Stránka 1 z 1

Divné chování PC - POMOC rychle prosím

Napsal: 27 říj 2010 18:00
od Castab
Počítač se opravdu začal chovat divně. Z ničeho nic mi odešel antivirový program a píše to chybu se spojení s jádrem. Dále se mi na začátku systému vypne na chvíli brána firewall a pak zase zapnu. Celkem často to na 5s zamrzá. Děkuji za pomoc. A nechce mi to dovolit nainstalovat znova ESETnod prý při instalaci nemam dostatečná práva..


Logfile of random's system information tool 1.08 (written by random/random)
Run by Kebaß at 2010-10-27 19:00:41
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 115 GB (76%) free of 153 GB
Total RAM: 1023 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:00:44, on 27.10.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Gamesy\World of Warcraft\Wow.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Kebaß\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Kebaß\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Kebaß\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Kebaß\Dokumenty\Downloads\RSIT.exe
C:\Program Files\trend micro\Kebaß.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe

--
End of file - 4643 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-10-03 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-10-03 79648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-08-12 2215064]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2003-11-13 62464]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-05-16 13529088]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-05-16 86016]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"NeroFilterCheck"=C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2008-06-19 570664]
"NBKeyScan"=C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2008-06-08 2221352]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-06-24 1840424]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoRealMode"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Gamesy\World of Warcraft\WoW-3.2.0-enGB-downloader.exe"="C:\Gamesy\World of Warcraft\WoW-3.2.0-enGB-downloader.exe:*:Disabled:Blizzard Downloader"
"C:\Gamesy\World of Warcraft\Launcher.exe"="C:\Gamesy\World of Warcraft\Launcher.exe:*:Disabled:Blizzard Launcher"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-10-27 18:57:54 ----D---- C:\Program Files\CCleaner
2010-10-27 14:01:28 ----HDC---- C:\WINDOWS\$NtUninstallKB963093$
2010-10-27 13:49:58 ----D---- C:\Program Files\Microsoft.NET
2010-10-27 13:48:53 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\Windows Search
2010-10-27 13:48:33 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\Windows Desktop Search
2010-10-27 13:48:08 ----D---- C:\WINDOWS\system32\GroupPolicy
2010-10-27 13:48:08 ----D---- C:\Program Files\Windows Desktop Search
2010-10-27 13:48:03 ----HDC---- C:\WINDOWS\$NtUninstallKB940157$
2010-10-27 13:47:59 ----HDC---- C:\WINDOWS\$NtUninstallKB915800-v4$
2010-10-27 13:47:13 ----HDC---- C:\WINDOWS\$NtUninstallKB971513$
2010-10-27 13:37:07 ----D---- C:\Documents and Settings\All Users\Data aplikací\Weskysoft
2010-10-27 13:09:34 ----D---- C:\Program Files\Perfect Optimizer
2010-10-22 22:55:49 ----D---- C:\WINDOWS\nview
2010-10-21 13:15:48 ----D---- C:\WINDOWS\Sun
2010-10-20 15:16:20 ----A---- C:\WINDOWS\unTMV.exe
2010-10-20 15:14:01 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\ODF
2010-10-20 15:13:46 ----D---- C:\Program Files\OD Fellowship
2010-10-14 07:08:04 ----A---- C:\WINDOWS\system32\Audio3D.dll
2010-10-14 07:08:04 ----A---- C:\WINDOWS\system32\a3d.dll
2010-10-14 07:08:03 ----A---- C:\WINDOWS\system32\drivers\ALCXSENS.SYS
2010-10-14 07:08:01 ----N---- C:\WINDOWS\alcupd.exe
2010-10-14 07:08:01 ----HD---- C:\Program Files\InstallShield Installation Information
2010-10-14 06:28:45 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2010-10-14 06:27:48 ----HDC---- C:\WINDOWS\$NtUninstallKB2279986$
2010-10-14 06:27:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2010-10-14 06:26:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2010-10-14 06:26:13 ----A---- C:\WINDOWS\system32\wmpns.dll
2010-10-14 06:26:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2010-10-14 06:25:54 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2010-10-14 06:25:16 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2010-10-14 06:21:19 ----HDC---- C:\WINDOWS\$NtUninstallKB981957$
2010-10-14 06:21:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$
2010-10-06 20:43:28 ----SHD---- C:\RECYCLER
2010-10-06 20:17:10 ----D---- C:\Program Files\Lavalys
2010-10-05 21:10:00 ----D---- C:\WINDOWS\temp
2010-10-05 21:05:15 ----A---- C:\Boot.bak
2010-10-05 21:05:13 ----RASHD---- C:\cmdcons
2010-10-05 19:27:34 ----D---- C:\Program Files\Teamspeak2_RC2
2010-10-05 18:19:18 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\TS3Client
2010-10-05 16:36:38 ----A---- C:\WINDOWS\UPGRADE.TXT
2010-10-05 07:13:34 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-10-04 20:37:07 ----N---- C:\WINDOWS\alcrmv.exe
2010-10-04 20:37:07 ----A---- C:\WINDOWS\system32\RTLCPAPI.dll
2010-10-04 20:37:07 ----A---- C:\WINDOWS\system32\drivers\ALCXWDM.SYS
2010-10-04 20:37:07 ----A---- C:\WINDOWS\SOUNDMAN.EXE
2010-10-04 20:19:22 ----A---- C:\WINDOWS\NeroDigital.ini
2010-10-04 18:04:07 ----D---- C:\Documents and Settings\All Users\Data aplikací\NVIDIA
2010-10-04 17:52:57 ----D---- C:\d95dc170031c07c7db7c
2010-10-04 07:51:48 ----D---- C:\WINDOWS\system32\Lang
2010-10-04 07:44:15 ----A---- C:\WINDOWS\system32\nvumpu.exe
2010-10-03 15:27:30 ----HDC---- C:\WINDOWS\$NtUninstallXPSEPSCLP$
2010-10-03 15:26:03 ----D---- C:\Program Files\MSBuild
2010-10-03 15:26:00 ----D---- C:\WINDOWS\system32\XPSViewer
2010-10-03 15:25:55 ----D---- C:\WINDOWS\system32\en-us
2010-10-03 15:25:55 ----D---- C:\Program Files\Reference Assemblies
2010-10-03 15:25:35 ----N---- C:\WINDOWS\system32\spmsg2.dll
2010-10-03 15:20:24 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sun
2010-10-03 15:20:23 ----D---- C:\Program Files\Common Files\Java
2010-10-03 15:20:13 ----A---- C:\WINDOWS\system32\javaws.exe
2010-10-03 15:20:13 ----A---- C:\WINDOWS\system32\javaw.exe
2010-10-03 15:20:13 ----A---- C:\WINDOWS\system32\java.exe
2010-10-03 15:20:13 ----A---- C:\WINDOWS\system32\deployJava1.dll
2010-10-03 15:19:58 ----D---- C:\Program Files\Java
2010-10-03 15:19:45 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\Sun
2010-10-03 15:13:20 ----D---- C:\WINDOWS\system32\appmgmt
2010-10-03 15:13:16 ----D---- C:\WINDOWS\SxsCaPendDel
2010-10-03 14:58:48 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2010-10-03 13:58:49 ----D---- C:\rsit
2010-10-03 11:09:47 ----D---- C:\Program Files\MSXML 4.0
2010-10-03 00:25:16 ----A---- C:\WINDOWS\system32\MsiExec.exe.log
2010-10-03 00:21:45 ----D---- C:\Program Files\Nero
2010-10-03 00:20:18 ----D---- C:\WINDOWS\RegisteredPackages
2010-10-03 00:19:33 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2010-10-03 00:19:31 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2010-10-02 23:29:56 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\Malwarebytes
2010-10-02 23:29:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-10-02 23:29:44 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-10-02 15:24:05 ----D---- C:\WINDOWS\Minidump
2010-10-02 14:21:34 ----D---- C:\WINDOWS\pss
2010-10-02 14:06:36 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\AskToolbar
2010-10-02 13:32:04 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\Nero
2010-10-02 13:31:04 ----D---- C:\Documents and Settings\All Users\Data aplikací\Nero
2010-10-02 13:31:01 ----D---- C:\Program Files\Common Files\Nero
2010-10-02 13:28:27 ----A---- C:\WINDOWS\system32\AdvrCntr4.dll
2010-10-02 13:16:06 ----D---- C:\Program Files\SlySoft
2010-10-02 01:55:26 ----D---- C:\Program Files\trend micro
2010-09-30 22:11:22 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\WinRAR
2010-09-30 22:11:08 ----D---- C:\Program Files\WinRAR
2010-09-30 21:48:17 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\mIRC
2010-09-29 06:25:42 ----HDC---- C:\WINDOWS\$NtUninstallKB979402_WM9$
2010-09-29 06:25:35 ----HDC---- C:\WINDOWS\$NtUninstallKB2158563$
2010-09-28 17:15:33 ----D---- C:\Documents and Settings\Kebaß\Data aplikací\teamspeak2
2010-09-28 10:24:33 ----D---- C:\Documents and Settings\All Users\Data aplikací\Blizzard Entertainment
2010-09-28 03:37:38 ----D---- C:\Documents and Settings\All Users\Data aplikací\Windows Genuine Advantage
2010-09-28 01:06:09 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
2010-09-28 00:53:16 ----RSD---- C:\WINDOWS\assembly
2010-09-28 00:51:51 ----D---- C:\WINDOWS\Microsoft.NET

======List of files/folders modified in the last 1 months======

2010-10-27 18:58:35 ----D---- C:\WINDOWS\Prefetch
2010-10-27 18:58:01 ----AD---- C:\WINDOWS
2010-10-27 18:57:54 ----RD---- C:\Program Files
2010-10-27 18:56:34 ----RASH---- C:\boot.ini
2010-10-27 18:56:34 ----A---- C:\WINDOWS\win.ini
2010-10-27 18:56:34 ----A---- C:\WINDOWS\system.ini
2010-10-27 18:54:03 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-10-27 14:04:36 ----D---- C:\WINDOWS\system32
2010-10-27 14:03:56 ----D---- C:\WINDOWS\system32\config
2010-10-27 14:01:35 ----HD---- C:\WINDOWS\inf
2010-10-27 13:59:39 ----D---- C:\WINDOWS\system32\CatRoot2
2010-10-27 13:55:10 ----SHD---- C:\WINDOWS\Installer
2010-10-27 13:55:10 ----D---- C:\Config.Msi
2010-10-27 13:54:51 ----D---- C:\WINDOWS\system32\cs-CZ
2010-10-27 13:54:20 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-10-27 13:50:27 ----D---- C:\WINDOWS\WinSxS
2010-10-27 13:49:13 ----D---- C:\WINDOWS\system32\CatRoot
2010-10-27 13:48:17 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-10-27 13:48:08 ----D---- C:\WINDOWS\system32\wbem
2010-10-27 13:48:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-10-27 13:37:07 ----SD---- C:\WINDOWS\Tasks
2010-10-27 10:36:36 ----D---- C:\Documents and Settings
2010-10-23 09:06:29 ----D---- C:\WINDOWS\Debug
2010-10-22 22:55:52 ----D---- C:\WINDOWS\Help
2010-10-22 22:55:38 ----D---- C:\WINDOWS\system32\drivers
2010-10-19 01:02:20 ----SD---- C:\Documents and Settings\Kebaß\Data aplikací\Microsoft
2010-10-14 07:08:20 ----D---- C:\WINDOWS\system
2010-10-14 07:07:59 ----D---- C:\Program Files\Common Files\InstallShield
2010-10-14 07:06:49 ----D---- C:\Program Files\Common Files
2010-10-14 06:28:15 ----HD---- C:\WINDOWS\$hf_mig$
2010-10-14 06:24:26 ----D---- C:\Program Files\Internet Explorer
2010-10-14 06:21:29 ----A---- C:\WINDOWS\system32\MRT.exe
2010-10-06 20:15:52 ----D---- C:\WINDOWS\system32\Restore
2010-10-06 06:48:56 ----D---- C:\WINDOWS\system32\drivers\etc
2010-10-06 06:47:47 ----D---- C:\WINDOWS\AppPatch
2010-10-05 18:18:39 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-10-04 18:00:30 ----D---- C:\NVIDIA
2010-10-04 17:53:26 ----RSD---- C:\WINDOWS\Fonts
2010-10-03 00:21:42 ----D---- C:\WINDOWS\Cursors
2010-10-03 00:20:46 ----D---- C:\WINDOWS\security
2010-10-03 00:20:46 ----D---- C:\Program Files\Windows Media Player
2010-10-03 00:19:33 ----D---- C:\WINDOWS\system32\DirectX
2010-10-02 01:36:53 ----D---- C:\Gamesy
2010-09-28 00:51:56 ----D---- C:\WINDOWS\system32\mui
2010-09-28 00:04:34 ----D---- C:\WINDOWS\SoftwareDistribution

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 nv_agp;NVIDIA nForce AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\nv_agp.sys [2004-04-02 21760]
R0 nvatabus;nvatabus; C:\WINDOWS\system32\DRIVERS\nvatabus.sys [2004-06-03 79360]
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-14 41600]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2010-07-29 115008]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2010-08-03 95896]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2010-08-04 140752]
R3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2003-11-13 391680]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2003-11-13 481596]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-11-18 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-05-16 6557408]
R3 NVENET;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENET.sys [2004-01-29 93764]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 EverestDriver;Lavalys EVEREST Kernel Driver; \??\C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt []
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-10-03 153376]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-06-08 877864]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-05-16 159812]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2010-08-12 33584]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-08-12 810144]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Divné chování PC

Napsal: 27 říj 2010 18:07
od Rudy
Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode, pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k nezadoucim kolizim s rezidentem antispyware

Re: Divné chování PC - POMOC rychle prosím

Napsal: 27 říj 2010 18:11
od Castab
jdu na to. stáhl jsem program perfect optimilizer a teď ho nemuzu ani smazat .. a nejde mi se dosatat do nouzoveho rezimu..

// problemy zacli od te doby co jsme ho použil

Re: Divné chování PC - POMOC rychle prosím

Napsal: 27 říj 2010 18:20
od Castab
Smazalo to všechny složky s Perfect optimilizer.. Byl to vir, nebo se mi někdo snažil nabourat do PC? Proč by to jinak vypínalo firewall

// Furt mi to nechce dovolit nainstalovat Antivirus.
// Nouzový režim už jde
// Brána firewall se vždy na začátku vypne a pak zapne, když jí chci zapnout ručně tak to píše, že z neznámých důvodů jí to nemůže zapnout.
// Ani z regedit nejde Eset odstranit něco to blokuje.


ComboFix 10-10-26.04 - Kebaß 27.10.2010 19:14:06.3.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1023.731 [GMT 2:00]
Spuštěný z: c:\documents and settings\Kebaß\Plocha\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Kebaß\Nabídka Start\Programy\Perfect Optimizer
c:\documents and settings\Kebaß\Nabídka Start\Programy\Perfect Optimizer\Perfect Optimizer.lnk
c:\documents and settings\Kebaß\Nabídka Start\Programy\Perfect Optimizer\Uninstall.lnk
c:\documents and settings\Kebaß\Nabídka Start\Programy\Perfect Optimizer\Website.lnk
c:\documents and settings\Kebaß\Plocha\Perfect Optimizer.lnk
c:\program files\Perfect Optimizer
c:\program files\Perfect Optimizer\aamd532.dll
c:\program files\Perfect Optimizer\ActiveX.dat
c:\program files\Perfect Optimizer\Apps.dat
c:\program files\Perfect Optimizer\Backup\Application\ActiveX.dat
c:\program files\Perfect Optimizer\Backup\Application\Apps.dat
c:\program files\Perfect Optimizer\Backup\Application\Components.dat
c:\program files\Perfect Optimizer\Backup\Application\MFC42D.DLL
c:\program files\Perfect Optimizer\Backup\Application\MFCO42D.DLL
c:\program files\Perfect Optimizer\Backup\Application\MSVCRTD.DLL
c:\program files\Perfect Optimizer\Backup\Application\Perfect Optimizer.url
c:\program files\Perfect Optimizer\Backup\Application\PerfectOptimizer.exe
c:\program files\Perfect Optimizer\Backup\Application\PerfectOptimizer.ini
c:\program files\Perfect Optimizer\Backup\Application\SEClean.dll
c:\program files\Perfect Optimizer\Backup\Application\SECleaner.dll
c:\program files\Perfect Optimizer\Backup\Application\SERepair.dll
c:\program files\Perfect Optimizer\Backup\Application\SEShred.dll
c:\program files\Perfect Optimizer\Backup\Application\SEStyle.dll
c:\program files\Perfect Optimizer\Backup\Application\unins000.dat
c:\program files\Perfect Optimizer\Backup\Application\unins000.exe
c:\program files\Perfect Optimizer\Backup\Application\Update.exe
c:\program files\Perfect Optimizer\Backup\Registry\FullBackup\20101027185247.Reg
c:\program files\Perfect Optimizer\Components.dat
c:\program files\Perfect Optimizer\Config.db
c:\program files\Perfect Optimizer\config\about.bmp
c:\program files\Perfect Optimizer\config\head.bmp
c:\program files\Perfect Optimizer\config\Lng2Const.xml
c:\program files\Perfect Optimizer\config\logo.ico
c:\program files\Perfect Optimizer\config\Menu.xml
c:\program files\Perfect Optimizer\config\PerfectOptimzer.chm
c:\program files\Perfect Optimizer\config\register.jpg
c:\program files\Perfect Optimizer\config\SmallLogo.bmp
c:\program files\Perfect Optimizer\config\splash.jpg
c:\program files\Perfect Optimizer\config\website.url
c:\program files\Perfect Optimizer\Data\Service\campus_model.bat
c:\program files\Perfect Optimizer\Data\Service\default_model.bat
c:\program files\Perfect Optimizer\Data\Service\home_model.bat
c:\program files\Perfect Optimizer\Data\Service\interner_model.bat
c:\program files\Perfect Optimizer\Data\Service\notebook_model.bat
c:\program files\Perfect Optimizer\Data\Service\office_model.bat
c:\program files\Perfect Optimizer\FreeUse.dll
c:\program files\Perfect Optimizer\InstallDll.dll
c:\program files\Perfect Optimizer\License.dll
c:\program files\Perfect Optimizer\License.ini
c:\program files\Perfect Optimizer\MiracleLib.dll
c:\program files\Perfect Optimizer\PerfectOptimizer.exe
c:\program files\Perfect Optimizer\PerfectOptimizer.ini
c:\program files\Perfect Optimizer\report.html
c:\program files\Perfect Optimizer\SEClean.DLL
c:\program files\Perfect Optimizer\SERes.DLL
c:\program files\Perfect Optimizer\sqlite3.dll
c:\program files\Perfect Optimizer\unins000.dat
c:\program files\Perfect Optimizer\unins000.exe
c:\program files\Perfect Optimizer\Update.exe
c:\program files\Perfect Optimizer\Update\Update.zip
c:\program files\Perfect Optimizer\website.url
c:\program files\Perfect Optimizer\WinUpdate.exe

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-09-27 do 2010-10-27 )))))))))))))))))))))))))))))))
.

2010-10-27 11:49 . 2010-10-27 11:49 -------- d-----w- c:\program files\Microsoft.NET
2010-10-27 11:48 . 2010-10-27 11:48 -------- d-----w- c:\documents and settings\Kebaß\Data aplikací\Windows Search
2010-10-27 11:48 . 2010-10-27 11:48 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-10-27 11:48 . 2010-10-27 11:48 -------- d-----w- c:\documents and settings\Kebaß\Data aplikací\Windows Desktop Search
2010-10-27 11:48 . 2010-10-27 12:01 -------- d-----w- c:\program files\Windows Desktop Search
2010-10-27 11:48 . 2010-10-27 11:48 -------- d-----w- c:\windows\system32\GroupPolicy
2010-10-27 11:47 . 2008-03-07 17:02 98304 -c----w- c:\windows\system32\dllcache\nlhtml.dll
2010-10-27 11:47 . 2008-03-07 17:02 29696 -c----w- c:\windows\system32\dllcache\mimefilt.dll
2010-10-27 11:47 . 2008-03-07 17:02 192000 -c----w- c:\windows\system32\dllcache\offfilt.dll
2010-10-27 11:37 . 2010-10-27 11:37 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Weskysoft
2010-10-27 08:36 . 2010-10-27 08:37 -------- d-----w- c:\documents and settings\Administrator
2010-10-22 20:55 . 2010-10-22 20:55 -------- d-----w- c:\windows\nview
2010-10-21 11:15 . 2010-10-21 11:15 -------- d-----w- c:\windows\Sun
2010-10-21 06:50 . 2010-10-21 06:50 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\ESET
2010-10-20 13:16 . 2010-02-03 16:27 68640 ----a-w- c:\windows\unTMV.exe
2010-10-20 13:14 . 2010-10-20 13:14 -------- d-----w- c:\documents and settings\Kebaß\Local Settings\Data aplikací\ODF
2010-10-20 13:14 . 2010-10-20 13:14 -------- d-----w- c:\documents and settings\Kebaß\Data aplikací\ODF
2010-10-20 13:13 . 2010-10-20 13:13 -------- d-----w- c:\program files\OD Fellowship
2010-10-14 05:08 . 2003-08-19 17:36 65536 -c--a-w- c:\windows\system32\dllcache\a3d.dll
2010-10-14 05:08 . 2003-08-19 17:36 65536 ----a-w- c:\windows\system32\Audio3D.dll
2010-10-14 05:08 . 2003-08-19 17:36 65536 ----a-w- c:\windows\system32\a3d.dll
2010-10-14 05:08 . 2002-11-21 13:07 765952 ----a-w- c:\windows\system\crlds3d.dll
2010-10-14 05:08 . 2003-11-13 17:25 391680 ----a-w- c:\windows\system32\drivers\ALCXSENS.SYS
2010-10-14 05:08 . 2010-10-14 05:08 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-10-14 05:08 . 2003-11-21 14:58 208896 ------w- c:\windows\alcupd.exe
2010-10-14 05:07 . 2001-04-11 16:25 77824 ----a-w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\ctor.dll
2010-10-14 05:07 . 2001-04-11 16:25 225280 ----a-w- c:\program files\Common Files\InstallShield\IScript\IScript.dll
2010-10-14 05:07 . 2001-04-11 16:21 176128 ----a-w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\iuser.dll
2010-10-14 05:07 . 2001-04-11 16:20 32768 ----a-w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\objectps.dll
2010-10-14 05:07 . 2000-01-04 04:39 212992 ----a-w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\ILog.dll
2010-10-14 04:26 . 2008-04-14 03:22 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-10-14 04:17 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-14 04:17 . 2010-09-18 06:53 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
2010-10-14 04:17 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2010-10-07 15:02 . 2010-10-07 15:02 -------- d-----w- c:\documents and settings\Kebaß\Local Settings\Data aplikací\ESET
2010-10-06 18:17 . 2010-10-06 18:17 -------- d-----w- c:\program files\Lavalys
2010-10-05 17:27 . 2010-10-05 17:27 -------- d-----w- c:\program files\Teamspeak2_RC2
2010-10-05 16:19 . 2010-10-05 16:53 -------- d-----w- c:\documents and settings\Kebaß\Data aplikací\TS3Client
2010-10-04 18:37 . 2003-11-21 14:56 139264 ------w- c:\windows\alcrmv.exe
2010-10-04 18:37 . 2003-11-13 16:23 62464 ----a-w- c:\windows\SOUNDMAN.EXE
2010-10-04 18:37 . 2003-11-13 13:05 481596 ----a-w- c:\windows\system32\drivers\ALCXWDM.SYS
2010-10-04 18:37 . 2002-01-01 22:54 147456 ----a-w- c:\windows\system32\RTLCPAPI.dll
2010-10-04 18:37 . 2003-11-13 14:36 13469696 ----a-w- c:\windows\system32\ALSNDMGR.CPL
2010-10-04 16:04 . 2010-10-04 16:04 -------- d-----w- c:\documents and settings\All Users\Data aplikací\NVIDIA
2010-10-04 15:52 . 2010-10-04 15:53 -------- d-----w- C:\d95dc170031c07c7db7c
2010-10-04 05:51 . 2010-10-04 05:51 -------- d-----w- c:\windows\system32\Lang
2010-10-04 05:49 . 2006-02-07 13:45 757760 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
2010-10-04 05:49 . 2006-02-07 13:40 204800 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
2010-10-04 05:49 . 2006-02-07 13:40 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
2010-10-04 05:49 . 2006-02-07 13:40 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
2010-10-04 05:49 . 2005-11-13 21:19 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
2010-10-04 05:49 . 2010-10-04 05:49 331908 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
2010-10-04 05:49 . 2010-10-04 05:49 200836 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
2010-10-04 05:44 . 2006-06-01 17:09 208896 ----a-w- c:\windows\system32\nvumpu.exe
2010-10-03 13:26 . 2010-10-03 13:26 -------- d-----w- c:\program files\MSBuild
2010-10-03 13:26 . 2010-10-04 15:53 -------- d-----w- c:\windows\system32\XPSViewer
2010-10-03 13:25 . 2010-10-03 13:25 -------- d-----w- c:\program files\Reference Assemblies
2010-10-03 13:25 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-10-03 13:25 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll
2010-10-03 13:20 . 2010-10-03 13:20 -------- d-----w- c:\program files\Common Files\Java
2010-10-03 13:20 . 2010-10-03 13:20 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-10-03 13:20 . 2010-10-03 13:20 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-10-03 13:19 . 2010-10-03 13:19 -------- d-----w- c:\program files\Java
2010-10-03 13:13 . 2010-10-03 13:18 -------- d-----w- c:\windows\SxsCaPendDel
2010-10-03 11:58 . 2010-10-03 11:58 -------- d-----w- C:\rsit
2010-10-03 09:09 . 2010-10-03 09:09 -------- d-----w- c:\program files\MSXML 4.0
2010-10-02 22:26 . 2010-10-02 22:26 -------- d-----w- c:\documents and settings\Kebaß\Local Settings\Data aplikací\Ahead
2010-10-02 22:21 . 2010-10-02 22:21 -------- d-----w- c:\program files\Nero
2010-10-02 22:20 . 2004-08-10 23:45 819200 ----a-w- c:\program files\Windows Media Player\wmsetsdk.exe
2010-10-02 22:20 . 2004-08-10 23:45 47616 ----a-w- c:\program files\Windows Media Player\msoobci.dll
2010-10-02 21:29 . 2010-10-02 21:29 -------- d-----w- c:\documents and settings\Kebaß\Data aplikací\Malwarebytes
2010-10-02 21:29 . 2010-10-02 21:29 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2010-10-02 21:29 . 2010-10-06 18:44 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-02 12:06 . 2010-10-02 12:06 -------- d-----w- c:\documents and settings\Kebaß\Data aplikací\AskToolbar
2010-10-02 12:06 . 2010-10-02 12:06 -------- d-----w- c:\documents and settings\Kebaß\Local Settings\Data aplikací\AskToolbar
2010-10-02 11:32 . 2010-10-02 11:36 -------- d-----w- c:\documents and settings\Kebaß\Data aplikací\Nero
2010-10-02 11:31 . 2010-10-02 22:21 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Nero
2010-10-02 11:31 . 2010-10-02 22:24 -------- d-----w- c:\program files\Common Files\Nero
2010-10-02 11:28 . 2008-10-29 12:01 5723432 ----a-w- c:\windows\system32\AdvrCntr4.dll
2010-10-02 11:16 . 2010-10-02 11:22 -------- d-----w- c:\program files\SlySoft
2010-10-01 23:55 . 2010-10-27 17:00 -------- d-----w- c:\program files\trend micro
2010-09-30 19:48 . 2010-09-30 20:02 -------- d-----w- c:\documents and settings\Kebaß\Data aplikací\mIRC
2010-09-28 15:15 . 2010-10-27 08:28 -------- d-----w- c:\documents and settings\Kebaß\Data aplikací\teamspeak2
2010-09-28 15:15 . 2010-09-28 15:15 34064 ----a-w- c:\windows\system32\lhacm.acm
2010-09-28 08:24 . 2010-09-28 08:52 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Blizzard Entertainment
2010-09-27 23:06 . 2010-10-03 13:38 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-09-27 22:03 . 2010-09-27 22:03 -------- d-sh--w- c:\documents and settings\Kebaß\PrivacIE

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 10:23 . 2004-08-17 14:49 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2004-08-17 14:49 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2001-10-25 15:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2001-10-25 15:00 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-10 05:52 . 2006-11-18 12:13 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:52 . 2004-08-17 14:49 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-09-10 05:52 . 2004-08-17 14:49 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-01 11:52 . 2004-08-17 14:48 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-09-01 07:57 . 2006-11-18 12:10 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 08:03 . 2006-11-18 12:12 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:54 . 2006-11-18 12:10 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-27 01:43 . 2008-05-05 05:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-26 13:39 . 2006-11-18 12:15 357248 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-23 16:12 . 2006-11-18 12:14 617472 ----a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2006-11-18 12:10 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45 . 2004-08-17 14:49 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-08-04 09:50 . 2010-08-04 09:50 140752 ----a-w- c:\windows\system32\drivers\eamon.sys
2010-08-03 11:28 . 2010-08-03 11:28 95896 ----a-w- c:\windows\system32\drivers\epfwtdir.sys
2010-09-27 00:54 . 2010-09-27 00:54 60526 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2010-09-27 00:54 . 2010-09-27 00:54 49256 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2010-09-27 00:54 . 2010-09-27 00:54 166000 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2003-11-13 62464]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"nwiz"="nwiz.exe" [2008-05-16 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-06-19 570664]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRealMode"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Gamesy\\World of Warcraft\\WoW-3.2.0-enGB-downloader.exe"=
"c:\\Gamesy\\World of Warcraft\\Launcher.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:*:Disabled:Blizzard Downloader: 3724

R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [29.7.2010 13:31 115008]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [3.8.2010 13:28 95896]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;\??\c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt --> c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
S4 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [12.8.2010 14:16 810144]
.
.
------- Doplňkový sken -------
.
uStart Page = about:
mStart Page = about:
FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

AddRemove-{A14A8608-CF1C-4010-A348-7EA220C70305}_is1 - c:\program files\Perfect Optimizer\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-27 19:18
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt"
.
Celkový čas: 2010-10-27 19:19:43
ComboFix-quarantined-files.txt 2010-10-27 17:19

Před spuštěním: Volných bajtů: 120 833 732 608
Po spuštění: Volných bajtů: 120 703 393 792

- - End Of File - - 9F7BE8393221DC8725B89025D7687206

Re: Divné chování PC - POMOC rychle prosím

Napsal: 27 říj 2010 18:37
od Castab
Budu rád, když mi někdo co nejdříve pomůže, protože podle mě se to množí.

Re: Divné chování PC - POMOC rychle prosím

Napsal: 27 říj 2010 19:00
od Rudy
Log již vypadá čistý. Zkuste ještě provést sken AVPTool: http://www.viry.cz/forum/viewtopic.php?f=29&t=58179 . Dejte log.

Re: Divné chování PC - POMOC rychle prosím

Napsal: 28 říj 2010 09:52
od Castab
Automatická kontrola: dokončeno před 6 hod. (události: 10, objekty: 157933, čas: 00:34:03)
28.10.2010 3:25:12 Úloha byla spuštěna
28.10.2010 3:34:13 Zjištěno: HackTool.Win32.Sniffer.WpePro.u C:\Documents and Settings\Kebaß\Dokumenty\Downloads\wpepro09x.zip/WPE PRO.exe
28.10.2010 3:34:13 Odstraněno: HackTool.Win32.Sniffer.WpePro.u C:\Documents and Settings\Kebaß\Dokumenty\Downloads\wpepro09x.zip/WPE PRO.exe
28.10.2010 3:34:13 Zjištěno: HackTool.Win32.Sniffer.WpePro.w C:\Documents and Settings\Kebaß\Dokumenty\Downloads\wpepro09x.zip/WpeSpy.dll
28.10.2010 3:34:13 Odstraněno: HackTool.Win32.Sniffer.WpePro.w C:\Documents and Settings\Kebaß\Dokumenty\Downloads\wpepro09x.zip/WpeSpy.dll
28.10.2010 3:34:15 Zjištěno: Backdoor.Win32.Hupigon.mcuc C:\Documents and Settings\Kebaß\Dokumenty\Downloads\wrar392cz.exe/Zip.SFX
28.10.2010 3:34:15 Odstraněno: Backdoor.Win32.Hupigon.mcuc C:\Documents and Settings\Kebaß\Dokumenty\Downloads\wrar392cz.exe
28.10.2010 3:42:01 Zjištěno: Backdoor.Win32.Hupigon.mcuc C:\Program Files\WinRAR\Zip.SFX
28.10.2010 3:42:44 Odstraněno: Backdoor.Win32.Hupigon.mcuc C:\Program Files\WinRAR\Zip.SFX
28.10.2010 3:59:16 Úloha byla dokončena

// Přes nouzový režim jsem smazal ESET z registru a pak ho normálně nainstaloval. Už to ani na začátku systému nevypíná firewall.
// Po Combofixu se zdá PC mnohem rychlejší a zatím to i vyřešilo mé errory, které jsem řešil s vašim kolegou v minulém topicu.
// PC se zatím nechová nijak divně, ani mi nic nebránilo v instalaci Nodu.

// Jinak nevíte nějaký dobrý a spolehlivý program na pročištění registrů? Nebo i celého PC, děkuji. (CCleaner se mi zdá jako slabý kalibr)

Re: Divné chování PC - POMOC rychle prosím

Napsal: 28 říj 2010 10:48
od Rudy
http://www.stahuj.centrum.cz/utility_a_ ... e_systemu/

Tam si můžete vybrat. Neručím ale za to, že vám některý program nesmaže něco potřebného. Osobně čistím CCleanerem, nebo ručně. CCleraner doporučujeme proto, že zaručeně nesmaže něco, co byste někdy v budoucnu mohl potřebovat. Nejúčinnější čištění je ruční, jenže se musí vědět, co smazat a co už ne. :D

Re: Divné chování PC - POMOC rychle prosím

Napsal: 28 říj 2010 11:24
od Castab
Chápu, mockrát vám děkuji, za vyřešení problému.

Re: Divné chování PC - POMOC rychle prosím

Napsal: 28 říj 2010 11:27
od Rudy
Nemáte zač!