Opět problémy s PC, prosím o log z combofixu
Napsal: 16 kvě 2012 19:57
Zdravím,
opět mám problémy s PC(pomalý,BSoD,záseky myše apod) :/ Jelikož odvádíte SKVĚLOU práci, která mi vždy pomohla, obracím se znovu na Vás.
Zasílám rovnou log z combofixu
Děkuji
opět mám problémy s PC(pomalý,BSoD,záseky myše apod) :/ Jelikož odvádíte SKVĚLOU práci, která mi vždy pomohla, obracím se znovu na Vás.
Zasílám rovnou log z combofixu
Děkuji
- ComboFix 12-05-16.02 - profil 16.05.2012 20:49:42.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2047.1468 [GMT 2:00]
Spuštěný z: c:\documents and settings\profil\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\iun6002.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\dllcache\dlimport.exe
c:\windows\system32\SET13C.tmp
c:\windows\system32\SET4FF.tmp
c:\windows\system32\SET51A.tmp
c:\windows\system32\SET51C.tmp
c:\windows\system32\SET52A.tmp
c:\windows\system32\SET54F.tmp
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-04-16 do 2012-05-16 )))))))))))))))))))))))))))))))
.
.
2012-04-29 10:02 . 2012-04-29 10:02 1 ----a-w- c:\windows\system32\SI.bin
2012-04-28 16:47 . 2012-04-28 16:47 -------- d-----w- C:\Ubisoft Game Launcher
2012-04-28 16:21 . 2012-04-28 16:21 -------- d-----w- c:\program files\Ubisoft
2012-04-23 13:38 . 2012-04-23 13:38 -------- d-----w- c:\documents and settings\profil\Local Settings\Data aplikací\The Witcher 2
2012-04-23 13:11 . 2012-04-23 13:11 -------- d-----w- c:\program files\Microsoft.NET
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-16 18:01 . 2011-07-23 10:02 139448 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-05-16 18:01 . 2011-07-23 10:02 282472 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-05-16 18:01 . 2011-07-23 10:02 282472 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-05-16 17:16 . 2011-07-23 10:02 282472 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-05-15 14:43 . 2011-07-22 16:35 76888 ----a-w- c:\windows\system32\PnkBstrA.exe
2012-05-06 07:27 . 2012-03-31 16:43 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-06 07:27 . 2011-07-22 08:45 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-11 13:55 . 2004-08-17 15:45 2028544 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-11 13:55 . 2004-08-18 12:00 1862272 ----a-w- c:\windows\system32\win32k.sys
2012-04-11 13:55 . 2004-08-18 12:00 2150400 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-03-07 00:15 . 2011-07-21 14:05 41184 ----a-w- c:\windows\avastSS.scr
2012-03-07 00:15 . 2011-07-21 14:05 201352 ----a-w- c:\windows\system32\aswBoot.exe
2012-03-07 00:03 . 2011-07-21 14:05 612184 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-03-07 00:03 . 2011-07-21 14:05 337880 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-03-07 00:02 . 2011-07-21 14:05 35672 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-03-07 00:01 . 2011-07-21 14:05 53848 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-03-07 00:01 . 2011-07-21 14:05 95704 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-03-07 00:01 . 2011-07-21 14:05 89048 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-03-07 00:01 . 2011-07-21 14:05 20696 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-03-06 23:58 . 2011-07-21 14:05 24920 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-03-01 10:59 . 2004-08-18 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-03-01 10:59 . 2004-08-18 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-03-01 10:59 . 2004-08-18 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-02-29 23:58 . 2011-08-10 16:40 881984 ----a-w- c:\windows\system32\nvgenco32.dll
2012-02-29 23:58 . 2011-08-10 16:40 1000256 ----a-w- c:\windows\system32\nvdispco32.dll
2012-02-29 23:58 . 2011-07-30 15:58 65536 ----a-w- c:\windows\system32\OpenCL.dll
2012-02-29 23:58 . 2011-07-30 15:58 17534976 ----a-w- c:\windows\system32\nvcompiler.dll
2012-02-29 23:58 . 2011-07-21 13:06 2522944 ----a-w- c:\windows\system32\nvcuvid.dll
2012-02-29 23:58 . 2011-07-21 13:06 2437440 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-02-29 23:58 . 2011-07-21 13:06 18624512 ----a-w- c:\windows\system32\nvoglnt.dll
2012-02-29 23:58 . 2011-07-21 13:06 5918720 ----a-w- c:\windows\system32\nvcuda.dll
2012-02-29 23:58 . 2011-07-21 13:06 2291712 ----a-w- c:\windows\system32\nvapi.dll
2012-02-29 23:58 . 2011-07-21 12:00 4309760 ----a-w- c:\windows\system32\nv4_disp.dll
2012-02-29 23:58 . 2011-07-21 11:57 13417632 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2012-02-29 20:30 . 2009-09-27 16:20 54272 ----a-w- c:\windows\system32\nvwddi.dll
2012-02-29 20:30 . 2009-09-27 16:19 15494464 ----a-w- c:\windows\system32\nvcpl.dll
2012-02-29 20:30 . 2009-09-27 16:19 143680 ----a-w- c:\windows\system32\nvcolor.exe
2012-02-29 20:30 . 2009-09-27 16:19 164160 ----a-w- c:\windows\system32\nvsvc32.exe
2012-02-29 20:30 . 2009-09-27 16:19 108352 ----a-w- c:\windows\system32\nvmctray.dll
2012-02-29 14:10 . 2004-08-18 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10 . 2004-08-18 12:00 148480 ----a-w- c:\windows\system32\imagehlp.dll
2012-02-29 12:17 . 2004-08-18 12:00 385024 ------w- c:\windows\system32\html.iec
2012-03-18 17:29 . 2011-07-22 13:18 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-07 00:15 123536 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-16 16862720]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-07 4241512]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2012-02-29 15494464]
"NvMediaCenter"="NvMCTray.dll" [2012-02-29 108352]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2012-02-29 1634112]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Steam"="c:\program files\Steam\Steam.exe" -silent
"Sony Ericsson PC Companion"="c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /Background
"ICQ"="d:\programs\ICQ 7.5\ICQ7.5\ICQ.exe" silent loginmode=4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="d:\programs\iTunes\iTunesHelper.exe"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Games\\Call of Duty 2\\CoD2MP_s.exe"=
"d:\\Programs\\HLSW\\hlsw.exe"=
"d:\\Programs\\ICQ 7.5\\ICQ7.5\\ICQ.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"d:\\Games\\Medal of Honor\\MP\\mohmpgame.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"d:\\Games\\FIFA 12\\Game\\fifa.exe"=
"d:\\Programs\\SopCast\\adv\\SopAdver.exe"=
"d:\\Programs\\SopCast\\SopCast.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"d:\\Programs\\iTunes\\iTunes.exe"=
"d:\\Games\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"d:\\Games\\Mass Effect 3\\Binaries\\Win32\\MassEffect3.exe"=
"d:\\Games\\Mass Effect 2\\Binaries\\MassEffect2.exe"=
"d:\\Games\\Mass Effect 2\\MassEffect2Launcher.exe"=
"d:\\Games\\Mass Effect\\Binaries\\MassEffect.exe"=
"d:\\Games\\Mass Effect\\MassEffectLauncher.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Update Core\\daemonu.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"d:\\Games\\Company of Heroes\\BugReport\\BugReport.exe"=
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [21.7.2011 16:05 612184]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [21.7.2011 16:05 337880]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [22.7.2011 15:07 218688]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [21.7.2011 16:05 20696]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [21.2.2012 15:53 2348352]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [27.10.2010 18:23 1483072]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [21.7.2011 15:12 123712]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [5.8.2011 16:42 27632]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [7.10.2010 13:34 10064]
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [21.7.2011 15:22 28344]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10.12.2011 21:31 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [31.3.2012 18:43 257696]
S3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\l151x86.sys [1.11.2007 8:56 36864]
S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\EagleXNt.sys --> c:\windows\system32\drivers\EagleXNt.sys [?]
S3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10.12.2011 21:31 136176]
S3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\drivers\s0017bus.sys [5.8.2011 16:46 86824]
S3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\drivers\s0017mdfl.sys [5.8.2011 16:46 15016]
S3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\drivers\s0017mdm.sys [5.8.2011 16:46 114600]
S3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0017mgmt.sys [5.8.2011 16:46 108328]
S3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\drivers\s0017nd5.sys [5.8.2011 16:46 26024]
S3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\drivers\s0017obex.sys [5.8.2011 16:46 104616]
S3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\drivers\s0017unic.sys [5.8.2011 16:46 109736]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
S4 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [5.8.2011 16:46 155344]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - PNKBSTRB
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'
.
2012-05-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-31 07:27]
.
2012-05-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-12-10 19:31]
.
2012-05-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-12-10 19:31]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - d:\programs\ICQ 7.5\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 10.255.255.10 10.255.255.20
TCP: Interfaces\{8D9AA0A5-E851-4F3F-AC64-49187CD2745A}: NameServer = 10.255.255.10,10.255.255.20
TCP: Interfaces\{AF5ED57B-69AC-45B8-AA3F-77BF42A7E351}: NameServer = 10.255.255.10,10.255.255.20
FF - ProfilePath - c:\documents and settings\profil\Data aplikací\Mozilla\Firefox\Profiles\ex6mg1r6.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedie (cs)
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe
AddRemove-FIFA 11 HYBRID GAMEPLAY 4.9.2 [DOCTOR+] - d:\games\FIFA 11\Game\Uninstal.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-05-16 20:53
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-839522115-73586283-2147167427-1004\Software\G*e*n*i*e*"!\FM Genie Scout 11]
"GameDir"="c:\\Documents and Settings\\profil\\Dokumenty\\Sports Interactive\\Football Manager 2011\\games"
"ShortlistDir"="c:\\Documents and Settings\\profil\\Dokumenty\\Sports Interactive\\Football Manager 2011\\shortlists"
"FMPath"=""
"ScreenshotsDir"="c:\\Documents and Settings\\profil\\Dokumenty\\Sports Interactive\\Football Manager 2011"
"SaveDir"="c:\\Documents and Settings\\profil\\Dokumenty\\Sports Interactive\\Football Manager 2011\\"
"HistoryDir"="d:\\Games\\Football Manager 2011\\FM Genie Scout 11\\History Points"
"LangDB"="d:\\Games\\Football Manager 2011\\FM Genie Scout 11\\lang_db.dat"
"LastSaveGame"=""
"Language"="English"
"LoadLangDB"=dword:00000001
"CompressHistoryPoints"=dword:00000000
"HighlightedAttributes"=dword:00000000
"MinCondition"=dword:00000050
"GraphStep"=dword:00000000
"SkinName"="PSV Eindhoven"
"LastUpdateCheck"=dword:00009f52
"VersionOf"=dword:0000007b
"HighQualityGUI"=dword:00000001
"AutomaticallyUpdateCheck"=dword:00000001
"AdvancedGeneration"=dword:00000000
"TranslateStaffSkills"=dword:00000001
"TranslatePlayerSkills"=dword:00000001
"TranslatePositions"=dword:00000001
"ShowHistory"=dword:00000001
"Version"=dword:00000081
"UniqueID"="8A-F2C5-2733"
"UseProxy"=dword:00000000
"ProxyHost"=""
"ProxyPort"=""
"UseAuthentication"=dword:00000000
"UserName"=""
"UserPassword"=""
"PlayerSearchFeatureNum"=dword:00000006
"StaffSearchFeatureNum"=dword:00000000
"ClubSearchFeatureNum"=dword:00000000
"FilterByClubFeatureNum"=dword:00000000
"CompareFeatureNum"=dword:00000000
"ShortlistFeatureNum"=dword:00000000
"ExportFeatureNum"=dword:00000000
"HistoryFeatureNum"=dword:00000000
"LanguageDBFeatureNum"=dword:00000006
"HintsFeatureNum"=dword:00000000
"GenieReportFeatureNum"=dword:00000000
"TopFormationFeatureNum"=dword:00000000
"ScreenshotFeatureNum"=dword:00000000
"Currency"=dword:00000056
.
Celkový čas: 2012-05-16 20:53:58
ComboFix-quarantined-files.txt 2012-05-16 18:53
.
Před spuštěním: Volných bajtů: 108 700 160 000
Po spuštění: Volných bajtů: 108 892 647 424
.
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer
.
- - End Of File - - F3965D410F9A33455F3B180C23E45AE4