Zpomalení běhu WIN7 a INTERNETU
Napsal: 13 led 2011 23:30
Dobrý den mám v poslední době docela problém s počítačem .... hodně se zpomalil běh systému (WIN7) a webové stránky se také načítají pomalu. Zkoušel jsem již všechny možné ANTIVIROVÉ a ANTISPYWAROVÉ testy s negativním výsledkem ... kromě nějakých cookies. Testoval jsem i hardware (ramky,HDD).
Standartně jsem měl nainstalovaný ESET IS, ale několikrát se mi již stalo že se test zasekl zhruba v polovině.
Mám podezření jestli není v PC zažraná nějaká havěť , která odstavuje antivir apod. Popř by mohl být narušený OS.
Prosím o prohlédnutí logu z COMBOFIXU.
ComboFix 11-01-12.04 - smoke 13.01.2011 22:50:42.4.2 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.3324.1045 [GMT 1:00]
Spuštěný z: c:\users\smoke\Desktop\ComboFix.exe
AV: ESET Smart Security 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-12-13 do 2011-01-13 )))))))))))))))))))))))))))))))
.
2011-01-13 22:05 . 2011-01-13 22:05 -------- d-----w- c:\users\Public\AppData\Local\temp
2011-01-13 22:05 . 2011-01-13 22:05 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-01-03 22:50 . 2011-01-03 22:50 -------- d-----w- c:\program files\Yamicsoft
2011-01-03 21:46 . 2011-01-03 21:46 -------- d-----w- c:\users\smoke\AppData\Roaming\Malwarebytes
2011-01-03 21:46 . 2011-01-03 21:46 -------- d-----w- c:\programdata\Malwarebytes
2011-01-03 21:46 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-03 21:46 . 2011-01-03 21:46 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-01-03 21:46 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-03 21:39 . 2010-01-14 19:27 25376 ----a-w- c:\windows\system32\drivers\RtVlan60.sys
2011-01-03 21:39 . 2010-01-14 19:26 40736 ----a-w- c:\windows\system32\drivers\RtTeam60.sys
2011-01-03 21:39 . 2010-01-14 19:26 33056 ----a-w- c:\windows\system32\drivers\RtNdPt60.sys
2010-12-29 15:35 . 2011-01-13 22:05 -------- d-----w- c:\users\smoke\AppData\Local\temp
2010-12-29 15:09 . 2010-12-29 15:09 -------- d-----w- c:\program files\ESET
2010-12-29 00:27 . 2010-12-29 00:27 -------- d-----w- c:\program files\Western Digital Corporation
2010-12-15 23:13 . 2010-12-15 23:13 -------- d-sh--w- c:\windows\system32\%APPDATA%
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-09 16:50 . 2010-11-09 16:50 252256 ----a-r- c:\users\smoke\AppData\Roaming\Microsoft\Installer\{17B2BD75-4172-4DEE-8B7B-9C282D1A521E}\Icon_DjVuViewer.exe
2010-10-27 06:48 . 2010-10-27 06:49 720896 ----a-w- c:\windows\iun6002.exe
2010-10-19 09:41 . 2010-05-04 09:40 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-10-18 08:00 . 2010-10-27 06:38 108032 ----a-w- c:\windows\system32\ff_vfw.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\users\smoke\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-05-04 136176]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-09-20 202024]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Device Detector"="DevDetect.exe -autorun" [X]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe Acrobat Speed Launcher"="e:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="e:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-05-25 37888]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-12-08 8120864]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-08-12 2215064]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLUA"= 2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKLM\~\startupfolder\C:^Users^smoke^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCD3000]
2010-07-03 11:19 548864 ----a-w- c:\windows\System32\bcd3kcpan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2007-09-20 07:51 1836328 ----a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
R2 ASTSRV;Nalpeiron Licensing Service;c:\windows\system32\ASTSRV.EXE [2010-05-31 57344]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 BCD3000;Behringer BCD3000 V1.2.0.0;c:\windows\system32\Drivers\BCD3000.SYS [2010-07-03 42784]
R3 BCD3000WDM;Behringer BCD3000WDM V1.2.0.0;c:\windows\system32\Drivers\BCD3000WDM.SYS [2010-07-03 21856]
R3 RTTEAMPT;Realtek Teaming Protocol Driver (NDIS 6.2);c:\windows\system32\DRIVERS\RtTeam60.sys [2010-01-14 40736]
R3 RTVLANPT;Realtek Vlan Protocol Driver (NDIS 6.2);c:\windows\system32\DRIVERS\RtVlan60.sys [2010-01-14 25376]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TEAM;Realtek Virtual Miniport Driver for Teaming (NDIS 6.2);c:\windows\system32\DRIVERS\RtTeam60.sys [2010-01-14 40736]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-23 1343400]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-05-07 691696]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-07-29 115008]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-07-29 136632]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2010-08-12 810144]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2010-07-29 41336]
S2 NIHardwareService;NIHardwareService;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [2009-12-08 3616768]
S2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\system32\DRIVERS\RtNdPt60.sys [2010-01-14 33056]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2007-09-07 1373480]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-06-23 275048]
.
Obsah adresáře 'Naplánované úlohy'
2011-01-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-811338897-2621670055-2306140442-1001Core.job
- c:\users\smoke\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-04 12:37]
2011-01-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-811338897-2621670055-2306140442-1001UA.job
- c:\users\smoke\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-04 12:37]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - c:\program files\ICQ7.1\ICQ.exe
TCP: {180CB8E4-61B7-46EA-BBE0-0F1EB9256B52} = 192.168.2.1
FF - ProfilePath - c:\users\smoke\AppData\Roaming\Mozilla\Firefox\Profiles\s0e99be0.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: LogMeIn, Inc. Remote Access Plugin: LogMeInClient@logmein.com - %profile%\extensions\LogMeInClient@logmein.com
FF - Ext: Adobe Contribute Toolbar: {01A8CA0A-4C96-465b-A49B-65C46FAD54F9} - r:\program files\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}
.
.
------- Asociace souborů -------
.
.txt=
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKCU-Run-AdobeBridge - (no file)
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'Explorer.exe'(4424)
c:\windows\system32\DeviceCenter.dll
.
Celkový čas: 2011-01-13 23:10:08
ComboFix-quarantined-files.txt 2011-01-13 22:10
ComboFix2.txt 2010-12-29 15:35
Před spuštěním: Volných bajtů: 154 949 017 600
Po spuštění: Volných bajtů: 155 280 035 840
- - End Of File - - 8F3300A477065CA07D93B3F6E64918D6
Standartně jsem měl nainstalovaný ESET IS, ale několikrát se mi již stalo že se test zasekl zhruba v polovině.
Mám podezření jestli není v PC zažraná nějaká havěť , která odstavuje antivir apod. Popř by mohl být narušený OS.
Prosím o prohlédnutí logu z COMBOFIXU.
ComboFix 11-01-12.04 - smoke 13.01.2011 22:50:42.4.2 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.3324.1045 [GMT 1:00]
Spuštěný z: c:\users\smoke\Desktop\ComboFix.exe
AV: ESET Smart Security 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-12-13 do 2011-01-13 )))))))))))))))))))))))))))))))
.
2011-01-13 22:05 . 2011-01-13 22:05 -------- d-----w- c:\users\Public\AppData\Local\temp
2011-01-13 22:05 . 2011-01-13 22:05 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-01-03 22:50 . 2011-01-03 22:50 -------- d-----w- c:\program files\Yamicsoft
2011-01-03 21:46 . 2011-01-03 21:46 -------- d-----w- c:\users\smoke\AppData\Roaming\Malwarebytes
2011-01-03 21:46 . 2011-01-03 21:46 -------- d-----w- c:\programdata\Malwarebytes
2011-01-03 21:46 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-03 21:46 . 2011-01-03 21:46 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-01-03 21:46 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-03 21:39 . 2010-01-14 19:27 25376 ----a-w- c:\windows\system32\drivers\RtVlan60.sys
2011-01-03 21:39 . 2010-01-14 19:26 40736 ----a-w- c:\windows\system32\drivers\RtTeam60.sys
2011-01-03 21:39 . 2010-01-14 19:26 33056 ----a-w- c:\windows\system32\drivers\RtNdPt60.sys
2010-12-29 15:35 . 2011-01-13 22:05 -------- d-----w- c:\users\smoke\AppData\Local\temp
2010-12-29 15:09 . 2010-12-29 15:09 -------- d-----w- c:\program files\ESET
2010-12-29 00:27 . 2010-12-29 00:27 -------- d-----w- c:\program files\Western Digital Corporation
2010-12-15 23:13 . 2010-12-15 23:13 -------- d-sh--w- c:\windows\system32\%APPDATA%
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-09 16:50 . 2010-11-09 16:50 252256 ----a-r- c:\users\smoke\AppData\Roaming\Microsoft\Installer\{17B2BD75-4172-4DEE-8B7B-9C282D1A521E}\Icon_DjVuViewer.exe
2010-10-27 06:48 . 2010-10-27 06:49 720896 ----a-w- c:\windows\iun6002.exe
2010-10-19 09:41 . 2010-05-04 09:40 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-10-18 08:00 . 2010-10-27 06:38 108032 ----a-w- c:\windows\system32\ff_vfw.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\users\smoke\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-05-04 136176]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-09-20 202024]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Device Detector"="DevDetect.exe -autorun" [X]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe Acrobat Speed Launcher"="e:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="e:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-05-25 37888]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-12-08 8120864]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-08-12 2215064]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLUA"= 2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKLM\~\startupfolder\C:^Users^smoke^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCD3000]
2010-07-03 11:19 548864 ----a-w- c:\windows\System32\bcd3kcpan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2007-09-20 07:51 1836328 ----a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
R2 ASTSRV;Nalpeiron Licensing Service;c:\windows\system32\ASTSRV.EXE [2010-05-31 57344]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 BCD3000;Behringer BCD3000 V1.2.0.0;c:\windows\system32\Drivers\BCD3000.SYS [2010-07-03 42784]
R3 BCD3000WDM;Behringer BCD3000WDM V1.2.0.0;c:\windows\system32\Drivers\BCD3000WDM.SYS [2010-07-03 21856]
R3 RTTEAMPT;Realtek Teaming Protocol Driver (NDIS 6.2);c:\windows\system32\DRIVERS\RtTeam60.sys [2010-01-14 40736]
R3 RTVLANPT;Realtek Vlan Protocol Driver (NDIS 6.2);c:\windows\system32\DRIVERS\RtVlan60.sys [2010-01-14 25376]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TEAM;Realtek Virtual Miniport Driver for Teaming (NDIS 6.2);c:\windows\system32\DRIVERS\RtTeam60.sys [2010-01-14 40736]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-23 1343400]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-05-07 691696]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-07-29 115008]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-07-29 136632]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2010-08-12 810144]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2010-07-29 41336]
S2 NIHardwareService;NIHardwareService;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [2009-12-08 3616768]
S2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\system32\DRIVERS\RtNdPt60.sys [2010-01-14 33056]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2007-09-07 1373480]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-06-23 275048]
.
Obsah adresáře 'Naplánované úlohy'
2011-01-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-811338897-2621670055-2306140442-1001Core.job
- c:\users\smoke\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-04 12:37]
2011-01-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-811338897-2621670055-2306140442-1001UA.job
- c:\users\smoke\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-04 12:37]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - c:\program files\ICQ7.1\ICQ.exe
TCP: {180CB8E4-61B7-46EA-BBE0-0F1EB9256B52} = 192.168.2.1
FF - ProfilePath - c:\users\smoke\AppData\Roaming\Mozilla\Firefox\Profiles\s0e99be0.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: LogMeIn, Inc. Remote Access Plugin: LogMeInClient@logmein.com - %profile%\extensions\LogMeInClient@logmein.com
FF - Ext: Adobe Contribute Toolbar: {01A8CA0A-4C96-465b-A49B-65C46FAD54F9} - r:\program files\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}
.
.
------- Asociace souborů -------
.
.txt=
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKCU-Run-AdobeBridge - (no file)
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'Explorer.exe'(4424)
c:\windows\system32\DeviceCenter.dll
.
Celkový čas: 2011-01-13 23:10:08
ComboFix-quarantined-files.txt 2011-01-13 22:10
ComboFix2.txt 2010-12-29 15:35
Před spuštěním: Volných bajtů: 154 949 017 600
Po spuštění: Volných bajtů: 155 280 035 840
- - End Of File - - 8F3300A477065CA07D93B3F6E64918D6