Stránka 1 z 2

nelze mi vypnout pc pomocí startu

Napsal: 18 lis 2010 09:44
od Karson
Logfile of random's system information tool 1.08 (written by random/random)
Run by Mirecek at 2010-11-18 09:33:23
Nelze mi vypnout notebook přes start a při spuštění windows mi vyskakují hlášky nalezen nový hardware - PORTS. Přitom jsem nic nepřidával

Systém Microsoft Windows XP Professional Service Pack 3
System drive D: has 5 GB (4%) free of 102 GB
Total RAM: 3037 MB (84% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:33:34, on 18.11.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\PnkBstrA.exe
D:\Program Files\Ralink\Common\RalinkRegistryWriter.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
D:\Program Files\Alwil Software\Avast5\avastUI.exe
D:\WINDOWS\RTHDCPL.EXE
D:\WINDOWS\system32\igfxtray.exe
D:\WINDOWS\system32\hkcmd.exe
D:\WINDOWS\system32\igfxpers.exe
D:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
D:\WINDOWS\system32\igfxsrvc.exe
D:\Documents and Settings\Mirecek\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Bluetooth File Sender\BTFileSender.exe
D:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
D:\Program Files\Ralink\Common\RaUI.exe
D:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
D:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
D:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
D:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
D:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
D:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
D:\Documents and Settings\Mirecek\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Mirecek\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Mirecek\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Mirecek\Plocha\RSIT.exe
D:\Program Files\trend micro\Mirecek.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avast5] "D:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [IgfxTray] D:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] D:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] D:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SMSERIAL] D:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
O4 - HKCU\..\Run: [Google Update] "D:\Documents and Settings\Mirecek\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BTFileSender] D:\Program Files\Bluetooth File Sender\BTFileSender.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Ralink Wireless Utility.lnk = D:\Program Files\Ralink\Common\RaUI.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - D:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Unibet Poker - {C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - D:\Microgaming\Poker\UnibetpokerMPP\MPPoker.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: PnkBstrA - Unknown owner - D:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Ralink Registry Writer (RalinkRegistryWriter) - Ralink Technology, Corp. - D:\Program Files\Ralink\Common\RalinkRegistryWriter.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - D:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

--
End of file - 7196 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - D:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-04 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-08-04 79648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-26 31016]
"avast5"=D:\Program Files\Alwil Software\Avast5\avastUI.exe [2010-09-07 2838912]
"RTHDCPL"=D:\WINDOWS\RTHDCPL.EXE [2008-09-09 16851968]
"IgfxTray"=D:\WINDOWS\system32\igfxtray.exe [2008-06-04 150040]
"HotKeysCmds"=D:\WINDOWS\system32\hkcmd.exe [2008-06-04 170520]
"Persistence"=D:\WINDOWS\system32\igfxpers.exe [2008-06-04 141848]
"SMSERIAL"=D:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [2007-01-17 634880]
"Adobe Reader Speed Launcher"=D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
"ITSecMng"=D:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe [2008-12-19 83336]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=D:\Documents and Settings\Mirecek\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2010-10-18 136176]
"ctfmon.exe"=D:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"BTFileSender"=D:\Program Files\Bluetooth File Sender\BTFileSender.exe [2006-12-28 1128448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WmiApSrv"=3

D:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Bluetooth Manager.lnk - D:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
Ralink Wireless Utility.lnk - D:\Program Files\Ralink\Common\RaUI.exe

D:\Documents and Settings\Mirecek\Nabídka Start\Programy\Po spuštění
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - D:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
D:\WINDOWS\system32\igfxdev.dll [2008-05-21 212992]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - D:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=D:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Documents and Settings\Mirecek\Data aplikací\uTorrent\utorrent.exe"="D:\Documents and Settings\Mirecek\Data aplikací\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"D:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="D:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"D:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="D:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Games\WSOP 2008\WSOPBFTB.exe"="C:\Games\WSOP 2008\WSOPBFTB.exe:*:Enabled:WSOPBFTB"
"C:\Games\Mirrors Edge\Binaries\MirrorsEdge.exe"="C:\Games\Mirrors Edge\Binaries\MirrorsEdge.exe:*:Enabled:Mirror's Edge™"
"D:\Program Files\Skype\Plugin Manager\skypePM.exe"="D:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Casino\ParadiseCasino\casino.exe"="C:\Casino\ParadiseCasino\casino.exe:*:Enabled:casino"
"D:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe"="D:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"D:\Program Files\Skype\Phone\Skype.exe"="D:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-11-10 14:52:55 ----A---- D:\WINDOWS\system32\drivers\tosrfusb.sys
2010-11-10 14:52:55 ----A---- D:\WINDOWS\system32\drivers\Tosrfhid.sys
2010-11-10 14:52:55 ----A---- D:\WINDOWS\system32\drivers\tosrfbd.sys
2010-11-10 14:52:54 ----A---- D:\WINDOWS\system32\drivers\TosRfSnd.sys
2010-11-10 14:52:54 ----A---- D:\WINDOWS\system32\drivers\tosrfnds.sys
2010-11-10 14:52:54 ----A---- D:\WINDOWS\system32\drivers\tosrfcom.sys
2010-11-10 14:52:54 ----A---- D:\WINDOWS\system32\drivers\tosrfbnp.sys
2010-11-10 14:52:53 ----A---- D:\WINDOWS\system32\drivers\tosporte.sys
2010-11-10 14:49:37 ----D---- D:\Program Files\Common Files\Adobe
2010-11-10 14:49:37 ----D---- D:\Program Files\Adobe
2010-11-10 13:40:44 ----D---- D:\Program Files\Motorola
2010-11-10 13:40:26 ----A---- D:\WINDOWS\system32\sm56co6a.dll
2010-11-10 13:40:26 ----A---- D:\WINDOWS\system32\drivers\smserial.sys
2010-11-10 12:44:41 ----D---- D:\WINDOWS\OPTIONS
2010-11-10 12:41:45 ----A---- D:\WINDOWS\system32\igfxzoom.exe
2010-11-10 12:41:45 ----A---- D:\WINDOWS\system32\igfxCoIn_v4953.dll
2010-11-10 12:41:45 ----A---- D:\WINDOWS\system32\igfxcfg.exe
2010-11-10 12:41:45 ----A---- D:\WINDOWS\system32\ig4dev32.dll
2010-11-10 12:41:44 ----A---- D:\WINDOWS\system32\igxpun.exe
2010-11-10 12:37:04 ----D---- D:\Documents and Settings\Mirecek\Data aplikací\Carambis
2010-11-10 12:18:22 ----D---- D:\Documents and Settings\All Users\Data aplikací\PC Drivers HeadQuarters
2010-11-10 12:12:08 ----D---- D:\Program Files\Bluetooth File Sender
2010-11-03 17:52:38 ----A---- D:\WINDOWS\system32\drivers\PnkBstrK.sys
2010-11-03 17:52:30 ----A---- D:\WINDOWS\system32\PnkBstrB.exe
2010-11-03 17:52:24 ----A---- D:\WINDOWS\system32\PnkBstrA.exe
2010-11-03 17:32:29 ----A---- D:\WINDOWS\game.ini
2010-11-03 17:26:33 ----D---- D:\Program Files\Activision
2010-11-02 08:46:03 ----D---- D:\Program Files\Zrychleni Pocitace
2010-10-29 15:22:39 ----D---- D:\Program Files\IObit
2010-10-29 14:14:59 ----A---- D:\WINDOWS\Čestina do SimCity 4 Rush Hour a Delux BETA Uninstaller.exe
2010-10-29 13:50:43 ----A---- D:\WINDOWS\system32\drivers\xmasscsi.sys
2010-10-29 13:50:43 ----A---- D:\WINDOWS\system32\drivers\xmasbus.sys
2010-10-29 13:50:40 ----D---- D:\Program Files\Alcohol Soft
2010-10-29 13:33:18 ----D---- D:\install
2010-10-23 21:39:44 ----SHD---- D:\RECYCLER
2010-10-23 21:27:14 ----D---- D:\Documents and Settings\Mirecek\Data aplikací\Microgaming
2010-10-23 21:26:29 ----D---- D:\Microgaming

======List of files/folders modified in the last 1 months======

2010-11-18 09:33:31 ----D---- D:\Program Files\trend micro
2010-11-18 09:33:30 ----D---- D:\WINDOWS\Prefetch
2010-11-18 09:27:42 ----D---- D:\WINDOWS\temp
2010-11-18 09:22:21 ----D---- D:\WINDOWS\system32
2010-11-18 09:22:20 ----A---- D:\WINDOWS\system32\PerfStringBackup.INI
2010-11-18 09:20:19 ----SHD---- D:\WINDOWS\Installer
2010-11-18 09:18:17 ----D---- D:\WINDOWS\system32\CatRoot2
2010-11-17 17:14:45 ----D---- D:\WINDOWS
2010-11-15 17:19:15 ----A---- D:\WINDOWS\NeroDigital.ini
2010-11-15 15:12:17 ----N---- D:\WINDOWS\SchedLgU.Txt
2010-11-12 10:01:16 ----SD---- D:\Documents and Settings\Mirecek\Data aplikací\Microsoft
2010-11-10 15:11:59 ----HD---- D:\WINDOWS\inf
2010-11-10 14:57:34 ----D---- D:\Documents and Settings\All Users\Data aplikací\TOSHIBA
2010-11-10 14:55:30 ----D---- D:\WINDOWS\system32\drivers
2010-11-10 14:52:55 ----DC---- D:\WINDOWS\system32\DRVSTORE
2010-11-10 14:51:29 ----RD---- D:\Program Files
2010-11-10 14:49:46 ----D---- D:\Documents and Settings\All Users\Data aplikací\Adobe
2010-11-10 14:49:37 ----D---- D:\Program Files\Common Files
2010-11-10 13:41:23 ----D---- D:\WINDOWS\system32\ReinstallBackups
2010-11-10 13:40:41 ----D---- D:\WINDOWS\system32\CatRoot
2010-11-10 12:41:44 ----D---- D:\WINDOWS\system32\Lang
2010-11-10 12:18:19 ----RSD---- D:\WINDOWS\assembly
2010-11-10 12:16:55 ----D---- D:\WINDOWS\system32\config
2010-11-10 11:34:29 ----SD---- D:\WINDOWS\system32\Microsoft
2010-11-10 11:15:07 ----RSHDC---- D:\WINDOWS\system32\dllcache
2010-11-09 17:52:29 ----D---- D:\Program Files\Full Tilt Poker
2010-11-09 17:49:06 ----D---- D:\Program Files\PokerStars
2010-11-07 16:30:44 ----D---- D:\Poker
2010-11-06 23:00:27 ----D---- D:\Documents and Settings\Mirecek\Data aplikací\Skype
2010-11-06 20:37:13 ----D---- D:\Documents and Settings\Mirecek\Data aplikací\skypePM
2010-11-03 17:52:25 ----D---- D:\WINDOWS\system32\LogFiles
2010-11-03 17:41:46 ----HD---- D:\Program Files\InstallShield Installation Information
2010-11-03 17:34:32 ----D---- D:\Documents and Settings\Mirecek\Data aplikací\uTorrent
2010-11-03 17:24:23 ----D---- D:\Program Files\Common Files\InstallShield
2010-10-31 07:46:48 ----RD---- D:\Program Files\Skype
2010-10-30 20:15:28 ----D---- D:\Program Files\DOSBox-0.74
2010-10-29 11:48:01 ----D---- D:\Program Files\Mozilla Firefox
2010-10-26 11:09:40 ----D---- D:\WINDOWS\Debug

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 BtHidBus;Bluetooth HID Bus Service; D:\WINDOWS\System32\Drivers\BtHidBus.sys [2008-07-31 20616]
R0 PxHelp20;PxHelp20; D:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 sptd;sptd; D:\WINDOWS\System32\Drivers\sptd.sys [2010-10-29 685816]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; D:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R0 xmasbus;xmasbus; D:\WINDOWS\system32\DRIVERS\xmasbus.sys [2003-12-21 140800]
R0 xmasscsi;xmasscsi; D:\WINDOWS\System32\Drivers\xmasscsi.sys [2003-12-23 5248]
R1 Aavmker4;avast! Asynchronous Virus Monitor; D:\WINDOWS\system32\drivers\Aavmker4.sys [2010-09-07 28880]
R1 aswSP;aswSP; D:\WINDOWS\system32\drivers\aswSP.sys [2010-09-07 165584]
R1 aswTdi;avast! Network Shield Support; D:\WINDOWS\system32\drivers\aswTdi.sys [2010-09-07 46672]
R1 intelppm;Řadič procesoru Intel; D:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 Tosrfcom;Bluetooth RFCOMM; D:\WINDOWS\System32\Drivers\tosrfcom.sys [2009-02-19 63872]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; D:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.7.5.0; D:\WINDOWS\system32\DRIVERS\AegisP.sys [2010-06-13 21361]
R2 aswFsBlk;aswFsBlk; D:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-09-07 17744]
R2 aswMon2;avast! Standard Shield Support; D:\WINDOWS\system32\drivers\aswMon2.sys [2010-09-07 100176]
R2 atksgt;atksgt; D:\WINDOWS\system32\DRIVERS\atksgt.sys [2010-08-22 281760]
R2 lirsgt;lirsgt; D:\WINDOWS\system32\DRIVERS\lirsgt.sys [2010-08-22 25888]
R3 aswRdr;aswRdr; D:\WINDOWS\system32\drivers\aswRdr.sys [2010-09-07 23376]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; D:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 ialm;ialm; D:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2008-05-21 6018464]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); D:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-09-09 4813824]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; D:\WINDOWS\System32\Drivers\RootMdm.sys [2001-10-25 5888]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; D:\WINDOWS\System32\Drivers\RtsUStor.sys [2010-01-07 182304]
R3 RT80x86;Ralink 802.11n Wireless Driver; D:\WINDOWS\system32\DRIVERS\RT2860.sys [2010-06-28 1334240]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; D:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2009-11-27 177152]
R3 smserial;smserial; D:\WINDOWS\system32\DRIVERS\smserial.sys [2007-01-17 983936]
R3 tosporte;Bluetooth COM Port; D:\WINDOWS\system32\DRIVERS\tosporte.sys [2008-03-25 41472]
R3 tosrfbd;Bluetooth RFBUS; D:\WINDOWS\system32\DRIVERS\tosrfbd.sys [2008-10-06 137984]
R3 tosrfbnp;Bluetooth RFBNEP; D:\WINDOWS\System32\Drivers\tosrfbnp.sys [2009-05-12 36992]
R3 Tosrfhid;Bluetooth RFHID; D:\WINDOWS\system32\DRIVERS\Tosrfhid.sys [2009-03-05 74368]
R3 tosrfnds;Bluetooth Personal Area Network; D:\WINDOWS\system32\DRIVERS\tosrfnds.sys [2009-03-12 16128]
R3 Tosrfusb;Bluetooth USB Controller; D:\WINDOWS\system32\DRIVERS\tosrfusb.sys [2009-03-19 43264]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; D:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 anlsoeap;anlsoeap; D:\WINDOWS\system32\drivers\anlsoeap.sys []
S3 BT;Bluetooth PAN Network Adapter; D:\WINDOWS\system32\DRIVERS\btnetdrv.sys []
S3 BTDriver;Bluetooth Virtual Communications Driver; D:\WINDOWS\system32\DRIVERS\btport.sys []
S3 BTWDNDIS;Bluetooth LAN Access Server; D:\WINDOWS\system32\DRIVERS\btwdndis.sys []
S3 catchme;catchme; \??\D:\DOCUME~1\Mirecek\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; D:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 cpuz132;cpuz132; \??\D:\DOCUME~1\Mirecek\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys []
S3 HidUsb;Ovladač třídy standardu HID; D:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 IvtBtBUs;IVT Bluetooth Bus Service; D:\WINDOWS\System32\Drivers\IvtBtBus.sys [2008-07-02 26248]
S3 mouhid;Ovladač myši standardu HID; D:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; D:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; D:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; D:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 RAPIProtocol;Ralink RAPI Protocol Driver; D:\WINDOWS\system32\DRIVERS\RAPIProtocol.sys [2008-08-07 16512]
S3 SLIP;BDA Slip De-Framer; D:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; D:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 TosRfSnd;Bluetooth Audio; D:\WINDOWS\system32\drivers\tosrfsnd.sys [2009-05-14 54400]
S3 UNDPX2A;UNDPX2A; \??\D:\WINDOWS\system32\drivers\UNDPX2A.SYS []
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; D:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 USBCM;Scientific-Atlanta USB Cable Modem Driver; D:\WINDOWS\system32\DRIVERS\Sacm2A.sys []
S3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 usbvideo;Zobrazovací zařízení USB (WDM); D:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
S3 VComm;Virtual Serial port driver; D:\WINDOWS\system32\DRIVERS\VComm.sys []
S3 VcommMgr;Bluetooth VComm Manager Service; D:\WINDOWS\System32\Drivers\VcommMgr.sys []
S3 WpdUsb;WpdUsb; D:\WINDOWS\system32\DRIVERS\wpdusb.sys [2005-01-28 18944]
S3 WSTCODEC;Dálnopisný kodek světového standardu; D:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; D:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; D:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R2 PnkBstrA;PnkBstrA; D:\WINDOWS\system32\PnkBstrA.exe [2010-11-03 75064]
R2 RalinkRegistryWriter;Ralink Registry Writer; D:\Program Files\Ralink\Common\RalinkRegistryWriter.exe [2008-09-05 75040]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; D:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2009-03-17 144752]
R2 UMWdf;Windows User Mode Driver Framework; D:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; D:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; D:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R3 avast! Web Scanner;avast! Web Scanner; D:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
S3 aspnet_state;ASP.NET State Service; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; D:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; D:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; D:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-26 65824]
S3 odserv;Microsoft Office Diagnostics Service; D:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 JavaQuickStarterService;Java Quick Starter; D:\Program Files\Java\jre6\bin\jqs.exe [2010-07-17 153376]
S4 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; D:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2009-09-23 935208]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; D:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: nelze mi vypnout pc pomocí startu

Napsal: 18 lis 2010 10:22
od motji
Hezké dopoledne :)
10.11. jsem dělal s počítačem co? Jsou tam soubory patřící http://translate.google.cz/translate?hl ... rmd%3Divfd

Re: nelze mi vypnout pc pomocí startu

Napsal: 18 lis 2010 10:35
od Karson
nemůžu pochopit vaši odpověď

Re: nelze mi vypnout pc pomocí startu

Napsal: 18 lis 2010 10:38
od motji
Pardon :oops:

2010-11-10 14:52:55 ----A---- D:\WINDOWS\system32\drivers\tosrfusb.sys
2010-11-10 14:52:55 ----A---- D:\WINDOWS\system32\drivers\Tosrfhid.sys
2010-11-10 14:52:55 ----A---- D:\WINDOWS\system32\drivers\tosrfbd.sys
2010-11-10 14:52:54 ----A---- D:\WINDOWS\system32\drivers\TosRfSnd.sys
2010-11-10 14:52:54 ----A---- D:\WINDOWS\system32\drivers\tosrfnds.sys
2010-11-10 14:52:54 ----A---- D:\WINDOWS\system32\drivers\tosrfcom.sys
2010-11-10 14:52:54 ----A---- D:\WINDOWS\system32\drivers\tosrfbnp.sys
2010-11-10 14:52:53 ----A---- D:\WINDOWS\system32\drivers\tosporte.sys

jsou soubory od Bluetooth USB ovladač Miniport. To by mohl být ten port. Neskáče Vám ta hláška od doby, kdy jste tento ovladač nainstaloval?

Re: nelze mi vypnout pc pomocí startu

Napsal: 18 lis 2010 10:45
od Karson
je to dost pravděpodobné jak se toho zbavim prosim Vás ?

Re: nelze mi vypnout pc pomocí startu

Napsal: 18 lis 2010 10:47
od Karson
vyskočí mě 8x já porád musím dávat storno. viz obr

Re: nelze mi vypnout pc pomocí startu

Napsal: 18 lis 2010 10:53
od Karson
ještě by jste měla vidět asi toto - SPRÁVCE ZAŘÍZENÍ 1/2

Re: nelze mi vypnout pc pomocí startu

Napsal: 18 lis 2010 10:54
od Karson
SPRÁVCE ZAŘÍZENÍ 2/2

Re: nelze mi vypnout pc pomocí startu

Napsal: 18 lis 2010 11:39
od motji
Víte co, já Vám sem raději pošlu kolegu na HW, tohle už není moje parketa :) .
Ale můžete ještě ro jistotu udělat sken mbamem. Kolega tu bude až v noci :)

:arrow: Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken

NIC NEMAZAT :!:
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.

Re: nelze mi vypnout pc pomocí startu

Napsal: 18 lis 2010 12:08
od Karson
dobře budu moc rád když se mi na to podívá, předem moc děkuji.
Sken sem samozřejmě dám

Re: nelze mi vypnout pc pomocí startu

Napsal: 18 lis 2010 13:40
od Karson
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Verze databáze: 4875

Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

18.11.2010 13:40:08
mbam-log-2010-11-18 (13-40-08).txt

Typ skenu: Úplný sken (C:\|D:\|)
Skenované objekty: 256907
Uplynulý čas: 1 hodina(y), 12 minuta(y), 55 sekunda(y)

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované složky: 0
Infikované soubory: 6

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované hodnoty registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
C:\System Volume Information\_restore{3B2153FA-4692-4D74-B089-00857ADA8760}\RP147\A0021753.exe (Trojan.Dropper) -> No action taken.
C:\System Volume Information\_restore{3B2153FA-4692-4D74-B089-00857ADA8760}\RP147\A0021754.exe (Adware.Casino) -> No action taken.
C:\System Volume Information\_restore{3B2153FA-4692-4D74-B089-00857ADA8760}\RP147\A0021755.exe (Adware.Casino) -> No action taken.
C:\System Volume Information\_restore{3B2153FA-4692-4D74-B089-00857ADA8760}\RP147\A0021756.exe (Adware.Casino) -> No action taken.
C:\System Volume Information\_restore{3B2153FA-4692-4D74-B089-00857ADA8760}\RP147\A0021765.exe (Trojan.Dropper) -> No action taken.
D:\System Volume Information\_restore{3B2153FA-4692-4D74-B089-00857ADA8760}\RP165\A0023616.exe (Adware.Casino) -> No action taken.

Re: nelze mi vypnout pc pomocí startu

Napsal: 18 lis 2010 13:45
od motji
V mbamu můžete smazat :)

:arrow: Spusťte combofix podle tohoto návodu
http://www.bleepingcomputer.com/combofi ... t-combofix

Re: nelze mi vypnout pc pomocí startu

Napsal: 18 lis 2010 13:52
od JaRon
pokial pride kolega na nocnu bolo by vhodne pohladat CD s ovladacmi k PC a nainstalovat nanovo ovladace k chipset-u :wink:

Re: nelze mi vypnout pc pomocí startu

Napsal: 18 lis 2010 15:38
od Karson
no ty asi težko najdu, pač je to notebook přítelkyně a ta netuší kde je má.
Jediná možnost je stáhnout někde u vyrobce na stránkách, jinak nevim

Re: nelze mi vypnout pc pomocí startu

Napsal: 19 lis 2010 07:18
od JaRon
Karson píše:Jediná možnost je stáhnout někde u vyrobce na stránkách, jinak nevim
presne tak :wink: