Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

prosim o kontrolu logu 2. pc

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
h4pple
Návštěvník
Návštěvník
Příspěvky: 74
Registrován: 21 led 2011 19:22

prosim o kontrolu logu 2. pc

#1 Příspěvek od h4pple »

Logfile of random's system information tool 1.08 (written by random/random)
Run by RH at 2011-01-21 20:46:42
Microsoft Windows 7 Ultimate
System drive D: has 38 GB (15%) free of 250 GB
Total RAM: 4095 MB (42% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:46:56, on 21. 1. 2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
D:\Program Files (x86)\Lexmark 2500 Series\lxddmon.exe
D:\Program Files (x86)\Lexmark 2500 Series\lxddamon.exe
D:\Program Files (x86)\Skype\Phone\Skype.exe
D:\Program Files\Alwil Software\Avast5\AvastUI.exe
D:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
D:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
D:\Program Files (x86)\IObit\Advanced SystemCare 3\AWC.exe
D:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
D:\Program Files (x86)\Mozilla Firefox\firefox.exe
D:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
D:\Program Files\trend micro\RH.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = D:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [avast5] "D:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [FaxCenterServer] "D:\Program Files (x86)\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [HDAudDeck] D:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [DivXUpdate] "D:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [StartCCC] "D:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Skype] "D:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [AlcoholAutomount] "D:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] D:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] D:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: CurseClientStartup.ccip
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://D:\PROGRA~2\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - D:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - D:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - D:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - D:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - D:\Windows\System32\lsass.exe (file missing)
O23 - Service: Folding Service #01 (FAH-01) - Stanford University - D:\Program Files (x86)\Folding@Home #01\Folding@Home #01\FAH-Console.exe
O23 - Service: Folding Service #02 (FAH-02) - Stanford University - D:\Program Files (x86)\Folding@Home #01\Folding@Home #02\FAH-Console.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - D:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - D:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - D:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - D:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - D:\Windows\system32\lsass.exe (file missing)
O23 - Service: lxddCATSCustConnectService - Lexmark International, Inc. - D:\Windows\system32\spool\DRIVERS\x64\3\\lxddserv.exe
O23 - Service: lxdd_device - - D:\Windows\system32\lxddcoms.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - D:\Windows\System32\msdtc.exe (file missing)
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: PnkBstrA - Unknown owner - D:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - D:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - D:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - D:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - D:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - D:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - D:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - D:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - D:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - D:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - D:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - D:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - D:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - D:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - D:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8432 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
D:\Windows\system32\services.exe
D:\Windows\system32\lsass.exe
D:\Windows\system32\lsm.exe
winlogon.exe
D:\Windows\system32\svchost.exe -k DcomLaunch
D:\Windows\system32\svchost.exe -k RPCSS
D:\Windows\system32\atiesrxx.exe
D:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
D:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
D:\Windows\system32\svchost.exe -k netsvcs
D:\Windows\system32\svchost.exe -k LocalService
atieclxx
D:\Windows\system32\svchost.exe -k NetworkService
"D:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
"D:\Windows\system32\Dwm.exe"
D:\Windows\Explorer.EXE
"D:\Program Files (x86)\Lexmark 2500 Series\lxddmon.exe"
"D:\Program Files (x86)\Lexmark 2500 Series\lxddamon.exe"
"D:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
"D:\Users\RH\AppData\Local\Apps\2.0\4DJH59AV.9JP\BB9DH39N.KTC\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\CurseClient.exe"
"D:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
D:\Windows\System32\spoolsv.exe
"taskhost.exe"
D:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"D:\Program Files (x86)\Folding@Home #01\Folding@Home #01\FAH-Console.exe" -forceasm -local -svcstart
"D:\Program Files (x86)\Folding@Home #01\Folding@Home #02\FAH-Console.exe" -forceasm -local -svcstart
D:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"D:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
"D:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"D:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
D:\Windows\system32\lxddcoms.exe -service
taskeng.exe {B602902E-4AD7-4097-8BE7-3497C3AD0DC6}
D:\Windows\SysWOW64\PnkBstrA.exe
D:\Windows\system32\svchost.exe -k imgsvc
"D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe"
"D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe"
"D:\Program Files (x86)\IObit\Advanced SystemCare 3\AWC.exe" /startup
"D:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"D:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
D:\Windows\system32\SearchIndexer.exe /Embedding
D:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"D:\Program Files\Windows Media Player\wmpnetwk.exe"
"D:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe" /SILENT
"D:\Program Files (x86)\Mozilla Firefox\firefox.exe"
D:\Windows\System32\svchost.exe -k LocalServicePeerNet
"D:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=208.a381520.487993548 "D:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" 208 plugin \\.\pipe\gecko-crash-server-pipe.208
D:\Windows\System32\svchost.exe -k secsvcs
D:\Windows\system32\AUDIODG.EXE 0x1c4
"D:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe8_ Global\UsGthrCtrlFltPipeMssGthrPipe8 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "D:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"D:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"D:\Users\RH\Desktop\RSITx64.exe"
D:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

D:\Windows\tasks\AWC Startup.job
D:\Windows\tasks\GoogleUpdateTaskMachineCore.job
D:\Windows\tasks\GoogleUpdateTaskMachineUA.job
D:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2598763766-2210094117-3482642199-1001Core.job
D:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2598763766-2210094117-3482642199-1001UA.job
D:\Windows\tasks\Install_NSS.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - D:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-11-24 41760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"lxddmon.exe"=D:\Program Files (x86)\Lexmark 2500 Series\lxddmon.exe [2007-06-11 291760]
"lxddamon"=D:\Program Files (x86)\Lexmark 2500 Series\lxddamon.exe [2007-04-30 20480]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=D:\Program Files (x86)\Skype\Phone\Skype.exe [2011-01-03 15028104]
"AlcoholAutomount"=D:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe -automount []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeBridge]
D:\Program Files (x86)\Adobe\Adobe Bridge CS4\Bridge.exe [2008-08-28 13145448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
D:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
D:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2010-09-16 1164584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
D:\Users\RH\AppData\Local\Google\Update\GoogleUpdate.exe [2010-05-12 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2010-12-06 1910152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Octoshape Streaming Services]
D:\Users\RH\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe [2009-01-08 70936]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
D:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [2011-01-08 3046808]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
D:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe [2010-05-14 1479680]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
d:\program files (x86)\steam\steam.exe [2010-10-29 1242448]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"avast5"=D:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-01-13 3396624]
"FaxCenterServer"=D:\Program Files (x86)\Lexmark Fax Solutions\fm3032.exe [2007-06-11 312240]
"HDAudDeck"=D:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2009-09-21 2583040]
"Adobe Reader Speed Launcher"=D:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"SunJavaUpdateSched"=D:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"DivXUpdate"=D:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2010-09-16 1164584]
"StartCCC"=D:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-10-01 98304]

D:\Users\RH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
CurseClientStartup.ccip

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - D:\Windows\System32\Notepad.exe %1
.js - open - D:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2011-01-21 20:46:43 ----D---- D:\Program Files\trend micro
2011-01-21 20:46:42 ----D---- D:\rsit
2011-01-18 17:55:56 ----A---- D:\Windows\system32\aswBoot.exe
2011-01-13 12:29:24 ----A---- D:\Windows\SYSWOW64\javaws.exe
2011-01-13 12:29:24 ----A---- D:\Windows\SYSWOW64\javaw.exe
2011-01-13 12:29:24 ----A---- D:\Windows\SYSWOW64\java.exe
2011-01-11 17:05:31 ----D---- D:\Program Files (x86)\Full Tilt Poker
2011-01-08 14:46:19 ----D---- D:\Users\RH\AppData\Roaming\LolClient
2011-01-08 14:40:47 ----A---- D:\Windows\SYSWOW64\XAudio2_2.dll
2011-01-08 14:40:47 ----A---- D:\Windows\SYSWOW64\XAPOFX1_1.dll
2011-01-08 14:40:46 ----A---- D:\Windows\SYSWOW64\d3dx10_39.dll
2011-01-08 14:40:46 ----A---- D:\Windows\SYSWOW64\D3DCompiler_39.dll
2011-01-08 14:33:34 ----D---- D:\Riot Games
2011-01-08 14:01:22 ----D---- D:\LeagueOfLegends.EU.12_20_2010
2011-01-07 19:42:17 ----D---- D:\Users\RH\AppData\Roaming\PC Suite
2011-01-07 19:42:16 ----D---- D:\Users\RH\AppData\Roaming\Nokia
2011-01-07 19:42:15 ----D---- D:\ProgramData\PC Suite
2011-01-07 19:41:30 ----D---- D:\Program Files\DIFX
2011-01-07 19:41:29 ----A---- D:\Windows\system32\drivers\pccsmcfdx64.sys
2011-01-07 19:41:25 ----DC---- D:\Windows\system32\DRVSTORE
2011-01-07 19:41:16 ----D---- D:\Program Files (x86)\PC Connectivity Solution
2011-01-07 19:40:47 ----D---- D:\Program Files (x86)\Nokia
2011-01-07 19:40:47 ----A---- D:\Windows\system32\nmwcdclsx64.dll
2011-01-07 19:39:30 ----D---- D:\ProgramData\Installations
2011-01-04 16:28:26 ----D---- D:\Program Files (x86)\GSC Game World
2010-12-25 21:05:17 ----D---- D:\Users\RH\AppData\Roaming\Xfire
2010-12-25 21:05:14 ----D---- D:\ProgramData\Xfire
2010-12-25 21:05:13 ----D---- D:\Program Files (x86)\Xfire

======List of files/folders modified in the last 1 months======

2011-01-21 20:46:51 ----D---- D:\Windows\Temp
2011-01-21 20:46:43 ----RD---- D:\Program Files
2011-01-21 20:25:11 ----D---- D:\Users\RH\AppData\Roaming\Skype
2011-01-21 18:13:47 ----D---- D:\Users\RH\AppData\Roaming\skypePM
2011-01-18 17:55:56 ----D---- D:\Windows\System32
2011-01-18 17:55:53 ----D---- D:\Windows\SysWOW64
2011-01-18 17:55:53 ----D---- D:\Windows
2011-01-15 09:27:57 ----D---- D:\Config.Msi
2011-01-14 23:28:40 ----SHD---- D:\Windows\Installer
2011-01-14 23:28:02 ----D---- D:\Windows\system32\Tasks
2011-01-14 12:11:32 ----D---- D:\Windows\system32\config
2011-01-13 17:26:26 ----SHD---- D:\System Volume Information
2011-01-13 12:29:06 ----D---- D:\Program Files (x86)\Java
2011-01-13 12:28:24 ----D---- D:\Windows\Prefetch
2011-01-13 09:47:32 ----A---- D:\Windows\SYSWOW64\aswBoot.exe
2011-01-11 17:05:31 ----D---- D:\Program Files (x86)
2011-01-08 14:33:33 ----HD---- D:\Program Files (x86)\InstallShield Installation Information
2011-01-08 13:59:53 ----D---- D:\ProgramData\PMB Files
2011-01-08 11:04:27 ----D---- D:\Windows\system32\catroot2
2011-01-07 19:44:58 ----D---- D:\Windows\system32\drivers
2011-01-07 19:44:53 ----D---- D:\Windows\system32\drivers\UMDF
2011-01-07 19:44:53 ----D---- D:\Windows\inf
2011-01-07 19:42:43 ----D---- D:\Windows\ModemLogs
2011-01-07 19:42:15 ----HD---- D:\ProgramData
2011-01-07 19:42:09 ----D---- D:\Windows\system32\catroot
2011-01-07 19:42:08 ----D---- D:\Windows\system32\DriverStore
2011-01-07 19:41:43 ----D---- D:\Program Files (x86)\Common Files
2011-01-07 19:40:36 ----D---- D:\Windows\winsxs
2011-01-07 18:56:35 ----AD---- D:\ProgramData\TEMP
2011-01-04 17:11:14 ----D---- D:\Program Files (x86)\Steam
2011-01-04 16:52:49 ----D---- D:\Users\RH\AppData\Roaming\uTorrent
2010-12-31 01:01:42 ----HD---- D:\PLOCHA

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; D:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; D:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; D:\Windows\System32\Drivers\sptd.sys [2010-03-28 834544]
R1 aswRdr;aswRdr; D:\Windows\system32\drivers\aswRdr.sys [2011-01-13 29264]
R1 aswSP;aswSP; D:\Windows\system32\drivers\aswSP.sys [2011-01-13 273488]
R1 aswTdi;avast! Network Shield Support; D:\Windows\system32\drivers\aswTdi.sys [2011-01-13 51792]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; D:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\D:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [2010-01-29 115600]
R2 adfs;adfs; D:\Windows\system32\drivers\adfs.sys [2008-06-27 88632]
R2 aswFsBlk;aswFsBlk; D:\Windows\system32\drivers\aswFsBlk.sys [2011-01-13 20560]
R2 aswMonFlt;aswMonFlt; \??\D:\Windows\system32\drivers\aswMonFlt.sys [2011-01-13 62032]
R3 amdkmdag;amdkmdag; D:\Windows\system32\DRIVERS\atikmdag.sys [2010-11-26 8120320]
R3 amdkmdap;amdkmdap; D:\Windows\system32\DRIVERS\atikmpag.sys [2010-11-26 289792]
R3 hamachi;Hamachi Network Interface; D:\Windows\system32\DRIVERS\hamachi.sys [2009-09-23 33856]
R3 NVNET;NVIDIA nForce 10/100 Mbps Ethernet ; D:\Windows\system32\DRIVERS\nvmf6264.sys [2009-04-30 339360]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; D:\Windows\system32\drivers\viahduaa.sys [2009-09-17 1250816]
S3 ALSysIO;ALSysIO; \??\D:\Users\RH\AppData\Local\Temp\ALSysIO64.sys []
S3 amdiox64;AMD IO Driver; D:\Windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service; D:\Windows\system32\drivers\AtihdW76.sys [2010-11-17 115216]
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; D:\Windows\system32\drivers\AtiHdmi.sys [2010-01-28 116736]
S3 BthEnum;Bluetooth Request Block Driver; D:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); D:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Bluetooth Port Driver; D:\Windows\System32\Drivers\BTHport.sys [2009-07-14 551936]
S3 BTHUSB;Bluetooth Radio USB Driver; D:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 79360]
S3 DrvAgent64;DrvAgent64; \??\D:\Windows\SysWOW64\Drivers\DrvAgent64.SYS [2010-12-06 21712]
S3 GGSAFERDriver;GGSAFER Driver; \??\D:\Program Files (x86)\Garena\plugins\UI\safedrv.sys []
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; D:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
S3 pccsmcfd;PCCS Mode Change Filter Driver; D:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 RDPDR;Terminal Server Device Redirector Driver; D:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); D:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; D:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; D:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 usbscan;USB Scanner Driver; D:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; D:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; D:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; D:\Windows\system32\atiesrxx.exe [2010-11-26 203776]
R2 avast! Antivirus;avast! Antivirus; D:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-01-13 40384]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; D:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 FAH-01;Folding Service #01; D:\Program Files (x86)\Folding@Home #01\Folding@Home #01\FAH-Console.exe [2008-06-30 253952]
R2 FAH-02;Folding Service #02; D:\Program Files (x86)\Folding@Home #01\Folding@Home #02\FAH-Console.exe [2008-06-30 253952]
R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [2009-04-19 625184]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2010-12-06 2101640]
R2 lxdd_device;lxdd_device; D:\Windows\system32\lxddcoms.exe [2007-05-25 567216]
R2 nSvcIp;ForceWare IP service; D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [2009-04-19 207904]
R2 PnkBstrA;PnkBstrA; D:\Windows\syswow64\PnkBstrA.exe [2010-12-14 75136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; D:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; D:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); D:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-12-02 136176]
S2 lxddCATSCustConnectService;lxddCATSCustConnectService; D:\Windows\system32\spool\DRIVERS\x64\3\\lxddserv.exe [2007-05-25 34224]
S3 aspnet_state;ASP.NET State Service; D:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe []
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-03-31 1038088]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; D:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-03-31 655624]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; D:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [2010-11-11 128928]
S3 ose;Office Source Engine; D:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; D:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 ServiceLayer;ServiceLayer; D:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2010-05-25 613888]
S3 Steam Client Service;Steam Client Service; D:\Program Files (x86)\Common Files\Steam\SteamService.exe [2010-11-05 403240]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; D:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 AppMgmt;@appmgmts.dll,-3250; D:\Windows\system32\svchost.exe [2009-07-14 27136]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119426
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: prosim o kontrolu logu 2. pc

#2 Příspěvek od Rudy »

Log vypadá čistý.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět