\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . d:\windows\ServicePackFiles\i386\tcpip.sys
[7] 2004-08-03 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . d:\windows\$NtServicePackUninstall$\tcpip.sys
.
((((((((((((((((((((((((((((( SnapShot@2011-03-27_10.41.24 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-11 22:02 . 2009-07-11 22:02 51008 d:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\vcomp90.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 59728 d:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90rus.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 42832 d:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90kor.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 43344 d:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90jpn.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 61264 d:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90ita.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 36688 d:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90cht.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 35648 d:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90chs.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 62800 d:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90fra.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 61760 d:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esp.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 61776 d:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esn.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 53568 d:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90enu.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 63296 d:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90deu.dll
+ 2009-07-11 22:05 . 2009-07-11 22:05 59904 d:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90u.dll
+ 2009-07-11 22:05 . 2009-07-11 22:05 59904 d:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90.dll
+ 2011-03-27 17:17 . 2011-03-27 17:17 16384 d:\windows\temp\Perflib_Perfdata_c8c.dat
+ 2001-10-25 13:00 . 2011-03-27 17:08 69506 d:\windows\system32\perfc009.dat
+ 2001-10-25 13:00 . 2011-03-27 17:08 80456 d:\windows\system32\perfc005.dat
+ 2011-03-27 11:01 . 2011-02-23 13:55 49240 d:\windows\system32\drivers\aswTdi.sys
+ 2011-03-27 11:01 . 2011-02-23 13:55 25432 d:\windows\system32\drivers\aswRdr.sys
+ 2011-03-27 11:01 . 2011-02-23 13:55 96344 d:\windows\system32\drivers\aswmon.sys
+ 2011-03-27 11:01 . 2011-02-23 13:54 19544 d:\windows\system32\drivers\aswFsBlk.sys
+ 2011-03-27 11:01 . 2011-02-23 13:54 30680 d:\windows\system32\drivers\aavmker4.sys
+ 2011-03-27 11:01 . 2011-02-23 14:04 40648 d:\windows\avastSS.scr
+ 2009-07-11 22:02 . 2009-07-11 22:02 653120 d:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 569664 d:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
+ 2009-07-11 22:05 . 2009-07-11 22:05 225280 d:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 159032 d:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
+ 2001-10-25 13:00 . 2011-03-27 17:08 438012 d:\windows\system32\perfh009.dat
+ 2001-10-25 13:00 . 2011-03-27 17:08 434894 d:\windows\system32\perfh005.dat
+ 2011-03-27 11:01 . 2011-02-23 13:56 301528 d:\windows\system32\drivers\aswSP.sys
+ 2011-03-27 11:01 . 2011-02-23 13:56 371544 d:\windows\system32\drivers\aswSnx.sys
+ 2011-03-27 11:01 . 2011-02-23 13:55 102232 d:\windows\system32\drivers\aswmon2.sys
+ 2011-03-27 11:01 . 2011-02-23 14:04 190016 d:\windows\system32\aswBoot.exe
+ 2011-03-27 11:01 . 2011-03-27 11:01 219648 d:\windows\Installer\1cd957.msi
+ 2009-07-11 22:02 . 2009-07-11 22:02 3780424 d:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90u.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 3765048 d:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "d:\program files\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-12-09 11:51 3911776 ----a-w- d:\program files\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2010-12-09 11:51 3911776 ----a-w- d:\program files\uTorrentBar\tbuTor.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "d:\program files\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "d:\program files\ConduitEngine\ConduitEngine.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}"= "d:\program files\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 14:04 122512 ----a-w- d:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Start WingMan Profiler"="d:\program files\Logitech\Profiler\lwemon.exe" [2005-04-18 73728]
"Core Temp"="e:\zaloha1\ALOHA\O.C\Core Temp.exe" [2009-05-29 260624]
"uTorrent"="d:\program files\uTorrent\uTorrent.exe" [2011-02-20 396152]
"ICQ"="d:\program files\ICQ7.4\ICQ.exe" [2011-03-27 119608]
"ctfmon.exe"="d:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="d:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"36X Raid Configurer"="d:\windows\system32\xRaidSetup.exe" [2007-03-21 1953792]
"GrooveMonitor"="d:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"StartCCC"="d:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]
"WinampAgent"="d:\program files\Winamp\winampa.exe" [2007-08-22 39424]
"SunJavaUpdateSched"="d:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"PWRISOVM.EXE"="d:\program files\PowerISO\PWRISOVM.EXE" [2010-04-12 180224]
"SoundMAXPnP"="d:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"avast"="d:\program files\AVAST Software\Avast\avastUI.exe" [2011-02-23 3451496]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
d:\documents and settings\Jan\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Z stupce - speedfan.exe.lnk - e:\zaloha1\SpeedFan\speedfan.exe [2009-5-27 3287552]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\program files\Microsoft ActiveSync\rapimgr.exe"= d:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"d:\program files\Microsoft ActiveSync\wcescomm.exe"= d:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"d:\program files\Microsoft ActiveSync\WCESMgr.exe"= d:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"d:\\Program Files\\Codemasters\\DiRT2\\dirt2_game.exe"=
"d:\\Program Files\\ICQ7.4\\ICQ.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
.
R1 aswSnx;aswSnx;d:\windows\system32\drivers\aswSnx.sys [27.3.2011 13:01 371544]
R1 aswSP;aswSP;d:\windows\system32\drivers\aswSP.sys [27.3.2011 13:01 301528]
R2 aswFsBlk;aswFsBlk;d:\windows\system32\drivers\aswFsBlk.sys [27.3.2011 13:01 19544]
R2 cpuz135;cpuz135;d:\windows\system32\drivers\cpuz135_x32.sys [19.2.2011 20:32 22504]
R2 ICQ Service;ICQ Service;d:\program files\ICQ6Toolbar\ICQ Service.exe [27.3.2011 15:57 246584]
R3 ALSysIO;ALSysIO;\??\d:\docume~1\Jan\LOCALS~1\Temp\ALSysIO.sys --> d:\docume~1\Jan\LOCALS~1\Temp\ALSysIO.sys [?]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;d:\windows\system32\drivers\RTL8187.sys [8.2.2011 19:45 176128]
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://start.icq.com/sm
IE: E&xportovat do aplikace Microsoft Excel - d:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - d:\program files\ICQ7.4\ICQ.exe
TCP: {4FE42FBC-A8C6-4C80-AF62-CF7D532108D9} = 212.71.150.16,82.209.19.226
FF - ProfilePath - d:\documents and settings\Jan\Data aplikací\Mozilla\Firefox\Profiles\dv83ap4n.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=sm&tb_ver=1.1.9&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - d:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - d:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - d:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - d:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - d:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: avast! WebRep: wrc@avast.com - d:\program files\AVAST Software\Avast\WebRep\FF
FF - Ext: NASA Night Launch: nasanightlaunch@example.com - %profile%\extensions\nasanightlaunch@example.com
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: QipAuthorizer: {32a1fd71-835e-4b11-8e54-886fda0b4c89} - %profile%\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}
FF - Ext: Foxamp: {F0B24ABB-A42D-4c82-AF2C-3FA6FF27E2C0} - %profile%\extensions\{F0B24ABB-A42D-4c82-AF2C-3FA6FF27E2C0}
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-27 19:19
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-507921405-1004336348-682003330-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:e3,ee,7b,8c,0d,38,a5,32,07,61,76,ed,db,51,bb,46,fb,36,af,a7,67,3f,d4,
63,d6,81,9d,0b,d8,89,d0,6e,3e,be,1d,5a,eb,79,bb,5b,6d,be,2e,cf,a3,ea,46,27,\
"??"=hex:dd,ab,42,a5,75,cb,6c,d1,39,ec,00,6a,ad,10,4d,95
.
[HKEY_USERS\S-1-5-21-507921405-1004336348-682003330-1003\Software\SecuROM\License information*]
"datasecu"=hex:ca,c0,b8,40,ac,4d,b6,de,db,1b,88,f1,a5,31,d4,30,28,56,d8,e5,f1,
19,37,2f,d7,1d,ce,52,b9,d4,cf,86,d8,37,ba,2a,f1,93,ee,b2,7f,fe,39,04,bd,c6,\
"rkeysecu"=hex:0a,8b,e7,68,98,a6,91,bc,e3,2b,0d,69,bc,3c,46,ba
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1076)
d:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3760)
d:\windows\system32\msi.dll
d:\windows\system32\webcheck.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
d:\windows\system32\Ati2evxx.exe
d:\windows\system32\Ati2evxx.exe
d:\program files\AVAST Software\Avast\AvastSvc.exe
d:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
d:\program files\Microsoft ActiveSync\wcescomm.exe
d:\progra~1\MI3AA1~1\rapimgr.exe
d:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
d:\program files\Java\jre6\bin\jqs.exe
d:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
d:\windows\system32\wdfmgr.exe
d:\windows\system32\wbem\wmiapsrv.exe
d:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2011-03-27 19:23:13 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-03-27 17:23
ComboFix2.txt 2011-03-27 10:42
.
Před spuštěním: Volných bajtů: 19 333 513 216
Po spuštění: Volných bajtů: 19 333 517 312
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
.
- - End Of File - - 3DCACDCFED2599B8B763F41473E46F1D
Nahr nˇ probŘhlo ŁspŘçnŘ
ASUS ROG Strix G10DK 27L Gray = ASUS PRIME B550M-K, AMD Ryzen7 5800X undervolted, GeForce RTX 3060, 2x Kingston FURY 32GB DDR4 3200MHz CL16 + ASUS ROG STRIX LC II 120 ARGB

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119506
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o kontrolu logu

#9 Příspěvek od Rudy »

Smazáno, log již vypadá čistý. Nyní nezbývá, než zkoušet, zda se PC nepřehřeje a nebudou se restarty opakovat.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

00Inferno00
1. Stupeň Varování
Příspěvky: 55
Registrován: 25 říj 2007 18:38
Bydliště: Dolní BenešoVW
Kontaktovat uživatele:

Re: Prosim o kontrolu logu

#10 Příspěvek od 00Inferno00 »

zatim to vypada dobre, v idle drzi obě jádra +/-35°. Zkusim co to udela v burnu
ASUS ROG Strix G10DK 27L Gray = ASUS PRIME B550M-K, AMD Ryzen7 5800X undervolted, GeForce RTX 3060, 2x Kingston FURY 32GB DDR4 3200MHz CL16 + ASUS ROG STRIX LC II 120 ARGB

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119506
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o kontrolu logu

#11 Příspěvek od Rudy »

00Inferno00 píše:zatim to vypada dobre, v idle drzi obě jádra +/-35°. Zkusim co to udela v burnu
OK.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

00Inferno00
1. Stupeň Varování
Příspěvky: 55
Registrován: 25 říj 2007 18:38
Bydliště: Dolní BenešoVW
Kontaktovat uživatele:

Re: Prosim o kontrolu logu

#12 Příspěvek od 00Inferno00 »

Procesor ma za sebou stabilní 2m:30s v burnu a obě jádra si udržely teplotu do 59°
Dik za pomoc Rudy
ASUS ROG Strix G10DK 27L Gray = ASUS PRIME B550M-K, AMD Ryzen7 5800X undervolted, GeForce RTX 3060, 2x Kingston FURY 32GB DDR4 3200MHz CL16 + ASUS ROG STRIX LC II 120 ARGB

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119506
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o kontrolu logu

#13 Příspěvek od Rudy »

Rádo se stalo!
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět