Stránka 2 z 2

Re: Prosím o kontrolu logu, NTB se chová divně

Napsal: 05 říj 2014 15:03
od Ariwen
V nouzovém režimu se to povedlo.
Mimochodem tyto kroky jsou na základě "znečištění" Windows a nebo z důvodu virové infekce? (Pokud se jedná o druhý případ, pak mě zaráží, že antivir nic nenašel.)

ComboFix 14-10-04.01 - oXide 05.10.2014 15:37:15.3.2 - x86 MINIMAL
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3062.2442 [GMT 2:00]
Spuštěný z: c:\users\oXide\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\oXide\Desktop\CFScript.txt
AV: Kaspersky Internet Security *Disabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984}
FW: Kaspersky Internet Security *Disabled* {1691B380-548E-1A7A-BE85-9A42CE15AEFF}
SP: Kaspersky Internet Security *Disabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\system32\drivers\03691068.sys"
"c:\windows\system32\drivers\0733297F.sys"
"c:\windows\system32\drivers\0AFC3F82.sys"
"c:\windows\system32\drivers\0CB77408.sys"
"c:\windows\system32\drivers\0F0B3510.sys"
"c:\windows\system32\drivers\18243C2D.sys"
"c:\windows\system32\drivers\1926530B.sys"
"c:\windows\system32\drivers\1D71325F.sys"
"c:\windows\system32\drivers\244C7753.sys"
"c:\windows\system32\drivers\2AE74B7D.sys"
"c:\windows\system32\drivers\2CB84145.sys"
"c:\windows\system32\drivers\2E4535C5.sys"
"c:\windows\system32\drivers\2EAE531C.sys"
"c:\windows\system32\drivers\30815E21.sys"
"c:\windows\system32\drivers\38A8202B.sys"
"c:\windows\system32\drivers\48230029.sys"
"c:\windows\system32\drivers\54FA42BD.sys"
"c:\windows\system32\drivers\56A823D7.sys"
"c:\windows\system32\drivers\58933F80.sys"
"c:\windows\system32\drivers\5A5142B4.sys"
"c:\windows\system32\drivers\5FA72658.sys"
"c:\windows\system32\drivers\61B47BDF.sys"
"c:\windows\system32\drivers\6B9A01EB.sys"
"c:\windows\system32\drivers\7B3E5AFD.sys"
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-09-05 do 2014-10-05 )))))))))))))))))))))))))))))))
.
.
2014-10-05 13:46 . 2014-10-05 13:52 -------- d-----w- c:\users\oXide\AppData\Local\temp
2014-10-05 13:46 . 2014-10-05 13:46 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-10-05 08:04 . 2014-10-05 13:20 110296 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-10-05 08:02 . 2014-05-12 05:26 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-10-05 08:02 . 2014-05-12 05:25 74456 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-10-05 08:02 . 2014-05-12 05:25 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-10-05 08:02 . 2014-10-05 08:07 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2014-10-04 15:36 . 2014-10-04 15:36 512 ----a-w- C:\PhysicalMBR.bin
2014-10-04 14:21 . 2010-08-30 06:34 536576 ----a-w- c:\windows\system32\sqlite3.dll
2014-10-04 14:16 . 2014-10-04 14:21 -------- d-----w- C:\AdwCleaner
2014-10-04 12:53 . 2014-10-04 12:53 -------- d-----w- c:\program files\trend micro
2014-10-04 08:56 . 2014-10-04 08:56 -------- d-----w- C:\rsit
2014-10-04 06:51 . 2014-10-04 06:51 110296 ----a-w- c:\windows\system32\drivers\30815E21.sys
2014-10-04 06:51 . 2014-10-04 06:51 110296 ----a-w- c:\windows\system32\drivers\61B47BDF.sys
2014-10-03 19:38 . 2014-10-03 19:38 -------- d-----w- C:\SUPERDelete
2014-10-03 11:01 . 2014-10-03 11:01 110296 ----a-w- c:\windows\system32\drivers\18243C2D.sys
2014-10-03 06:40 . 2014-10-03 06:40 110296 ----a-w- c:\windows\system32\drivers\5FA72658.sys
2014-10-03 06:40 . 2014-10-03 06:40 110296 ----a-w- c:\windows\system32\drivers\54FA42BD.sys
2014-10-03 06:35 . 2014-09-09 01:24 8806800 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3FCB8B2A-C67F-4137-A734-7E691BF485AE}\mpengine.dll
2014-09-30 16:46 . 2014-09-30 16:46 110296 ----a-w- c:\windows\system32\drivers\56A823D7.sys
2014-09-30 08:35 . 2014-09-30 08:35 110296 ----a-w- c:\windows\system32\drivers\1D71325F.sys
2014-09-29 18:01 . 2014-09-29 18:01 110296 ----a-w- c:\windows\system32\drivers\0AFC3F82.sys
2014-09-28 09:27 . 2014-09-28 09:27 110296 ----a-w- c:\windows\system32\drivers\38A8202B.sys
2014-09-25 14:23 . 2014-09-25 14:23 110296 ----a-w- c:\windows\system32\drivers\2EAE531C.sys
2014-09-24 18:36 . 2014-09-09 06:24 2048 ----a-w- c:\windows\system32\tzres.dll
2014-09-24 16:50 . 2014-09-24 16:50 110296 ----a-w- c:\windows\system32\drivers\2CB84145.sys
2014-09-24 16:06 . 2014-09-24 16:06 110296 ----a-w- c:\windows\system32\drivers\1926530B.sys
2014-09-24 15:00 . 2014-09-24 15:00 110296 ----a-w- c:\windows\system32\drivers\7B3E5AFD.sys
2014-09-14 12:56 . 2014-09-14 12:56 -------- d-----w- c:\users\oXide\AppData\Local\Chromium
2014-09-14 11:45 . 2014-09-14 11:45 110296 ----a-w- c:\windows\system32\drivers\2E4535C5.sys
2014-09-14 10:26 . 2014-09-14 10:26 -------- d-----w- c:\users\oXide\AppData\Local\Macromedia
2014-09-14 10:25 . 2014-09-14 10:25 -------- d-----w- c:\users\oXide\AppData\Local\Mozilla
2014-09-14 10:24 . 2014-09-30 09:27 -------- d-----w- c:\program files\Mozilla Maintenance Service
2014-09-14 09:59 . 2014-09-14 09:59 -------- d-----w- c:\users\oXide\AppData\Local\Razer_Inc
2014-09-13 16:18 . 2014-09-13 16:18 -------- d-----w- c:\program files\Outlast
2014-09-12 14:04 . 2014-09-12 14:04 110296 ----a-w- c:\windows\system32\drivers\03691068.sys
2014-09-10 14:07 . 2014-09-10 14:07 110296 ----a-w- c:\windows\system32\drivers\0733297F.sys
2014-09-07 16:01 . 2014-10-05 13:51 -------- d-----w- c:\users\oXide\AppData\Local\HTC MediaHub
2014-09-07 16:01 . 2014-09-07 16:01 -------- d-----w- c:\programdata\HTC
2014-09-07 16:00 . 2014-09-07 16:00 -------- d-----w- c:\program files\Common Files\Nero
2014-09-07 15:56 . 2009-06-10 13:49 24576 ----a-w- c:\windows\system32\drivers\ANDROIDUSB.sys
2014-09-07 15:56 . 2014-09-07 15:56 -------- d-----w- c:\program files\Spirent Communications
2014-09-07 15:48 . 2014-09-07 15:51 -------- d-----w- c:\users\oXide\.android
2014-09-07 06:45 . 2014-09-07 06:45 110296 ----a-w- c:\windows\system32\drivers\6B9A01EB.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-10-05 13:51 . 2011-11-06 13:54 45056 ----a-w- c:\windows\system32\acovcnt.exe
2014-10-03 06:39 . 2014-07-02 16:21 110296 ----a-w- c:\windows\system32\drivers\48230029.sys
2014-09-24 15:54 . 2013-02-26 18:16 701104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-09-24 15:54 . 2011-11-06 12:20 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-09-15 07:06 . 2011-11-06 08:40 231568 ------w- c:\windows\system32\MpSigStub.exe
2014-09-01 15:05 . 2014-09-01 15:05 110296 ----a-w- c:\windows\system32\drivers\244C7753.sys
2014-08-31 05:32 . 2014-08-31 05:32 110296 ----a-w- c:\windows\system32\drivers\58933F80.sys
2014-08-24 04:05 . 2014-08-24 04:05 110296 ----a-w- c:\windows\system32\drivers\0CB77408.sys
2014-08-23 01:03 . 2014-08-29 01:04 297984 ----a-w- c:\windows\system32\gdi32.dll
2014-08-22 23:26 . 2014-08-29 01:04 2054656 ----a-w- c:\windows\system32\win32k.sys
2014-08-20 10:16 . 2014-08-20 10:16 243128 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2014-08-20 05:57 . 2014-08-20 05:57 110296 ----a-w- c:\windows\system32\drivers\2AE74B7D.sys
2014-08-20 05:57 . 2014-08-20 05:57 110296 ----a-w- c:\windows\system32\drivers\5A5142B4.sys
2014-08-15 05:45 . 2014-08-15 05:45 110296 ----a-w- c:\windows\system32\drivers\0F0B3510.sys
2014-08-13 16:52 . 2014-08-13 16:53 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2014-07-25 00:35 . 2014-07-25 00:35 875688 ----a-w- c:\windows\system32\msvcr120_clr0400.dll
2014-07-16 15:54 . 2013-01-27 17:08 281152 ----a-w- c:\windows\system32\PnkBstrB.xtr
2014-07-16 14:14 . 2011-11-17 12:46 281152 ----a-w- c:\windows\system32\PnkBstrB.ex0
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 01:08 143360 ----a-w- c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"="c:\program files\ATKOSD2\ATKOSD2.exe" [2007-10-18 7737344]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-22 141848]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-22 133656]
"RtHDVCpl"="RtHDVCpl.exe" [2007-10-31 4702208]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 1821576]
"Skytel"="Skytel.exe" [2007-10-11 1826816]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files\PROGRAMY\Stardock\Fences\FencesMenu.dll" [2010-06-22 202088]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^oXide^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
path=c:\users\oXide\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
backup=c:\windows\pss\Dropbox.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BTMTrayAgent]
2011-07-19 19:33 32955440 ----a-w- c:\program files\Motorola\Bluetooth\btmshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2008-02-22 02:34 166424 ----a-w- c:\windows\System32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2008-02-22 02:34 133656 ----a-w- c:\windows\System32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
2009-04-11 06:28 2153472 ----a-w- c:\windows\System32\oobefldr.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
.
2014-10-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-26 15:54]
.
2014-10-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2442781902-818226900-1603411712-1000Core.job
- c:\users\oXide\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-06 06:35]
.
2014-10-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2442781902-818226900-1603411712-1000UA.job
- c:\users\oXide\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-06 06:35]
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
mStart Page = about:blank
uInternet Settings,ProxyServer = 128.199.144.215:80
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: {{bd707fe6-39f6-4bda-9265-86a76719bdc5} - c:\program files\Motorola\Bluetooth\btmiesend.htm
TCP: Interfaces\{930DE09B-9641-4354-AAAD-018A0B57971C}: NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
FF - ProfilePath - c:\users\oXide\AppData\Roaming\Mozilla\Firefox\Profiles\wqnzsupp.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-10-05 15:52
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2442781902-818226900-1603411712-1000\(;ť™—l*]
@Allowed: (Read) (RestrictedCode)
"Running"=dword:00000001
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(3732)
c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt.dll
c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll
c:\program files\PROGRAMY\Stardock\Fences\FencesMenu.dll
c:\program files\programy\stardock\fences\DesktopDock.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
c:\program files\ATK Hotkey\ASLDRSrv.exe
c:\program files\ATKGFNEX\GFNEXSrv.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Motorola\Bluetooth\devmgrsrv.exe
c:\program files\Motorola\Bluetooth\audiosrv.exe
c:\program files\HTC\HTC Sync Manager\HSMServiceEntry.exe
c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe
c:\program files\Razer\Razer Cortex\RzKLService.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Motorola\Bluetooth\LEsrv.exe
c:\program files\Motorola\Bluetooth\obexsrv.exe
c:\windows\servicing\TrustedInstaller.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\ATK Hotkey\Hcontrol.exe
c:\program files\ATK Hotkey\MsgTranAgt.exe
c:\program files\Wireless Console 2\wcourier.exe
c:\program files\P4G\BatteryLife.exe
c:\program files\ASUS\Splendid\ACMON.exe
c:\program files\HTC\HTC Sync Manager\HTC Sync\adb.exe
c:\windows\System32\ACEngSvr.exe
c:\program files\ATK Hotkey\ATKOSD.exe
c:\program files\ATK Hotkey\KBFiltr.exe
c:\program files\ATK Hotkey\WDC.exe
c:\windows\system32\conime.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\System32\fsquirt.exe
.
**************************************************************************
.
Celkový čas: 2014-10-05 15:55:52 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-10-05 13:55
ComboFix2.txt 2014-10-04 18:25
.
Před spuštěním: Volných bajtů: 47 729 414 144
Po spuštění: Volných bajtů: 44 466 360 320
.
- - End Of File - - D278909A65B8F1EC2FBD7FEB5B51064A
64B1E91C5C6C2157642651010728F90F

Re: Prosím o kontrolu logu, NTB se chová divně

Napsal: 05 říj 2014 17:19
od Márty84
Nejsem si jisty, jestli je to infekci, kazdopadne je tam neco spatne :boxed:

:???: Odinstalovaval jste to MBAM? Vsechno to tam zustalo :?:

Re: Prosím o kontrolu logu, NTB se chová divně

Napsal: 05 říj 2014 18:20
od Ariwen
odinstaloval, provedl další krok a znovu nainstaloval. Pardon.

Zde je nový log s odinstalovaným MBAM.

ComboFix 14-10-04.01 - oXide 05.10.2014 18:56:30.3.2 - x86 MINIMAL
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3062.2418 [GMT 2:00]
Spuštěný z: c:\users\oXide\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\oXide\Desktop\CFScript.txt
AV: Kaspersky Internet Security *Disabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984}
FW: Kaspersky Internet Security *Disabled* {1691B380-548E-1A7A-BE85-9A42CE15AEFF}
SP: Kaspersky Internet Security *Disabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\system32\drivers\03691068.sys"
"c:\windows\system32\drivers\0733297F.sys"
"c:\windows\system32\drivers\0AFC3F82.sys"
"c:\windows\system32\drivers\0CB77408.sys"
"c:\windows\system32\drivers\0F0B3510.sys"
"c:\windows\system32\drivers\18243C2D.sys"
"c:\windows\system32\drivers\1926530B.sys"
"c:\windows\system32\drivers\1D71325F.sys"
"c:\windows\system32\drivers\244C7753.sys"
"c:\windows\system32\drivers\2AE74B7D.sys"
"c:\windows\system32\drivers\2CB84145.sys"
"c:\windows\system32\drivers\2E4535C5.sys"
"c:\windows\system32\drivers\2EAE531C.sys"
"c:\windows\system32\drivers\30815E21.sys"
"c:\windows\system32\drivers\38A8202B.sys"
"c:\windows\system32\drivers\48230029.sys"
"c:\windows\system32\drivers\54FA42BD.sys"
"c:\windows\system32\drivers\56A823D7.sys"
"c:\windows\system32\drivers\58933F80.sys"
"c:\windows\system32\drivers\5A5142B4.sys"
"c:\windows\system32\drivers\5FA72658.sys"
"c:\windows\system32\drivers\61B47BDF.sys"
"c:\windows\system32\drivers\6B9A01EB.sys"
"c:\windows\system32\drivers\7B3E5AFD.sys"
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-09-05 do 2014-10-05 )))))))))))))))))))))))))))))))
.
.
2014-10-05 17:07 . 2014-10-05 17:11 -------- d-----w- c:\users\oXide\AppData\Local\temp
2014-10-05 17:07 . 2014-10-05 17:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-10-04 15:36 . 2014-10-04 15:36 512 ----a-w- C:\PhysicalMBR.bin
2014-10-04 14:21 . 2010-08-30 06:34 536576 ----a-w- c:\windows\system32\sqlite3.dll
2014-10-04 14:16 . 2014-10-04 14:21 -------- d-----w- C:\AdwCleaner
2014-10-04 12:53 . 2014-10-04 12:53 -------- d-----w- c:\program files\trend micro
2014-10-04 08:56 . 2014-10-04 08:56 -------- d-----w- C:\rsit
2014-10-04 06:51 . 2014-10-04 06:51 110296 ----a-w- c:\windows\system32\drivers\30815E21.sys
2014-10-04 06:51 . 2014-10-04 06:51 110296 ----a-w- c:\windows\system32\drivers\61B47BDF.sys
2014-10-03 19:38 . 2014-10-03 19:38 -------- d-----w- C:\SUPERDelete
2014-10-03 11:01 . 2014-10-03 11:01 110296 ----a-w- c:\windows\system32\drivers\18243C2D.sys
2014-10-03 06:40 . 2014-10-03 06:40 110296 ----a-w- c:\windows\system32\drivers\5FA72658.sys
2014-10-03 06:40 . 2014-10-03 06:40 110296 ----a-w- c:\windows\system32\drivers\54FA42BD.sys
2014-10-03 06:35 . 2014-09-09 01:24 8806800 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3FCB8B2A-C67F-4137-A734-7E691BF485AE}\mpengine.dll
2014-09-30 16:46 . 2014-09-30 16:46 110296 ----a-w- c:\windows\system32\drivers\56A823D7.sys
2014-09-30 08:35 . 2014-09-30 08:35 110296 ----a-w- c:\windows\system32\drivers\1D71325F.sys
2014-09-29 18:01 . 2014-09-29 18:01 110296 ----a-w- c:\windows\system32\drivers\0AFC3F82.sys
2014-09-28 09:27 . 2014-09-28 09:27 110296 ----a-w- c:\windows\system32\drivers\38A8202B.sys
2014-09-25 14:23 . 2014-09-25 14:23 110296 ----a-w- c:\windows\system32\drivers\2EAE531C.sys
2014-09-24 18:36 . 2014-09-09 06:24 2048 ----a-w- c:\windows\system32\tzres.dll
2014-09-24 16:50 . 2014-09-24 16:50 110296 ----a-w- c:\windows\system32\drivers\2CB84145.sys
2014-09-24 16:06 . 2014-09-24 16:06 110296 ----a-w- c:\windows\system32\drivers\1926530B.sys
2014-09-24 15:00 . 2014-09-24 15:00 110296 ----a-w- c:\windows\system32\drivers\7B3E5AFD.sys
2014-09-14 12:56 . 2014-09-14 12:56 -------- d-----w- c:\users\oXide\AppData\Local\Chromium
2014-09-14 11:45 . 2014-09-14 11:45 110296 ----a-w- c:\windows\system32\drivers\2E4535C5.sys
2014-09-14 10:26 . 2014-09-14 10:26 -------- d-----w- c:\users\oXide\AppData\Local\Macromedia
2014-09-14 10:25 . 2014-09-14 10:25 -------- d-----w- c:\users\oXide\AppData\Local\Mozilla
2014-09-14 10:24 . 2014-09-30 09:27 -------- d-----w- c:\program files\Mozilla Maintenance Service
2014-09-14 09:59 . 2014-09-14 09:59 -------- d-----w- c:\users\oXide\AppData\Local\Razer_Inc
2014-09-13 16:18 . 2014-09-13 16:18 -------- d-----w- c:\program files\Outlast
2014-09-12 14:04 . 2014-09-12 14:04 110296 ----a-w- c:\windows\system32\drivers\03691068.sys
2014-09-10 14:07 . 2014-09-10 14:07 110296 ----a-w- c:\windows\system32\drivers\0733297F.sys
2014-09-07 16:01 . 2014-10-05 17:10 -------- d-----w- c:\users\oXide\AppData\Local\HTC MediaHub
2014-09-07 16:01 . 2014-09-07 16:01 -------- d-----w- c:\programdata\HTC
2014-09-07 16:00 . 2014-09-07 16:00 -------- d-----w- c:\program files\Common Files\Nero
2014-09-07 15:56 . 2009-06-10 13:49 24576 ----a-w- c:\windows\system32\drivers\ANDROIDUSB.sys
2014-09-07 15:56 . 2014-09-07 15:56 -------- d-----w- c:\program files\Spirent Communications
2014-09-07 15:48 . 2014-09-07 15:51 -------- d-----w- c:\users\oXide\.android
2014-09-07 06:45 . 2014-09-07 06:45 110296 ----a-w- c:\windows\system32\drivers\6B9A01EB.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-10-05 17:11 . 2011-11-06 13:54 45056 ----a-w- c:\windows\system32\acovcnt.exe
2014-10-03 06:39 . 2014-07-02 16:21 110296 ----a-w- c:\windows\system32\drivers\48230029.sys
2014-09-24 15:54 . 2013-02-26 18:16 701104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-09-24 15:54 . 2011-11-06 12:20 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-09-15 07:06 . 2011-11-06 08:40 231568 ------w- c:\windows\system32\MpSigStub.exe
2014-09-01 15:05 . 2014-09-01 15:05 110296 ----a-w- c:\windows\system32\drivers\244C7753.sys
2014-08-31 05:32 . 2014-08-31 05:32 110296 ----a-w- c:\windows\system32\drivers\58933F80.sys
2014-08-24 04:05 . 2014-08-24 04:05 110296 ----a-w- c:\windows\system32\drivers\0CB77408.sys
2014-08-23 01:03 . 2014-08-29 01:04 297984 ----a-w- c:\windows\system32\gdi32.dll
2014-08-22 23:26 . 2014-08-29 01:04 2054656 ----a-w- c:\windows\system32\win32k.sys
2014-08-20 10:16 . 2014-08-20 10:16 243128 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2014-08-20 05:57 . 2014-08-20 05:57 110296 ----a-w- c:\windows\system32\drivers\2AE74B7D.sys
2014-08-20 05:57 . 2014-08-20 05:57 110296 ----a-w- c:\windows\system32\drivers\5A5142B4.sys
2014-08-15 05:45 . 2014-08-15 05:45 110296 ----a-w- c:\windows\system32\drivers\0F0B3510.sys
2014-08-13 16:52 . 2014-08-13 16:53 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2014-07-25 00:35 . 2014-07-25 00:35 875688 ----a-w- c:\windows\system32\msvcr120_clr0400.dll
2014-07-16 15:54 . 2013-01-27 17:08 281152 ----a-w- c:\windows\system32\PnkBstrB.xtr
2014-07-16 14:14 . 2011-11-17 12:46 281152 ----a-w- c:\windows\system32\PnkBstrB.ex0
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 01:08 143360 ----a-w- c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"="c:\program files\ATKOSD2\ATKOSD2.exe" [2007-10-18 7737344]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-22 141848]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-22 133656]
"RtHDVCpl"="RtHDVCpl.exe" [2007-10-31 4702208]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 1821576]
"Skytel"="Skytel.exe" [2007-10-11 1826816]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files\PROGRAMY\Stardock\Fences\FencesMenu.dll" [2010-06-22 202088]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^oXide^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
path=c:\users\oXide\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
backup=c:\windows\pss\Dropbox.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BTMTrayAgent]
2011-07-19 19:33 32955440 ----a-w- c:\program files\Motorola\Bluetooth\btmshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2008-02-22 02:34 166424 ----a-w- c:\windows\System32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2008-02-22 02:34 133656 ----a-w- c:\windows\System32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
2009-04-11 06:28 2153472 ----a-w- c:\windows\System32\oobefldr.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
.
2014-10-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-26 15:54]
.
2014-10-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2442781902-818226900-1603411712-1000Core.job
- c:\users\oXide\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-06 06:35]
.
2014-10-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2442781902-818226900-1603411712-1000UA.job
- c:\users\oXide\AppData\Local\Google\Update\GoogleUpdate.exe [2011-11-06 06:35]
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
mStart Page = about:blank
uInternet Settings,ProxyServer = 128.199.144.215:80
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: {{bd707fe6-39f6-4bda-9265-86a76719bdc5} - c:\program files\Motorola\Bluetooth\btmiesend.htm
TCP: Interfaces\{930DE09B-9641-4354-AAAD-018A0B57971C}: NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
FF - ProfilePath - c:\users\oXide\AppData\Roaming\Mozilla\Firefox\Profiles\wqnzsupp.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-10-05 19:11
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2442781902-818226900-1603411712-1000\(;ť™—l*]
@Allowed: (Read) (RestrictedCode)
"Running"=dword:00000001
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(3280)
c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt.dll
c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll
c:\program files\PROGRAMY\Stardock\Fences\FencesMenu.dll
c:\program files\programy\stardock\fences\DesktopDock.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
c:\program files\ATK Hotkey\ASLDRSrv.exe
c:\program files\ATKGFNEX\GFNEXSrv.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Motorola\Bluetooth\devmgrsrv.exe
c:\program files\Motorola\Bluetooth\audiosrv.exe
c:\program files\HTC\HTC Sync Manager\HSMServiceEntry.exe
c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe
c:\program files\Razer\Razer Cortex\RzKLService.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Motorola\Bluetooth\LEsrv.exe
c:\program files\Motorola\Bluetooth\obexsrv.exe
c:\windows\servicing\TrustedInstaller.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\ATK Hotkey\Hcontrol.exe
c:\program files\ATK Hotkey\MsgTranAgt.exe
c:\program files\Wireless Console 2\wcourier.exe
c:\program files\P4G\BatteryLife.exe
c:\program files\ASUS\Splendid\ACMON.exe
c:\program files\HTC\HTC Sync Manager\HTC Sync\adb.exe
c:\windows\System32\ACEngSvr.exe
c:\program files\ATK Hotkey\ATKOSD.exe
c:\program files\ATK Hotkey\KBFiltr.exe
c:\program files\ATK Hotkey\WDC.exe
c:\windows\system32\conime.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\System32\fsquirt.exe
.
**************************************************************************
.
Celkový čas: 2014-10-05 19:17:16 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-10-05 17:17
ComboFix2.txt 2014-10-05 13:55
ComboFix3.txt 2014-10-04 18:25
.
Před spuštěním: Volných bajtů: 48 173 891 584
Po spuštění: Volných bajtů: 44 815 527 936
.
- - End Of File - - EF72C26655CBC02C77FDEB3094CB550F
64B1E91C5C6C2157642651010728F90F

Re: Prosím o kontrolu logu, NTB se chová divně

Napsal: 05 říj 2014 20:21
od Márty84
Pouzijte http://www.malwarebytes.org/mbam-clean.exe

Pak dejte novy log z RSIT

Re: Prosím o kontrolu logu, NTB se chová divně

Napsal: 06 říj 2014 07:29
od Ariwen
Hotovo. Jinak notebook se už chová o něco lépe, rychleji.

Logfile of random's system information tool 1.10 (written by random/random)
Run by oXide at 2014-10-06 08:27:00
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 43 GB (31%) free of 137 GB
Total RAM: 3062 MB (44% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:27:09, on 6.10.2014
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16575)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\HTC\HTC Sync Manager\HTC Sync\adb.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\conime.exe
C:\Users\oXide\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\oXide\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\oXide\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\oXide\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\oXide\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\oXide\Desktop\RSIT (3).exe
C:\Program Files\trend micro\oXide.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 128.199.144.215:80
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [ATKOSD2] "C:\Program Files\ATKOSD2\ATKOSD2.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [avp] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe"
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Přidat do Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Virtuální klávesnice - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files\Motorola\Bluetooth\Resources\csy.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\Motorola\Bluetooth\Resources\csy.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O9 - Extra button: K&ontrola adres URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{930DE09B-9641-4354-AAAD-018A0B57971C}: NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O22 - SharedTaskScheduler: FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\PROGRAMY\Stardock\Fences\FencesMenu.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Služba Kaspersky Anti-Virus (AVP) - Kaspersky Lab ZAO - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
O23 - Service: Bluetooth Device Manager - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
O23 - Service: Bluetooth Low Energy Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\LEsrv.exe
O23 - Service: Bluetooth Media Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: HTCMonitorService - Nero AG - C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: RzKLService - Razer Inc. - C:\Program Files\Razer\Razer Cortex\RzKLService.exe

--
End of file - 8297 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2442781902-818226900-1603411712-1000Core.job - C:\Users\oXide\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2442781902-818226900-1603411712-1000UA.job - C:\Users\oXide\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\oXide\AppData\Roaming\Mozilla\Firefox\Profiles\wqnzsupp.default

"linkfilter@kaspersky.ru"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\linkfilter@kaspersky.ru
"virtualKeyboard@kaspersky.ru"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru
"KavAntiBanner@Kaspersky.ru"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\KavAntiBanner@Kaspersky.ru
"{20a82645-c095-46ed-80e3-08825760534b}"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"smartwebprinting@hp.com"=C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.67.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll [2011-04-25 86416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-08-13 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-08-13 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
FilterBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll [2011-04-25 229776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22 517688]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"=C:\Program Files\ATKOSD2\ATKOSD2.exe [2007-10-18 7737344]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-02-22 141848]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-02-22 133656]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-10-31 4702208]
"IntelliPoint"=C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2011-08-01 1821576]
"Skytel"=C:\Windows\Skytel.exe [2007-10-11 1826816]
"avp"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe [2012-10-29 206448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BTMTrayAgent]
C:\Program Files\Motorola\Bluetooth\btmshell.dll [2011-07-19 32955440]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\Windows\system32\hkcmd.exe [2008-02-22 166424]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\Windows\system32\igfxpers.exe [2008-02-22 133656]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
oobefldr.dll,ShowWelcomeCenter []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2009-11-18 275072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^oXide^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
C:\Users\oXide\AppData\Roaming\Dropbox\bin\Dropbox.exe []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-02-11 204800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\Windows\system32\klogon.dll [2011-04-25 229776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\PROGRAMY\Stardock\Fences\FencesMenu.dll [2010-06-22 202088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
"NoResolveSearch"=1
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"msacm.l3codec"=l3codecp.acm
"msacm.vorbis"=vorbis.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FPS1"=frapsvid.dll
"vidc.XVID"=xvidvfw.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2014-10-05 19:17:19 ----D---- C:\Windows\temp
2014-10-05 19:17:17 ----A---- C:\ComboFix.txt
2014-10-05 19:11:33 ----SHD---- C:\$RECYCLE.BIN
2014-10-05 19:09:25 ----ASH---- C:\hiberfil.sys
2014-10-05 18:55:40 ----D---- C:\ComboFix
2014-10-05 14:44:26 ----A---- C:\Windows\ntbtlog.txt
2014-10-04 19:38:34 ----A---- C:\Windows\zip.exe
2014-10-04 19:38:34 ----A---- C:\Windows\SWREG.exe
2014-10-04 19:38:34 ----A---- C:\Windows\PEV.exe
2014-10-04 19:38:34 ----A---- C:\Windows\NIRCMD.exe
2014-10-04 19:38:34 ----A---- C:\Windows\MBR.exe
2014-10-04 19:38:34 ----A---- C:\Windows\grep.exe
2014-10-04 19:38:33 ----A---- C:\Windows\SWSC.exe
2014-10-04 19:38:33 ----A---- C:\Windows\sed.exe
2014-10-04 19:38:21 ----D---- C:\Qoobox
2014-10-04 19:37:48 ----D---- C:\Windows\erdnt
2014-10-04 16:21:01 ----A---- C:\Windows\system32\sqlite3.dll
2014-10-04 16:16:55 ----D---- C:\AdwCleaner
2014-10-04 14:53:18 ----D---- C:\Program Files\trend micro
2014-10-04 12:16:05 ----A---- C:\TDSSKiller.3.0.0.40_04.10.2014_12.16.05_log.txt
2014-10-04 10:56:15 ----D---- C:\rsit
2014-10-04 08:51:23 ----A---- C:\Windows\system32\drivers\30815E21.sys
2014-10-04 08:51:20 ----A---- C:\Windows\system32\drivers\61B47BDF.sys
2014-10-03 21:38:47 ----D---- C:\SUPERDelete
2014-10-03 20:22:35 ----A---- C:\TDSSKiller.3.0.0.40_03.10.2014_20.22.35_log.txt
2014-10-03 13:01:44 ----A---- C:\Windows\system32\drivers\18243C2D.sys
2014-10-03 08:40:07 ----A---- C:\Windows\system32\drivers\5FA72658.sys
2014-10-03 08:40:05 ----A---- C:\Windows\system32\drivers\54FA42BD.sys
2014-10-01 08:31:20 ----A---- C:\TDSSKiller.3.0.0.40_01.10.2014_08.31.20_log.txt
2014-09-30 18:46:15 ----A---- C:\Windows\system32\drivers\56A823D7.sys
2014-09-30 10:35:14 ----A---- C:\Windows\system32\drivers\1D71325F.sys
2014-09-29 20:01:06 ----A---- C:\Windows\system32\drivers\0AFC3F82.sys
2014-09-28 11:27:48 ----A---- C:\Windows\system32\drivers\38A8202B.sys
2014-09-27 07:28:57 ----D---- C:\Program Files\Mozilla Firefox
2014-09-25 16:23:12 ----A---- C:\Windows\system32\drivers\2EAE531C.sys
2014-09-24 20:36:40 ----A---- C:\Windows\system32\tzres.dll
2014-09-24 18:50:24 ----A---- C:\Windows\system32\drivers\2CB84145.sys
2014-09-24 18:06:05 ----A---- C:\Windows\system32\drivers\1926530B.sys
2014-09-24 17:00:13 ----A---- C:\Windows\system32\drivers\7B3E5AFD.sys
2014-09-14 13:45:37 ----A---- C:\Windows\system32\drivers\2E4535C5.sys
2014-09-14 12:24:30 ----D---- C:\Program Files\Mozilla Maintenance Service
2014-09-13 18:18:39 ----D---- C:\Program Files\OutlastOutlast
2014-09-13 18:18:39 ----D---- C:\Program Files\Outlast
2014-09-12 16:04:41 ----A---- C:\Windows\system32\drivers\03691068.sys
2014-09-11 03:20:07 ----A---- C:\Windows\system32\vbscript.dll
2014-09-11 03:20:07 ----A---- C:\Windows\system32\mshtmled.dll
2014-09-11 03:20:06 ----A---- C:\Windows\system32\jsproxy.dll
2014-09-11 03:20:05 ----A---- C:\Windows\system32\msfeedsbs.dll
2014-09-11 03:20:05 ----A---- C:\Windows\system32\msfeeds.dll
2014-09-11 03:20:05 ----A---- C:\Windows\system32\iertutil.dll
2014-09-11 03:20:05 ----A---- C:\Windows\system32\dxtmsft.dll
2014-09-11 03:20:04 ----A---- C:\Windows\system32\wininet.dll
2014-09-11 03:20:04 ----A---- C:\Windows\system32\msfeedssync.exe
2014-09-11 03:20:04 ----A---- C:\Windows\system32\ieui.dll
2014-09-11 03:20:04 ----A---- C:\Windows\system32\dxtrans.dll
2014-09-11 03:20:03 ----A---- C:\Windows\system32\url.dll
2014-09-11 03:20:03 ----A---- C:\Windows\system32\jscript9.dll
2014-09-11 03:20:03 ----A---- C:\Windows\system32\jscript.dll
2014-09-11 03:20:03 ----A---- C:\Windows\system32\ieUnatt.exe
2014-09-11 03:20:02 ----A---- C:\Windows\system32\urlmon.dll
2014-09-11 03:20:02 ----A---- C:\Windows\system32\mshta.exe
2014-09-11 03:20:01 ----A---- C:\Windows\system32\ieframe.dll
2014-09-11 03:19:59 ----A---- C:\Windows\system32\mshtml.dll
2014-09-10 16:07:19 ----A---- C:\Windows\system32\drivers\0733297F.sys
2014-09-07 18:01:25 ----D---- C:\ProgramData\HTC
2014-09-07 18:00:37 ----D---- C:\Program Files\Common Files\Nero
2014-09-07 17:56:57 ----A---- C:\Windows\system32\drivers\ANDROIDUSB.sys
2014-09-07 17:56:22 ----D---- C:\Program Files\Spirent Communications
2014-09-07 08:45:22 ----A---- C:\Windows\system32\drivers\6B9A01EB.sys

======List of files/folders modified in the last 1 month======

2014-10-06 08:21:45 ----D---- C:\ProgramData\Kaspersky Lab
2014-10-06 08:20:16 ----A---- C:\Windows\system32\acovcnt.exe
2014-10-06 08:17:03 ----D---- C:\ProgramData
2014-10-05 19:17:20 ----D---- C:\Windows\system32\drivers
2014-10-05 19:17:19 ----D---- C:\Windows
2014-10-05 19:11:21 ----A---- C:\Windows\system.ini
2014-10-05 19:11:14 ----D---- C:\Windows\system32\drivers\etc
2014-10-05 19:04:14 ----D---- C:\Windows\System32
2014-10-05 19:04:14 ----D---- C:\Windows\AppPatch
2014-10-05 19:04:12 ----D---- C:\Program Files\Common Files
2014-10-05 18:45:05 ----RD---- C:\Program Files
2014-10-05 15:31:00 ----D---- C:\Users\oXide\AppData\Roaming\uTorrent
2014-10-05 14:28:20 ----D---- C:\Users\oXide\AppData\Roaming\vlc
2014-10-05 14:14:26 ----D---- C:\Windows\inf
2014-10-05 14:14:26 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-10-04 20:32:29 ----D---- C:\Windows\Prefetch
2014-10-04 20:08:26 ----D---- C:\Program Files\Feed Notifier
2014-10-04 19:26:36 ----D---- C:\Windows\system32\catroot2
2014-10-04 19:22:00 ----D---- C:\Program Files\SUPERAntiSpyware
2014-10-04 17:36:10 ----SHD---- C:\System Volume Information
2014-10-04 16:56:46 ----SHD---- C:\Windows\Installer
2014-10-04 16:56:46 ----D---- C:\Config.Msi
2014-10-04 09:03:27 ----D---- C:\Windows\system32\config
2014-10-04 09:03:27 ----D---- C:\Boot
2014-10-03 21:39:22 ----D---- C:\Users\oXide\AppData\Roaming\IObit
2014-10-03 21:39:17 ----D---- C:\Program Files\IObit
2014-10-01 19:35:34 ----D---- C:\Users\oXide\AppData\Roaming\Skype
2014-09-30 19:52:18 ----HD---- C:\Program Files\InstallShield Installation Information
2014-09-30 19:32:20 ----RSD---- C:\Windows\Fonts
2014-09-30 14:26:23 ----D---- C:\Windows\Debug
2014-09-30 14:10:33 ----D---- C:\Windows\Tasks
2014-09-30 14:10:29 ----D---- C:\Windows\system32\Tasks
2014-09-30 11:30:34 ----D---- C:\Program Files\P4G
2014-09-30 11:27:08 ----D---- C:\Program Files\OpenAL
2014-09-30 10:52:59 ----D---- C:\Windows\Minidump
2014-09-30 10:28:42 ----D---- C:\ProgramData\ProductData
2014-09-29 21:25:19 ----D---- C:\Program Files\EA Games
2014-09-25 06:39:45 ----D---- C:\Windows\rescache
2014-09-25 06:04:13 ----D---- C:\Windows\ASUS
2014-09-24 20:38:27 ----D---- C:\Windows\winsxs
2014-09-24 20:38:27 ----D---- C:\Windows\system32\cs-CZ
2014-09-24 20:38:06 ----D---- C:\Windows\system32\catroot
2014-09-24 17:54:31 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2014-09-22 06:45:08 ----D---- C:\Users\oXide\AppData\Roaming\AIMP3
2014-09-15 09:06:04 ----N---- C:\Windows\system32\MpSigStub.exe
2014-09-14 12:26:08 ----D---- C:\Users\oXide\AppData\Roaming\Mozilla
2014-09-14 11:40:41 ----D---- C:\ProgramData\Razer
2014-09-14 11:40:41 ----D---- C:\Program Files\Razer
2014-09-11 03:37:10 ----D---- C:\Windows\system32\migration
2014-09-11 03:37:08 ----D---- C:\Program Files\Internet Explorer
2014-09-11 03:31:57 ----D---- C:\Windows\Microsoft.NET
2014-09-11 03:30:28 ----RSD---- C:\Windows\assembly
2014-09-11 03:19:00 ----D---- C:\ProgramData\Microsoft Help
2014-09-11 03:17:51 ----D---- C:\Windows\system32\MRT
2014-09-11 03:07:18 ----A---- C:\Windows\system32\mrt.exe
2014-09-07 18:04:47 ----D---- C:\Users\oXide\AppData\Roaming\HTC
2014-09-07 17:56:59 ----D---- C:\Program Files\HTC

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AsDsm;AsDsm; C:\Windows\system32\drivers\AsDsm.sys [2007-08-11 29752]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2007-09-29 308248]
R0 KL1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2011-03-04 133208]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-08-20 243128]
R1 kl2;kl2; C:\Windows\system32\DRIVERS\kl2.sys [2011-03-04 11352]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2011-11-06 570160]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2011-03-10 23856]
R2 ASMMAP;ASMMAP; \??\C:\Program Files\ATKGFNEX\ASMMAP.sys [2007-07-24 13880]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2014-01-04 279712]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2014-01-04 25888]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2009-06-25 48128]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2009-06-25 44544]
R3 dc3d;MS Hardware Device Detection Driver (USB); C:\Windows\system32\DRIVERS\dc3d.sys [2011-08-01 45288]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-11-01 2011224]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2007-01-24 5632]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\Windows\system32\DRIVERS\klmouflt.sys [2009-11-02 19984]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2006-12-14 7680]
R3 Point32;Microsoft IntelliPoint Filter Driver; C:\Windows\system32\DRIVERS\point32.sys [2011-08-01 40936]
R3 RTL8023xp;Realtek 10/100 NIC Family NDIS x86 Driver; C:\Windows\system32\DRIVERS\Rtnicxp.sys [2006-11-02 47104]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-11 89088]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2006-11-02 1010560]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560]
S0 bbxfoi;bbxfoi; C:\Windows\system32\drivers\bbxfoi.sys []
S0 mwihybh;mwihybh; C:\Windows\system32\drivers\mwihybh.sys []
S0 pnee;pnee; C:\Windows\system32\drivers\pnee.sys []
S3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2011-10-04 2205696]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2008-04-29 220160]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2008-04-29 29184]
S3 BTMCOM;Bluetooth Serial Port; C:\Windows\System32\Drivers\btmcom.sys [2011-02-22 41472]
S3 BTMUSB;Motorola Bluetooth Radio Service; C:\Windows\System32\Drivers\btmusb.sys [2011-07-25 564736]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 cnnctfy2MP;cnnctfy2MP; C:\Windows\system32\drivers\cnnctfy2MP.sys []
S3 Dot4;Ovladač MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
S3 Dot4Print;Ovladač třídy tiskárny standardu IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 esgiguard;esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys []
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\drivers\ew_hwusbdev.sys []
S3 ew_usbenumfilter;huawei_CompositeFilter; C:\Windows\system32\drivers\ew_usbenumfilter.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 HTCAND32;HTC Device Driver; C:\Windows\System32\Drivers\ANDROIDUSB.sys [2009-06-10 24576]
S3 htcnprot;HTC NDIS Protocol Driver; C:\Windows\system32\DRIVERS\htcnprot.sys [2012-12-07 23040]
S3 huawei_cdcacm;huawei_cdcacm; C:\Windows\system32\drivers\huawei_cdcacm.sys []
S3 huawei_cdcecm;huawei_cdcecm; C:\Windows\system32\drivers\huawei_cdcecm.sys []
S3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\drivers\huawei_enumerator.sys []
S3 huawei_ext_ctrl;huawei_ext_ctrl; C:\Windows\system32\drivers\huawei_ext_ctrl.sys []
S3 moufiltr;Tablet Mouse Filter Driver; C:\Windows\system32\drivers\moufiltr.sys []
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2013-02-12 15872]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 35328]
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
S3 vhidmini;Generic Virtual HID Driver; C:\Windows\system32\drivers\vhidmini.sys []
S3 WinRing0_1_2_0;WinRing0_1_2_0; \??\C:\Program Files\Razer\Razer Game Booster\Driver\WinRing0.sys []
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136]
S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 194048]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]
R2 ADSMService;ADSM Service; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2007-05-18 73728]
R2 ASLDRService;ASLDR Service; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [2007-10-03 94208]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208]
R2 AVP;Služba Kaspersky Anti-Virus; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe [2012-10-29 206448]
R2 Bluetooth Low Energy Service;Bluetooth Low Energy Service; C:\Program Files\Motorola\Bluetooth\LEsrv.exe [2011-07-20 452656]
R2 Bluetooth Media Service;Bluetooth Media Service; C:\Program Files\Motorola\Bluetooth\audiosrv.exe [2011-07-20 948272]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files\Motorola\Bluetooth\obexsrv.exe [2011-06-17 566832]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 HTCMonitorService;HTCMonitorService; C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe [2014-08-04 87368]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 PassThru Service;Internet Pass-Through Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [2012-12-07 167424]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 RzKLService;RzKLService; C:\Program Files\Razer\Razer Cortex\RzKLService.exe [2014-08-28 105448]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
R3 Bluetooth Device Manager;Bluetooth Device Manager; C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe [2011-07-20 3538480]
R3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2011-12-07 647680]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-24 267440]
S3 MatSvc;@%ProgramFiles%\Microsoft Fix it Center\MatsRes.dll,-9000; C:\Program Files\Microsoft Fix it Center\Matsvc.exe [2011-06-13 267568]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-09-11 770168]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-03-12 271920]

-----------------EOF-----------------

Re: Prosím o kontrolu logu, NTB se chová divně

Napsal: 06 říj 2014 10:17
od Márty84
:arrow: Napiste mi velikost adresare plochy (C:\Users\oXide\Desktop)




:!: Vypnete antivir, at nebrani programu v praci.
:arrow: Znovu spustte OTL jako spravce
Do spodniho okna vlozte nasledujici text (vcetne te dvojtecky pred slovem commands)

Kód: Vybrat vše

:commands
[EMPTYTEMP]
[EMPTYFLASH]
[Purity]
[ClearAllRestorePoints]

:services
bbxfoi
mwihybh
pnee
cnnctfy2MP
esgiguard
WinRing0_1_2_0
AdobeARMservice
AdobeFlashPlayerUpdateSvc

:files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2442781902-818226900-1603411712-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2442781902-818226900-1603411712-1000UA.job
c:\windows\system32\drivers\30815E21.sys
c:\windows\system32\drivers\61B47BDF.sys
c:\windows\system32\drivers\18243C2D.sys
c:\windows\system32\drivers\5FA72658.sys
c:\windows\system32\drivers\54FA42BD.sys
c:\windows\system32\drivers\56A823D7.sys
c:\windows\system32\drivers\1D71325F.sys
c:\windows\system32\drivers\0AFC3F82.sys
c:\windows\system32\drivers\38A8202B.sys
c:\windows\system32\drivers\2EAE531C.sys
c:\windows\system32\drivers\2CB84145.sys
c:\windows\system32\drivers\1926530B.sys
c:\windows\system32\drivers\7B3E5AFD.sys
c:\windows\system32\drivers\2E4535C5.sys
c:\windows\system32\drivers\03691068.sys
c:\windows\system32\drivers\0733297F.sys
c:\windows\system32\drivers\6B9A01EB.sys
c:\windows\system32\drivers\48230029.sys
c:\windows\system32\drivers\244C7753.sys
c:\windows\system32\drivers\58933F80.sys
c:\windows\system32\drivers\0CB77408.sys
c:\windows\system32\drivers\2AE74B7D.sys
c:\windows\system32\drivers\5A5142B4.sys
c:\windows\system32\drivers\0F0B3510.sys
C:\Users\oXide\AppData\Roaming\IObit
C:\Program Files\IObit
C:\Windows\system32\drivers\bbxfoi.sys
C:\Windows\system32\drivers\mwihybh.sys
C:\Windows\system32\drivers\pnee.sys
C:\Windows\system32\drivers\cnnctfy2MP.sys

:otl
SRV - [2014.05.12 07:24:42 | 000,860,472 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2014.05.12 07:24:40 | 001,809,720 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
DRV - [2014.05.12 07:26:04 | 000,051,928 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mwac.sys -- (MBAMWebAccessControl)
DRV - [2014.05.12 07:25:54 | 000,023,256 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-2442781902-818226900-1603411712-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-2442781902-818226900-1603411712-1000\..\SearchScopes\{B78D19F3-748A-4CB9-AFD8-EA0471CBB9CA}: "URL" = http://search.yahoo.com/search?fr=chr-g ... =937811&p={searchTerms}
IE - HKU\S-1-5-21-2442781902-818226900-1603411712-1000\..\SearchScopes\{EB483C58-5FBB-4A71-89E9-5B9D2924DDAE}: "URL" = http://blekko.com/ws/?source=5f97ddbe&t ... 3619553&q={searchTerms}&r=638
[2014.10.04 08:51:23 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\30815E21.sys
[2014.10.04 08:51:20 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\61B47BDF.sys
[2014.10.03 13:01:44 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\18243C2D.sys
[2014.10.03 08:40:07 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\5FA72658.sys
[2014.10.03 08:40:05 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\54FA42BD.sys
[2014.09.30 18:46:15 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\56A823D7.sys
[2014.09.30 10:35:14 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\1D71325F.sys
[2014.09.29 20:01:06 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\0AFC3F82.sys
[2014.09.28 11:27:48 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\38A8202B.sys
[2014.09.25 16:23:12 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\2EAE531C.sys
[2014.09.24 18:50:24 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\2CB84145.sys
[2014.09.24 18:06:05 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\1926530B.sys
[2014.09.24 17:00:13 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\7B3E5AFD.sys
[2014.09.14 13:45:37 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\2E4535C5.sys
[2014.09.12 16:04:41 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\03691068.sys
[2014.09.10 16:07:19 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\0733297F.sys
[2014.09.07 08:45:22 | 000,110,296 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\6B9A01EB.sys
[2014.10.04 16:35:05 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys
[2014.10.04 08:51:23 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\30815E21.sys
[2014.10.04 08:51:20 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\61B47BDF.sys
[2014.10.03 18:35:01 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2442781902-818226900-1603411712-1000Core.job
[2014.10.03 13:01:44 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\18243C2D.sys
[2014.10.03 08:40:07 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\5FA72658.sys
[2014.10.03 08:40:05 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\54FA42BD.sys
[2014.10.03 08:39:29 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\48230029.sys
[2014.09.30 18:46:15 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\56A823D7.sys
[2014.09.30 10:35:14 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\1D71325F.sys
[2014.09.29 20:01:06 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\0AFC3F82.sys
[2014.09.28 11:27:48 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\38A8202B.sys
[2014.09.25 16:23:12 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\2EAE531C.sys
[2014.09.24 18:50:24 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\2CB84145.sys
[2014.09.24 18:06:05 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\1926530B.sys
[2014.09.24 17:00:13 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\7B3E5AFD.sys
[2014.09.14 13:45:37 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\2E4535C5.sys
[2014.09.12 16:04:41 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\03691068.sys
[2014.09.10 16:07:19 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\0733297F.sys
[2014.09.07 08:45:22 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\6B9A01EB.sys
[2012.12.29 22:10:05 | 000,000,000 | ---D | M] -- C:\Users\oXide\AppData\Roaming\AVG
[2014.10.03 21:39:22 | 000,000,000 | ---D | M] -- C:\Users\oXide\AppData\Roaming\IObit
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[8 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\twain_32\*.tmp files -> C:\Windows\twain_32\*.tmp -> ]
[2014.10.03 13:01:44 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\system32\drivers\18243C2D.sys
[2014.10.04 08:51:23 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\system32\drivers\30815E21.sys
[2014.10.03 08:39:29 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\system32\drivers\48230029.sys
[2014.10.03 08:40:05 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\system32\drivers\54FA42BD.sys
[2014.10.03 08:40:07 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\system32\drivers\5FA72658.sys
[2014.10.04 08:51:20 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\system32\drivers\61B47BDF.sys
[2014.10.04 16:35:05 | 000,110,296 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\system32\drivers\MBAMSwissArmy.sys
@Alternate Data Stream - 6144 bytes -> C:\Windows\Cursors\arrow_n.cur:NEDTA.DAT
@Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:0B4227B4

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Kliknete na Opravit a nechte program pracovat. Pri otazce na restart souhlaste.
Po restartu se objevi novy log, ten sem dejte.

Re: Prosím o kontrolu logu, NTB se chová divně

Napsal: 06 říj 2014 10:55
od Ariwen
Velikost plochy: 32,4 MB

All processes killed
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 57472 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: oXide
->Temp folder emptied: 31931 bytes
->Temporary Internet Files folder emptied: 133034 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 246049698 bytes
->Google Chrome cache emptied: 264646617 bytes
->Flash cache emptied: 727 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1461055 bytes
%systemroot%\System32 .tmp files removed: 5 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 120197 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 489,00 mb


[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: oXide
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0,00 mb

Restore point Set: OTL Restore Point
========== SERVICES/DRIVERS ==========
Service bbxfoi stopped successfully!
Service bbxfoi deleted successfully!
Service mwihybh stopped successfully!
Service mwihybh deleted successfully!
Service pnee stopped successfully!
Service pnee deleted successfully!
Service cnnctfy2MP stopped successfully!
Service cnnctfy2MP deleted successfully!
Service esgiguard stopped successfully!
Service esgiguard deleted successfully!
Service WinRing0_1_2_0 stopped successfully!
Service WinRing0_1_2_0 deleted successfully!
Service AdobeARMservice stopped successfully!
Service AdobeARMservice deleted successfully!
Service AdobeFlashPlayerUpdateSvc stopped successfully!
Service AdobeFlashPlayerUpdateSvc deleted successfully!
========== FILES ==========
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
C:\Windows\tasks\Adobe Flash Player Updater.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2442781902-818226900-1603411712-1000Core.job moved successfully.
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2442781902-818226900-1603411712-1000UA.job moved successfully.
c:\windows\system32\drivers\30815E21.sys moved successfully.
c:\windows\system32\drivers\61B47BDF.sys moved successfully.
c:\windows\system32\drivers\18243C2D.sys moved successfully.
c:\windows\system32\drivers\5FA72658.sys moved successfully.
c:\windows\system32\drivers\54FA42BD.sys moved successfully.
c:\windows\system32\drivers\56A823D7.sys moved successfully.
c:\windows\system32\drivers\1D71325F.sys moved successfully.
c:\windows\system32\drivers\0AFC3F82.sys moved successfully.
c:\windows\system32\drivers\38A8202B.sys moved successfully.
c:\windows\system32\drivers\2EAE531C.sys moved successfully.
c:\windows\system32\drivers\2CB84145.sys moved successfully.
c:\windows\system32\drivers\1926530B.sys moved successfully.
c:\windows\system32\drivers\7B3E5AFD.sys moved successfully.
c:\windows\system32\drivers\2E4535C5.sys moved successfully.
c:\windows\system32\drivers\03691068.sys moved successfully.
c:\windows\system32\drivers\0733297F.sys moved successfully.
c:\windows\system32\drivers\6B9A01EB.sys moved successfully.
c:\windows\system32\drivers\48230029.sys moved successfully.
c:\windows\system32\drivers\244C7753.sys moved successfully.
c:\windows\system32\drivers\58933F80.sys moved successfully.
c:\windows\system32\drivers\0CB77408.sys moved successfully.
c:\windows\system32\drivers\2AE74B7D.sys moved successfully.
c:\windows\system32\drivers\5A5142B4.sys moved successfully.
c:\windows\system32\drivers\0F0B3510.sys moved successfully.
C:\Users\oXide\AppData\Roaming\IObit\Advanced SystemCare V6 folder moved successfully.
C:\Users\oXide\AppData\Roaming\IObit folder moved successfully.
C:\Program Files\IObit\LiveUpdate\update folder moved successfully.
C:\Program Files\IObit\LiveUpdate\Language folder moved successfully.
C:\Program Files\IObit\LiveUpdate folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\Update folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\LatestNews folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\BrowerProtect\images folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6\BrowerProtect folder moved successfully.
C:\Program Files\IObit\Advanced SystemCare 6 folder moved successfully.
C:\Program Files\IObit folder moved successfully.
File\Folder C:\Windows\system32\drivers\bbxfoi.sys not found.
File\Folder C:\Windows\system32\drivers\mwihybh.sys not found.
File\Folder C:\Windows\system32\drivers\pnee.sys not found.
File\Folder C:\Windows\system32\drivers\cnnctfy2MP.sys not found.
========== OTL ==========
Error: No service named MBAMService was found to stop!
Service\Driver key MBAMService not found.
File C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe not found.
Error: No service named MBAMScheduler was found to stop!
Service\Driver key MBAMScheduler not found.
File C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe not found.
Error: No service named MBAMWebAccessControl was found to stop!
Service\Driver key MBAMWebAccessControl not found.
File C:\Windows\System32\drivers\mwac.sys not found.
Error: No service named MBAMProtector was found to stop!
Service\Driver key MBAMProtector not found.
File C:\Windows\System32\drivers\mbam.sys not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_USERS\S-1-5-21-2442781902-818226900-1603411712-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_USERS\S-1-5-21-2442781902-818226900-1603411712-1000\Software\Microsoft\Internet Explorer\SearchScopes\{B78D19F3-748A-4CB9-AFD8-EA0471CBB9CA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B78D19F3-748A-4CB9-AFD8-EA0471CBB9CA}\ not found.
Registry key HKEY_USERS\S-1-5-21-2442781902-818226900-1603411712-1000\Software\Microsoft\Internet Explorer\SearchScopes\{EB483C58-5FBB-4A71-89E9-5B9D2924DDAE}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EB483C58-5FBB-4A71-89E9-5B9D2924DDAE}\ not found.
File C:\Windows\System32\drivers\30815E21.sys not found.
File C:\Windows\System32\drivers\61B47BDF.sys not found.
File C:\Windows\System32\drivers\18243C2D.sys not found.
File C:\Windows\System32\drivers\5FA72658.sys not found.
File C:\Windows\System32\drivers\54FA42BD.sys not found.
File C:\Windows\System32\drivers\56A823D7.sys not found.
File C:\Windows\System32\drivers\1D71325F.sys not found.
File C:\Windows\System32\drivers\0AFC3F82.sys not found.
File C:\Windows\System32\drivers\38A8202B.sys not found.
File C:\Windows\System32\drivers\2EAE531C.sys not found.
File C:\Windows\System32\drivers\2CB84145.sys not found.
File C:\Windows\System32\drivers\1926530B.sys not found.
File C:\Windows\System32\drivers\7B3E5AFD.sys not found.
File C:\Windows\System32\drivers\2E4535C5.sys not found.
File C:\Windows\System32\drivers\03691068.sys not found.
File C:\Windows\System32\drivers\0733297F.sys not found.
File C:\Windows\System32\drivers\6B9A01EB.sys not found.
File C:\Windows\System32\drivers\MBAMSwissArmy.sys not found.
File C:\Windows\System32\drivers\30815E21.sys not found.
File C:\Windows\System32\drivers\61B47BDF.sys not found.
File C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2442781902-818226900-1603411712-1000Core.job not found.
File C:\Windows\System32\drivers\18243C2D.sys not found.
File C:\Windows\System32\drivers\5FA72658.sys not found.
File C:\Windows\System32\drivers\54FA42BD.sys not found.
File C:\Windows\System32\drivers\48230029.sys not found.
File C:\Windows\System32\drivers\56A823D7.sys not found.
File C:\Windows\System32\drivers\1D71325F.sys not found.
File C:\Windows\System32\drivers\0AFC3F82.sys not found.
File C:\Windows\System32\drivers\38A8202B.sys not found.
File C:\Windows\System32\drivers\2EAE531C.sys not found.
File C:\Windows\System32\drivers\2CB84145.sys not found.
File C:\Windows\System32\drivers\1926530B.sys not found.
File C:\Windows\System32\drivers\7B3E5AFD.sys not found.
File C:\Windows\System32\drivers\2E4535C5.sys not found.
File C:\Windows\System32\drivers\03691068.sys not found.
File C:\Windows\System32\drivers\0733297F.sys not found.
File C:\Windows\System32\drivers\6B9A01EB.sys not found.
C:\Users\oXide\AppData\Roaming\AVG\Track Eraser folder moved successfully.
C:\Users\oXide\AppData\Roaming\AVG\Rescue\Strartup Manager folder moved successfully.
C:\Users\oXide\AppData\Roaming\AVG\Rescue\ServiceManager folder moved successfully.
C:\Users\oXide\AppData\Roaming\AVG\Rescue\PC Tuneup 2011 folder moved successfully.
C:\Users\oXide\AppData\Roaming\AVG\Rescue\Internet Optimizer folder moved successfully.
C:\Users\oXide\AppData\Roaming\AVG\Rescue\AVG Registry Cleaner folder moved successfully.
C:\Users\oXide\AppData\Roaming\AVG\Rescue folder moved successfully.
C:\Users\oXide\AppData\Roaming\AVG\Registry Defrag\Reports folder moved successfully.
C:\Users\oXide\AppData\Roaming\AVG\Registry Defrag folder moved successfully.
C:\Users\oXide\AppData\Roaming\AVG\PC Tuneup 2011\User Reports folder moved successfully.
C:\Users\oXide\AppData\Roaming\AVG\PC Tuneup 2011\Logs folder moved successfully.
C:\Users\oXide\AppData\Roaming\AVG\PC Tuneup 2011\Disk Doctor\User Reports folder moved successfully.
C:\Users\oXide\AppData\Roaming\AVG\PC Tuneup 2011\Disk Doctor\Logs folder moved successfully.
C:\Users\oXide\AppData\Roaming\AVG\PC Tuneup 2011\Disk Doctor folder moved successfully.
C:\Users\oXide\AppData\Roaming\AVG\PC Tuneup 2011 folder moved successfully.
C:\Users\oXide\AppData\Roaming\AVG\Disk Defrag\Reports folder moved successfully.
C:\Users\oXide\AppData\Roaming\AVG\Disk Defrag folder moved successfully.
C:\Users\oXide\AppData\Roaming\AVG\BoostSpeed folder moved successfully.
C:\Users\oXide\AppData\Roaming\AVG folder moved successfully.
Folder C:\Users\oXide\AppData\Roaming\IObit\ not found.
File/Folder C:\Windows\*.tmp not found.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP19C5.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2DF2.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP5C42.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP78E.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP81A.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP95E7.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPE752.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPEEF0.tmp folder deleted successfully.
C:\Windows\twain_32\hpqgnds2.tmp deleted successfully.
File C:\Windows\system32\drivers\18243C2D.sys not found.
File C:\Windows\system32\drivers\30815E21.sys not found.
File C:\Windows\system32\drivers\48230029.sys not found.
File C:\Windows\system32\drivers\54FA42BD.sys not found.
File C:\Windows\system32\drivers\5FA72658.sys not found.
File C:\Windows\system32\drivers\61B47BDF.sys not found.
File C:\Windows\system32\drivers\MBAMSwissArmy.sys not found.
ADS C:\Windows\Cursors\arrow_n.cur:NEDTA.DAT deleted successfully.
ADS C:\ProgramData\TEMP:0B4227B4 deleted successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9030D464-4C02-4ABF-8ECC-5164760863C6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\ deleted successfully.

OTL by OldTimer - Version 3.2.69.0 log created on 10062014_113138

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Re: Prosím o kontrolu logu, NTB se chová divně

Napsal: 06 říj 2014 18:26
od Márty84
Dejte novy log z RSIT

Re: Prosím o kontrolu logu, NTB se chová divně

Napsal: 06 říj 2014 18:53
od Ariwen
Logfile of random's system information tool 1.10 (written by random/random)
Run by oXide at 2014-10-06 19:51:12
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 41 GB (30%) free of 137 GB
Total RAM: 3062 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:51:42, on 6.10.2014
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16575)
Boot mode: Normal

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Windows\System32\wbem\unsecapp.exe
C:\Windows\System32\igfxsrvc.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\conime.exe
C:\Program Files\HTC\HTC Sync Manager\HTC Sync\adb.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
C:\Users\oXide\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Users\oXide\Desktop\RSIT (3).exe
C:\Program Files\trend micro\oXide.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 128.199.144.215:80
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [ATKOSD2] "C:\Program Files\ATKOSD2\ATKOSD2.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [avp] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe"
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Přidat do Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Virtuální klávesnice - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files\Motorola\Bluetooth\Resources\csy.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\Motorola\Bluetooth\Resources\csy.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O9 - Extra button: K&ontrola adres URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{930DE09B-9641-4354-AAAD-018A0B57971C}: NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O22 - SharedTaskScheduler: FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\PROGRAMY\Stardock\Fences\FencesMenu.dll
O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Služba Kaspersky Anti-Virus (AVP) - Kaspersky Lab ZAO - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
O23 - Service: Bluetooth Device Manager - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
O23 - Service: Bluetooth Low Energy Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\LEsrv.exe
O23 - Service: Bluetooth Media Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: HTCMonitorService - Nero AG - C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: RzKLService - Razer Inc. - C:\Program Files\Razer\Razer Cortex\RzKLService.exe

--
End of file - 7251 bytes

=========Mozilla firefox=========

ProfilePath - C:\Users\oXide\AppData\Roaming\Mozilla\Firefox\Profiles\wqnzsupp.default

"linkfilter@kaspersky.ru"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\linkfilter@kaspersky.ru
"virtualKeyboard@kaspersky.ru"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru
"KavAntiBanner@Kaspersky.ru"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\KavAntiBanner@Kaspersky.ru
"{20a82645-c095-46ed-80e3-08825760534b}"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"smartwebprinting@hp.com"=C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.67.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll [2011-04-25 86416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-08-13 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-08-13 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
FilterBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll [2011-04-25 229776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22 517688]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"=C:\Program Files\ATKOSD2\ATKOSD2.exe [2007-10-18 7737344]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-02-22 141848]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-02-22 133656]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-10-31 4702208]
"IntelliPoint"=C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2011-08-01 1821576]
"Skytel"=C:\Windows\Skytel.exe [2007-10-11 1826816]
"avp"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe [2012-10-29 206448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BTMTrayAgent]
C:\Program Files\Motorola\Bluetooth\btmshell.dll [2011-07-19 32955440]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\Windows\system32\hkcmd.exe [2008-02-22 166424]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\Windows\system32\igfxpers.exe [2008-02-22 133656]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
oobefldr.dll,ShowWelcomeCenter []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2009-11-18 275072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^oXide^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
C:\Users\oXide\AppData\Roaming\Dropbox\bin\Dropbox.exe []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-02-11 204800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\Windows\system32\klogon.dll [2011-04-25 229776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\PROGRAMY\Stardock\Fences\FencesMenu.dll [2010-06-22 202088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
"NoResolveSearch"=1
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"msacm.l3codec"=l3codecp.acm
"msacm.vorbis"=vorbis.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FPS1"=frapsvid.dll
"vidc.XVID"=xvidvfw.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2014-10-06 12:01:12 ----D---- C:\Users\oXide\AppData\Roaming\AVG
2014-10-06 11:31:38 ----D---- C:\_OTL
2014-10-06 09:21:38 ----A---- C:\TDSSKiller.3.0.0.40_06.10.2014_09.21.38_log.txt
2014-10-05 19:17:19 ----D---- C:\Windows\temp
2014-10-05 19:17:17 ----A---- C:\ComboFix.txt
2014-10-05 19:11:33 ----SHD---- C:\$RECYCLE.BIN
2014-10-05 19:09:25 ----ASH---- C:\hiberfil.sys
2014-10-05 18:55:40 ----D---- C:\ComboFix
2014-10-04 19:38:34 ----A---- C:\Windows\zip.exe
2014-10-04 19:38:34 ----A---- C:\Windows\SWREG.exe
2014-10-04 19:38:34 ----A---- C:\Windows\PEV.exe
2014-10-04 19:38:34 ----A---- C:\Windows\NIRCMD.exe
2014-10-04 19:38:34 ----A---- C:\Windows\MBR.exe
2014-10-04 19:38:34 ----A---- C:\Windows\grep.exe
2014-10-04 19:38:33 ----A---- C:\Windows\SWSC.exe
2014-10-04 19:38:33 ----A---- C:\Windows\sed.exe
2014-10-04 19:38:21 ----D---- C:\Qoobox
2014-10-04 19:37:48 ----D---- C:\Windows\erdnt
2014-10-04 16:21:01 ----A---- C:\Windows\system32\sqlite3.dll
2014-10-04 16:16:55 ----D---- C:\AdwCleaner
2014-10-04 14:53:18 ----D---- C:\Program Files\trend micro
2014-10-04 12:16:05 ----A---- C:\TDSSKiller.3.0.0.40_04.10.2014_12.16.05_log.txt
2014-10-04 10:56:15 ----D---- C:\rsit
2014-10-03 21:38:47 ----D---- C:\SUPERDelete
2014-10-03 20:22:35 ----A---- C:\TDSSKiller.3.0.0.40_03.10.2014_20.22.35_log.txt
2014-10-01 08:31:20 ----A---- C:\TDSSKiller.3.0.0.40_01.10.2014_08.31.20_log.txt
2014-09-27 07:28:57 ----D---- C:\Program Files\Mozilla Firefox
2014-09-24 20:36:40 ----A---- C:\Windows\system32\tzres.dll
2014-09-14 12:24:30 ----D---- C:\Program Files\Mozilla Maintenance Service
2014-09-13 18:18:39 ----D---- C:\Program Files\OutlastOutlast
2014-09-13 18:18:39 ----D---- C:\Program Files\Outlast
2014-09-11 03:20:07 ----A---- C:\Windows\system32\vbscript.dll
2014-09-11 03:20:07 ----A---- C:\Windows\system32\mshtmled.dll
2014-09-11 03:20:06 ----A---- C:\Windows\system32\jsproxy.dll
2014-09-11 03:20:05 ----A---- C:\Windows\system32\msfeedsbs.dll
2014-09-11 03:20:05 ----A---- C:\Windows\system32\msfeeds.dll
2014-09-11 03:20:05 ----A---- C:\Windows\system32\iertutil.dll
2014-09-11 03:20:05 ----A---- C:\Windows\system32\dxtmsft.dll
2014-09-11 03:20:04 ----A---- C:\Windows\system32\wininet.dll
2014-09-11 03:20:04 ----A---- C:\Windows\system32\msfeedssync.exe
2014-09-11 03:20:04 ----A---- C:\Windows\system32\ieui.dll
2014-09-11 03:20:04 ----A---- C:\Windows\system32\dxtrans.dll
2014-09-11 03:20:03 ----A---- C:\Windows\system32\url.dll
2014-09-11 03:20:03 ----A---- C:\Windows\system32\jscript9.dll
2014-09-11 03:20:03 ----A---- C:\Windows\system32\jscript.dll
2014-09-11 03:20:03 ----A---- C:\Windows\system32\ieUnatt.exe
2014-09-11 03:20:02 ----A---- C:\Windows\system32\urlmon.dll
2014-09-11 03:20:02 ----A---- C:\Windows\system32\mshta.exe
2014-09-11 03:20:01 ----A---- C:\Windows\system32\ieframe.dll
2014-09-11 03:19:59 ----A---- C:\Windows\system32\mshtml.dll
2014-09-07 18:01:25 ----D---- C:\ProgramData\HTC
2014-09-07 18:00:37 ----D---- C:\Program Files\Common Files\Nero
2014-09-07 17:56:57 ----A---- C:\Windows\system32\drivers\ANDROIDUSB.sys
2014-09-07 17:56:22 ----D---- C:\Program Files\Spirent Communications

======List of files/folders modified in the last 1 month======

2014-10-06 18:20:59 ----D---- C:\ProgramData\Kaspersky Lab
2014-10-06 12:40:52 ----D---- C:\Windows\system32\config
2014-10-06 12:40:52 ----D---- C:\Boot
2014-10-06 11:59:07 ----D---- C:\Users\oXide\AppData\Roaming\uTorrent
2014-10-06 11:59:07 ----D---- C:\Users\oXide\AppData\Roaming\DAEMON Tools Lite
2014-10-06 11:59:07 ----D---- C:\Users\oXide\AppData\Roaming\AIMP3
2014-10-06 11:58:44 ----D---- C:\Windows\inf
2014-10-06 11:58:43 ----D---- C:\Windows
2014-10-06 11:46:32 ----A---- C:\Windows\system32\acovcnt.exe
2014-10-06 11:41:29 ----D---- C:\Windows\twain_32
2014-10-06 11:41:27 ----RD---- C:\Program Files
2014-10-06 11:41:27 ----D---- C:\Windows\system32\drivers
2014-10-06 11:41:26 ----D---- C:\Windows\Tasks
2014-10-06 11:41:04 ----SHD---- C:\System Volume Information
2014-10-06 11:40:23 ----D---- C:\Windows\System32
2014-10-06 09:24:00 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-10-06 08:17:03 ----D---- C:\ProgramData
2014-10-05 19:11:21 ----A---- C:\Windows\system.ini
2014-10-05 19:11:14 ----D---- C:\Windows\system32\drivers\etc
2014-10-05 19:04:14 ----D---- C:\Windows\AppPatch
2014-10-05 19:04:12 ----D---- C:\Program Files\Common Files
2014-10-05 14:28:20 ----D---- C:\Users\oXide\AppData\Roaming\vlc
2014-10-04 20:32:29 ----D---- C:\Windows\Prefetch
2014-10-04 20:08:26 ----D---- C:\Program Files\Feed Notifier
2014-10-04 19:26:36 ----D---- C:\Windows\system32\catroot2
2014-10-04 19:22:00 ----D---- C:\Program Files\SUPERAntiSpyware
2014-10-04 16:56:46 ----SHD---- C:\Windows\Installer
2014-10-04 16:56:46 ----D---- C:\Config.Msi
2014-10-01 19:35:34 ----D---- C:\Users\oXide\AppData\Roaming\Skype
2014-09-30 19:52:18 ----HD---- C:\Program Files\InstallShield Installation Information
2014-09-30 19:32:20 ----RSD---- C:\Windows\Fonts
2014-09-30 14:26:23 ----D---- C:\Windows\Debug
2014-09-30 14:10:29 ----D---- C:\Windows\system32\Tasks
2014-09-30 11:30:34 ----D---- C:\Program Files\P4G
2014-09-30 11:27:08 ----D---- C:\Program Files\OpenAL
2014-09-30 10:52:59 ----D---- C:\Windows\Minidump
2014-09-30 10:28:42 ----D---- C:\ProgramData\ProductData
2014-09-29 21:25:19 ----D---- C:\Program Files\EA Games
2014-09-25 06:39:45 ----D---- C:\Windows\rescache
2014-09-25 06:04:13 ----D---- C:\Windows\ASUS
2014-09-24 20:38:27 ----D---- C:\Windows\winsxs
2014-09-24 20:38:27 ----D---- C:\Windows\system32\cs-CZ
2014-09-24 20:38:06 ----D---- C:\Windows\system32\catroot
2014-09-24 17:54:31 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2014-09-15 09:06:04 ----N---- C:\Windows\system32\MpSigStub.exe
2014-09-14 12:26:08 ----D---- C:\Users\oXide\AppData\Roaming\Mozilla
2014-09-14 11:40:41 ----D---- C:\ProgramData\Razer
2014-09-14 11:40:41 ----D---- C:\Program Files\Razer
2014-09-11 03:37:10 ----D---- C:\Windows\system32\migration
2014-09-11 03:37:08 ----D---- C:\Program Files\Internet Explorer
2014-09-11 03:31:57 ----D---- C:\Windows\Microsoft.NET
2014-09-11 03:30:28 ----RSD---- C:\Windows\assembly
2014-09-11 03:19:00 ----D---- C:\ProgramData\Microsoft Help
2014-09-11 03:17:51 ----D---- C:\Windows\system32\MRT
2014-09-11 03:07:18 ----A---- C:\Windows\system32\mrt.exe
2014-09-07 18:04:47 ----D---- C:\Users\oXide\AppData\Roaming\HTC
2014-09-07 17:56:59 ----D---- C:\Program Files\HTC

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AsDsm;AsDsm; C:\Windows\system32\drivers\AsDsm.sys [2007-08-11 29752]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2007-09-29 308248]
R0 KL1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2011-03-04 133208]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-08-20 243128]
R1 kl2;kl2; C:\Windows\system32\DRIVERS\kl2.sys [2011-03-04 11352]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2011-11-06 570160]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2011-03-10 23856]
R2 ASMMAP;ASMMAP; \??\C:\Program Files\ATKGFNEX\ASMMAP.sys [2007-07-24 13880]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2014-01-04 279712]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2014-01-04 25888]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2009-06-25 48128]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2009-06-25 44544]
R3 dc3d;MS Hardware Device Detection Driver (USB); C:\Windows\system32\DRIVERS\dc3d.sys [2011-08-01 45288]
R3 HTCAND32;HTC Device Driver; C:\Windows\System32\Drivers\ANDROIDUSB.sys [2009-06-10 24576]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-11-01 2011224]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2007-01-24 5632]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\Windows\system32\DRIVERS\klmouflt.sys [2009-11-02 19984]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2006-12-14 7680]
R3 Point32;Microsoft IntelliPoint Filter Driver; C:\Windows\system32\DRIVERS\point32.sys [2011-08-01 40936]
R3 RTL8023xp;Realtek 10/100 NIC Family NDIS x86 Driver; C:\Windows\system32\DRIVERS\Rtnicxp.sys [2006-11-02 47104]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-11 89088]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2006-11-02 1010560]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560]
S3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2011-10-04 2205696]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2008-04-29 220160]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2008-04-29 29184]
S3 BTMCOM;Bluetooth Serial Port; C:\Windows\System32\Drivers\btmcom.sys [2011-02-22 41472]
S3 BTMUSB;Motorola Bluetooth Radio Service; C:\Windows\System32\Drivers\btmusb.sys [2011-07-25 564736]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 Dot4;Ovladač MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
S3 Dot4Print;Ovladač třídy tiskárny standardu IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\drivers\ew_hwusbdev.sys []
S3 ew_usbenumfilter;huawei_CompositeFilter; C:\Windows\system32\drivers\ew_usbenumfilter.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 htcnprot;HTC NDIS Protocol Driver; C:\Windows\system32\DRIVERS\htcnprot.sys [2012-12-07 23040]
S3 huawei_cdcacm;huawei_cdcacm; C:\Windows\system32\drivers\huawei_cdcacm.sys []
S3 huawei_cdcecm;huawei_cdcecm; C:\Windows\system32\drivers\huawei_cdcecm.sys []
S3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\drivers\huawei_enumerator.sys []
S3 huawei_ext_ctrl;huawei_ext_ctrl; C:\Windows\system32\drivers\huawei_ext_ctrl.sys []
S3 moufiltr;Tablet Mouse Filter Driver; C:\Windows\system32\drivers\moufiltr.sys []
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2013-02-12 15872]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 35328]
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
S3 vhidmini;Generic Virtual HID Driver; C:\Windows\system32\drivers\vhidmini.sys []
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136]
S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 194048]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ADSMService;ADSM Service; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2007-05-18 73728]
R2 ASLDRService;ASLDR Service; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [2007-10-03 94208]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208]
R2 AVP;Služba Kaspersky Anti-Virus; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe [2012-10-29 206448]
R2 Bluetooth Low Energy Service;Bluetooth Low Energy Service; C:\Program Files\Motorola\Bluetooth\LEsrv.exe [2011-07-20 452656]
R2 Bluetooth Media Service;Bluetooth Media Service; C:\Program Files\Motorola\Bluetooth\audiosrv.exe [2011-07-20 948272]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files\Motorola\Bluetooth\obexsrv.exe [2011-06-17 566832]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 HTCMonitorService;HTCMonitorService; C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe [2014-08-04 87368]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 PassThru Service;Internet Pass-Through Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [2012-12-07 167424]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 RzKLService;RzKLService; C:\Program Files\Razer\Razer Cortex\RzKLService.exe [2014-08-28 105448]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
R3 Bluetooth Device Manager;Bluetooth Device Manager; C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe [2011-07-20 3538480]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-09-11 770168]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2011-12-07 647680]
S3 MatSvc;@%ProgramFiles%\Microsoft Fix it Center\MatsRes.dll,-9000; C:\Program Files\Microsoft Fix it Center\Matsvc.exe [2011-06-13 267568]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-03-12 271920]

-----------------EOF-----------------

Re: Prosím o kontrolu logu, NTB se chová divně

Napsal: 06 říj 2014 18:56
od Márty84
:!: Vsechny tyto programy - vcetne pripadne instalace - spoustejte jako spravce (kliknete na ne pravym mysidlem a zvolte - Spustit jako spravce)

:arrow: Prejmenujte ComboFix na Uninstall a spustte ho. CF by se mel odinstalovat.

:arrow:
vyosek píše: :arrow: T-Cleaner http://tharifas.sweb.cz/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry mohou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: Stahnete OTC http://oldtimer.geekstogo.com/OTC.exe , ulozte a spustte.
Kliknete na napis CleanUp a pote OK - Po uklidu dojde k restartu pc.

:arrow: Stahnete Ccleaner http://www.filehippo.com/download_ccleaner a spustte.
Pri instalaci pozor na toolbar (ci jine doplnky), jestli vam nabidne jeho instalaci, tak zruste zatrzitko.
Po spusteni se ocitnete ve funkci Cistic. Vlevo je spousta zatrzitek. Pozor dejte hlavne na kos, pokud nechate zatrzene, vzdy ho vysype.
Dale, podle toho jak je nastaven, smaze vsechna hesla ulozena na netu!!! Takze jestli mate nastavene, at si pocitac hesla pamatuje (coz neni pro bezpecnost dobre), budete je muset pak napsat znova rucne (napr mail, facebook, ruzna fora atd.)
Kliknete na Analyzovat a az dokonci analyzu, kliknete na Spustit Cleaner.
Potom kliknete vlevo na funkci Registry
Kliknete na Hledej problemy, kdyz najde, kliknete na Opravit problemy. Nabidne Vam zalohu, tu udelejte a ulozte ji tak, at ji v pripade potreby najdete.
Funkce Nastroje umoznuje odinstalovani programu. Je dukladnejsi nez samotny windows!
(Pokud je v pc vice uzivatelskych uctu, pouzijte program i v nich)

:arrow: Defragmentujte disk(y) (SSD Disky ne!)
Stahnete program Defraggler http://www.stahuj.centrum.cz/utility_a_ ... efraggler/
Pri instalaci opet pozor na toolbar
Po nainstalovani program spustte a kliknete na Analyzovat, po analyze kliknete na Defragmentovat a programek odvede svou praci.




:arrow: Pak napiste, jak je na tom pc. Pokud bude vse v poradku, mame hotovo.

Re: Prosím o kontrolu logu, NTB se chová divně

Napsal: 07 říj 2014 14:46
od Ariwen
Notebook je výrazně rychlejší a chová se, řekl bych, jak má.

Děkuji mnohokrát za pomoc. Opravdu si toho vážím, mějte se.

Re: Prosím o kontrolu logu, NTB se chová divně

Napsal: 07 říj 2014 17:51
od Márty84
To jsem rad :)

Nemate zac! ;-)

Mejte se a treba zase nekdy :bye:

:closed: