Stránka 1 z 1

Zpomalený PC log z RSIT

Napsal: 18 čer 2012 09:18
od Blein
Ahoj. Počítač se mi poslední týden loudá víc a víc. Přiznám se, že jsem od nainstalování windows ještě nenainstaloval antivirový program. Ale já jsem ho nechcel a PC si projíždím MBAM a čistím jej CCleanerem. Asi to nestačí. Prosím o kontrolu logů z rsitu. Děkuji.


info.txt logfile of random's system information tool 1.09 2012-06-18 10:13:08

======Uninstall list======

µTorrent-->"C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
jetAudio Basic VX-->"C:\Program Files\InstallShield Installation Information\{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}\setup.exe" -runfromtemp -l0x0405 -removeonly
K-Lite Mega Codec Pack 8.6.0-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
Kodek 0.16 CZ-->"C:\Program Files\Kodek CZ\unins000.exe"
Malwarebytes Anti-Malware verze 1.61.0.1400-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /lcid 1029 /parameterfolder ClientLP
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->MsiExec.exe /X{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}
Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}
Microsoft .NET Framework 4 Extended CSY Language Pack-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ExtendedLP\Setup.exe /repair /x86 /lcid 1029 /parameterfolder ExtendedLP
Microsoft .NET Framework 4 Extended CSY Language Pack-->MsiExec.exe /X{A2DE62D8-EF1B-36CB-B461-B1E221ED8608}
Microsoft .NET Framework 4 Extended-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\Setup.exe /repair /x86 /parameterfolder Extended
Microsoft .NET Framework 4 Extended-->MsiExec.exe /X{0A0CADCF-78DA-33C4-A350-CD51849B9702}
Microsoft Office Word Viewer 2003-->MsiExec.exe /I{90850405-6000-11D3-8CFE-0150048383C9}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Ogg Vorbis ACM Codec-->C:\Windows\system32\rundll32.exe setupapi,InstallHinfSection Remove_ACM 132 C:\Windows\INF\Vorbis.inf
Opera 12.00-->"C:\Program Files\Opera\Opera.exe" /uninstall
ParadisePoker-->C:\Program Files\ParadisePoker\ParadisePoker\uninstall.exe
PokerStars-->"C:\Program Files\PokerStars\PokerStarsUninstall.exe" /u:PokerStars
Skype™ 5.8-->MsiExec.exe /X{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}
WinRAR 4.11 (32-bit)-->C:\Program Files\WinRAR\uninstall.exe

======System event log======

Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Distributed Link Tracking Client byl změněn na: stopped
Record Number: 5
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:

Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Security Center byl změněn na: stopped
Record Number: 4
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:

Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Desktop Window Manager Session Manager byl změněn na: stopped
Record Number: 3
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:

Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Diagnostic Policy Service byl změněn na: stopped
Record Number: 2
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:

Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Microsoft Software Shadow Copy Provider byl změněn na: stopped
Record Number: 1
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:

=====Application event log=====

Computer Name: 37L4247D28-05
Event Code: 1001
Message: Chybný blok , typ 0
Název události: PnPDriverNotFound
Reakce: Není k dispozici
ID souboru CAB: 0

Podpis problému:
P1: x86
P2: ACPI\ATK0110
P3:
P4:
P5:
P6:
P7:
P8:
P9:
P10:

Připojené soubory:
C:\Windows\Temp\DMI45C4.tmp.log.xml

Tyto soubory mohou být k dispozici zde:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x86_93856eefc23cb6f60c4f9525ca72dec1a9d7155_cab_057b47e7

Symbol analýzy:
Opětovné hledání řešení: 0
ID hlášení: 5657969e-8b1d-11e1-a8f9-96098a317826
Stav hlášení: 6
Record Number: 5
Source Name: Windows Error Reporting
Time Written: 20120420191633.000000-000
Event Type: Informace
User:

Computer Name: 37L4247D28-05
Event Code: 5617
Message: Windows Management Instrumentation Service subsystems initialized successfully
Record Number: 4
Source Name: Microsoft-Windows-WMI
Time Written: 20120420191506.000000-000
Event Type: Informace
User:

Computer Name: 37L4247D28-05
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 3
Source Name: Microsoft-Windows-WMI
Time Written: 20120420191457.000000-000
Event Type: Informace
User:

Computer Name: 37L4247D28-05
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.


Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20120420191449.500000-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: 37L4247D28-05
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 1
Source Name: Microsoft-Windows-EventSystem
Time Written: 20120420191450.000000-000
Event Type: Informace
User:

=====Security event log=====

Computer Name: 37L4247D28-05
Event Code: 4735
Message: Byla změněna zabezpečená místní skupina.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247D28-05$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7

Skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin

Změněné atributy:
Název účtu SAM: -
Historie identifikátoru zabezpečení: -

Další informace:
Oprávnění: -
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120420191359.531250-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247D28-05
Event Code: 4731
Message: Byla vytvořena zabezpečená místní skupina.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247D28-05$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7

Nová skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin

Atributy:
Název účtu SAM: Backup Operators
Historie identifikátoru zabezpečení: -

Další informace:
Oprávnění: -
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120420191359.500000-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247D28-05
Event Code: 4902
Message: Tabulka zásad auditu pro jednotlivé uživatele byla vytvořena.

Počet prvků: 0
ID zásady: 0x22e10
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120420191358.687500-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247D28-05
Event Code: 4624
Message: Účet byl úspěšně přihlášen.

Předmět:
ID zabezpečení: S-1-0-0
Název účtu: -
Doména účtu: -
ID přihlášení: 0x0

Typ přihlášení: 0

Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Informace o procesu:
ID procesu: 0x4
Název procesu:

Informace o síti:
Název pracovní stanice: -
Adresa zdrojové sítě -
Zdrojový port: -

Podrobné informace o ověření:
Proces přihlášení: -
Balíček ověření: -
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0

Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.

Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.

Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).

Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.

Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120420191353.843750-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247D28-05
Event Code: 4608
Message: Spouští se systém Windows.

Tato událost je zaznamenána při spuštění procesu LSASS.EXE a inicializaci kontrolního podsystému.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120420191353.578125-000
Event Type: Úspěšný audit
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=16
"PROCESSOR_IDENTIFIER"=x86 Family 16 Model 6 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=0602

-----------------EOF-----------------




Logfile of random's system information tool 1.09 (written by random/random)
Run by Ondra at 2012-06-18 10:12:53
Microsoft Windows 7 Ultimate
System drive C: has 41 GB (52%) free of 78 GB
Total RAM: 2047 MB (65% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:13:07, on 18.6.2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Users\Ondra\AppData\Local\Google\Update\1.3.21.111\GoogleCrashHandler.exe
C:\Windows\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Ondra\AppData\Local\Apps\2.0\CNV2QN8P.23W\CQ82E8W1.VRO\czsh..tion_0000000000000000_0000.0000_4b0cea5ebb54b0d6\CZShareManager.exe
C:\Program Files\Opera\Opera.exe
C:\Windows\system32\taskhost.exe
D:\CZ share\RSIT.exe
C:\Program Files\trend micro\Ondra.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?st=1&crg=3.101 ... E07DB6EC46}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=iron2& ... =717558194
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {687578b9-7132-4a7a-80e4-30ee31099e03} - (no file)
O2 - BHO: Help the General-Search Project - {CA4520F3-AE13-4FB1-A513-58E23991C86D} - C:\Users\Ondra\AppData\Roaming\MEDIAF~1\EXTENS~1\GENCRA~1.DLL
O3 - Toolbar: (no name) - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - (no file)
O4 - HKCU\..\Run: [Google Update] "C:\Users\Ondra\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [MSIDLL] rundll32.exe msimld32.dll,UzAjZHYckmPJ
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files\Media Finder\hook.html
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 3261 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1443169670-1317229146-775207768-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1443169670-1317229146-775207768-1000UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA4520F3-AE13-4FB1-A513-58E23991C86D}]
Help the General-Search Project - C:\Users\Ondra\AppData\Roaming\MEDIAF~1\EXTENS~1\GENCRA~1.DLL [2012-03-06 431104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Ondra\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-21 116648]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2012-02-15 17146504]
"MSIDLL"=msimld32.dll,UzAjZHYckmPJ []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=l3codecp.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"vidc.divx"=divx.dll
"vidc.div4"=DivXc32f.dll
"vidc.div3"=DivXc32.dll
"vidc.xvid"=xvidvfw.dll
"vidc.mp43"=mpg4c32.dll
"msacm.l3radius"=l3codecp.acm
"msacm.divxa"=divxa32.acm
"msacm.vorbis"=Vorbis.acm
"msacm.a3d"=a3d.dll
"VIDC.YV12"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"VIDC.FFDS"=ff_vfw.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 3 months======

2012-06-18 10:12:54 ----D---- C:\Program Files\trend micro
2012-06-18 10:12:53 ----D---- C:\rsit
2012-06-16 23:20:22 ----D---- C:\Users\Ondra\AppData\Roaming\Opera
2012-06-16 23:19:53 ----D---- C:\Program Files\Opera
2012-06-16 18:10:36 ----SHD---- C:\Config.Msi
2012-06-16 18:06:15 ----RASH---- C:\MSDOS.SYS
2012-06-16 18:06:15 ----RASH---- C:\IO.SYS
2012-06-12 05:49:38 ----D---- C:\Program Files\Conduit
2012-06-10 14:47:34 ----D---- C:\Sierra
2012-06-09 18:16:03 ----D---- C:\Users\Ondra\AppData\Roaming\Media Finder
2012-06-06 09:34:49 ----D---- C:\Program Files\uTorrent
2012-06-06 09:34:05 ----D---- C:\Users\Ondra\AppData\Roaming\uTorrent
2012-06-06 09:29:43 ----D---- C:\ProgramData\Tarma Installer
2012-06-06 09:29:07 ----D---- C:\Program Files\SweetIM
2012-06-06 09:28:46 ----D---- C:\Users\Ondra\AppData\Roaming\Mozilla
2012-06-06 09:28:31 ----D---- C:\Program Files\1ClickDownload
2012-06-06 09:28:10 ----D---- C:\Users\Ondra\AppData\Roaming\Python-Eggs
2012-06-06 09:28:05 ----D---- C:\Users\Ondra\AppData\Roaming\BitLord
2012-06-06 09:28:05 ----A---- C:\Users\Ondra\AppData\Roaming\bitlord_log.txt
2012-06-06 09:24:10 ----D---- C:\Program Files\BitLord 2
2012-05-31 22:24:33 ----D---- C:\Program Files\Microsoft Office
2012-05-31 22:23:47 ----D---- C:\Program Files\MSECache
2012-05-18 13:21:27 ----D---- C:\Users\Ondra\AppData\Roaming\Skype
2012-05-18 13:21:11 ----RD---- C:\Program Files\Skype
2012-05-18 13:21:11 ----D---- C:\ProgramData\Skype
2012-05-18 13:21:11 ----D---- C:\Program Files\Common Files\Skype
2012-04-26 21:38:19 ----D---- C:\Users\Ondra\AppData\Roaming\Malwarebytes
2012-04-26 21:38:04 ----D---- C:\ProgramData\Malwarebytes
2012-04-26 21:38:04 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2012-04-26 21:38:04 ----A---- C:\Windows\system32\drivers\mbam.sys
2012-04-26 21:36:31 ----D---- C:\Program Files\CCleaner
2012-04-26 21:35:38 ----D---- C:\Program Files\Google
2012-04-25 14:58:29 ----D---- C:\ProgramData\boost_interprocess
2012-04-25 14:50:36 ----D---- C:\ProgramData\Boss Media
2012-04-25 14:50:20 ----D---- C:\Program Files\ParadisePoker
2012-04-25 14:38:24 ----D---- C:\Program Files\PokerStars
2012-04-24 21:47:36 ----D---- C:\Users\Ondra\AppData\Roaming\Ashampoo
2012-04-24 11:27:51 ----D---- C:\Users\Ondra\AppData\Roaming\Media Player Classic
2012-04-24 11:12:30 ----A---- C:\Windows\system32\xvidvfw.dll
2012-04-24 11:12:30 ----A---- C:\Windows\system32\xvidcore.dll
2012-04-24 11:12:29 ----A---- C:\Windows\system32\unrar.dll
2012-04-24 11:12:25 ----A---- C:\Windows\system32\ff_vfw.dll
2012-04-24 11:12:22 ----D---- C:\Program Files\K-Lite Codec Pack
2012-04-22 23:19:08 ----A---- C:\Windows\iun6002.exe
2012-04-22 22:49:48 ----D---- C:\Users\Ondra\AppData\Roaming\COWON
2012-04-22 22:14:40 ----D---- C:\Program Files\Kodek CZ
2012-04-22 22:07:09 ----D---- C:\Program Files\Common Files\COWON
2012-04-22 22:07:08 ----D---- C:\Program Files\JetAudio
2012-04-22 22:06:49 ----HD---- C:\Program Files\InstallShield Installation Information
2012-04-21 18:36:03 ----D---- C:\Users\Ondra\AppData\Roaming\WinRAR
2012-04-21 18:35:58 ----D---- C:\Program Files\WinRAR
2012-04-21 05:30:16 ----N---- C:\Windows\system32\MpSigStub.exe
2012-04-21 05:07:47 ----D---- C:\Program Files\Microsoft.NET
2012-04-21 04:49:36 ----D---- C:\Users\Ondra\AppData\Roaming\Macromedia
2012-04-21 04:49:36 ----D---- C:\Users\Ondra\AppData\Roaming\Adobe
2012-04-21 04:44:20 ----SHD---- C:\Windows\Installer
2012-04-21 02:42:51 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2012-04-21 02:42:51 ----A---- C:\Windows\system32\PresentationHost.exe
2012-04-21 02:42:51 ----A---- C:\Windows\system32\netfxperf.dll
2012-04-21 02:42:51 ----A---- C:\Windows\system32\mscoree.dll
2012-04-21 02:42:51 ----A---- C:\Windows\system32\dfshim.dll
2012-04-21 02:37:31 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-04-20 21:40:15 ----D---- C:\Windows\Panther
2012-04-20 21:40:00 ----RASH---- C:\BOOTSECT.BAK
2012-04-20 21:39:57 ----SHD---- C:\Boot
2012-04-20 21:26:36 ----D---- C:\Users\Ondra\AppData\Roaming\Identities
2012-04-20 21:25:56 ----SD---- C:\Users\Ondra\AppData\Roaming\Microsoft
2012-04-20 21:25:56 ----D---- C:\Users\Ondra\AppData\Roaming\Media Center Programs
2012-04-20 21:22:53 ----SHD---- C:\Recovery
2012-04-20 21:22:53 ----SHD---- C:\ProgramData\Šablony
2012-04-20 21:22:52 ----SHD---- C:\ProgramData\Plocha
2012-04-20 21:22:52 ----SHD---- C:\ProgramData\Oblíbené položky
2012-04-20 21:22:52 ----SHD---- C:\ProgramData\Nabídka Start
2012-04-20 21:22:52 ----SHD---- C:\ProgramData\Dokumenty
2012-04-20 21:22:52 ----SHD---- C:\ProgramData\Data aplikací
2012-04-20 21:18:24 ----A---- C:\Windows\system32\atiicdxx.dat
2012-04-20 21:17:13 ----D---- C:\Windows\SoftwareDistribution
2012-04-20 21:13:35 ----D---- C:\Windows\Prefetch
2012-04-20 21:13:26 ----ASH---- C:\pagefile.sys
2012-04-20 21:13:24 ----SHD---- C:\System Volume Information
2012-04-20 21:13:24 ----ASH---- C:\hiberfil.sys

======List of files/folders modified in the last 3 months======

2012-06-18 10:12:57 ----D---- C:\Windows\Temp
2012-06-18 10:12:54 ----RD---- C:\Program Files
2012-06-17 01:30:53 ----D---- C:\Windows\system32\config
2012-06-17 01:00:01 ----D---- C:\Windows
2012-06-17 01:00:00 ----D---- C:\Windows\inf
2012-06-16 18:11:04 ----HD---- C:\ProgramData
2012-06-16 17:03:45 ----D---- C:\Windows\system32\catroot2
2012-06-08 07:23:29 ----D---- C:\Windows\system32\drivers
2012-06-06 09:27:10 ----D---- C:\Windows\winsxs
2012-06-06 09:25:55 ----D---- C:\Program Files\Common Files\microsoft shared
2012-05-18 13:21:11 ----D---- C:\Program Files\Common Files
2012-05-12 16:44:28 ----D---- C:\Windows\system32\wdi
2012-04-28 05:58:10 ----D---- C:\Windows\system32\Tasks
2012-04-28 05:58:09 ----D---- C:\Windows\Tasks
2012-04-28 05:31:17 ----D---- C:\Windows\debug
2012-04-27 20:50:44 ----D---- C:\Windows\System32
2012-04-26 19:39:37 ----D---- C:\Windows\Microsoft.NET
2012-04-26 19:08:48 ----RSD---- C:\Windows\assembly
2012-04-26 19:06:06 ----D---- C:\Windows\system32\en-US
2012-04-23 00:00:02 ----SD---- C:\ProgramData\Microsoft
2012-04-22 23:58:07 ----D---- C:\Windows\system32\drivers\UMDF
2012-04-22 09:21:27 ----D---- C:\Windows\system32\LogFiles
2012-04-21 09:59:07 ----D---- C:\Windows\system32\catroot
2012-04-21 09:41:22 ----D---- C:\Windows\Logs
2012-04-21 05:10:12 ----D---- C:\Windows\system32\cs-CZ
2012-04-21 04:46:29 ----D---- C:\Windows\system32\CodeIntegrity
2012-04-21 02:42:25 ----D---- C:\Windows\system32\restore
2012-04-20 21:39:39 ----D---- C:\Windows\Setup
2012-04-20 21:26:32 ----SHD---- C:\$Recycle.Bin
2012-04-20 21:25:56 ----RD---- C:\Users
2012-04-20 21:22:53 ----D---- C:\Program Files\Windows NT
2012-04-20 21:19:01 ----D---- C:\Windows\system32\sysprep
2012-04-20 21:14:48 ----D---- C:\Windows\CSC
2012-04-20 20:38:30 ----D---- C:\Windows\system32\wbem

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-07-14 4194816]
R3 RTL8023xp;Realtek 10/100 NIC Family NDIS x86 Driver; C:\Windows\system32\DRIVERS\Rtnicxp.sys [2009-07-14 43008]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-14 139776]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x32.sys [2009-07-14 347264]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-02-15 158856]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Re: Zpomalený PC log z RSIT

Napsal: 18 čer 2012 16:46
od Rudy
Zdravím!

V systému zcela chybí antivir. Nainstalujte, udělejte sken a smažte vše, co najde. Pak dejte nový log RSIT.

Re: Zpomalený PC log z RSIT

Napsal: 18 čer 2012 23:43
od Blein
Nainstaloval jsem avast udělal sken uložišť C a D ale nic nenašel. Nový log z RSIT považuji za zbytečný. Zkusím ještě jednou MBAM před posledním spuštěním jsem jej neaktulizoval.

Re: Zpomalený PC log z RSIT

Napsal: 19 čer 2012 08:29
od Blein
Ou aktualizace je věda :oD zde je log z MBAM


Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Verze databáze: v2012.06.18.09

Windows 7 x86 NTFS
Internet Explorer 8.0.7600.16385
Ondra :: ONDRA-PC [administrátor]

19.6.2012 0:46:45
mbam-log-2012-06-19 (09-26-16).txt

Typ: Úplná kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 367452
Uplynulý čas: 2 hodin, 19 minut, 46 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 10
HKCR\CLSID\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Žádná instrukce nebyla provedena.
HKCR\gencrawler_gc.GenCrawler (Trojan.Downloader) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Google\chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki (PUP.Funmoods) -> Žádná instrukce nebyla provedena.

Nalezené hodnoty v registru: 3
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Data: Funmoods Toolbar -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Data: -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|MSIDLL (Trojan.Agent) -> Data: rundll32.exe msimld32.dll,UzAjZHYckmPJ -> Žádná instrukce nebyla provedena.

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 2
C:\Users\Ondra\AppData\Roaming\Media Finder\Extensions\gencrawler_gc.dll (Trojan.Downloader) -> Žádná instrukce nebyla provedena.
C:\Users\Ondra\AppData\Local\Temp\~nsu.tmp\Au_.exe (PUP.FunMoods) -> Žádná instrukce nebyla provedena.

(konec)

Re: Zpomalený PC log z RSIT

Napsal: 19 čer 2012 16:49
od Rudy
Vše, co MBAM nalezl, smažte.

Re: Zpomalený PC log z RSIT

Napsal: 19 čer 2012 18:55
od Blein
Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Verze databáze: v2012.06.18.09

Windows 7 x86 NTFS
Internet Explorer 8.0.7600.16385
Ondra :: ONDRA-PC [administrátor]

19.6.2012 0:46:45
mbam-log-2012-06-19 (00-46-45).txt

Typ: Úplná kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 367452
Uplynulý čas: 2 hodin, 19 minut, 46 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 10
HKCR\CLSID\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Umístnění do karantény a smazání se zdařilo.
HKCR\gencrawler_gc.GenCrawler (Trojan.Downloader) -> Umístnění do karantény a smazání se zdařilo.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Umístnění do karantény a smazání se zdařilo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Umístnění do karantény a smazání se zdařilo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Umístnění do karantény a smazání se zdařilo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> Umístnění do karantény a smazání se zdařilo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> Umístnění do karantény a smazání se zdařilo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Umístnění do karantény a smazání se zdařilo.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Umístnění do karantény a smazání se zdařilo.
HKLM\SOFTWARE\Google\chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki (PUP.Funmoods) -> Umístnění do karantény a smazání se zdařilo.

Nalezené hodnoty v registru: 3
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Data: Funmoods Toolbar -> Umístnění do karantény a smazání se zdařilo.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Data: -> Umístnění do karantény a smazání se zdařilo.
HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|MSIDLL (Trojan.Agent) -> Data: rundll32.exe msimld32.dll,UzAjZHYckmPJ -> Umístnění do karantény a smazání se zdařilo.

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 2
C:\Users\Ondra\AppData\Roaming\Media Finder\Extensions\gencrawler_gc.dll (Trojan.Downloader) -> Bude smazán při restartu.
C:\Users\Ondra\AppData\Local\Temp\~nsu.tmp\Au_.exe (PUP.FunMoods) -> Umístnění do karantény a smazání se zdařilo.

(konec)
















Udělám log z rsit

Re: Zpomalený PC log z RSIT

Napsal: 19 čer 2012 19:03
od Blein
Zde je log z RSIT. Počítač vypadá líp. Ale ještě to není ono.






Logfile of random's system information tool 1.09 (written by random/random)
Run by Ondra at 2012-06-19 20:02:29
Microsoft Windows 7 Ultimate
System drive C: has 42 GB (54%) free of 78 GB
Total RAM: 2047 MB (45% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:02:36, on 19.6.2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Users\Ondra\AppData\Local\Google\Update\1.3.21.111\GoogleCrashHandler.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ondra\AppData\Local\Apps\2.0\CNV2QN8P.23W\CQ82E8W1.VRO\czsh..tion_0000000000000000_0000.0000_4b0cea5ebb54b0d6\CZShareManager.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\dfsvc.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
D:\CZ share\RSIT.exe
C:\Program Files\trend micro\Ondra.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?st=1&crg=3.101 ... E07DB6EC46}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=iron2& ... =717558194
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {687578b9-7132-4a7a-80e4-30ee31099e03} - (no file)
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [Google Update] "C:\Users\Ondra\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files\Media Finder\hook.html
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 4070 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1443169670-1317229146-775207768-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1443169670-1317229146-775207768-1000UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-03-07 1003704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-03-07 1003704]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-03-07 4241512]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Ondra\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-21 116648]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2012-02-15 17146504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=l3codecp.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"vidc.divx"=divx.dll
"vidc.div4"=DivXc32f.dll
"vidc.div3"=DivXc32.dll
"vidc.xvid"=xvidvfw.dll
"vidc.mp43"=mpg4c32.dll
"msacm.l3radius"=l3codecp.acm
"msacm.divxa"=divxa32.acm
"msacm.vorbis"=Vorbis.acm
"msacm.a3d"=a3d.dll
"VIDC.YV12"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"VIDC.FFDS"=ff_vfw.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 3 months======

2012-06-19 00:45:52 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2012-06-18 22:32:59 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2012-06-18 22:32:57 ----A---- C:\Windows\system32\drivers\aswSP.sys
2012-06-18 22:32:47 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2012-06-18 22:32:43 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2012-06-18 22:32:40 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2012-06-18 22:32:30 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2012-06-18 22:28:59 ----A---- C:\Windows\avastSS.scr
2012-06-18 22:28:58 ----A---- C:\Windows\system32\aswBoot.exe
2012-06-18 22:28:47 ----D---- C:\ProgramData\AVAST Software
2012-06-18 22:28:47 ----D---- C:\Program Files\AVAST Software
2012-06-18 10:12:54 ----D---- C:\Program Files\trend micro
2012-06-18 10:12:53 ----D---- C:\rsit
2012-06-16 23:20:22 ----D---- C:\Users\Ondra\AppData\Roaming\Opera
2012-06-16 23:19:53 ----D---- C:\Program Files\Opera
2012-06-16 18:10:36 ----SHD---- C:\Config.Msi
2012-06-16 18:06:15 ----RASH---- C:\MSDOS.SYS
2012-06-16 18:06:15 ----RASH---- C:\IO.SYS
2012-06-12 05:49:38 ----D---- C:\Program Files\Conduit
2012-06-10 14:47:34 ----D---- C:\Sierra
2012-06-09 18:16:03 ----D---- C:\Users\Ondra\AppData\Roaming\Media Finder
2012-06-06 09:34:49 ----D---- C:\Program Files\uTorrent
2012-06-06 09:34:05 ----D---- C:\Users\Ondra\AppData\Roaming\uTorrent
2012-06-06 09:29:43 ----D---- C:\ProgramData\Tarma Installer
2012-06-06 09:29:07 ----D---- C:\Program Files\SweetIM
2012-06-06 09:28:46 ----D---- C:\Users\Ondra\AppData\Roaming\Mozilla
2012-06-06 09:28:31 ----D---- C:\Program Files\1ClickDownload
2012-06-06 09:28:10 ----D---- C:\Users\Ondra\AppData\Roaming\Python-Eggs
2012-06-06 09:28:05 ----D---- C:\Users\Ondra\AppData\Roaming\BitLord
2012-06-06 09:28:05 ----A---- C:\Users\Ondra\AppData\Roaming\bitlord_log.txt
2012-06-06 09:24:10 ----D---- C:\Program Files\BitLord 2
2012-05-31 22:24:33 ----D---- C:\Program Files\Microsoft Office
2012-05-31 22:23:47 ----D---- C:\Program Files\MSECache
2012-05-18 13:21:27 ----D---- C:\Users\Ondra\AppData\Roaming\Skype
2012-05-18 13:21:11 ----RD---- C:\Program Files\Skype
2012-05-18 13:21:11 ----D---- C:\ProgramData\Skype
2012-05-18 13:21:11 ----D---- C:\Program Files\Common Files\Skype
2012-04-26 21:38:19 ----D---- C:\Users\Ondra\AppData\Roaming\Malwarebytes
2012-04-26 21:38:04 ----D---- C:\ProgramData\Malwarebytes
2012-04-26 21:38:04 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2012-04-26 21:38:04 ----A---- C:\Windows\system32\drivers\mbam.sys
2012-04-26 21:36:31 ----D---- C:\Program Files\CCleaner
2012-04-26 21:35:38 ----D---- C:\Program Files\Google
2012-04-25 14:58:29 ----D---- C:\ProgramData\boost_interprocess
2012-04-25 14:50:36 ----D---- C:\ProgramData\Boss Media
2012-04-25 14:50:20 ----D---- C:\Program Files\ParadisePoker
2012-04-25 14:38:24 ----D---- C:\Program Files\PokerStars
2012-04-24 21:47:36 ----D---- C:\Users\Ondra\AppData\Roaming\Ashampoo
2012-04-24 11:27:51 ----D---- C:\Users\Ondra\AppData\Roaming\Media Player Classic
2012-04-24 11:12:30 ----A---- C:\Windows\system32\xvidvfw.dll
2012-04-24 11:12:30 ----A---- C:\Windows\system32\xvidcore.dll
2012-04-24 11:12:29 ----A---- C:\Windows\system32\unrar.dll
2012-04-24 11:12:25 ----A---- C:\Windows\system32\ff_vfw.dll
2012-04-24 11:12:22 ----D---- C:\Program Files\K-Lite Codec Pack
2012-04-22 23:19:08 ----A---- C:\Windows\iun6002.exe
2012-04-22 22:49:48 ----D---- C:\Users\Ondra\AppData\Roaming\COWON
2012-04-22 22:14:40 ----D---- C:\Program Files\Kodek CZ
2012-04-22 22:07:09 ----D---- C:\Program Files\Common Files\COWON
2012-04-22 22:07:08 ----D---- C:\Program Files\JetAudio
2012-04-22 22:06:49 ----HD---- C:\Program Files\InstallShield Installation Information
2012-04-21 18:36:03 ----D---- C:\Users\Ondra\AppData\Roaming\WinRAR
2012-04-21 18:35:58 ----D---- C:\Program Files\WinRAR
2012-04-21 05:30:16 ----N---- C:\Windows\system32\MpSigStub.exe
2012-04-21 05:07:47 ----D---- C:\Program Files\Microsoft.NET
2012-04-21 04:49:36 ----D---- C:\Users\Ondra\AppData\Roaming\Macromedia
2012-04-21 04:49:36 ----D---- C:\Users\Ondra\AppData\Roaming\Adobe
2012-04-21 04:44:20 ----SHD---- C:\Windows\Installer
2012-04-21 02:42:51 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2012-04-21 02:42:51 ----A---- C:\Windows\system32\PresentationHost.exe
2012-04-21 02:42:51 ----A---- C:\Windows\system32\netfxperf.dll
2012-04-21 02:42:51 ----A---- C:\Windows\system32\mscoree.dll
2012-04-21 02:42:51 ----A---- C:\Windows\system32\dfshim.dll
2012-04-21 02:37:31 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-04-20 21:40:15 ----D---- C:\Windows\Panther
2012-04-20 21:40:00 ----RASH---- C:\BOOTSECT.BAK
2012-04-20 21:39:57 ----SHD---- C:\Boot
2012-04-20 21:26:36 ----D---- C:\Users\Ondra\AppData\Roaming\Identities
2012-04-20 21:25:56 ----SD---- C:\Users\Ondra\AppData\Roaming\Microsoft
2012-04-20 21:25:56 ----D---- C:\Users\Ondra\AppData\Roaming\Media Center Programs
2012-04-20 21:22:53 ----SHD---- C:\Recovery
2012-04-20 21:22:53 ----SHD---- C:\ProgramData\Šablony
2012-04-20 21:22:52 ----SHD---- C:\ProgramData\Plocha
2012-04-20 21:22:52 ----SHD---- C:\ProgramData\Oblíbené položky
2012-04-20 21:22:52 ----SHD---- C:\ProgramData\Nabídka Start
2012-04-20 21:22:52 ----SHD---- C:\ProgramData\Dokumenty
2012-04-20 21:22:52 ----SHD---- C:\ProgramData\Data aplikací
2012-04-20 21:18:24 ----A---- C:\Windows\system32\atiicdxx.dat
2012-04-20 21:17:13 ----D---- C:\Windows\SoftwareDistribution
2012-04-20 21:13:35 ----D---- C:\Windows\Prefetch
2012-04-20 21:13:26 ----ASH---- C:\pagefile.sys
2012-04-20 21:13:24 ----SHD---- C:\System Volume Information
2012-04-20 21:13:24 ----ASH---- C:\hiberfil.sys

======List of files/folders modified in the last 3 months======

2012-06-19 20:02:32 ----D---- C:\Windows\Temp
2012-06-19 19:58:00 ----D---- C:\Windows
2012-06-19 19:57:56 ----D---- C:\Windows\system32\drivers
2012-06-19 19:54:41 ----D---- C:\Windows\Branding
2012-06-19 03:40:57 ----D---- C:\Windows\system32\config
2012-06-18 22:32:05 ----D---- C:\Windows\winsxs
2012-06-18 22:30:04 ----D---- C:\Program Files\Common Files\microsoft shared
2012-06-18 22:28:58 ----D---- C:\Windows\System32
2012-06-18 22:28:47 ----RD---- C:\Program Files
2012-06-18 22:28:47 ----HD---- C:\ProgramData
2012-06-18 22:28:29 ----D---- C:\Windows\inf
2012-06-16 17:03:45 ----D---- C:\Windows\system32\catroot2
2012-05-18 13:21:11 ----D---- C:\Program Files\Common Files
2012-05-12 16:44:28 ----D---- C:\Windows\system32\wdi
2012-04-28 05:58:10 ----D---- C:\Windows\system32\Tasks
2012-04-28 05:58:09 ----D---- C:\Windows\Tasks
2012-04-28 05:31:17 ----D---- C:\Windows\debug
2012-04-26 19:39:37 ----D---- C:\Windows\Microsoft.NET
2012-04-26 19:08:48 ----RSD---- C:\Windows\assembly
2012-04-26 19:06:06 ----D---- C:\Windows\system32\en-US
2012-04-23 00:00:02 ----SD---- C:\ProgramData\Microsoft
2012-04-22 23:58:07 ----D---- C:\Windows\system32\drivers\UMDF
2012-04-22 09:21:27 ----D---- C:\Windows\system32\LogFiles
2012-04-21 09:59:07 ----D---- C:\Windows\system32\catroot
2012-04-21 09:41:22 ----D---- C:\Windows\Logs
2012-04-21 05:10:12 ----D---- C:\Windows\system32\cs-CZ
2012-04-21 04:46:29 ----D---- C:\Windows\system32\CodeIntegrity
2012-04-21 02:42:25 ----D---- C:\Windows\system32\restore
2012-04-20 21:39:39 ----D---- C:\Windows\Setup
2012-04-20 21:26:32 ----SHD---- C:\$Recycle.Bin
2012-04-20 21:25:56 ----RD---- C:\Users
2012-04-20 21:22:53 ----D---- C:\Program Files\Windows NT
2012-04-20 21:19:01 ----D---- C:\Windows\system32\sysprep
2012-04-20 21:14:48 ----D---- C:\Windows\CSC
2012-04-20 20:38:30 ----D---- C:\Windows\system32\wbem

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [2012-03-07 44376]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2012-03-07 612184]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2012-03-07 337880]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2012-03-07 53848]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2012-03-07 20696]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2012-03-07 57688]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-07-14 4194816]
R3 RTL8023xp;Realtek 10/100 NIC Family NDIS x86 Driver; C:\Windows\system32\DRIVERS\Rtnicxp.sys [2009-07-14 43008]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-14 139776]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [2012-06-19 40776]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x32.sys [2009-07-14 347264]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-03-07 44768]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-02-15 158856]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Re: Zpomalený PC log z RSIT

Napsal: 19 čer 2012 19:24
od Rudy
Ještě poprosím o log ComboFix:
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware

Re: Zpomalený PC log z RSIT

Napsal: 19 čer 2012 21:39
od Blein
Log z combofixu:





ComboFix 12-06-19.03 - Ondra 19.06.2012 22:31:48.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.2047.1198 [GMT 2:00]
Spuštěný z: c:\users\Ondra\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\iun6002.exe
c:\windows\system32\is-SCIO6.tmp
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-05-19 do 2012-06-19 )))))))))))))))))))))))))))))))
.
.
2012-06-19 20:37 . 2012-06-19 20:37 -------- d-----w- c:\users\Ondra\AppData\Local\temp
2012-06-19 20:37 . 2012-06-19 20:37 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-06-18 22:45 . 2012-06-18 22:46 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-06-18 20:32 . 2012-03-06 23:01 20696 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-06-18 20:32 . 2012-03-06 23:03 337880 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-06-18 20:32 . 2012-03-06 23:02 44376 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-06-18 20:32 . 2012-03-06 23:01 53848 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-06-18 20:32 . 2012-03-06 23:03 612184 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-06-18 20:32 . 2012-03-06 23:01 57688 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-06-18 20:28 . 2012-03-06 23:15 41184 ----a-w- c:\windows\avastSS.scr
2012-06-18 20:28 . 2012-03-06 23:15 201352 ----a-w- c:\windows\system32\aswBoot.exe
2012-06-18 20:28 . 2012-06-18 20:28 -------- d-----w- c:\programdata\AVAST Software
2012-06-18 20:28 . 2012-06-18 20:28 -------- d-----w- c:\program files\AVAST Software
2012-06-18 08:12 . 2012-06-19 18:02 -------- d-----w- c:\program files\trend micro
2012-06-18 08:12 . 2012-06-18 08:13 -------- d-----w- C:\rsit
2012-06-16 21:20 . 2012-06-16 21:20 -------- d-----w- c:\users\Ondra\AppData\Local\Opera
2012-06-16 21:19 . 2012-06-16 21:20 -------- d-----w- c:\program files\Opera
2012-06-06 07:28 . 2012-06-06 07:28 -------- d-----w- c:\users\Ondra\AppData\Roaming\Python-Eggs
2012-06-06 07:28 . 2012-06-08 05:53 -------- d-----w- c:\users\Ondra\AppData\Roaming\BitLord
2012-06-06 07:24 . 2012-06-16 16:06 -------- d-----w- c:\program files\BitLord 2
2012-05-31 20:23 . 2012-05-31 20:23 -------- d-----w- c:\program files\MSECache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-18 01:06 . 2012-04-21 03:30 6734704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9513D782-6B4D-46D4-9203-0B31D79C2CBF}\mpengine.dll
2012-04-04 13:56 . 2012-04-26 19:38 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-22 18:00 . 2012-04-24 09:12 79360 ----a-w- c:\windows\system32\ff_vfw.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-06 23:15 123536 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-02-15 17146504]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-06 4241512]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2012-02-15 158856]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2012-06-18 40776]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-03-06 57688]
S3 RTL8167;Ovladač Realtek 8167 NT;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-06-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1443169670-1317229146-775207768-1000Core.job
- c:\users\Ondra\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-21 00:38]
.
2012-06-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1443169670-1317229146-775207768-1000UA.job
- c:\users\Ondra\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-21 00:38]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://home.sweetim.com/?st=1&crg=3.1010000.10011&barid={4E03905E-AFA9-11E1-A0F9-00E07DB6EC46}
mStart Page = hxxp://start.funmoods.com/?f=1&a=iron2&chnl=iron2&cd=2XzutAtN2Y1L1QzuyEtDyCtCzzyCtD0DtC0E0ByD0B0E0FyDtN0D0TzutBtDtCtBtDyCtDzy&cr=717558194
IE: Download with &Media Finder - c:\program files\Media Finder\hook.html
TCP: DhcpNameServer = 10.0.0.138 10.0.0.138
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
URLSearchHooks-{687578b9-7132-4a7a-80e4-30ee31099e03} - (no file)
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
WebBrowser-{687578B9-7132-4A7A-80E4-30EE31099E03} - (no file)
AddRemove-Funmoods Web Search - c:\progra~1\Funmoods\1.5.23.22\uninstall.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2012-06-19 22:38:56
ComboFix-quarantined-files.txt 2012-06-19 20:38
.
Před spuštěním: Volných bajtů: 43 865 038 848
Po spuštění: Volných bajtů: 43 784 060 928
.
- - End Of File - - 3FABBAD85785F62C727E9757EB137765

Re: Zpomalený PC log z RSIT

Napsal: 19 čer 2012 22:01
od Rudy
CF něco smazal, zbytek logu vypadá čistý. Ještě jednou se vrátíme k RSIT. Dvouklikem na soubor C:\Program Files\trend micro\Ondra.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtněte:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?st=1&crg=3.101 ... 011&barid={4E03905E-AFA9-11E1-A0F9-00E07DB6EC46}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=iron2& ... =717558194
R3 - URLSearchHook: (no name) - {687578b9-7132-4a7a-80e4-30ee31099e03} - (no file)
Klikněte na >FixChecked< a restartujte PC.

Re: Zpomalený PC log z RSIT

Napsal: 20 čer 2012 02:58
od Blein
Hijackthis:





Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:51:49, on 20.6.2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\explorer.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ondra\AppData\Local\Apps\2.0\CPZ614WR.8QR\6OZ5YQ5L.2MA\czsh..tion_0000000000000000_0000.0000_4b0cea5ebb54b0d6\CZShareManager.exe
C:\Program Files\JetAudio\JetAudio.exe
C:\Users\Ondra\AppData\Local\Google\Update\1.3.21.111\GoogleCrashHandler.exe
C:\Program Files\trend micro\Ondra.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files\Media Finder\hook.html
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 2639 bytes




Nebylo nalezeno : ----->


R3 - URLSearchHook: (no name) - {687578b9-7132-4a7a-80e4-30ee31099e03} - (no file)





Nemám zaškrtnout i totok? ----->

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =


O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll






LOG z RSIT:




Logfile of random's system information tool 1.09 (written by random/random)
Run by Ondra at 2012-06-20 03:55:24
Microsoft Windows 7 Ultimate
System drive C: has 41 GB (53%) free of 78 GB
Total RAM: 2047 MB (57% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:55:29, on 20.6.2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\explorer.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Ondra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ondra\AppData\Local\Apps\2.0\CPZ614WR.8QR\6OZ5YQ5L.2MA\czsh..tion_0000000000000000_0000.0000_4b0cea5ebb54b0d6\CZShareManager.exe
C:\Program Files\JetAudio\JetAudio.exe
C:\Users\Ondra\AppData\Local\Google\Update\1.3.21.111\GoogleCrashHandler.exe
C:\Users\Ondra\Desktop\RSIT.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\trend micro\Ondra.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files\Media Finder\hook.html
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 2705 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1443169670-1317229146-775207768-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1443169670-1317229146-775207768-1000UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-03-07 1003704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-03-07 1003704]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-03-07 4241512]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2012-02-15 17146504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2009-07-14 229376]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=l3codecp.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"vidc.divx"=divx.dll
"vidc.div4"=DivXc32f.dll
"vidc.div3"=DivXc32.dll
"vidc.xvid"=xvidvfw.dll
"vidc.mp43"=mpg4c32.dll
"msacm.l3radius"=l3codecp.acm
"msacm.divxa"=divxa32.acm
"msacm.vorbis"=Vorbis.acm
"msacm.a3d"=a3d.dll
"VIDC.YV12"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.lameacm"=lameACM.acm
"VIDC.FFDS"=ff_vfw.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 3 months======

2012-06-19 23:59:27 ----D---- C:\TEMP
2012-06-19 22:39:00 ----SHD---- C:\$RECYCLE.BIN
2012-06-19 22:38:57 ----A---- C:\ComboFix.txt
2012-06-19 22:30:10 ----A---- C:\Windows\zip.exe
2012-06-19 22:30:10 ----A---- C:\Windows\SWSC.exe
2012-06-19 22:30:10 ----A---- C:\Windows\SWREG.exe
2012-06-19 22:30:10 ----A---- C:\Windows\sed.exe
2012-06-19 22:30:10 ----A---- C:\Windows\PEV.exe
2012-06-19 22:30:10 ----A---- C:\Windows\NIRCMD.exe
2012-06-19 22:30:10 ----A---- C:\Windows\MBR.exe
2012-06-19 22:30:10 ----A---- C:\Windows\grep.exe
2012-06-19 22:30:03 ----D---- C:\ComboFix
2012-06-19 22:30:01 ----D---- C:\Qoobox
2012-06-19 22:29:39 ----D---- C:\Windows\erdnt
2012-06-19 00:45:52 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2012-06-18 22:32:59 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2012-06-18 22:32:57 ----A---- C:\Windows\system32\drivers\aswSP.sys
2012-06-18 22:32:47 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2012-06-18 22:32:43 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2012-06-18 22:32:40 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2012-06-18 22:32:30 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2012-06-18 22:28:59 ----A---- C:\Windows\avastSS.scr
2012-06-18 22:28:58 ----A---- C:\Windows\system32\aswBoot.exe
2012-06-18 22:28:47 ----D---- C:\ProgramData\AVAST Software
2012-06-18 22:28:47 ----D---- C:\Program Files\AVAST Software
2012-06-18 10:12:54 ----D---- C:\Program Files\trend micro
2012-06-18 10:12:53 ----D---- C:\rsit
2012-06-16 23:20:22 ----D---- C:\Users\Ondra\AppData\Roaming\Opera
2012-06-16 23:19:53 ----D---- C:\Program Files\Opera
2012-06-16 18:10:36 ----D---- C:\Config.Msi
2012-06-16 18:06:15 ----RASH---- C:\MSDOS.SYS
2012-06-16 18:06:15 ----RASH---- C:\IO.SYS
2012-06-12 05:49:38 ----D---- C:\Program Files\Conduit
2012-06-10 14:47:34 ----D---- C:\Sierra
2012-06-09 18:16:03 ----D---- C:\Users\Ondra\AppData\Roaming\Media Finder
2012-06-06 09:34:49 ----D---- C:\Program Files\uTorrent
2012-06-06 09:34:05 ----D---- C:\Users\Ondra\AppData\Roaming\uTorrent
2012-06-06 09:29:43 ----D---- C:\ProgramData\Tarma Installer
2012-06-06 09:29:07 ----D---- C:\Program Files\SweetIM
2012-06-06 09:28:46 ----D---- C:\Users\Ondra\AppData\Roaming\Mozilla
2012-06-06 09:28:31 ----D---- C:\Program Files\1ClickDownload
2012-06-06 09:28:10 ----D---- C:\Users\Ondra\AppData\Roaming\Python-Eggs
2012-06-06 09:28:05 ----D---- C:\Users\Ondra\AppData\Roaming\BitLord
2012-06-06 09:28:05 ----A---- C:\Users\Ondra\AppData\Roaming\bitlord_log.txt
2012-06-06 09:24:10 ----D---- C:\Program Files\BitLord 2
2012-05-31 22:24:33 ----D---- C:\Program Files\Microsoft Office
2012-05-31 22:23:47 ----D---- C:\Program Files\MSECache
2012-05-18 13:21:27 ----D---- C:\Users\Ondra\AppData\Roaming\Skype
2012-05-18 13:21:11 ----RD---- C:\Program Files\Skype
2012-05-18 13:21:11 ----D---- C:\ProgramData\Skype
2012-05-18 13:21:11 ----D---- C:\Program Files\Common Files\Skype
2012-04-26 21:38:19 ----D---- C:\Users\Ondra\AppData\Roaming\Malwarebytes
2012-04-26 21:38:04 ----D---- C:\ProgramData\Malwarebytes
2012-04-26 21:38:04 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2012-04-26 21:38:04 ----A---- C:\Windows\system32\drivers\mbam.sys
2012-04-26 21:36:31 ----D---- C:\Program Files\CCleaner
2012-04-26 21:35:38 ----D---- C:\Program Files\Google
2012-04-25 14:58:29 ----D---- C:\ProgramData\boost_interprocess
2012-04-25 14:50:36 ----D---- C:\ProgramData\Boss Media
2012-04-25 14:50:20 ----D---- C:\Program Files\ParadisePoker
2012-04-25 14:38:24 ----D---- C:\Program Files\PokerStars
2012-04-24 21:47:36 ----D---- C:\Users\Ondra\AppData\Roaming\Ashampoo
2012-04-24 11:27:51 ----D---- C:\Users\Ondra\AppData\Roaming\Media Player Classic
2012-04-24 11:12:30 ----A---- C:\Windows\system32\xvidvfw.dll
2012-04-24 11:12:30 ----A---- C:\Windows\system32\xvidcore.dll
2012-04-24 11:12:29 ----A---- C:\Windows\system32\unrar.dll
2012-04-24 11:12:25 ----A---- C:\Windows\system32\ff_vfw.dll
2012-04-24 11:12:22 ----D---- C:\Program Files\K-Lite Codec Pack
2012-04-22 22:49:48 ----D---- C:\Users\Ondra\AppData\Roaming\COWON
2012-04-22 22:14:40 ----D---- C:\Program Files\Kodek CZ
2012-04-22 22:07:09 ----D---- C:\Program Files\Common Files\COWON
2012-04-22 22:07:08 ----D---- C:\Program Files\JetAudio
2012-04-22 22:06:49 ----HD---- C:\Program Files\InstallShield Installation Information
2012-04-21 18:36:03 ----D---- C:\Users\Ondra\AppData\Roaming\WinRAR
2012-04-21 18:35:58 ----D---- C:\Program Files\WinRAR
2012-04-21 05:30:16 ----N---- C:\Windows\system32\MpSigStub.exe
2012-04-21 05:07:47 ----D---- C:\Program Files\Microsoft.NET
2012-04-21 04:49:36 ----D---- C:\Users\Ondra\AppData\Roaming\Macromedia
2012-04-21 04:49:36 ----D---- C:\Users\Ondra\AppData\Roaming\Adobe
2012-04-21 04:44:20 ----SHD---- C:\Windows\Installer
2012-04-21 02:42:51 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2012-04-21 02:42:51 ----A---- C:\Windows\system32\PresentationHost.exe
2012-04-21 02:42:51 ----A---- C:\Windows\system32\netfxperf.dll
2012-04-21 02:42:51 ----A---- C:\Windows\system32\mscoree.dll
2012-04-21 02:42:51 ----A---- C:\Windows\system32\dfshim.dll
2012-04-21 02:37:31 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-04-20 21:40:15 ----D---- C:\Windows\Panther
2012-04-20 21:40:00 ----RASH---- C:\BOOTSECT.BAK
2012-04-20 21:39:57 ----D---- C:\Boot
2012-04-20 21:26:36 ----D---- C:\Users\Ondra\AppData\Roaming\Identities
2012-04-20 21:25:56 ----SD---- C:\Users\Ondra\AppData\Roaming\Microsoft
2012-04-20 21:25:56 ----D---- C:\Users\Ondra\AppData\Roaming\Media Center Programs
2012-04-20 21:22:53 ----SHD---- C:\ProgramData\Šablony
2012-04-20 21:22:53 ----D---- C:\Recovery
2012-04-20 21:22:52 ----SHD---- C:\ProgramData\Plocha
2012-04-20 21:22:52 ----SHD---- C:\ProgramData\Oblíbené položky
2012-04-20 21:22:52 ----SHD---- C:\ProgramData\Nabídka Start
2012-04-20 21:22:52 ----SHD---- C:\ProgramData\Dokumenty
2012-04-20 21:22:52 ----SHD---- C:\ProgramData\Data aplikací
2012-04-20 21:18:24 ----A---- C:\Windows\system32\atiicdxx.dat
2012-04-20 21:17:13 ----D---- C:\Windows\SoftwareDistribution
2012-04-20 21:13:35 ----D---- C:\Windows\Prefetch
2012-04-20 21:13:26 ----ASH---- C:\pagefile.sys
2012-04-20 21:13:24 ----SHD---- C:\System Volume Information
2012-04-20 21:13:24 ----ASH---- C:\hiberfil.sys

======List of files/folders modified in the last 3 months======

2012-06-19 22:39:02 ----D---- C:\Windows
2012-06-19 22:37:43 ----A---- C:\Windows\system.ini
2012-06-19 22:37:39 ----D---- C:\Windows\system32\drivers\etc
2012-06-19 22:37:09 ----D---- C:\Windows\System32
2012-06-19 22:35:38 ----D---- C:\Windows\system32\drivers
2012-06-19 22:35:38 ----D---- C:\Windows\AppPatch
2012-06-19 22:35:37 ----D---- C:\Program Files\Common Files
2012-06-19 19:57:56 ----D---- C:\Windows\Branding
2012-06-19 03:40:57 ----D---- C:\Windows\system32\config
2012-06-18 22:32:05 ----D---- C:\Windows\winsxs
2012-06-18 22:30:04 ----D---- C:\Program Files\Common Files\microsoft shared
2012-06-18 22:28:47 ----RD---- C:\Program Files
2012-06-18 22:28:47 ----D---- C:\ProgramData
2012-06-18 22:28:29 ----D---- C:\Windows\inf
2012-06-16 17:03:45 ----D---- C:\Windows\system32\catroot2
2012-05-12 16:44:28 ----D---- C:\Windows\system32\wdi
2012-04-28 05:58:10 ----D---- C:\Windows\system32\Tasks
2012-04-28 05:58:09 ----D---- C:\Windows\Tasks
2012-04-28 05:31:17 ----D---- C:\Windows\debug
2012-04-26 19:39:37 ----D---- C:\Windows\Microsoft.NET
2012-04-26 19:08:48 ----RSD---- C:\Windows\assembly
2012-04-26 19:06:06 ----D---- C:\Windows\system32\en-US
2012-04-23 00:00:02 ----SD---- C:\ProgramData\Microsoft
2012-04-22 23:58:07 ----D---- C:\Windows\system32\drivers\UMDF
2012-04-22 09:21:27 ----D---- C:\Windows\system32\LogFiles
2012-04-21 09:59:07 ----D---- C:\Windows\system32\catroot
2012-04-21 09:41:22 ----D---- C:\Windows\Logs
2012-04-21 05:10:12 ----D---- C:\Windows\system32\cs-CZ
2012-04-21 04:46:29 ----D---- C:\Windows\system32\CodeIntegrity
2012-04-21 02:42:25 ----D---- C:\Windows\system32\restore
2012-04-20 21:39:39 ----D---- C:\Windows\Setup
2012-04-20 21:25:56 ----RD---- C:\Users
2012-04-20 21:22:53 ----D---- C:\Program Files\Windows NT
2012-04-20 21:19:01 ----D---- C:\Windows\system32\sysprep
2012-04-20 21:14:48 ----D---- C:\Windows\CSC
2012-04-20 20:38:30 ----D---- C:\Windows\system32\wbem

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [2012-03-07 44376]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2012-03-07 612184]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2012-03-07 337880]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2012-03-07 53848]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2012-03-07 20696]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2012-03-07 57688]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-07-14 4194816]
R3 RTL8023xp;Realtek 10/100 NIC Family NDIS x86 Driver; C:\Windows\system32\DRIVERS\Rtnicxp.sys [2009-07-14 43008]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-14 139776]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 78336]
S3 catchme;catchme; \??\C:\Users\Ondra\AppData\Local\Temp\catchme.sys []
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [2012-06-19 40776]
S3 mbr;mbr; \??\C:\ComboFix\mbr.sys []
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x32.sys [2009-07-14 347264]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-03-07 44768]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-02-15 158856]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------





Počítač je na tom ok. Ještě něják pročistit stačí CCleaner?




A další dotaz byl jsem zvyklý na windows XP ted mám windows 7 ultimate poradíte mi? V XP při rozbalení ikony start byla funkce spustit, spouštěl jsem přes ní CHKDSK a ms_config. Teď nevím jak na to.

Re: Zpomalený PC log z RSIT

Napsal: 20 čer 2012 18:13
od Rudy
CCleaner používejte. Nyní toho ale mnoho nebude, PC je vyčištěn a log vypadá OK.

Re: Zpomalený PC log z RSIT

Napsal: 20 čer 2012 18:32
od Blein
Tohle to mám teda nechat být?




Nebylo nalezeno : ----->


R3 - URLSearchHook: (no name) - {687578b9-7132-4a7a-80e4-30ee31099e03} - (no file)





Nemám zaškrtnout i totok? ----->

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =


O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll




a tady na tento dotaz mi poradíte prosím?





A další dotaz byl jsem zvyklý na windows XP ted mám windows 7 ultimate poradíte mi? V XP při rozbalení ikony start byla funkce spustit, spouštěl jsem přes ní CHKDSK a ms_config. Teď nevím jak na to.




Jinak děkuji za pomoc s odvirováním PC :|

Re: Zpomalený PC log z RSIT

Napsal: 20 čer 2012 18:50
od Rudy
Kromě toho Avastu můžete fixovat.