Stránka 1 z 1

Spomalenie PC a internetového pripojenia

Napsal: 26 říj 2010 20:23
od SiGnaL
Logfile of random's system information tool 1.08 (written by random/random)
Run by _c at 2010-10-26 21:09:59
WIN_XP Service Pack 2
System drive C: has 11 GB (13%) free of 80 GB
Total RAM: 2047 MB (74% free)

HijackThis download failed

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-746137067-362288127-725345543-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-746137067-362288127-725345543-1003UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1017A80C-6F09-4548-A84D-EDD6AC9525F0}]
Lexmark Panel nástrojů - C:\Program Files\Lexmark Toolbar\toolband.dll [2006-08-10 184320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-04 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-08-04 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{1017A80C-6F09-4548-A84D-EDD6AC9525F0} - Lexmark Panel nástrojů - C:\Program Files\Lexmark Toolbar\toolband.dll [2006-08-10 184320]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-08-01 61440]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2006-11-17 577536]
"Ashampoo FireWall"=C:\Program Files\Ashampoo\Ashampoo FireWall\FireWall.exe [2007-04-05 3251800]
"lxddmon.exe"=C:\Program Files\Lexmark 2500 Series\lxddmon.exe [2007-02-13 291760]
"lxddamon"=C:\Program Files\Lexmark 2500 Series\lxddamon.exe [2007-02-06 20480]
"FaxCenterServer"=C:\Program Files\Lexmark Fax Solutions\fm3032.exe [2007-02-13 312240]
"LXDDCATS"=rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDDtime.dll,_RunDLLEntry@16 []
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-21 932288]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2010-03-02 282792]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]
"Google Update"=C:\Documents and Settings\_c\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2010-09-17 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2008-02-19 267048]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2004-08-17 1667584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PromoReg]
C:\WINDOWS\TEMP\BN17.tmp []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-08-21 143360]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati5msxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati5msxx.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoResolveSearch"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Counter-Strike\hl.exe"="C:\Program Files\Counter-Strike\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\WINDOWS\system32\lxddcoms.exe"="C:\WINDOWS\system32\lxddcoms.exe:*:Enabled:Lexmark Communications System"
"C:\Program Files\Lexmark 2500 Series\lxddamon.exe"="C:\Program Files\Lexmark 2500 Series\lxddamon.exe:*:Enabled:Lexmark Device Monitor"
"C:\Program Files\Lexmark 2500 Series\App4R.exe"="C:\Program Files\Lexmark 2500 Series\App4R.exe:*:Enabled:Lexmark Imaging Studio"
"C:\WINDOWS\system32\dpnsvr.exe"="C:\WINDOWS\system32\dpnsvr.exe:*:Disabled:Microsoft DirectPlay8 Server"
"C:\Program Files\EA GAMES\Battlefield 2\BF2.exe"="C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:*:Enabled:Battlefield 2"
"C:\Program Files\ICQ7.2\ICQ.exe"="C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"C:\Program Files\ICQ7.2\aolload.exe"="C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Lexmark 2500 Series\app4r.exe"="C:\Program Files\Lexmark 2500 Series\App4R.exe:*:Enabled:BorgListener"
"C:\Program Files\ICQ7.2\ICQ.exe"="C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"C:\Program Files\ICQ7.2\aolload.exe"="C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"

======List of files/folders created in the last 1 months======

2010-10-26 21:09:59 ----D---- C:\rsit
2010-10-26 21:09:59 ----D---- C:\Program Files\trend micro
2010-10-26 15:45:33 ----D---- C:\Program Files\Gameforge4D
2010-10-26 00:40:28 ----D---- C:\Documents and Settings\All Users\Data aplikací\IObit
2010-10-23 18:26:37 ----A---- C:\DelUS.bat
2010-10-19 20:40:22 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-10-12 06:09:23 ----D---- C:\Documents and Settings\_c\Data aplikací\Avira
2010-10-11 16:02:36 ----A---- C:\WINDOWS\system32\drivers\ssmdrv.sys
2010-10-11 16:02:34 ----D---- C:\Program Files\Avira
2010-10-11 16:02:34 ----D---- C:\Documents and Settings\All Users\Data aplikací\Avira
2010-10-11 16:02:34 ----A---- C:\WINDOWS\system32\drivers\avipbb.sys
2010-10-11 16:02:34 ----A---- C:\WINDOWS\system32\drivers\avgntmgr.sys
2010-10-11 16:02:34 ----A---- C:\WINDOWS\system32\drivers\avgntflt.sys
2010-10-11 16:02:34 ----A---- C:\WINDOWS\system32\drivers\avgntdd.sys
2010-10-11 15:59:09 ----SHD---- C:\Config.Msi
2010-10-06 16:45:01 ----D---- C:\Program Files\Robster Productions
2010-10-05 22:12:04 ----D---- C:\Documents and Settings\_c\Data aplikací\Eltima Software
2010-10-05 22:11:52 ----D---- C:\Program Files\Eltima Software
2010-10-01 11:23:36 ----D---- C:\Program Files\AAMS
2010-09-29 18:14:02 ----D---- C:\Documents and Settings\_c\Data aplikací\AVG10
2010-09-29 18:09:07 ----HD---- C:\Documents and Settings\All Users\Data aplikací\Common Files
2010-09-29 18:08:17 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVG10
2010-09-29 17:58:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\MFAData

======List of files/folders modified in the last 1 months======

2010-10-26 21:09:59 ----RD---- C:\Program Files
2010-10-26 21:09:59 ----A---- C:\WINDOWS\ntbtlog.txt
2010-10-26 20:53:39 ----D---- C:\WINDOWS\Prefetch
2010-10-26 20:45:31 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-10-26 19:38:38 ----D---- C:\Documents and Settings\_c\Data aplikací\ICQ
2010-10-26 17:06:54 ----D---- C:\WINDOWS\system32\drivers
2010-10-26 16:50:17 ----D---- C:\WINDOWS\Temp
2010-10-26 16:50:16 ----D---- C:\WINDOWS\system32\CatRoot2
2010-10-26 16:50:10 ----D---- C:\WINDOWS
2010-10-26 15:50:52 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-10-26 15:45:28 ----A---- C:\WINDOWS\wincmd.ini
2010-10-23 18:27:22 ----D---- C:\Program Files\Metin2
2010-10-22 20:21:33 ----D---- C:\Documents and Settings\_c\Data aplikací\U3
2010-10-22 16:35:06 ----D---- C:\Program Files\Lx_cats
2010-10-22 01:42:29 ----D---- C:\Documents and Settings\_c\Data aplikací\uTorrent
2010-10-21 13:16:16 ----D---- C:\Program Files\Mozilla Firefox
2010-10-19 18:11:21 ----A---- C:\WINDOWS\dirsaver.ini
2010-10-19 12:08:02 ----D---- C:\Program Files\Counter-Strike
2010-10-11 16:17:56 ----D---- C:\WINDOWS\system32\NtmsData
2010-10-11 16:17:22 ----D---- C:\WINDOWS\Registration
2010-10-11 15:59:39 ----SHD---- C:\WINDOWS\Installer
2010-10-11 15:58:57 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-10-11 15:58:46 ----D---- C:\WINDOWS\system32
2010-10-04 01:26:32 ----D---- C:\Documents and Settings\_c\Data aplikací\vlc
2010-10-01 17:14:37 ----A---- C:\WINDOWS\AudioConverter.INI
2010-10-01 16:55:07 ----D---- C:\AudioConverter
2010-10-01 16:53:51 ----A---- C:\WINDOWS\aceg.ini
2010-09-29 18:08:54 ----HD---- C:\WINDOWS\inf

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSEH;AVGIDSEH; C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys [2010-09-13 25680]
R0 nv_agp;NVIDIA nForce AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\nv_agp.sys [2004-04-02 21760]
R0 nvatabus;nvatabus; C:\WINDOWS\system32\DRIVERS\nvatabus.sys [2004-06-03 79360]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2009-02-03 59000]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2006-06-14 13680]
R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:\WINDOWS\System32\drivers\sfsync02.sys [2006-07-10 27032]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\WINDOWS\System32\drivers\sfvfs02.sys [2007-02-08 83320]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-06-29 691696]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2010-03-01 124784]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2009-12-30 271360]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2010-02-16 60936]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2009-12-30 18048]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2007-01-25 4027456]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-08-21 3299840]
R3 bbcap;bbcap; C:\WINDOWS\system32\DRIVERS\bbcap.sys [2009-04-19 4096]
R3 EagleXNt;EagleXNt; \??\C:\WINDOWS\system32\drivers\EagleXNt.sys []
R3 GEARAspiWDM;GEARAspiWDM; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2006-09-19 15664]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2004-05-17 33280]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2004-05-17 12928]
S1 6c4cc79f;6c4cc79f; C:\WINDOWS\System32\drivers\6c4cc79f.sys []
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
S3 a1kelsti;a1kelsti; C:\WINDOWS\system32\drivers\a1kelsti.sys []
S3 ASFWHide;ASFWHide; \??\C:\DOCUME~1\_c\LOCALS~1\Temp\ASFWHide []
S3 EagleNT;EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys []
S3 hdcabab;hdcabab; C:\WINDOWS\System32\drivers\hdcabab.sys []
S3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-10-25 9600]
S3 lhh2b44;lhh2b44; C:\WINDOWS\System32\drivers\lhh2b44.sys []
S3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\WINDOWS\system32\DRIVERS\mcdbus.sys []
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2004-08-11 18944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2010-04-01 267432]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-08-21 573440]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-07-17 153376]
R2 lxdd_device;lxdd_device; C:\WINDOWS\system32\lxddcoms.exe [2007-02-13 537520]
R2 LXDDCustomerConnect;LXDDCustomerConnect; C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\LXDDserv.exe [2007-02-13 91056]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2008-08-20 593920]
S2 AVGIDSWatcher;AVGIDSWatcher; C:\Program Files\AVG\AVG8\IdentityProtection\agent\Bin\AVGIDSWatcher.exe []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-02-19 504104]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe []
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

-----------------EOF-----------------

Re: Spomalenie PC a internetového pripojenia

Napsal: 27 říj 2010 08:01
od JaRon
stiahni a uloz na plochu ComboFix

potom spust pod uctom s administratorskym opravnenim


akcia trva cca. 5-10 minut, niekedy i dlhsie -, Pocas scanu nespustaj ziadne ine aplikacie

Nie je dovod na paniku ak stroj bude restartovany
upozornenie: ak pouzivas antispyware s rezidentnim stitem, ten pred scanom vypni.

po restarte aplikacie vytvori log, ulozeny na C:\Combofix.txt (jeho obsah vloz sem)

Re: Spomalenie PC a internetového pripojenia

Napsal: 27 říj 2010 12:47
od SiGnaL
Tak ComboFix mi comp restarol takmer okamžite, a výsledok už vidíte nižšie.


ComboFix 10-10-26.03 - _c . 10. 2010 13:34:42.1.1 - x86
Spuštěný z: c:\documents and settings\_c\Plocha\Download\ComboFix.exe
* Vytvořen nový Bod Obnovení

VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\DelUS.bat
D:\resycled

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_fci
-------\Legacy_gaopdxserv.sys
-------\Legacy_tcpsr
-------\Service_gaopdxserv.sys


((((((((((((((((((((((((( Soubory vytvořené od 2010-09-27 do 2010-10-27 )))))))))))))))))))))))))))))))
.

2010-10-26 19:09 . 2010-10-26 19:10 -------- d-----w- C:\rsit
2010-10-26 19:09 . 2010-10-26 19:09 -------- d-----w- c:\program files\trend micro
2010-10-26 13:45 . 2010-10-26 13:45 -------- d-----w- c:\program files\Gameforge4D
2010-10-25 22:40 . 2010-10-25 22:40 -------- d-----w- c:\documents and settings\All Users\Data aplikací\IObit
2010-10-19 18:40 . 2010-10-26 18:45 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-10-18 11:30 . 2010-10-18 11:30 1409 ----a-w- c:\windows\QTFont.for
2010-10-12 04:09 . 2010-10-12 04:09 -------- d-----w- c:\documents and settings\_c\Data aplikací\Avira
2010-10-11 14:02 . 2010-10-11 14:02 -------- d-----w- c:\program files\Avira
2010-10-11 14:02 . 2010-10-11 14:02 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Avira
2010-10-11 14:02 . 2010-03-01 08:05 124784 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-10-11 14:02 . 2010-02-16 12:24 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-10-11 14:02 . 2009-05-11 10:49 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-10-11 14:02 . 2009-05-11 10:49 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-10-06 14:45 . 2010-10-06 14:45 -------- d-----w- c:\program files\Robster Productions
2010-10-05 20:12 . 2010-10-05 20:12 -------- d-----w- c:\documents and settings\_c\Data aplikací\Eltima Software
2010-10-05 20:11 . 2010-10-05 20:11 -------- d-----w- c:\program files\Eltima Software
2010-10-03 23:27 . 2010-10-03 23:27 143360 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2010-10-03 23:27 . 2010-10-03 23:27 143360 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2010-10-03 23:27 . 2010-10-03 23:27 143360 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2010-10-03 23:27 . 2010-10-03 23:27 143360 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2010-10-03 23:27 . 2010-10-03 23:27 143360 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2010-10-03 23:27 . 2010-10-03 23:27 143360 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2010-10-03 23:27 . 2010-10-03 23:27 143360 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2010-10-01 09:23 . 2010-10-01 09:23 -------- d-----w- c:\program files\AAMS
2010-09-29 16:14 . 2010-09-29 16:14 -------- d-----w- c:\documents and settings\_c\Data aplikací\AVG10
2010-09-29 16:09 . 2010-09-29 16:09 -------- d-----w- c:\documents and settings\LocalService\Plocha
2010-09-29 16:09 . 2010-09-29 16:09 -------- d--h--w- c:\documents and settings\All Users\Data aplikací\Common Files
2010-09-29 16:08 . 2010-10-11 13:59 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVG10
2010-09-29 15:58 . 2010-09-29 16:07 -------- d-----w- c:\documents and settings\All Users\Data aplikací\MFAData

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-13 14:27 . 2010-09-13 14:27 25680 ----a-w- c:\windows\system32\drivers\AVGIDSEH.sys
2010-08-01 14:46 . 2010-08-01 14:46 640017 ----a-w- c:\windows\system32\qt6B.tmp
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\_c\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2010-09-17 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-01 61440]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 577536]
"Ashampoo FireWall"="c:\program files\Ashampoo\Ashampoo FireWall\FireWall.exe" [2007-04-05 3251800]
"lxddmon.exe"="c:\program files\Lexmark 2500 Series\lxddmon.exe" [2007-02-12 291760]
"lxddamon"="c:\program files\Lexmark 2500 Series\lxddamon.exe" [2007-02-05 20480]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2007-02-13 312240]
"LXDDCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXDDtime.dll" [2007-01-22 102400]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sprestrt

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2008-02-19 12:10 267048 ----a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-08-17 14:58 1667584 ------w- c:\program files\Messenger\msmsgs.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Counter-Strike\\hl.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\lxddcoms.exe"=
"c:\\Program Files\\Lexmark 2500 Series\\lxddamon.exe"=
"c:\\Program Files\\Lexmark 2500 Series\\App4R.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=

R1 6c4cc79f;6c4cc79f;c:\windows\System32\drivers\6c4cc79f.sys [2009-02-09 0]
R2 AVGIDSWatcher;AVGIDSWatcher;c:\program files\AVG\AVG8\IdentityProtection\agent\Bin\AVGIDSWatcher.exe [x]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 hdcabab;hdcabab;c:\windows\System32\drivers\hdcabab.sys [x]
R3 lhh2b44;lhh2b44;c:\windows\System32\drivers\lhh2b44.sys [x]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-06-29 691696]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2010-09-13 25680]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
S2 lxdd_device;lxdd_device;c:\windows\system32\lxddcoms.exe [2007-02-12 537520]
S2 LXDDCustomerConnect;LXDDCustomerConnect;c:\windows\System32\spool\DRIVERS\W32X86\3\\LXDDserv.exe [2007-02-12 91056]
S3 bbcap;bbcap;c:\windows\system32\DRIVERS\bbcap.sys [2009-04-19 4096]

.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://qip.ru
uDefault_Search_URL = hxxp://search.qip.ru
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://search.qip.ru/ie
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\program files\Ashampoo\Ashampoo FireWall\spi.dll
TCP: {1FE75DFA-5947-47AA-B453-2BE044812CD0} = 213.215.79.146,213.215.79.147
FF - ProfilePath - c:\documents and settings\_c\Data aplikací\Mozilla\Firefox\Profiles\e7od3iis.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.fastbrowsersearch.com/results/resul ... EF&v=18&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://azet.sk
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll

---- NASTAVENÍ FIREFOXU ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

SafeBoot-ati5msxx.sys
MSConfigStartUp-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
MSConfigStartUp-NeroFilterCheck - c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
MSConfigStartUp-PromoReg - c:\windows\TEMP\BN17.tmp
AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-27 13:39
Windows 5.1.2600 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXDDCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXDDtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\controlset003\Services\ASFWHide]
"ImagePath"="\??\c:\docume~1\_c\LOCALS~1\Temp\ASFWHide"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(716)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(772)
c:\program files\Ashampoo\Ashampoo FireWall\spi.dll

- - - - - - - > 'explorer.exe'(196)
c:\windows\system32\msi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\SOUNDMAN.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\System32\spool\DRIVERS\W32X86\3\LXDDserv.exe
c:\windows\system32\wdfmgr.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2010-10-27 13:43:50 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-10-27 11:43

Před spuštěním: Volných bajtů: 14 617 251 840
Po spuštění: Volných bajtů: 14 496 202 752

Current=3 Default=3 Failed=6 LastKnownGood=4 Sets=1,2,3,4,5,6
- - End Of File - - 39D37750EE94410FD115564E33154465

Re: Spomalenie PC a internetového pripojenia

Napsal: 27 říj 2010 13:44
od JaRon
no je to o cosi lepsie :)
c:\program files\AVG\AVG8 - toto bud odinstaluj, alebo ZMAZ adresar
+
vycisti PC s CureIT

Re: Spomalenie PC a internetového pripojenia

Napsal: 28 říj 2010 13:07
od SiGnaL
To AVG zmazať neviem, lebo ten súbor neexistuje, alebo ho neviem nájsť... No aj Tak sa moje pripojenie podstatne zrýchlilo, a taktiež aj celý comp. Vďaka za pomoc :)

Re: Spomalenie PC a internetového pripojenia

Napsal: 28 říj 2010 13:22
od JaRon
OKi - nemas zac - ak by cosi, ukaz sa :)