Stránka 1 z 1

PC sa zblaznilo :)

Napsal: 10 dub 2012 18:04
od milol10
Dobry den mam nasledujuci problem,

V PC mi prestalo pracovat takmer vse, neotvorim prehliadac chroome, nespustim ziadny film,
nejde nic nainstalovat, to bolo pre hodinou, z aktualizoval sa PC a momnetalne ide vsetko,
ale spyvare doctor hlasi 2 viry neviem ci to ma s tym suvistlost,alebo bola chyba v syteme.
prosil by som o radu, prikladam log z RSIT , dakujem za kazdu radu.

Logfile of random's system information tool 1.09 (written by random/random)
Run by Michal at 2012-04-10 18:56:45
Microsoft Windows 7 Ultimate
System drive C: has 50 GB (43%) free of 114 GB
Total RAM: 1406 MB (43% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:57:15, on 10. 4. 2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\s3trayp.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\VIA\VIAudioi\VistaADeck\HDAudioCPL.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Spyware Doctor\pctsGui.exe
C:\Program Files\Spyware Doctor\BDT\FGuard.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\SearchCore for Browsers\SearchCore for Browsers\datamngrUI.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Michal\Desktop\RSIT_2.exe
C:\Program Files\trend micro\Michal.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.imesh.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: MediaBar - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\ToolBar\imeshdtxmltbpi.dll (file missing)
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SearchCore for Browsers - {BE7A24F5-69CB-4708-B77B-B1EDA6043B95} - C:\PROGRA~1\SEARCH~1\SEARCH~1\BROWSE~1.DLL
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O3 - Toolbar: MediaBar - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\ToolBar\imeshdtxmltbpi.dll (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe -chkautorun
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VistaADeck\HDAudioCPL.exe 1
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsGui.exe" /hideGUI
O4 - HKLM\..\Run: [PCTools FGuard] C:\Program Files\Spyware Doctor\BDT\FGuard.exe
O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~1\SEARCH~1\SEARCH~1\DATAMN~1.EXE
O4 - HKCU\..\Run: [Google Update] "C:\Users\Michal\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O20 - AppInit_DLLs: C:\PROGRA~1\SEARCH~1\SEARCH~1\datamngr.dll C:\PROGRA~1\SEARCH~1\SEARCH~1\IEBHO.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Ralink Registry Writer (RalinkRegistryWriter) - Ralink Technology, Corp. - C:\Program Files\INTELLINET\Common\RalinkRegistryWriter.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

--
End of file - 6167 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2292740464-1343227500-283536619-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2292740464-1343227500-283536619-1000UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{28387537-e3f9-4ed7-860c-11e69af4a8a0}]
MediaBar - C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\ToolBar\imeshdtxmltbpi.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}]
PC Tools Browser Guard BHO - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll [2011-04-27 1144784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2012-04-10 192112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95}]
SearchCore for Browsers - C:\PROGRA~1\SEARCH~1\SEARCH~1\BROWSE~1.DLL [2011-09-15 101256]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{472734EA-242A-422B-ADF8-83D1E48CC825} - PC Tools Browser Guard - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll [2011-04-27 1144784]
{28387537-e3f9-4ed7-860c-11e69af4a8a0} - MediaBar - C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\ToolBar\imeshdtxmltbpi.dll []
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2012-04-10 192112]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-08-14 1348904]
"S3Trayp"=S3trayp.exe -chkautorun []
"SMSERIAL"=C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [2009-10-26 1458176]
"HDAudDeck"=C:\Program Files\VIA\VIAudioi\VistaADeck\HDAudioCPL.exe [2007-10-12 1224704]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-09-06 3722416]
"ISTray"=C:\Program Files\Spyware Doctor\pctsGui.exe [2011-05-09 1600984]
"PCTools FGuard"=C:\Program Files\Spyware Doctor\BDT\FGuard.exe [2011-04-27 247760]
"DATAMNGR"=C:\PROGRA~1\SEARCH~1\SEARCH~1\DATAMN~1.EXE [2011-09-15 1700272]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Michal\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-14 136176]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2011-04-21 39408]
"ccleaner"=C:\Program Files\CCleaner\CCleaner.exe /AUTO []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~1\SEARCH~1\SEARCH~1\datamngr.dll C:\PROGRA~1\SEARCH~1\SEARCH~1\IEBHO.dll "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=serwvdrv.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-04-10 18:56:45 ----D---- C:\rsit
2012-04-10 18:55:35 ----D---- C:\Users\Michal\AppData\Roaming\vlc
2012-04-10 18:52:38 ----D---- C:\Program Files\VideoLAN
2012-04-10 18:42:15 ----D---- C:\Program Files\trend micro
2012-04-10 18:33:19 ----A---- C:\Windows\ntbtlog.txt
2012-04-10 17:35:18 ----A---- C:\Windows\system32\csrsrv.dll
2012-04-10 17:34:47 ----A---- C:\Windows\system32\qdvd.dll
2012-04-10 17:34:46 ----A---- C:\Windows\system32\quartz.dll
2012-04-10 17:04:54 ----A---- C:\Windows\system32\mshtmled.dll
2012-04-10 17:04:53 ----A---- C:\Windows\system32\jscript.dll
2012-04-10 17:04:53 ----A---- C:\Windows\system32\iertutil.dll
2012-04-10 17:04:52 ----A---- C:\Windows\system32\jsproxy.dll
2012-04-10 17:04:52 ----A---- C:\Windows\system32\jscript9.dll
2012-04-10 17:04:51 ----A---- C:\Windows\system32\wininet.dll
2012-04-10 17:04:51 ----A---- C:\Windows\system32\url.dll
2012-04-10 17:04:50 ----A---- C:\Windows\system32\ieui.dll
2012-04-10 17:04:49 ----A---- C:\Windows\system32\mshtml.dll
2012-04-10 17:04:45 ----A---- C:\Windows\system32\urlmon.dll
2012-04-10 17:04:45 ----A---- C:\Windows\system32\ieframe.dll
2012-04-10 17:04:07 ----A---- C:\Windows\system32\ntkrnlpa.exe
2012-04-10 17:04:00 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-04-10 16:57:05 ----A---- C:\Windows\system32\win32k.sys
2012-04-10 16:56:49 ----A---- C:\Windows\system32\DWrite.dll
2012-04-10 16:56:48 ----A---- C:\Windows\system32\d3d10warp.dll
2012-04-10 16:56:48 ----A---- C:\Windows\system32\d3d10_1core.dll
2012-04-10 16:56:48 ----A---- C:\Windows\system32\d2d1.dll
2012-04-10 16:56:47 ----A---- C:\Windows\system32\d3d10_1.dll
2012-04-10 16:56:43 ----A---- C:\Windows\system32\drivers\tcpip.sys
2012-04-10 16:56:36 ----A---- C:\Windows\system32\ntdll.dll
2012-04-10 16:56:24 ----A---- C:\Windows\system32\packager.dll
2012-04-10 16:55:49 ----A---- C:\Windows\system32\tzres.dll
2012-04-10 16:53:29 ----A---- C:\Windows\system32\schannel.dll
2012-04-10 16:53:29 ----A---- C:\Windows\system32\lsasrv.dll
2012-04-10 16:53:28 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2012-04-10 16:53:28 ----A---- C:\Windows\system32\drivers\cng.sys
2012-04-10 16:53:27 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2012-04-10 16:53:26 ----A---- C:\Windows\system32\webio.dll
2012-04-10 16:53:25 ----A---- C:\Windows\system32\sspicli.dll
2012-04-10 16:53:25 ----A---- C:\Windows\system32\secur32.dll
2012-04-10 16:53:25 ----A---- C:\Windows\system32\lsass.exe
2012-04-10 16:53:24 ----A---- C:\Windows\system32\sspisrv.dll
2012-04-10 16:52:17 ----A---- C:\Windows\system32\rdrmemptylst.exe
2012-04-10 16:52:16 ----A---- C:\Windows\system32\rdpwsx.dll
2012-04-10 16:52:16 ----A---- C:\Windows\system32\rdpcorekmts.dll
2012-04-10 16:52:08 ----D---- C:\32788R22FWJFW
2012-04-10 16:49:46 ----A---- C:\Windows\system32\EncDec.dll
2012-04-10 16:49:43 ----A---- C:\Windows\system32\msvcrt.dll
2012-04-10 16:49:24 ----A---- C:\Windows\system32\shell32.dll
2012-04-10 16:49:22 ----A---- C:\Windows\system32\ntshrui.dll
2012-04-10 16:33:31 ----A---- C:\Windows\system32\rdpcore.dll
2012-04-10 16:33:26 ----A---- C:\Windows\system32\drivers\tdtcp.sys
2012-04-10 16:33:25 ----A---- C:\Windows\system32\drivers\rdpwd.sys

======List of files/folders modified in the last 1 month======

2012-04-11 02:18:32 ----D---- C:\Windows\Tasks
2012-04-11 02:18:32 ----D---- C:\Windows\system32\wfp
2012-04-11 02:18:30 ----D---- C:\Windows\system32\wbem
2012-04-11 02:18:30 ----D---- C:\Windows\system32\drivers\etc
2012-04-11 02:18:22 ----D---- C:\Windows\registration
2012-04-11 02:16:02 ----D---- C:\Windows\system32\LogFiles
2012-04-10 18:56:54 ----D---- C:\Windows\Temp
2012-04-10 18:54:17 ----D---- C:\Windows\System32
2012-04-10 18:54:16 ----D---- C:\Windows\inf
2012-04-10 18:54:16 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-04-10 18:52:38 ----RD---- C:\Program Files
2012-04-10 18:51:16 ----AD---- C:\ProgramData\TEMP
2012-04-10 18:49:37 ----D---- C:\Program Files\Spyware Doctor
2012-04-10 18:49:02 ----D---- C:\Windows
2012-04-10 18:28:40 ----D---- C:\Windows\system32\config
2012-04-10 18:28:39 ----D---- C:\Windows\winsxs
2012-04-10 18:23:15 ----SHD---- C:\System Volume Information
2012-04-10 18:17:59 ----D---- C:\Windows\Microsoft.NET
2012-04-10 18:17:46 ----RSD---- C:\Windows\assembly
2012-04-10 17:35:25 ----D---- C:\Windows\system32\catroot
2012-04-10 17:35:05 ----D---- C:\Windows\system32\catroot2
2012-04-10 17:26:29 ----D---- C:\Windows\system32\sk-SK
2012-04-10 17:26:29 ----D---- C:\Windows\system32\en-US
2012-04-10 17:26:29 ----D---- C:\Windows\system32\drivers
2012-04-10 17:26:29 ----D---- C:\Program Files\Common Files\System
2012-04-10 17:26:26 ----D---- C:\Windows\system32\migration
2012-04-10 17:26:25 ----D---- C:\Program Files\Internet Explorer
2012-04-10 17:23:14 ----SHD---- C:\Windows\Installer
2012-04-10 17:12:39 ----D---- C:\Program Files\Microsoft Silverlight
2012-04-10 16:30:12 ----D---- C:\download

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PCTCore;PCTools KDS; C:\Windows\system32\drivers\PCTCore.sys [2011-03-10 263888]
R0 pctDS;PC Tools Data Store; C:\Windows\system32\drivers\pctDS.sys [2010-07-16 338880]
R0 pctEFA;PC Tools Extended File Attributes; C:\Windows\system32\drivers\pctEFA.sys [2010-07-16 656320]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-09-06 34392]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-09-06 442200]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-09-06 320856]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-09-06 52568]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 PCTSD;PC Tools Spyware Doctor Driver; C:\Windows\System32\Drivers\PCTSD.sys [2011-03-10 233976]
R1 VWiFiFlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-09-06 20568]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-09-06 54616]
R2 RMCAST;@%SystemRoot%\system32\wshrm.dll,-102; C:\Windows\system32\DRIVERS\RMCAST.sys [2009-07-14 117248]
R3 FETNDIS;VIA Rhine Family Fast Ethernet Adapter Driver; C:\Windows\system32\DRIVERS\fetn62.sys [2011-04-08 53872]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\Windows\system32\drivers\MODEMCSA.sys [2009-07-14 18432]
R3 S3GIGP;S3GIGP; C:\Windows\system32\DRIVERS\VTGKModeDX32.sys [2008-04-29 833024]
R3 SIS163u;SiS163 USB Wireless LAN Adapter Driver; C:\Windows\system32\DRIVERS\sis163u.sys [2011-02-14 218624]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2009-10-26 1095936]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-08-14 203312]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2007-09-28 228352]
S1 MpKsl5ea5ae96;MpKsl5ea5ae96; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{9418EE49-8855-4D64-B60D-A870AC9D0A13}\MpKsl5ea5ae96.sys []
S1 MpKsl60ab9bf0;MpKsl60ab9bf0; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{78D4714C-662C-4086-BE1F-8C13F8867769}\MpKsl60ab9bf0.sys []
S1 MpKsl6e1b21c1;MpKsl6e1b21c1; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{6B5C617A-3813-4F0F-B0BD-9D271D999692}\MpKsl6e1b21c1.sys []
S1 MpKsl73a2885f;MpKsl73a2885f; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CFBF572F-00C8-4812-9F8D-4F7FB86E074F}\MpKsl73a2885f.sys []
S1 MpKsl7786cb55;MpKsl7786cb55; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{6B5C617A-3813-4F0F-B0BD-9D271D999692}\MpKsl7786cb55.sys []
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista; C:\Windows\system32\DRIVERS\netr28u.sys [2009-07-14 657408]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 14336]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-09-06 44768]
R2 Browser Defender Update Service;Browser Defender Update Service; C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe [2011-04-27 337872]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 RalinkRegistryWriter;Ralink Registry Writer; C:\Program Files\INTELLINET\Common\RalinkRegistryWriter.exe [2008-09-05 75040]
R2 sdAuxService;PC Tools Auxiliary Service; C:\Program Files\Spyware Doctor\pctsAuxs.exe [2011-02-18 371472]
R2 sdCoreService;PC Tools Security Service; C:\Program Files\Spyware Doctor\pctsSvc.exe [2011-04-06 1117144]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-04-21 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-04-21 136176]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-04-21 182768]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-04-09 1343400]

-----------------EOF-----------------

Re: PC sa zblaznilo :)

Napsal: 10 dub 2012 18:17
od Rudy
Zdravím!
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Program Files\Google\GoogleToolbarNotifier
C:\PROGRA~1\IMESHA~1\MediaBar
C:\Program Files\Google\Google Toolbar
C:\PROGRA~1\SEARCH~1
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2292740464-1343227500-283536619-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2292740464-1343227500-283536619-1000UA.job

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{28387537-e3f9-4ed7-860c-11e69af4a8a0}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt<. Po skenu restartujte PC a dejte nový log RSIT.

Re: PC sa zblaznilo :)

Napsal: 10 dub 2012 18:52
od milol10
Dakujem za zaujem pomoct, prikladam log

Logfile of random's system information tool 1.09 (written by random/random)
Run by Michal at 2012-04-10 19:46:46
Microsoft Windows 7 Ultimate
System drive C: has 49 GB (43%) free of 114 GB
Total RAM: 1406 MB (40% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:47:11, on 10. 4. 2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Spyware Doctor\pctsGui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\s3trayp.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\VIA\VIAudioi\VistaADeck\HDAudioCPL.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Spyware Doctor\BDT\FGuard.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Users\Michal\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Michal\Desktop\RSIT_2.exe
C:\Program Files\trend micro\Michal.exe
C:\Windows\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.imesh.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe -chkautorun
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VistaADeck\HDAudioCPL.exe 1
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsGui.exe" /hideGUI
O4 - HKLM\..\Run: [PCTools FGuard] C:\Program Files\Spyware Doctor\BDT\FGuard.exe
O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~1\SEARCH~1\SEARCH~1\DATAMN~1.EXE
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKCU\..\Run: [Google Update] "C:\Users\Michal\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Ralink Registry Writer (RalinkRegistryWriter) - Ralink Technology, Corp. - C:\Program Files\INTELLINET\Common\RalinkRegistryWriter.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

--
End of file - 5424 bytes

=========Mozilla firefox=========

ProfilePath - C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\uf2cahkk.default

prefs.js - "browser.startup.homepage" - "www.google.sk"
prefs.js - "extensions.enabledItems" - "{cb84136f-9c44-433a-9048-c5cd9df1dc16}:3.0.0.311, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.16"

"{cb84136f-9c44-433a-9048-c5cd9df1dc16}"=C:\Program Files\Spyware Doctor\BDT\Firefox\
"{23fcfd51-4958-4f00-80a3-ae97e717ed8b}"=C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Plus Web Player
"Path"=C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]
"Description"=DivX VOD Helper Plug-in
"Path"=C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=1.0.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}]
PC Tools Browser Guard BHO - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll [2011-04-27 1144784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll [2011-12-12 194432]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-08-14 1348904]
"S3Trayp"=S3trayp.exe -chkautorun []
"SMSERIAL"=C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [2009-10-26 1458176]
"HDAudDeck"=C:\Program Files\VIA\VIAudioi\VistaADeck\HDAudioCPL.exe [2007-10-12 1224704]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-09-06 3722416]
"ISTray"=C:\Program Files\Spyware Doctor\pctsGui.exe [2011-05-09 1600984]
"PCTools FGuard"=C:\Program Files\Spyware Doctor\BDT\FGuard.exe [2011-04-27 247760]
"DATAMNGR"=C:\PROGRA~1\SEARCH~1\SEARCH~1\DATAMN~1.EXE []
"DivXUpdate"=C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2011-07-29 1259376]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Michal\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-14 136176]
"ccleaner"=C:\Program Files\CCleaner\CCleaner.exe /AUTO []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=serwvdrv.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.DIVX"=DivX.dll
"vidc.yv12"=DivX.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-04-10 19:46:46 ----D---- C:\rsit
2012-04-10 19:35:52 ----D---- C:\_OTM
2012-04-10 19:32:21 ----D---- C:\Users\Michal\AppData\Roaming\DivX
2012-04-10 19:31:10 ----D---- C:\Program Files\Common Files\PX Storage Engine
2012-04-10 19:30:04 ----D---- C:\Program Files\Common Files\DivX Shared
2012-04-10 19:26:27 ----D---- C:\Program Files\DivX
2012-04-10 19:25:06 ----D---- C:\ProgramData\DivX
2012-04-10 19:14:10 ----A---- C:\Windows\nsreg.dat
2012-04-10 19:14:01 ----D---- C:\Users\Michal\AppData\Roaming\Mozilla
2012-04-10 19:12:47 ----D---- C:\Program Files\Mozilla Firefox
2012-04-10 18:55:35 ----D---- C:\Users\Michal\AppData\Roaming\vlc
2012-04-10 18:52:38 ----D---- C:\Program Files\VideoLAN
2012-04-10 18:42:15 ----D---- C:\Program Files\trend micro
2012-04-10 18:33:19 ----A---- C:\Windows\ntbtlog.txt
2012-04-10 17:35:18 ----A---- C:\Windows\system32\csrsrv.dll
2012-04-10 17:34:47 ----A---- C:\Windows\system32\qdvd.dll
2012-04-10 17:34:46 ----A---- C:\Windows\system32\quartz.dll
2012-04-10 17:04:54 ----A---- C:\Windows\system32\mshtmled.dll
2012-04-10 17:04:53 ----A---- C:\Windows\system32\jscript.dll
2012-04-10 17:04:53 ----A---- C:\Windows\system32\iertutil.dll
2012-04-10 17:04:52 ----A---- C:\Windows\system32\jsproxy.dll
2012-04-10 17:04:52 ----A---- C:\Windows\system32\jscript9.dll
2012-04-10 17:04:51 ----A---- C:\Windows\system32\wininet.dll
2012-04-10 17:04:51 ----A---- C:\Windows\system32\url.dll
2012-04-10 17:04:50 ----A---- C:\Windows\system32\ieui.dll
2012-04-10 17:04:49 ----A---- C:\Windows\system32\mshtml.dll
2012-04-10 17:04:45 ----A---- C:\Windows\system32\urlmon.dll
2012-04-10 17:04:45 ----A---- C:\Windows\system32\ieframe.dll
2012-04-10 17:04:07 ----A---- C:\Windows\system32\ntkrnlpa.exe
2012-04-10 17:04:00 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-04-10 16:57:05 ----A---- C:\Windows\system32\win32k.sys
2012-04-10 16:56:49 ----A---- C:\Windows\system32\DWrite.dll
2012-04-10 16:56:48 ----A---- C:\Windows\system32\d3d10warp.dll
2012-04-10 16:56:48 ----A---- C:\Windows\system32\d3d10_1core.dll
2012-04-10 16:56:48 ----A---- C:\Windows\system32\d2d1.dll
2012-04-10 16:56:47 ----A---- C:\Windows\system32\d3d10_1.dll
2012-04-10 16:56:43 ----A---- C:\Windows\system32\drivers\tcpip.sys
2012-04-10 16:56:36 ----A---- C:\Windows\system32\ntdll.dll
2012-04-10 16:56:24 ----A---- C:\Windows\system32\packager.dll
2012-04-10 16:55:49 ----A---- C:\Windows\system32\tzres.dll
2012-04-10 16:53:29 ----A---- C:\Windows\system32\schannel.dll
2012-04-10 16:53:29 ----A---- C:\Windows\system32\lsasrv.dll
2012-04-10 16:53:28 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2012-04-10 16:53:28 ----A---- C:\Windows\system32\drivers\cng.sys
2012-04-10 16:53:27 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2012-04-10 16:53:26 ----A---- C:\Windows\system32\webio.dll
2012-04-10 16:53:25 ----A---- C:\Windows\system32\sspicli.dll
2012-04-10 16:53:25 ----A---- C:\Windows\system32\secur32.dll
2012-04-10 16:53:25 ----A---- C:\Windows\system32\lsass.exe
2012-04-10 16:53:24 ----A---- C:\Windows\system32\sspisrv.dll
2012-04-10 16:52:17 ----A---- C:\Windows\system32\rdrmemptylst.exe
2012-04-10 16:52:16 ----A---- C:\Windows\system32\rdpwsx.dll
2012-04-10 16:52:16 ----A---- C:\Windows\system32\rdpcorekmts.dll
2012-04-10 16:52:08 ----D---- C:\32788R22FWJFW
2012-04-10 16:49:46 ----A---- C:\Windows\system32\EncDec.dll
2012-04-10 16:49:43 ----A---- C:\Windows\system32\msvcrt.dll
2012-04-10 16:49:24 ----A---- C:\Windows\system32\shell32.dll
2012-04-10 16:49:22 ----A---- C:\Windows\system32\ntshrui.dll
2012-04-10 16:33:31 ----A---- C:\Windows\system32\rdpcore.dll
2012-04-10 16:33:26 ----A---- C:\Windows\system32\drivers\tdtcp.sys
2012-04-10 16:33:25 ----A---- C:\Windows\system32\drivers\rdpwd.sys

======List of files/folders modified in the last 1 month======

2012-04-11 02:18:32 ----D---- C:\Windows\system32\wfp
2012-04-11 02:18:30 ----D---- C:\Windows\system32\wbem
2012-04-11 02:18:30 ----D---- C:\Windows\system32\drivers\etc
2012-04-11 02:18:22 ----D---- C:\Windows\registration
2012-04-11 02:16:02 ----D---- C:\Windows\system32\LogFiles
2012-04-10 19:47:03 ----D---- C:\Windows\Temp
2012-04-10 19:46:41 ----D---- C:\Windows\system32\config
2012-04-10 19:43:37 ----AD---- C:\ProgramData\TEMP
2012-04-10 19:42:59 ----D---- C:\Program Files\Spyware Doctor
2012-04-10 19:41:43 ----D---- C:\Windows
2012-04-10 19:35:57 ----RD---- C:\Program Files
2012-04-10 19:35:57 ----D---- C:\Windows\Tasks
2012-04-10 19:35:57 ----D---- C:\Program Files\Google
2012-04-10 19:31:10 ----D---- C:\Program Files\Common Files
2012-04-10 19:30:33 ----D---- C:\Windows\System32
2012-04-10 19:30:16 ----SHD---- C:\Windows\Installer
2012-04-10 19:30:16 ----D---- C:\Windows\winsxs
2012-04-10 19:25:06 ----HD---- C:\ProgramData
2012-04-10 19:07:16 ----D---- C:\Windows\inf
2012-04-10 19:07:16 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-04-10 18:23:15 ----SHD---- C:\System Volume Information
2012-04-10 18:17:59 ----D---- C:\Windows\Microsoft.NET
2012-04-10 18:17:46 ----RSD---- C:\Windows\assembly
2012-04-10 17:35:25 ----D---- C:\Windows\system32\catroot
2012-04-10 17:35:05 ----D---- C:\Windows\system32\catroot2
2012-04-10 17:26:29 ----D---- C:\Windows\system32\sk-SK
2012-04-10 17:26:29 ----D---- C:\Windows\system32\en-US
2012-04-10 17:26:29 ----D---- C:\Windows\system32\drivers
2012-04-10 17:26:29 ----D---- C:\Program Files\Common Files\System
2012-04-10 17:26:26 ----D---- C:\Windows\system32\migration
2012-04-10 17:26:25 ----D---- C:\Program Files\Internet Explorer
2012-04-10 17:12:39 ----D---- C:\Program Files\Microsoft Silverlight
2012-04-10 16:30:12 ----D---- C:\download

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PCTCore;PCTools KDS; C:\Windows\system32\drivers\PCTCore.sys [2011-03-10 263888]
R0 pctDS;PC Tools Data Store; C:\Windows\system32\drivers\pctDS.sys [2010-07-16 338880]
R0 pctEFA;PC Tools Extended File Attributes; C:\Windows\system32\drivers\pctEFA.sys [2010-07-16 656320]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-09-06 34392]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-09-06 442200]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-09-06 320856]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-09-06 52568]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 PCTSD;PC Tools Spyware Doctor Driver; C:\Windows\System32\Drivers\PCTSD.sys [2011-03-10 233976]
R1 VWiFiFlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-09-06 20568]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-09-06 54616]
R2 RMCAST;@%SystemRoot%\system32\wshrm.dll,-102; C:\Windows\system32\DRIVERS\RMCAST.sys [2009-07-14 117248]
R3 FETNDIS;VIA Rhine Family Fast Ethernet Adapter Driver; C:\Windows\system32\DRIVERS\fetn62.sys [2011-04-08 53872]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\Windows\system32\drivers\MODEMCSA.sys [2009-07-14 18432]
R3 S3GIGP;S3GIGP; C:\Windows\system32\DRIVERS\VTGKModeDX32.sys [2008-04-29 833024]
R3 SIS163u;SiS163 USB Wireless LAN Adapter Driver; C:\Windows\system32\DRIVERS\sis163u.sys [2011-02-14 218624]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2009-10-26 1095936]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-08-14 203312]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2007-09-28 228352]
S1 MpKsl5ea5ae96;MpKsl5ea5ae96; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{9418EE49-8855-4D64-B60D-A870AC9D0A13}\MpKsl5ea5ae96.sys []
S1 MpKsl60ab9bf0;MpKsl60ab9bf0; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{78D4714C-662C-4086-BE1F-8C13F8867769}\MpKsl60ab9bf0.sys []
S1 MpKsl6e1b21c1;MpKsl6e1b21c1; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{6B5C617A-3813-4F0F-B0BD-9D271D999692}\MpKsl6e1b21c1.sys []
S1 MpKsl73a2885f;MpKsl73a2885f; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CFBF572F-00C8-4812-9F8D-4F7FB86E074F}\MpKsl73a2885f.sys []
S1 MpKsl7786cb55;MpKsl7786cb55; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{6B5C617A-3813-4F0F-B0BD-9D271D999692}\MpKsl7786cb55.sys []
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista; C:\Windows\system32\DRIVERS\netr28u.sys [2009-07-14 657408]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 14336]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-09-06 44768]
R2 Browser Defender Update Service;Browser Defender Update Service; C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe [2011-04-27 337872]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 RalinkRegistryWriter;Ralink Registry Writer; C:\Program Files\INTELLINET\Common\RalinkRegistryWriter.exe [2008-09-05 75040]
R2 sdAuxService;PC Tools Auxiliary Service; C:\Program Files\Spyware Doctor\pctsAuxs.exe [2011-02-18 371472]
R2 sdCoreService;PC Tools Security Service; C:\Program Files\Spyware Doctor\pctsSvc.exe [2011-04-06 1117144]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-04-21 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-04-21 136176]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-04-21 182768]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-04-09 1343400]

-----------------EOF-----------------

Re: PC sa zblaznilo :)

Napsal: 10 dub 2012 19:00
od Rudy
Dvouklikem na soubor C:\Program Files\trend micro\Michal.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtnete:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.imesh.com
Klikněte na >FixChecked a restartujte PC.

Re: PC sa zblaznilo :)

Napsal: 10 dub 2012 19:59
od milol10
dakujem, vsetko som spravil ako ste napisali, pc sa sprava normalnym sposobom ale
na ploche sa objavili dve slozky desktop.ini a ked na to kliknem otvori sa to v poznamkovom bloku, prikladam:

desktop.ini

[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21799

a dalsi s tym istym nazvom

[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21769
IconResource=%SystemRoot%\system32\imageres.dll,-183

su to skryte subory operacneho sytemu ale ako je mozne ze maju rovnaky nazov, mam ponechat obidve?

Re: PC sa zblaznilo :)

Napsal: 10 dub 2012 21:01
od Rudy
Spusťte znovu OTM a klikněte na Cleanup. OTM po sobě uklidí.

Re: PC sa zblaznilo :)

Napsal: 10 dub 2012 22:12
od milol10
Dakujem vsetko precitene, PC funguje skvele, este raz vdaka.

Re: PC sa zblaznilo :)

Napsal: 11 dub 2012 16:41
od Rudy
Nemáte zač!