
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o preventivku - občas zamrzne IE8, nelze ukončit
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Prosím o preventivku - občas zamrzne IE8, nelze ukončit
ComboFix 11-12-12.02 - Miloš 15.12.2011 20:43:40.7.4 - FAT32x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3326.2275 [GMT 1:00]
Spuštěný z: C:\ComboFix.exe
Použité ovládací přepínače :: C:\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *Disabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
.
FILE ::
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\askcom.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-1.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-10.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-2.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-3.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-4.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-5.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-6.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-7.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-8.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-9.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\SearchResults.xml"
"c:\program files\Vuze_Remote\prxtbVuz0.dll"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\tasks\Norton Security Scan for Miloš.job"
"c:\windows\tasks\RealUpgradeLogonTaskS-1-5-21-4036164967-4113303836-1484400983-1005.job"
"c:\windows\tasks\RealUpgradeScheduledTaskS-1-5-21-4036164967-4113303836-1484400983-1005.job"
"c:\windows\tasks\Scheduled Update for Ask Toolbar.job"
"c:\windows\tasks\SpeedUpMyPC.job"
"c:\windows\tasks\User_Feed_Synchronization-{27F5AB2D-4486-4DE2-BDE0-21639BA93517}.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\tasks\RealUpgradeLogonTaskS-1-5-21-4036164967-4113303836-1484400983-1005.job
c:\windows\tasks\RealUpgradeScheduledTaskS-1-5-21-4036164967-4113303836-1484400983-1005.job
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-11-15 do 2011-12-15 )))))))))))))))))))))))))))))))
.
.
2011-12-12 22:13 . 2011-12-12 22:13 -------- d-----w- C:\FOUND.001
2011-12-12 21:52 . 2011-12-12 21:52 -------- d-----w- C:\FOUND.000
2011-12-10 15:27 . 2011-12-10 15:27 -------- d-----w- c:\documents and settings\Miloš\Local Settings\Data aplikací\AskToolbar
2011-12-10 15:27 . 2011-12-10 15:27 -------- d-----w- c:\program files\FotoSketcher
2011-11-29 15:39 . 2011-11-29 15:39 -------- d-----w- c:\program files\BT
2011-11-25 16:55 . 2011-11-25 16:55 -------- d--h--w- c:\windows\ie8
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-28 07:31 . 2011-10-28 07:31 25248 ----a-w- c:\windows\system32\drivers\AmgHips.sys
2011-10-10 14:22 . 2009-01-19 09:19 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 1979-12-31 23:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 10:41 . 2008-07-29 18:59 613376 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 10:41 . 1979-12-31 23:00 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 10:41 . 1979-12-31 23:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-03-18 17:55 . 2011-03-23 20:23 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-14_17.06.08 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-07 05:12 . 2011-12-15 19:45 217609 c:\windows\system32\inetsrv\MetaBase.bin
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"USB Safely Remove"="c:\program files\USB Safely Remove\USBSafelyRemove.exe" [2010-12-25 1794392]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="c:\progra~1\SYMANT~1\\vptray.exe" [2006-07-17 125072]
"RTHDCPL"="RTHDCPL.EXE" [2008-12-09 18063872]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-03-24 53408]
"MDS_Menu"="c:\program files\CyberLink\MediaShow4\MUITransfer\MUIStartMenu.exe" [2009-02-25 218408]
"TrayServer"="c:\program files\MAGIX\Movie_Edit_Pro_15_silver\TrayServer.exe" [2008-11-13 90112]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
RAMASST.lnk - c:\windows\system32\RAMAsst.exe [2009-2-26 167936]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Foxit Software\\PDF Editor\\PDFEdit.exe"=
"c:\\Program Files\\Real\\RealPlayer\\RecordingManager.exe"=
"c:\\Program Files\\Java\\JRE6\\BIN\\java.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe"=
"c:\\Program Files\\SnugTV\\SnugTV Station\\ConfigMaster.exe"=
"c:\\Program Files\\SnugTV\\SnugTV Station\\ConfigWizard.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\EPLAN\\Electric P8\\1.9.11\\BIN\\W3u.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\WINDOWS\\System32\\hasplms.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\ICQ7.6\\ICQ.exe"=
"c:\\Program Files\\SnugTV\\SnugTV Station\\AMAServer.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R1 AmgHips;AmgHips;c:\windows\system32\drivers\AmgHips.sys [28.10.2011 8:31 25248]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
R2 hasplms;Sentinel HASP License Manager;c:\windows\system32\hasplms.exe -run --> c:\windows\system32\hasplms.exe -run [?]
R2 SZASSIST;SecretZone Assist Service;c:\program files\Clarus\Samsung SecretZone\SZAssistSVC.exe [16.1.2011 23:29 90112]
R2 USBSafelyRemoveService;USB Safely Remove Assistant;c:\program files\USB Safely Remove\USBSRService.exe [27.8.2011 22:31 246616]
R2 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\eengine\EraserUtilRebootDrv.sys [19.2.2009 19:01 106104]
R3 mdf15;mdf15;c:\program files\Clarus\Samsung SecretZone\mdf15.sys [16.1.2011 23:29 12288]
R3 mvd21;mvd21;c:\program files\Clarus\Samsung SecretZone\mvd21.sys [16.1.2011 23:29 64512]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [25.2.2009 20:49 47360]
S3 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [6.12.2007 21:03 660768]
S3 AVerAF35;AVerMedia A867 USB DVB-T;c:\windows\system32\drivers\AVerAF35.sys [9.11.2010 22:03 477312]
S3 AVerRemote;AVerRemote;c:\program files\Common Files\AVerMedia\Service\AVerRemote.exe [9.11.2010 22:04 348160]
S3 AVerScheduleService;AVerScheduleService;c:\program files\Common Files\AVerMedia\Service\AVerScheduleService.exe [9.11.2010 22:04 397312]
S3 AVerUpdateServer;AVerUpdateServer;c:\program files\AVerMedia\AVerUpdate\AVerUpdateServer.exe [6.1.2011 13:42 168448]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe [3.9.2011 15:34 1527900]
S3 OODefragAgent;O&O Defrag Agent;c:\program files\OO Software\Defrag\oodag.exe [25.1.2011 11:41 2336072]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [28.5.2010 13:04 14896]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [17.7.2006 17:38 118928]
S3 SnugTV Service;SnugTV Service;c:\program files\SnugTV\SnugTV Station\AMAServer.exe [5.1.2011 3:31 570880]
S3 XHASP;XHASP;c:\windows\system32\drivers\XHASP.sys [28.5.2011 15:25 259584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A8D647C8-65AC-409F-B7B2-3C0FEE1A32F2}]
2010-02-16 18:02 114688 ----a-w- c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2011-12-15 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-02-23 16:58]
.
2011-12-15 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 14:07]
.
2011-12-14 c:\windows\Tasks\Norton Security Scan for Miloš.job
- c:\progra~1\NORTON~2\Engine\301~1.8\Nss.exe [2011-01-17 22:47]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: &Winamp Search - c:\documents and settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Free YouTube Download - c:\documents and settings\Miloš\Data aplikací\DVDVideoSoftIEHelpers\youtubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\documents and settings\Miloš\Data aplikací\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files\ICQ7.6\ICQ.exe
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
DPF: {4FEE6316-7B6F-4A6C-BD4E-4157C59A9E9D} - hxxp://static.s2g.gate5.de/ovi_maps/OviMapsPlugin_4.0.12.11.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://62.168.0.189/activex/AMC.cab
FF - ProfilePath - c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-15 20:58
Windows 5.1.2600 Service Pack 3 FAT NTAPI
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-4036164967-4113303836-1484400983-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1028)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(7428)
c:\program files\ScanSoft\OmniPageSE4\OpHookSE4.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\windows\system32\bgsvcgen.exe
c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe
c:\progra~1\SYMANT~1\vptray.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\windows\System32\DVDRAMSV.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\hasplms.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
c:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
c:\windows\system32\IoctlSvc.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2011-12-15 21:00:11 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-12-15 20:00
ComboFix2.txt 2011-12-15 19:26
ComboFix3.txt 2011-12-14 17:09
ComboFix4.txt 2011-04-16 11:23
C:\DeQuarantine.txt
.
Před spuštěním: Volných bajtů: 277 416 509 440
Po spuštění: Volných bajtů: 277 409 693 696
.
- - End Of File - - C3A61B39DF8F531AF1569242163C9D4D
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3326.2275 [GMT 1:00]
Spuštěný z: C:\ComboFix.exe
Použité ovládací přepínače :: C:\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *Disabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
.
FILE ::
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\askcom.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-1.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-10.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-2.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-3.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-4.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-5.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-6.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-7.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-8.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin-9.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\icqplugin.xml"
"c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\searchplugins\SearchResults.xml"
"c:\program files\Vuze_Remote\prxtbVuz0.dll"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\tasks\Norton Security Scan for Miloš.job"
"c:\windows\tasks\RealUpgradeLogonTaskS-1-5-21-4036164967-4113303836-1484400983-1005.job"
"c:\windows\tasks\RealUpgradeScheduledTaskS-1-5-21-4036164967-4113303836-1484400983-1005.job"
"c:\windows\tasks\Scheduled Update for Ask Toolbar.job"
"c:\windows\tasks\SpeedUpMyPC.job"
"c:\windows\tasks\User_Feed_Synchronization-{27F5AB2D-4486-4DE2-BDE0-21639BA93517}.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\tasks\RealUpgradeLogonTaskS-1-5-21-4036164967-4113303836-1484400983-1005.job
c:\windows\tasks\RealUpgradeScheduledTaskS-1-5-21-4036164967-4113303836-1484400983-1005.job
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-11-15 do 2011-12-15 )))))))))))))))))))))))))))))))
.
.
2011-12-12 22:13 . 2011-12-12 22:13 -------- d-----w- C:\FOUND.001
2011-12-12 21:52 . 2011-12-12 21:52 -------- d-----w- C:\FOUND.000
2011-12-10 15:27 . 2011-12-10 15:27 -------- d-----w- c:\documents and settings\Miloš\Local Settings\Data aplikací\AskToolbar
2011-12-10 15:27 . 2011-12-10 15:27 -------- d-----w- c:\program files\FotoSketcher
2011-11-29 15:39 . 2011-11-29 15:39 -------- d-----w- c:\program files\BT
2011-11-25 16:55 . 2011-11-25 16:55 -------- d--h--w- c:\windows\ie8
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-28 07:31 . 2011-10-28 07:31 25248 ----a-w- c:\windows\system32\drivers\AmgHips.sys
2011-10-10 14:22 . 2009-01-19 09:19 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 1979-12-31 23:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 10:41 . 2008-07-29 18:59 613376 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 10:41 . 1979-12-31 23:00 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 10:41 . 1979-12-31 23:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-03-18 17:55 . 2011-03-23 20:23 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-14_17.06.08 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-07 05:12 . 2011-12-15 19:45 217609 c:\windows\system32\inetsrv\MetaBase.bin
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"USB Safely Remove"="c:\program files\USB Safely Remove\USBSafelyRemove.exe" [2010-12-25 1794392]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="c:\progra~1\SYMANT~1\\vptray.exe" [2006-07-17 125072]
"RTHDCPL"="RTHDCPL.EXE" [2008-12-09 18063872]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-03-24 53408]
"MDS_Menu"="c:\program files\CyberLink\MediaShow4\MUITransfer\MUIStartMenu.exe" [2009-02-25 218408]
"TrayServer"="c:\program files\MAGIX\Movie_Edit_Pro_15_silver\TrayServer.exe" [2008-11-13 90112]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
RAMASST.lnk - c:\windows\system32\RAMAsst.exe [2009-2-26 167936]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Foxit Software\\PDF Editor\\PDFEdit.exe"=
"c:\\Program Files\\Real\\RealPlayer\\RecordingManager.exe"=
"c:\\Program Files\\Java\\JRE6\\BIN\\java.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe"=
"c:\\Program Files\\SnugTV\\SnugTV Station\\ConfigMaster.exe"=
"c:\\Program Files\\SnugTV\\SnugTV Station\\ConfigWizard.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\EPLAN\\Electric P8\\1.9.11\\BIN\\W3u.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\WINDOWS\\System32\\hasplms.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\ICQ7.6\\ICQ.exe"=
"c:\\Program Files\\SnugTV\\SnugTV Station\\AMAServer.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R1 AmgHips;AmgHips;c:\windows\system32\drivers\AmgHips.sys [28.10.2011 8:31 25248]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
R2 hasplms;Sentinel HASP License Manager;c:\windows\system32\hasplms.exe -run --> c:\windows\system32\hasplms.exe -run [?]
R2 SZASSIST;SecretZone Assist Service;c:\program files\Clarus\Samsung SecretZone\SZAssistSVC.exe [16.1.2011 23:29 90112]
R2 USBSafelyRemoveService;USB Safely Remove Assistant;c:\program files\USB Safely Remove\USBSRService.exe [27.8.2011 22:31 246616]
R2 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\eengine\EraserUtilRebootDrv.sys [19.2.2009 19:01 106104]
R3 mdf15;mdf15;c:\program files\Clarus\Samsung SecretZone\mdf15.sys [16.1.2011 23:29 12288]
R3 mvd21;mvd21;c:\program files\Clarus\Samsung SecretZone\mvd21.sys [16.1.2011 23:29 64512]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [25.2.2009 20:49 47360]
S3 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [6.12.2007 21:03 660768]
S3 AVerAF35;AVerMedia A867 USB DVB-T;c:\windows\system32\drivers\AVerAF35.sys [9.11.2010 22:03 477312]
S3 AVerRemote;AVerRemote;c:\program files\Common Files\AVerMedia\Service\AVerRemote.exe [9.11.2010 22:04 348160]
S3 AVerScheduleService;AVerScheduleService;c:\program files\Common Files\AVerMedia\Service\AVerScheduleService.exe [9.11.2010 22:04 397312]
S3 AVerUpdateServer;AVerUpdateServer;c:\program files\AVerMedia\AVerUpdate\AVerUpdateServer.exe [6.1.2011 13:42 168448]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe [3.9.2011 15:34 1527900]
S3 OODefragAgent;O&O Defrag Agent;c:\program files\OO Software\Defrag\oodag.exe [25.1.2011 11:41 2336072]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [28.5.2010 13:04 14896]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [17.7.2006 17:38 118928]
S3 SnugTV Service;SnugTV Service;c:\program files\SnugTV\SnugTV Station\AMAServer.exe [5.1.2011 3:31 570880]
S3 XHASP;XHASP;c:\windows\system32\drivers\XHASP.sys [28.5.2011 15:25 259584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A8D647C8-65AC-409F-B7B2-3C0FEE1A32F2}]
2010-02-16 18:02 114688 ----a-w- c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2011-12-15 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-02-23 16:58]
.
2011-12-15 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 14:07]
.
2011-12-14 c:\windows\Tasks\Norton Security Scan for Miloš.job
- c:\progra~1\NORTON~2\Engine\301~1.8\Nss.exe [2011-01-17 22:47]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: &Winamp Search - c:\documents and settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Free YouTube Download - c:\documents and settings\Miloš\Data aplikací\DVDVideoSoftIEHelpers\youtubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\documents and settings\Miloš\Data aplikací\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files\ICQ7.6\ICQ.exe
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
DPF: {4FEE6316-7B6F-4A6C-BD4E-4157C59A9E9D} - hxxp://static.s2g.gate5.de/ovi_maps/OviMapsPlugin_4.0.12.11.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://62.168.0.189/activex/AMC.cab
FF - ProfilePath - c:\documents and settings\Miloš\Data aplikací\Mozilla\Firefox\Profiles\0fzox30t.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-15 20:58
Windows 5.1.2600 Service Pack 3 FAT NTAPI
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-4036164967-4113303836-1484400983-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1028)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(7428)
c:\program files\ScanSoft\OmniPageSE4\OpHookSE4.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\windows\system32\bgsvcgen.exe
c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe
c:\progra~1\SYMANT~1\vptray.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\windows\System32\DVDRAMSV.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\hasplms.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
c:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
c:\windows\system32\IoctlSvc.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2011-12-15 21:00:11 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-12-15 20:00
ComboFix2.txt 2011-12-15 19:26
ComboFix3.txt 2011-12-14 17:09
ComboFix4.txt 2011-04-16 11:23
C:\DeQuarantine.txt
.
Před spuštěním: Volných bajtů: 277 416 509 440
Po spuštění: Volných bajtů: 277 409 693 696
.
- - End Of File - - C3A61B39DF8F531AF1569242163C9D4D
Re: Prosím o preventivku - občas zamrzne IE8, nelze ukončit
- Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
- Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
Kód: Vybrat vše
:reg [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MDS_Menu"=- :files C:\FOUND.001 C:\FOUND.000 c:\documents and settings\Miloš\Local Settings\Data aplikací\AskToolbar c:\windows\Tasks\OGALogon.job %windir%\system32\*.tmp.dll /s %windir%\system32\SET*.tmp /s %windir%\*.tmp :commands [RESETHOSTS] [EMPTYTEMP] [EMPTYFLASH]- Kliknete na cervene tlacitko MoveIt!
- Budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles, obsah sem vlozte
Re: Prosím o preventivku - občas zamrzne IE8, nelze ukončit
All processes killed
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus\\"DisableMonitoring"|dword:00000000 /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\MDS_Menu deleted successfully.
========== FILES ==========
C:\FOUND.001 folder moved successfully.
C:\FOUND.000 folder moved successfully.
c:\documents and settings\Miloš\Local Settings\Data aplikací\AskToolbar folder moved successfully.
c:\windows\Tasks\OGALogon.job moved successfully.
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: All Users
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32835 bytes
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Miloš
->Temp folder emptied: 339090 bytes
->Temporary Internet Files folder emptied: 3125984 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 54277715 bytes
->Google Chrome cache emptied: 6528756 bytes
->Flash cache emptied: 1097 bytes
User: miloa
User: Milo�
User: Milo
User: Miloç
User: DVDVideoSoft
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 8405015 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 69,00 mb
[EMPTYFLASH]
User: Default User
User: All Users
User: NetworkService
User: LocalService
User: Administrator
User: Miloš
->Flash cache emptied: 0 bytes
User: miloa
User: Milo�
User: Milo
User: Miloç
User: DVDVideoSoft
Total Flash Files Cleaned = 0,00 mb
OTM by OldTimer - Version 3.1.19.0 log created on 12152011_211342
Files moved on Reboot...
C:\WINDOWS\temp\hlktmp moved successfully.
Registry entries deleted on Reboot...
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus\\"DisableMonitoring"|dword:00000000 /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\MDS_Menu deleted successfully.
========== FILES ==========
C:\FOUND.001 folder moved successfully.
C:\FOUND.000 folder moved successfully.
c:\documents and settings\Miloš\Local Settings\Data aplikací\AskToolbar folder moved successfully.
c:\windows\Tasks\OGALogon.job moved successfully.
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: All Users
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32835 bytes
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Miloš
->Temp folder emptied: 339090 bytes
->Temporary Internet Files folder emptied: 3125984 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 54277715 bytes
->Google Chrome cache emptied: 6528756 bytes
->Flash cache emptied: 1097 bytes
User: miloa
User: Milo�
User: Milo
User: Miloç
User: DVDVideoSoft
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 8405015 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 69,00 mb
[EMPTYFLASH]
User: Default User
User: All Users
User: NetworkService
User: LocalService
User: Administrator
User: Miloš
->Flash cache emptied: 0 bytes
User: miloa
User: Milo�
User: Milo
User: Miloç
User: DVDVideoSoft
Total Flash Files Cleaned = 0,00 mb
OTM by OldTimer - Version 3.1.19.0 log created on 12152011_211342
Files moved on Reboot...
C:\WINDOWS\temp\hlktmp moved successfully.
Registry entries deleted on Reboot...
Re: Prosím o preventivku - občas zamrzne IE8, nelze ukončit
Jak se chova nas pacient 
Re: Prosím o preventivku - občas zamrzne IE8, nelze ukončit
Myslím, že to bude v pořádku. Děkuji za trpělivost a doufám, že si PC více "pohlídám".
Miloš M.
Miloš M.
Naposledy upravil(a) miloš dne 15 pro 2011 21:51, celkem upraveno 1 x.
Re: Prosím o preventivku - občas zamrzne IE8, nelze ukončit
- Prejmenujte ComboFix na Uninstall
- Spustte jej
- Tohle smaze Combofix a jeho slozky
- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC
- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte
Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy
Re: Prosím o preventivku - občas zamrzne IE8, nelze ukončit
Děkuji za pomoc,
CCleaner pravidelně používám minimálně 1x týdně.
Miloš M.
CCleaner pravidelně používám minimálně 1x týdně.
Miloš M.
Re: Prosím o preventivku - občas zamrzne IE8, nelze ukončit
za odmazani linku dekuji, doufam ze se to nebude opakovat...
Nemate zac, rad jsem pomohl
Zase nekdy 
Nemate zac, rad jsem pomohl




Přispějete na provoz fóra?