Taskhost 50% CPU, opatovne sa spusta
Napsal: 04 led 2012 15:15
Dobre popoludnie prajem, Vas malu prosbu, sam si neviem rady.
C:\Windows\System32\taskhost.exe (49 152 bajtov) zerie cez 50% CPU a aj po jeho manualnom vypnuti sa po nejakom case sam opat zapne. MBAM rychla kontrola neukazuje nic. Prikladam cerstvy log z RSIT. Dakujem
//EDIT:
Prave som sa docital ze pouzitim Combofix stracam narok na podporu a ja som ho pouzil uz skor, najskor som myslel ze to nejako spravim a neudem Vas zatazovat. Opsravedlnujem sa za to a vedomy tejto skutocnosti uz to nebudem skusat na vlastnu past. Verim ze mi vsak stale budete ochotni pomoct. Log z CF mam ulozeny, nieco zmazal ale problem pretrvava tak som sa obratil na Vas, aby som to upresnil.
Logfile of random's system information tool 1.08 (written by random/random)
Run by Peto at 2012-01-04 15:08:58
Microsoft Windows 7 Ultimate
System drive C: has 18 GB (35%) free of 51 GB
Total RAM: 3069 MB (74% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:09:11, on 4. 1. 2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\!rsit\RSIT.exe
C:\Program Files\trend micro\Peto.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 172.16.0.42:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O17 - HKLM\System\CCS\Services\Tcpip\..\{50A8BB01-8D74-4B6A-B620-1522485C3782}: NameServer = 192.168.1.1
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: SIMATIC IEPG Help Service (s7oiehsx) - SIEMENS AG - C:\program files\common files\Siemens\S7IEPG\s7oiehsx.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: VirtualBox Guest Additions Service (VBoxService) - Oracle Corporation - C:\Windows\system32\VBoxService.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.17\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.5.8\bin\mysqld.exe
--
End of file - 3258 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"LManager"=C:\Program Files\Launch Manager\LManager.exe [2010-07-31 1115728]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2010-07-31 8092192]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe Reader 9.0\Reader\Reader_sl.exe [2011-09-07 37296]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-02-28 1828136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2011-08-15 1955208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VBoxTray]
C:\Windows\system32\VBoxTray.exe [2011-01-18 907792]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2009-07-14 229376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveTypeAutoRun"=255
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.scr - open - "C:\Windows\system32\notepad.exe" "%1"
.scr - install -
.scr - config -
======List of files/folders created in the last 2 months======
2012-01-03 21:04:19 ----SHD---- C:\$RECYCLE.BIN
2012-01-03 21:04:16 ----A---- C:\ComboFix.txt
2012-01-03 21:02:05 ----D---- C:\Windows\temp
2011-12-25 14:13:20 ----D---- C:\Users\Peto\AppData\Roaming\NVIDIA
2011-12-25 14:10:58 ----D---- C:\Windows\system32\appmgmt
2011-12-25 13:51:52 ----D---- C:\Program Files\LogMeIn Hamachi
2011-12-25 00:40:25 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2011-12-25 00:39:36 ----A---- C:\Windows\system32\XAudio2_7.dll
2011-12-25 00:39:36 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2011-12-25 00:39:35 ----A---- C:\Windows\system32\xactengine3_7.dll
2011-12-25 00:39:35 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2011-12-25 00:39:34 ----A---- C:\Windows\system32\d3dx11_43.dll
2011-12-25 00:39:34 ----A---- C:\Windows\system32\d3dx10_43.dll
2011-12-25 00:39:34 ----A---- C:\Windows\system32\d3dcsx_43.dll
2011-12-25 00:39:33 ----A---- C:\Windows\system32\D3DX9_43.dll
2011-12-23 13:40:08 ----D---- C:\Users\Peto\AppData\Roaming\GarenaPlus
2011-12-23 13:39:29 ----D---- C:\ProgramData\GarenaMessenger
2011-12-12 13:14:48 ----D---- C:\Program Files\macmakeup
2011-12-02 15:24:59 ----D---- C:\Users\Peto\AppData\Roaming\Dev-Cpp
2011-12-02 15:24:40 ----D---- C:\Dev-Cpp
2011-11-14 22:47:26 ----A---- C:\Windows\system32\XAudio2_6.dll
2011-11-14 22:47:26 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2011-11-14 22:47:26 ----A---- C:\Windows\system32\xactengine3_6.dll
2011-11-14 22:47:26 ----A---- C:\Windows\system32\X3DAudio1_7.dll
======List of files/folders modified in the last 2 months======
2012-01-04 15:09:02 ----D---- C:\Program Files\trend micro
2012-01-03 23:10:44 ----D---- C:\Windows\system32\drivers
2012-01-03 22:26:35 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2012-01-03 21:54:04 ----D---- C:\Windows\system32\config
2012-01-03 21:30:13 ----SHD---- C:\System Volume Information
2012-01-03 21:04:18 ----D---- C:\Qoobox
2012-01-03 21:02:21 ----D---- C:\Windows
2012-01-03 21:02:21 ----A---- C:\Windows\system.ini
2012-01-03 21:02:14 ----D---- C:\Windows\system32\drivers\etc
2012-01-03 20:59:34 ----D---- C:\Windows\System32
2012-01-03 20:59:34 ----D---- C:\Windows\AppPatch
2012-01-03 20:59:33 ----D---- C:\Program Files\Common Files
2012-01-03 20:54:43 ----D---- C:\Windows\Prefetch
2012-01-01 19:59:33 ----D---- C:\Windows\inf
2012-01-01 19:59:33 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-12-29 13:43:16 ----D---- C:\ProgramData
2011-12-28 09:35:51 ----D---- C:\Windows\system32\Tasks
2011-12-25 14:12:24 ----SHD---- C:\Windows\Installer
2011-12-25 14:12:21 ----D---- C:\Program Files\NVIDIA Corporation
2011-12-25 14:10:57 ----RD---- C:\Program Files
2011-12-25 14:02:26 ----D---- C:\Program Files\Common Files\Steam
2011-12-25 00:39:16 ----RSD---- C:\Windows\assembly
2011-12-24 22:51:13 ----D---- C:\!images
2011-12-06 21:13:02 ----D---- C:\Windows\system32\NDF
2011-12-02 15:52:24 ----D---- C:\Program Files\Mozilla Firefox
2011-11-21 23:13:50 ----D---- C:\Windows\system32\catroot2
2011-11-20 15:25:08 ----D---- C:\Users\Peto\AppData\Roaming\Skype
2011-11-14 22:40:45 ----D---- C:\ProgramData\Ubisoft
2011-11-14 22:40:07 ----HD---- C:\Program Files\InstallShield Installation Information
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-09-02 691696]
R0 VBoxGuest;VirtualBox Guest Driver; C:\Windows\system32\DRIVERS\VBoxGuest.sys [2011-01-18 109584]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 RMCAST;@%SystemRoot%\system32\wshrm.dll,-102; C:\Windows\system32\DRIVERS\RMCAST.sys [2009-07-14 117248]
R2 s7otranx;s7otranx; C:\Windows\System32\Drivers\s7otranx.sys [2005-06-23 494135]
R2 SNTIE;SIMATIC Industrial Ethernet (ISO); C:\Windows\system32\DRIVERS\sntie.sys [2004-05-28 172032]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2009-07-13 1035776]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2010-07-31 21000]
R3 GGSAFERDriver;GGSAFER Driver; \??\D:\games\Warcraft III EN\Garena Plus\Room\safedrv.sys []
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2010-07-31 2807392]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1E62x86.sys [2009-08-23 48640]
R3 NETw5s32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit; C:\Windows\system32\DRIVERS\NETw5s32.sys [2009-09-15 6114816]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2010-06-21 105576]
R3 S7oppilx;S7oppilx; C:\Windows\System32\Drivers\S7oppilx.sys [2005-06-23 133688]
R3 VBoxMouse;VirtualBox Guest Mouse Service; C:\Windows\system32\DRIVERS\VBoxMouse.sys [2011-01-18 79120]
S1 VBoxSF;VirtualBox Shared Folders; C:\Windows\system32\drivers\VBoxSF.sys [2011-01-18 235280]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 a63ptkmn;a63ptkmn; C:\Windows\system32\drivers\a63ptkmn.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 392704]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880]
S3 catchme;catchme; \??\C:\Users\Peto\AppData\Local\Temp\catchme.sys []
S3 E1G60;Intel(R) PRO/1000 NDIS 6 Adapter Driver; C:\Windows\system32\DRIVERS\E1G60I32.sys [2009-07-13 118784]
S3 GarenaPEngine;GarenaPEngine; \??\C:\Users\Peto\AppData\Local\Temp\FKVFB9B.tmp []
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 s7oppitx;s7oppitx; C:\Windows\System32\Drivers\S7oppitx.sys [2005-06-23 76343]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-07-14 84992]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 VBoxVideo;VBoxVideo; C:\Windows\system32\DRIVERS\VBoxVideo.sys [2011-01-18 120080]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2011-08-15 1361288]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-09 129640]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2011-03-18 75136]
R2 s7oiehsx;SIMATIC IEPG Help Service; C:\program files\common files\Siemens\S7IEPG\s7oiehsx.exe [2004-07-07 200769]
S2 VBoxService;VirtualBox Guest Additions Service; C:\Windows\system32\VBoxService.exe [2011-01-18 1022480]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-06-10 31064]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2010-09-27 85096]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-02-28 529704]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-12-08 628736]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 wampapache;wampapache; c:\wamp\bin\apache\apache2.2.17\bin\httpd.exe [2010-10-18 20549]
S3 wampmysqld;wampmysqld; c:\wamp\bin\mysql\mysql5.5.8\bin\mysqld.exe [2010-12-24 8133120]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-08-31 1343400]
-----------------EOF-----------------
C:\Windows\System32\taskhost.exe (49 152 bajtov) zerie cez 50% CPU a aj po jeho manualnom vypnuti sa po nejakom case sam opat zapne. MBAM rychla kontrola neukazuje nic. Prikladam cerstvy log z RSIT. Dakujem
//EDIT:
Prave som sa docital ze pouzitim Combofix stracam narok na podporu a ja som ho pouzil uz skor, najskor som myslel ze to nejako spravim a neudem Vas zatazovat. Opsravedlnujem sa za to a vedomy tejto skutocnosti uz to nebudem skusat na vlastnu past. Verim ze mi vsak stale budete ochotni pomoct. Log z CF mam ulozeny, nieco zmazal ale problem pretrvava tak som sa obratil na Vas, aby som to upresnil.
Logfile of random's system information tool 1.08 (written by random/random)
Run by Peto at 2012-01-04 15:08:58
Microsoft Windows 7 Ultimate
System drive C: has 18 GB (35%) free of 51 GB
Total RAM: 3069 MB (74% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:09:11, on 4. 1. 2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\!rsit\RSIT.exe
C:\Program Files\trend micro\Peto.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 172.16.0.42:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O17 - HKLM\System\CCS\Services\Tcpip\..\{50A8BB01-8D74-4B6A-B620-1522485C3782}: NameServer = 192.168.1.1
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: SIMATIC IEPG Help Service (s7oiehsx) - SIEMENS AG - C:\program files\common files\Siemens\S7IEPG\s7oiehsx.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: VirtualBox Guest Additions Service (VBoxService) - Oracle Corporation - C:\Windows\system32\VBoxService.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.17\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.5.8\bin\mysqld.exe
--
End of file - 3258 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"LManager"=C:\Program Files\Launch Manager\LManager.exe [2010-07-31 1115728]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2010-07-31 8092192]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe Reader 9.0\Reader\Reader_sl.exe [2011-09-07 37296]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-02-28 1828136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2011-08-15 1955208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VBoxTray]
C:\Windows\system32\VBoxTray.exe [2011-01-18 907792]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2009-07-14 229376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveTypeAutoRun"=255
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.scr - open - "C:\Windows\system32\notepad.exe" "%1"
.scr - install -
.scr - config -
======List of files/folders created in the last 2 months======
2012-01-03 21:04:19 ----SHD---- C:\$RECYCLE.BIN
2012-01-03 21:04:16 ----A---- C:\ComboFix.txt
2012-01-03 21:02:05 ----D---- C:\Windows\temp
2011-12-25 14:13:20 ----D---- C:\Users\Peto\AppData\Roaming\NVIDIA
2011-12-25 14:10:58 ----D---- C:\Windows\system32\appmgmt
2011-12-25 13:51:52 ----D---- C:\Program Files\LogMeIn Hamachi
2011-12-25 00:40:25 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2011-12-25 00:39:36 ----A---- C:\Windows\system32\XAudio2_7.dll
2011-12-25 00:39:36 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2011-12-25 00:39:35 ----A---- C:\Windows\system32\xactengine3_7.dll
2011-12-25 00:39:35 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2011-12-25 00:39:34 ----A---- C:\Windows\system32\d3dx11_43.dll
2011-12-25 00:39:34 ----A---- C:\Windows\system32\d3dx10_43.dll
2011-12-25 00:39:34 ----A---- C:\Windows\system32\d3dcsx_43.dll
2011-12-25 00:39:33 ----A---- C:\Windows\system32\D3DX9_43.dll
2011-12-23 13:40:08 ----D---- C:\Users\Peto\AppData\Roaming\GarenaPlus
2011-12-23 13:39:29 ----D---- C:\ProgramData\GarenaMessenger
2011-12-12 13:14:48 ----D---- C:\Program Files\macmakeup
2011-12-02 15:24:59 ----D---- C:\Users\Peto\AppData\Roaming\Dev-Cpp
2011-12-02 15:24:40 ----D---- C:\Dev-Cpp
2011-11-14 22:47:26 ----A---- C:\Windows\system32\XAudio2_6.dll
2011-11-14 22:47:26 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2011-11-14 22:47:26 ----A---- C:\Windows\system32\xactengine3_6.dll
2011-11-14 22:47:26 ----A---- C:\Windows\system32\X3DAudio1_7.dll
======List of files/folders modified in the last 2 months======
2012-01-04 15:09:02 ----D---- C:\Program Files\trend micro
2012-01-03 23:10:44 ----D---- C:\Windows\system32\drivers
2012-01-03 22:26:35 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2012-01-03 21:54:04 ----D---- C:\Windows\system32\config
2012-01-03 21:30:13 ----SHD---- C:\System Volume Information
2012-01-03 21:04:18 ----D---- C:\Qoobox
2012-01-03 21:02:21 ----D---- C:\Windows
2012-01-03 21:02:21 ----A---- C:\Windows\system.ini
2012-01-03 21:02:14 ----D---- C:\Windows\system32\drivers\etc
2012-01-03 20:59:34 ----D---- C:\Windows\System32
2012-01-03 20:59:34 ----D---- C:\Windows\AppPatch
2012-01-03 20:59:33 ----D---- C:\Program Files\Common Files
2012-01-03 20:54:43 ----D---- C:\Windows\Prefetch
2012-01-01 19:59:33 ----D---- C:\Windows\inf
2012-01-01 19:59:33 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-12-29 13:43:16 ----D---- C:\ProgramData
2011-12-28 09:35:51 ----D---- C:\Windows\system32\Tasks
2011-12-25 14:12:24 ----SHD---- C:\Windows\Installer
2011-12-25 14:12:21 ----D---- C:\Program Files\NVIDIA Corporation
2011-12-25 14:10:57 ----RD---- C:\Program Files
2011-12-25 14:02:26 ----D---- C:\Program Files\Common Files\Steam
2011-12-25 00:39:16 ----RSD---- C:\Windows\assembly
2011-12-24 22:51:13 ----D---- C:\!images
2011-12-06 21:13:02 ----D---- C:\Windows\system32\NDF
2011-12-02 15:52:24 ----D---- C:\Program Files\Mozilla Firefox
2011-11-21 23:13:50 ----D---- C:\Windows\system32\catroot2
2011-11-20 15:25:08 ----D---- C:\Users\Peto\AppData\Roaming\Skype
2011-11-14 22:40:45 ----D---- C:\ProgramData\Ubisoft
2011-11-14 22:40:07 ----HD---- C:\Program Files\InstallShield Installation Information
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-09-02 691696]
R0 VBoxGuest;VirtualBox Guest Driver; C:\Windows\system32\DRIVERS\VBoxGuest.sys [2011-01-18 109584]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 RMCAST;@%SystemRoot%\system32\wshrm.dll,-102; C:\Windows\system32\DRIVERS\RMCAST.sys [2009-07-14 117248]
R2 s7otranx;s7otranx; C:\Windows\System32\Drivers\s7otranx.sys [2005-06-23 494135]
R2 SNTIE;SIMATIC Industrial Ethernet (ISO); C:\Windows\system32\DRIVERS\sntie.sys [2004-05-28 172032]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2009-07-13 1035776]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2010-07-31 21000]
R3 GGSAFERDriver;GGSAFER Driver; \??\D:\games\Warcraft III EN\Garena Plus\Room\safedrv.sys []
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2010-07-31 2807392]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1E62x86.sys [2009-08-23 48640]
R3 NETw5s32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit; C:\Windows\system32\DRIVERS\NETw5s32.sys [2009-09-15 6114816]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2010-06-21 105576]
R3 S7oppilx;S7oppilx; C:\Windows\System32\Drivers\S7oppilx.sys [2005-06-23 133688]
R3 VBoxMouse;VirtualBox Guest Mouse Service; C:\Windows\system32\DRIVERS\VBoxMouse.sys [2011-01-18 79120]
S1 VBoxSF;VirtualBox Shared Folders; C:\Windows\system32\drivers\VBoxSF.sys [2011-01-18 235280]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 a63ptkmn;a63ptkmn; C:\Windows\system32\drivers\a63ptkmn.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 392704]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880]
S3 catchme;catchme; \??\C:\Users\Peto\AppData\Local\Temp\catchme.sys []
S3 E1G60;Intel(R) PRO/1000 NDIS 6 Adapter Driver; C:\Windows\system32\DRIVERS\E1G60I32.sys [2009-07-13 118784]
S3 GarenaPEngine;GarenaPEngine; \??\C:\Users\Peto\AppData\Local\Temp\FKVFB9B.tmp []
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 s7oppitx;s7oppitx; C:\Windows\System32\Drivers\S7oppitx.sys [2005-06-23 76343]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-07-14 84992]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 VBoxVideo;VBoxVideo; C:\Windows\system32\DRIVERS\VBoxVideo.sys [2011-01-18 120080]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2011-08-15 1361288]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-09 129640]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2011-03-18 75136]
R2 s7oiehsx;SIMATIC IEPG Help Service; C:\program files\common files\Siemens\S7IEPG\s7oiehsx.exe [2004-07-07 200769]
S2 VBoxService;VirtualBox Guest Additions Service; C:\Windows\system32\VBoxService.exe [2011-01-18 1022480]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-06-10 31064]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2010-09-27 85096]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-02-28 529704]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-12-08 628736]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 wampapache;wampapache; c:\wamp\bin\apache\apache2.2.17\bin\httpd.exe [2010-10-18 20549]
S3 wampmysqld;wampmysqld; c:\wamp\bin\mysql\mysql5.5.8\bin\mysqld.exe [2010-12-24 8133120]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-08-31 1343400]
-----------------EOF-----------------