Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

prosím o kontrolu

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Kukemale
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 21 srp 2010 11:51

prosím o kontrolu

#1 Příspěvek od Kukemale »

Dobrý den, občas se mi zabrzdí a pak zase rozjede. Tak prosím o zkouknutí.

Logfile of random's system information tool 1.08 (written by random/random)
Run by Kukemale at 2012-11-18 10:57:55
Systém Microsoft Windows XP Professional Service Pack 3
System drive H: has 5 GB (13%) free of 40 GB
Total RAM: 3326 MB (86% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:58:32, on 18.11.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\Program Files\AVAST Software\Avast\AvastSvc.exe
H:\WINDOWS\Explorer.EXE
H:\WINDOWS\system32\spoolsv.exe
H:\Program Files\AVAST Software\Avast\avastUI.exe
H:\WINDOWS\system32\RunDLL32.exe
H:\WINDOWS\RTHDCPL.EXE
H:\WINDOWS\system32\ctfmon.exe
H:\Program Files\SUPERAntiSpyware\SASCORE.EXE
H:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
H:\Program Files\Dokan\DokanLibrary\mounter.exe
H:\Program Files\CDBurnerXP\NMSAccessU.exe
H:\WINDOWS\system32\nvsvc32.exe
H:\Program Files\PANDORA.TV\PanService\PandoraService.exe
H:\WINDOWS\system32\PrintCtrl.exe
H:\WINDOWS\system32\svchost.exe
H:\Documents and Settings\Kukemale\Plocha\RSIT.exe
H:\WINDOWS\system32\wbem\wmiapsrv.exe
H:\Program Files\AVAST Software\Avast\setup\avast.setup
H:\Program Files\trend micro\Kukemale.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com/?l=dis&o=14597
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - H:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - H:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - H:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - H:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - H:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "H:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE H:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://H:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - H:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - H:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - H:\WINDOWS\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - H:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - H:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AODService - Unknown owner - H:\Program Files\AMD\OverDrive\AODAssist.exe
O23 - Service: avast! Antivirus - AVAST Software - H:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Capture Device Service - InterVideo Inc. - H:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - H:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DokanMounter - Unknown owner - H:\Program Files\Dokan\DokanLibrary\mounter.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - H:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - H:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NMSAccess - Unknown owner - H:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - H:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - H:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PandoraService (PanService) - Pandora.TV - H:\Program Files\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: Printer Control - ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM - H:\WINDOWS\system32\PrintCtrl.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - H:\Program Files\SiSoftware Sandra Professional 2005\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - H:\Program Files\SiSoftware Sandra Professional 2005\RpcSandraSrv.exe
O23 - Service: ServiceLayer - Nokia - H:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 6285 bytes

======Scheduled tasks folder======

H:\WINDOWS\tasks\Adobe Flash Player Updater.job
H:\WINDOWS\tasks\avast! Emergency Update.job
H:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-448539723-1993962763-725345543-1003Core.job
H:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-448539723-1993962763-725345543-1003UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - H:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - H:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll [2012-04-04 453504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - H:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-10-30 1227736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - H:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll [2012-04-04 157576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - H:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-10-30 1227736]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast"=H:\Program Files\AVAST Software\Avast\avastUI.exe [2012-10-30 4297136]
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit -login []
"NvCplDaemon"=H:\WINDOWS\system32\NvCpl.dll [2012-08-30 15512424]
"RTHDCPL"=H:\WINDOWS\RTHDCPL.EXE [2000-01-01 20065936]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=H:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
H:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27 919008]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
H:\Documents and Settings\Kukemale\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2012-03-28 116648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mouseElf]
H:\PROGRA~1\GAMING~1\MouseElf.EXE [2006-02-27 471166]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrintDisp]
H:\WINDOWS\system32\PrintDisp.exe [2011-01-03 976896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
H:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [2011-05-04 551296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=H:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2011-07-19 113024]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoResolveSearch"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"F:\Program Files\StrongDC++\StrongDC.exe"="F:\Program Files\StrongDC++\StrongDC.exe:*:Enabled:StrongDC++"
"F:\Program Files\StrongDC++ 222\StrongDC.exe"="F:\Program Files\StrongDC++ 222\StrongDC.exe:*:Enabled:StrongDC++"
"F:\Program Files\1uTorrent\uTorrent.exe"="F:\Program Files\1uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"H:\Program Files\totalcmd\TOTALCMD.EXE"="H:\Program Files\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"H:\Program Files\Gigabyte\ET5Pro\update.exe"="H:\Program Files\Gigabyte\ET5Pro\update.exe:*:Enabled:ftptest"
"H:\Games\Quake III\quake3.exe"="H:\Games\Quake III\quake3.exe:*:Enabled:quake3"
"E:\________Games Install\Tom Clancy's H.A.W.X\HAWX.exe"="E:\________Games Install\Tom Clancy's H.A.W.X\HAWX.exe:*:Enabled:Tom Clancy's H.A.W.X"
"E:\________Games Install\Counter-Strike 1.6\hl.exe"="E:\________Games Install\Counter-Strike 1.6\hl.exe:*:Enabled:Half-Life Launcher"
"H:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe"="H:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater"
"H:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe"="H:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process "
"H:\Program Files\Skype\Phone\Skype.exe"="H:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype "
"E:\________Games Install\DiRT2\dirt2_game.exe"="E:\________Games Install\DiRT2\dirt2_game.exe:*:Enabled:DiRT2"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"H:\Program Files\SiSoftware Sandra Professional 2005\sandra.exe"="H:\Program Files\SiSoftware Sandra Professional 2005\sandra.exe:*:Enabled:SiSoftware Sandra Professional"
"H:\Program Files\SiSoftware Sandra Professional 2005\RpcSandraSrv.exe"="H:\Program Files\SiSoftware Sandra Professional 2005\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Professional"
"H:\Program Files\SiSoftware Sandra Professional 2005\RpcDataSrv.exe"="H:\Program Files\SiSoftware Sandra Professional 2005\RpcDataSrv.exe:*:Enabled:SiSoftware Sandra Professional"

======List of files/folders created in the last 1 months======

2012-11-18 10:57:55 ----D---- H:\rsit
2012-11-16 18:53:44 ----D---- H:\Program Files\Mozilla Thunderbird
2012-11-15 19:23:58 ----D---- H:\ségra pro mamku
2012-10-28 17:34:50 ----A---- H:\WINDOWS\system32\drivers\gHidUsbF.sys
2012-10-28 17:34:48 ----D---- H:\Program Files\Gaming Mouse

======List of files/folders modified in the last 1 months======

2012-11-18 10:58:21 ----D---- H:\WINDOWS\Prefetch
2012-11-18 10:58:19 ----D---- H:\Program Files\trend micro
2012-11-18 10:58:14 ----D---- H:\WINDOWS\Temp
2012-11-18 10:58:09 ----D---- H:\WINDOWS
2012-11-18 10:52:58 ----D---- H:\WINDOWS\system32\CatRoot2
2012-11-18 10:52:58 ----A---- H:\WINDOWS\SchedLgU.Txt
2012-11-18 10:49:51 ----D---- H:\WINDOWS\system32
2012-11-18 10:49:51 ----A---- H:\WINDOWS\system32\PerfStringBackup.INI
2012-11-18 10:49:35 ----D---- H:\WINDOWS\system32\drivers
2012-11-18 10:39:24 ----D---- H:\Documents and Settings\Kukemale\Data aplikací\uTorrent
2012-11-17 20:21:57 ----A---- H:\WINDOWS\wincmd.ini
2012-11-17 09:04:46 ----D---- H:\Program Files\Mozilla Maintenance Service
2012-11-16 21:42:30 ----D---- H:\Documents and Settings\Kukemale\Data aplikací\vlc
2012-11-16 18:54:34 ----RD---- H:\Program Files
2012-11-16 00:50:05 ----A---- H:\WINDOWS\win.ini
2012-11-16 00:50:05 ----A---- H:\WINDOWS\system.ini
2012-11-16 00:42:26 ----D---- H:\Documents and Settings\Kukemale\Data aplikací\ConMet
2012-11-16 00:42:26 ----D---- H:\Documents and Settings\All Users\Data aplikací\ConMet
2012-11-16 00:42:26 ----A---- H:\WINDOWS\WININIT.INI
2012-11-12 20:20:12 ----D---- H:\Program Files\Malwarebytes' Anti-Malware
2012-11-11 20:44:14 ----SD---- H:\WINDOWS\Tasks
2012-11-03 17:17:11 ----D---- H:\Program Files\Mozilla Firefox
2012-10-30 23:50:59 ----A---- H:\WINDOWS\system32\aswBoot.exe
2012-10-28 17:35:04 ----HD---- H:\WINDOWS\inf
2012-10-28 17:34:58 ----D---- H:\WINDOWS\system32\ReinstallBackups

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 a347scsi;a347scsi; H:\WINDOWS\System32\Drivers\a347scsi.sys [2004-04-30 5248]
R0 MMRTKRNL;MMRTKRNL; H:\WINDOWS\system32\drivers\mmrtkrnl.sys [2005-01-11 92672]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; H:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 PxHelp20;PxHelp20; H:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); H:\WINDOWS\System32\drivers\sfhlp02.sys [2005-05-16 6656]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; H:\WINDOWS\system32\DRIVERS\WudfPf.sys [2009-07-13 91904]
R1 Aavmker4;avast! Asynchronous Virus Monitor; H:\WINDOWS\system32\drivers\Aavmker4.sys [2012-10-30 25256]
R1 AmdK8;Ovladač procesoru AMD; H:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-01 43008]
R1 AswRdr;aswRdr; H:\WINDOWS\system32\drivers\AswRdr.sys [2012-10-30 35928]
R1 aswSnx;aswSnx; H:\WINDOWS\system32\drivers\aswSnx.sys [2012-10-30 738504]
R1 aswSP;aswSP; H:\WINDOWS\system32\drivers\aswSP.sys [2012-10-30 361032]
R1 aswTdi;avast! Network Shield Support; H:\WINDOWS\system32\drivers\aswTdi.sys [2012-10-30 54232]
R1 EIO_XP;EIO_XP; \??\H:\WINDOWS\system32\drivers\EIO_XP.sys []
R1 PQNTDrv;PQNTDrv; H:\WINDOWS\system32\drivers\PQNTDrv.sys [2003-04-16 4228]
R1 SASDIFSV;SASDIFSV; \??\H:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\H:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; H:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R2 acedrv11;acedrv11; \??\H:\WINDOWS\system32\drivers\acedrv11.sys []
R2 Aspi32;Aspi32; H:\WINDOWS\system32\drivers\Aspi32.sys [1997-12-23 23936]
R2 aswFsBlk;aswFsBlk; H:\WINDOWS\system32\drivers\aswFsBlk.sys [2012-10-30 21256]
R2 aswMon2;avast! Standard Shield Support; H:\WINDOWS\system32\drivers\aswMon2.sys [2012-10-30 97608]
R2 Dokan;Dokan; \??\H:\WINDOWS\system32\drivers\dokan.sys []
R2 hwpsgt;hwpsgt; H:\WINDOWS\system32\DRIVERS\hwpsgt.sys [2009-11-11 137344]
R2 lemsgt;lemsgt; H:\WINDOWS\system32\DRIVERS\lemsgt.sys [2009-11-11 9472]
R2 PfModNT;PfModNT; \??\H:\WINDOWS\system32\drivers\PfModNT.sys []
R2 RtNdPt5x;Realtek NDIS Protocol Driver; H:\WINDOWS\system32\DRIVERS\RtNdPt5x.sys [2008-07-09 22016]
R2 StarOpen;StarOpen; H:\WINDOWS\system32\drivers\StarOpen.sys [2009-11-12 5504]
R3 AmdLLD;AMD Low Level Device Driver; H:\WINDOWS\system32\DRIVERS\AmdLLD.sys [2007-06-29 34304]
R3 Arp1394;Protokol 1394 ARP Client; H:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 dtscsi;dtscsi; H:\WINDOWS\System32\Drivers\dtscsi.sys [2011-02-13 223128]
R3 genmcmnUSB;USB Scroll Mouse Driver; H:\WINDOWS\system32\DRIVERS\gflmouhid.sys [2005-07-12 7808]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; H:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; H:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); H:\WINDOWS\system32\drivers\RtkHDAud.sys [2000-01-01 6141584]
R3 mouhid;Ovladač myši standardu HID; H:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 NIC1394;1394 Net Driver; H:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; H:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2012-08-30 12555680]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; H:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2000-01-01 327400]
S0 sptd;sptd; H:\WINDOWS\System32\Drivers\sptd.sys [2011-02-13 664064]
S1 asusgsb;ASUS Virtual Video Capture Device Driver; H:\WINDOWS\system32\drivers\asusgsb32.sys []
S1 ATITool;ATITool Overclocking Utility; H:\WINDOWS\system32\DRIVERS\ATITool.sys [2006-11-10 24064]
S1 SBRE;SBRE; \??\H:\WINDOWS\system32\drivers\SBREdrv.sys []
S2 EIO;EIO; \??\H:\WINDOWS\system32\drivers\EIO.sys []
S3 Ambfilt;Ambfilt; H:\WINDOWS\system32\drivers\Ambfilt.sys [2000-01-01 1691480]
S3 CCDECODE;Dekodér Closed Caption; H:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 cpuz129;cpuz129; \??\H:\DOCUME~1\Kukemale\LOCALS~1\Temp\cpuz_x32.sys []
S3 cpuz132;cpuz132; \??\H:\DOCUME~1\Kukemale\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys []
S3 ENTECH;ENTECH; \??\H:\WINDOWS\system32\DRIVERS\ENTECH.sys []
S3 ET5Drv;ET5Drv; \??\H:\WINDOWS\system32\Drivers\ET5Drv.sys []
S3 gdrv;gdrv; \??\H:\WINDOWS\gdrv.sys []
S3 genmcmn;Genius Mouse Driver; H:\WINDOWS\system32\DRIVERS\gmfiltr.sys [2005-07-02 16896]
S3 hid7906;hid7906; H:\WINDOWS\system32\drivers\hid7906.sys [2006-07-04 53921]
S3 Jukebox3;Jukebox3; H:\WINDOWS\system32\DRIVERS\ctpdusb.sys [2004-05-18 16880]
S3 Monfilt;Monfilt; H:\WINDOWS\system32\drivers\Monfilt.sys [2000-01-01 1395800]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; H:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; H:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; H:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 nmwcd;Nokia USB Phone Parent Driver; H:\WINDOWS\system32\drivers\ccdcmb.sys [2010-07-30 18048]
S3 nmwcdc;Nokia USB Communication Driver; H:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-07-30 23040]
S3 pccsmcfd;PCCS Mode Change Filter Driver; H:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 Rockusb;Driver for Emgeton Cult M1; H:\WINDOWS\system32\DRIVERS\rockusb.sys [2011-11-02 44528]
S3 RTLTEAMING;Realtek Intermediate Driver for Ethernet Extended Features; H:\WINDOWS\system32\DRIVERS\RTLTEAMING.SYS [2009-10-12 29440]
S3 RTLVLAN;Realtek VLAN Intermediate Driver; H:\WINDOWS\system32\DRIVERS\RTLVLAN.SYS [2009-02-16 17536]
S3 SLIP;BDA Slip De-Framer; H:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; H:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 SWDUMon;SWDUMon; H:\WINDOWS\system32\DRIVERS\SWDUMon.sys [2012-10-28 13024]
S3 SymIM;Symantec Network Security Intermediate Filter Service; H:\WINDOWS\system32\DRIVERS\SymIM.sys []
S3 SymIMMP;SymIMMP; H:\WINDOWS\system32\DRIVERS\SymIM.sys []
S3 upperdev;upperdev; H:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-07-30 8192]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; H:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbscan;Ovladač skeneru USB; H:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; H:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; H:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-07-30 8192]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; H:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Video3D;ASUS Video3D Service; H:\WINDOWS\System32\Drivers\Video3D32.sys []
S3 Wdf01000;Kernel Mode Driver Frameworks service; H:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WSTCODEC;Dálnopisný kodek světového standardu; H:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; H:\WINDOWS\system32\DRIVERS\wudfrd.sys [2009-07-13 132224]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; H:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; H:\Program Files\SUPERAntiSpyware\SASCORE.EXE [2011-08-12 116608]
R2 avast! Antivirus;avast! Antivirus; H:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-10-30 44808]
R2 Capture Device Service;Capture Device Service; H:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe [2007-03-06 198168]
R2 DokanMounter;DokanMounter; H:\Program Files\Dokan\DokanLibrary\mounter.exe [2011-01-10 25088]
R2 NMSAccess;NMSAccess; H:\Program Files\CDBurnerXP\NMSAccessU.exe [2010-03-04 71096]
R2 NVSvc;NVIDIA Driver Helper Service; H:\WINDOWS\system32\nvsvc32.exe [2012-08-30 164200]
R2 PanService;PandoraService; H:\Program Files\PANDORA.TV\PanService\PandoraService.exe [2012-06-22 625816]
R2 Printer Control;Printer Control; H:\WINDOWS\system32\PrintCtrl.exe [2009-10-28 65536]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; H:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 AODService;AODService; H:\Program Files\AMD\OverDrive\AODAssist.exe [2011-05-25 136616]
S2 nvUpdatusService;NVIDIA Update Service Daemon; H:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-08-30 1258856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; H:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-08 250808]
S3 aspnet_state;ASP.NET State Service; H:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; H:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 Creative Service for CDROM Access;Creative Service for CDROM Access; H:\WINDOWS\system32\CTsvcCDA.EXE [1999-12-13 44032]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; H:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-11-08 651720]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; H:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; H:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 idsvc;Windows CardSpace; H:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MozillaMaintenance;Mozilla Maintenance Service; H:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-11-16 115168]
S3 SandraDataSrv;Sandra Data Service; H:\Program Files\SiSoftware Sandra Professional 2005\RpcDataSrv.exe [2004-11-21 156656]
S3 SandraTheSrv;Sandra Service; H:\Program Files\SiSoftware Sandra Professional 2005\RpcSandraSrv.exe [2004-11-21 1131496]
S3 ServiceLayer;ServiceLayer; H:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-12-08 628736]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; H:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: prosím o kontrolu

#2 Příspěvek od Roli »

Zdravím, smaž nepotřebné soubory

pomocí CCleaneru

návod :

Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš

Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)

čištění registru je třeba několikrát zopakovat !

Nástroje - tady lze odinstalovat programy, upravit co se spustí po Startu systému a obnovit systém


Pak použij Mbam z mého podpisu a dej mi sem z něj log, předem nic nemazat !!!
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Kukemale
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 21 srp 2010 11:51

Re: prosím o kontrolu

#3 Příspěvek od Kukemale »

vše provedeno..
(CCleaner používám jednou týdně ;MbAM jednou za 2 týdny)

Vše v pořádku, nic to neukázalo.

..a problém zůstává :(

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: prosím o kontrolu

#4 Příspěvek od Roli »

Tak jdeme ještě hlouběji.


Stáhni a ulož na plochu ComboFix,

spusť aplikaci jako Administrátor a povol instalaci Konzole pro zotavení - Recovery Console.

Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,

pak ještě jednou klik na ANO a už to jede.

Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.

Při skenovaní může být PC i restartováno nelekat se.

Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,

protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.

Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt

(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.


V případě nejasností je ZDE obrázkový návod.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Kukemale
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 21 srp 2010 11:51

Re: prosím o kontrolu

#5 Příspěvek od Kukemale »

tu je log:

ComboFix 12-11-20.02 - Kukemale 20.11.2012 20:45:19.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3326.2686 [GMT 1:00]
Spuštěný z: h:\documents and settings\Kukemale\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
h:\documents and settings\Kukemale\WINDOWS
h:\program files\Downloaded Installers
h:\program files\Downloaded Installers\{1E91951D-0114-4692-8F55-F95E1B2F3542}\setup.msi
h:\windows\iun6002.exe
h:\windows\pkunzip.pif
h:\windows\pkzip.pif
h:\windows\system32\URTTemp
h:\windows\system32\URTTemp\regtlib.exe
h:\windows\UA000079.DLL
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-10-20 do 2012-11-20 )))))))))))))))))))))))))))))))
.
.
2012-11-18 09:57 . 2012-11-18 09:58 -------- d-----w- H:\rsit
2012-11-16 17:53 . 2012-11-16 17:54 -------- d-----w- h:\program files\Mozilla Thunderbird
2012-11-15 18:23 . 2012-11-15 18:48 -------- d-----w- H:\ségra pro mamku
2012-10-28 16:34 . 2005-07-11 10:03 12800 ----a-w- h:\windows\system32\drivers\gHidUsbF.sys
2012-10-28 16:34 . 2012-10-28 16:34 -------- d-----w- h:\program files\Gaming Mouse
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-30 22:51 . 2012-05-21 16:50 361032 ----a-w- h:\windows\system32\drivers\aswSP.sys
2012-10-30 22:51 . 2012-05-21 16:50 738504 ----a-w- h:\windows\system32\drivers\aswSnx.sys
2012-10-30 22:51 . 2012-05-21 16:50 54232 ----a-w- h:\windows\system32\drivers\aswTdi.sys
2012-10-30 22:51 . 2012-05-21 16:50 35928 ----a-w- h:\windows\system32\drivers\aswRdr.sys
2012-10-30 22:51 . 2012-05-21 16:50 97608 ----a-w- h:\windows\system32\drivers\aswmon2.sys
2012-10-30 22:51 . 2012-05-21 16:50 89752 ----a-w- h:\windows\system32\drivers\aswmon.sys
2012-10-30 22:51 . 2012-05-21 16:50 21256 ----a-w- h:\windows\system32\drivers\aswFsBlk.sys
2012-10-30 22:51 . 2012-05-21 16:50 25256 ----a-w- h:\windows\system32\drivers\aavmker4.sys
2012-10-30 22:51 . 2012-05-21 16:50 41224 ----a-w- h:\windows\avastSS.scr
2012-10-30 22:50 . 2012-05-21 16:50 227648 ----a-w- h:\windows\system32\aswBoot.exe
2012-10-28 16:33 . 2012-10-03 20:36 13024 ----a-w- h:\windows\system32\drivers\SWDUMon.sys
2012-10-08 22:00 . 2012-05-10 18:07 696760 ----a-w- h:\windows\system32\FlashPlayerApp.exe
2012-10-08 22:00 . 2011-09-21 22:05 73656 ----a-w- h:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-29 18:54 . 2012-05-21 17:03 22856 ----a-w- h:\windows\system32\drivers\mbam.sys
2012-08-30 19:10 . 2012-10-03 20:50 888168 ----a-w- h:\windows\system32\nvdispgenco32.dll
2012-08-30 19:10 . 2012-10-03 20:50 5947392 ----a-w- h:\windows\system32\nvopencl.dll
2012-08-30 19:10 . 2011-09-14 16:06 1009512 ----a-w- h:\windows\system32\nvdispco32.dll
2012-08-30 19:10 . 2010-08-09 20:40 2578792 ----a-w- h:\windows\system32\nvcuvid.dll
2012-08-30 19:10 . 2010-08-09 20:40 19103744 ----a-w- h:\windows\system32\nvoglnt.dll
2012-08-30 19:10 . 2010-08-09 20:40 1866088 ----a-w- h:\windows\system32\nvcuvenc.dll
2012-08-30 19:10 . 2010-08-09 20:39 7446528 ----a-w- h:\windows\system32\nvcuda.dll
2012-08-30 19:10 . 2010-08-09 20:39 2376704 ----a-w- h:\windows\system32\nvapi.dll
2012-08-30 19:10 . 2010-08-09 20:39 17551360 ----a-w- h:\windows\system32\nvcompiler.dll
2012-08-30 19:10 . 2009-03-29 13:22 12555680 ----a-w- h:\windows\system32\drivers\nv4_mini.sys
2012-08-30 19:10 . 2008-04-14 03:21 4494208 ----a-w- h:\windows\system32\nv4_disp.dll
2012-08-30 16:49 . 2010-07-09 14:24 253952 ----a-w- h:\windows\system32\nvrsth.dll
2012-08-30 16:49 . 2010-07-09 14:24 335872 ----a-w- h:\windows\system32\nvrshe.dll
2012-08-30 16:49 . 2010-07-09 14:24 274432 ----a-w- h:\windows\system32\nvrsnl.dll
2012-08-30 16:49 . 2010-07-09 14:24 249856 ----a-w- h:\windows\system32\nvrsfi.dll
2012-08-30 16:49 . 2010-07-09 14:24 253952 ----a-w- h:\windows\system32\nvrsno.dll
2012-08-30 16:49 . 2010-07-09 14:24 274432 ----a-w- h:\windows\system32\nvrspt.dll
2012-08-30 16:49 . 2010-07-09 14:24 274432 ----a-w- h:\windows\system32\nvrsesm.dll
2012-08-30 16:49 . 2010-07-09 14:24 282624 ----a-w- h:\windows\system32\nvrsit.dll
2012-08-30 16:49 . 2010-07-09 14:24 253952 ----a-w- h:\windows\system32\nvrssv.dll
2012-08-30 16:49 . 2010-07-09 14:24 286720 ----a-w- h:\windows\system32\nvrsfr.dll
2012-08-30 16:49 . 2010-07-09 14:24 258048 ----a-w- h:\windows\system32\nvrssk.dll
2012-08-30 16:49 . 2010-07-09 14:24 126976 ----a-w- h:\windows\system32\nvrszht.dll
2012-08-30 16:49 . 2010-07-09 14:24 253952 ----a-w- h:\windows\system32\nvrsda.dll
2012-08-30 16:49 . 2010-07-09 14:24 270336 ----a-w- h:\windows\system32\nvrsptb.dll
2012-08-30 16:49 . 2010-07-09 14:24 282624 ----a-w- h:\windows\system32\nvrsel.dll
2012-08-30 16:49 . 2010-07-09 14:24 270336 ----a-w- h:\windows\system32\nvrsru.dll
2012-08-30 16:49 . 2010-07-09 14:24 258048 ----a-w- h:\windows\system32\nvrstr.dll
2012-08-30 16:49 . 2010-07-09 14:24 335872 ----a-w- h:\windows\system32\nvrsar.dll
2012-08-30 16:49 . 2010-07-09 14:24 262144 ----a-w- h:\windows\system32\nvrshu.dll
2012-08-30 16:49 . 2010-07-09 14:24 249856 ----a-w- h:\windows\system32\nvrseng.dll
2012-08-30 16:49 . 2010-07-09 14:24 229376 ----a-w- h:\windows\system32\nvrszhc.dll
2012-08-30 16:49 . 2010-07-09 14:24 274432 ----a-w- h:\windows\system32\nvrsja.dll
2012-08-30 16:49 . 2010-07-09 14:24 266240 ----a-w- h:\windows\system32\nvrsko.dll
2012-08-30 16:49 . 2010-07-09 14:24 258048 ----a-w- h:\windows\system32\nvrssl.dll
2012-08-30 16:49 . 2010-07-09 14:24 258048 ----a-w- h:\windows\system32\nvrspl.dll
2012-08-30 16:49 . 2010-07-09 14:24 282624 ----a-w- h:\windows\system32\nvrses.dll
2012-08-30 16:49 . 2010-07-09 14:24 278528 ----a-w- h:\windows\system32\nvrsde.dll
2012-08-30 16:49 . 2010-07-09 14:24 249856 ----a-w- h:\windows\system32\nvrscs.dll
2012-08-30 16:44 . 2010-07-09 14:24 54272 ----a-w- h:\windows\system32\nvwddi.dll
2012-08-30 16:43 . 2010-07-09 14:24 164200 ----a-w- h:\windows\system32\nvsvc32.exe
2012-08-30 16:43 . 2010-07-09 14:24 15512424 ----a-w- h:\windows\system32\nvcpl.dll
2012-08-30 16:43 . 2010-07-09 14:24 108392 ----a-w- h:\windows\system32\nvmctray.dll
2012-08-30 16:43 . 2010-07-09 14:24 143720 ----a-w- h:\windows\system32\nvcolor.exe
2012-09-07 12:11 . 2012-09-07 12:11 266720 ----a-w- h:\program files\mozilla firefox\components\browsercomps.dll
2009-04-07 18:52 . 2012-09-07 12:11 28672 ----a-w- h:\program files\mozilla firefox\components\GooglePlusVideosXPCOM.dll
2008-10-19 09:58 . 2012-09-07 12:11 49152 ----a-w- h:\program files\mozilla firefox\components\SiteVacuumXPCOM.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 121528 ----a-w- h:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="h:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
"NvMediaCenter"="NvMCTray.dll" [2012-08-30 108392]
"NvCplDaemon"="h:\windows\system32\NvCpl.dll" [2012-08-30 15512424]
"RTHDCPL"="RTHDCPL.EXE" [2000-01-01 20065936]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "h:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- h:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-07-27 20:51 919008 ----a-w- h:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2012-03-28 06:34 116648 ----atw- h:\documents and settings\Kukemale\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mouseElf]
2006-02-27 04:47 471166 ----a-w- h:\progra~1\GAMING~1\MouseElf.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrintDisp]
2011-01-03 01:29 976896 ----a-w- h:\windows\system32\PrintDisp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"f:\\Program Files\\StrongDC++\\StrongDC.exe"=
"f:\\Program Files\\StrongDC++ 222\\StrongDC.exe"=
"f:\\Program Files\\1uTorrent\\uTorrent.exe"=
"h:\\Program Files\\totalcmd\\TOTALCMD.EXE"=
"h:\\Program Files\\Gigabyte\\ET5Pro\\update.exe"=
"h:\\Games\\Quake III\\quake3.exe"=
"e:\\________Games Install\\Tom Clancy's H.A.W.X\\HAWX.exe"=
"e:\\________Games Install\\Counter-Strike 1.6\\hl.exe"=
"h:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"h:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"h:\\Program Files\\Skype\\Phone\\Skype.exe"=
"e:\\________Games Install\\DiRT2\\dirt2_game.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1033:TCP"= 1033:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R0 a347scsi;a347scsi;h:\windows\system32\drivers\a347scsi.sys [21.8.2010 22:30 5248]
R1 aswSnx;aswSnx;h:\windows\system32\drivers\aswSnx.sys [21.5.2012 17:50 738504]
R1 aswSP;aswSP;h:\windows\system32\drivers\aswSP.sys [21.5.2012 17:50 361032]
R1 SASDIFSV;SASDIFSV;h:\program files\SUPERAntiSpyware\sasdifsv.sys [22.7.2011 17:27 12880]
R1 SASKUTIL;SASKUTIL;h:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12.7.2011 22:55 67664]
R2 !SASCORE;SAS Core Service;h:\program files\SUPERAntiSpyware\SASCore.exe [12.8.2011 0:38 116608]
R2 acedrv11;acedrv11;h:\windows\system32\drivers\acedrv11.sys [19.1.2009 19:31 277544]
R2 aswFsBlk;aswFsBlk;h:\windows\system32\drivers\aswFsBlk.sys [21.5.2012 17:50 21256]
R2 Dokan;Dokan;h:\windows\system32\drivers\dokan.sys [10.1.2011 13:50 91904]
R2 Printer Control;Printer Control;h:\windows\system32\PrintCtrl.exe [3.6.2012 20:00 65536]
R2 RtNdPt5x;Realtek NDIS Protocol Driver;h:\windows\system32\drivers\RtNdPt5x.sys [10.8.2010 20:31 22016]
S1 SBRE;SBRE;\??\h:\windows\system32\drivers\SBREdrv.sys --> h:\windows\system32\drivers\SBREdrv.sys [?]
S2 AODService;AODService;h:\program files\AMD\OverDrive\AODAssist.exe [25.5.2011 21:54 136616]
S2 DokanMounter;DokanMounter;h:\program files\Dokan\DokanLibrary\mounter.exe [10.1.2011 13:50 25088]
S3 Ambfilt;Ambfilt;h:\windows\system32\drivers\Ambfilt.sys [30.3.2009 19:00 1691480]
S3 cpuz129;cpuz129;\??\h:\docume~1\Kukemale\LOCALS~1\Temp\cpuz_x32.sys --> h:\docume~1\Kukemale\LOCALS~1\Temp\cpuz_x32.sys [?]
S3 genmcmnUSB;USB Scroll Mouse Driver;h:\windows\system32\drivers\gflmouhid.sys [13.10.2012 18:21 7808]
S3 hid7906;hid7906;h:\windows\system32\drivers\hid7906.sys [6.9.2010 20:22 53921]
S3 Rockusb;Driver for Emgeton Cult M1;h:\windows\system32\drivers\rockusb.sys [27.2.2012 22:49 44528]
S3 RTLTEAMING;Realtek Intermediate Driver for Ethernet Extended Features;h:\windows\system32\drivers\RTLTEAMING.SYS [10.8.2010 20:31 29440]
S3 RTLVLAN;Realtek VLAN Intermediate Driver;h:\windows\system32\drivers\RTLVLAN.SYS [10.8.2010 20:31 17536]
S3 SWDUMon;SWDUMon;h:\windows\system32\drivers\SWDUMon.sys [3.10.2012 21:36 13024]
.
--- Ostatní služby/ovladače v paměti ---
.
*Deregistered* - sptd
.
Obsah adresáře 'Naplánované úlohy'
.
2012-11-20 h:\windows\Tasks\Adobe Flash Player Updater.job
- h:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-10 22:00]
.
2012-11-20 h:\windows\Tasks\avast! Emergency Update.job
- h:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2012-07-03 22:50]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://eu.ask.com/?l=dis&o=14597
uInternet Settings,ProxyOverride = <local>
IE: E&xportovat do aplikace Microsoft Excel - h:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - h:\documents and settings\Kukemale\Data aplikací\Mozilla\Firefox\Profiles\5o6geqr1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://eu.ask.com/?l=dis&o=14597
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&q=
FF - ExtSQL: !HIDDEN! 2009-09-02 20:12; {20a82645-c095-46ed-80e3-08825760534b}; h:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - ExtSQL: !HIDDEN! 2010-01-27 21:14; xmlfiller@software602.cz; h:\program files\Mozilla Firefox\extensions\xmlfiller@software602.cz
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
SafeBoot-WudfPf
SafeBoot-WudfRd
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-20 20:49
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-448539723-1993962763-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:c8,38,ac,ae,4e,59,35,37,23,8a,af,b0,76,0d,01,41,4c,ec,ce,ee,bd,0c,f3,
cc,9b,cd,c1,d2,e0,9e,ca,2a,0d,e6,eb,88,2d,50,ba,6d,88,ea,7f,af,2f,09,a3,b1,\
"??"=hex:72,c9,9d,87,c6,85,85,b7,bb,54,4b,10,f4,22,b9,80
.
[HKEY_USERS\S-1-5-21-448539723-1993962763-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:8e,00,a1,e1,86,86,07,e3,6c,8a,e0,fe,7e,91,9d,35,a6,c0,0c,e1,5e,
cd,19,2e,ea,45,55,8f,32,f5,32,4e,32,df,56,be,30,68,69,80,92,c1,2c,07,40,f2,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@h:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="h:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(860)
h:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
Celkový čas: 2012-11-20 20:50:51
ComboFix-quarantined-files.txt 2012-11-20 19:50
.
Před spuštěním: 6 751 211 520
Po spuštění: 6 689 681 408
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
multi(0)disk(0)rdisk(0)partition(3)\WINDOWS="Windows XP Professional New" /noexecute=optin /fastdetect /usepmtimer
.
- - End Of File - - 75834868D85F1AC6B42A34A497DDF246

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: prosím o kontrolu

#6 Příspěvek od Roli »

Pokud jsi tak ještě neučinil, přesuň Combofix na plochu

otevři si Poznámkový blok

do něj zkopíruj skript z následujícího okna:

Kód: Vybrat vše

Registry:: 
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=-
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=-

FireFox::
FF - ProfilePath - h:\documents and settings\Kukemale\Data aplikací\Mozilla\Firefox\Profiles\5o6geqr1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://eu.ask.com/?l=dis&o=14597
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.as ... 1750559&q=
ulož Tebou vytvořený TXT soubor jako CFScript.txt na plochu,

po uložení uchop vytvořený skript levým myšítkem a přesuň ho nad ikonu Combofixu, kde ho upustíš:

Obrázek

Po aplikaci na Tebe vypadne další log, zkopíruj ho sem

Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou,

v tom případě znovu restartuj a přitom mačkej F8 poté zvol Poslední známou funkční konfiguraci
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Kukemale
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 21 srp 2010 11:51

Re: prosím o kontrolu

#7 Příspěvek od Kukemale »

ComboFix 12-11-20.02 - Kukemale 20.11.2012 23:52:41.3.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3326.2630 [GMT 1:00]
Spuštěný z: h:\documents and settings\Kukemale\Plocha\ComboFix.exe
Použité ovládací přepínače :: h:\documents and settings\Kukemale\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-10-20 do 2012-11-20 )))))))))))))))))))))))))))))))
.
.
2012-11-20 19:54 . 2012-11-20 20:04 -------- d-----w- h:\windows\LastGood
2012-11-18 09:57 . 2012-11-18 09:58 -------- d-----w- H:\rsit
2012-11-16 17:53 . 2012-11-16 17:54 -------- d-----w- h:\program files\Mozilla Thunderbird
2012-11-15 18:23 . 2012-11-15 18:48 -------- d-----w- H:\ségra pro mamku
2012-10-28 16:34 . 2005-07-11 10:03 12800 ----a-w- h:\windows\system32\drivers\gHidUsbF.sys
2012-10-28 16:34 . 2012-10-28 16:34 -------- d-----w- h:\program files\Gaming Mouse
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-30 22:51 . 2012-05-21 16:50 361032 ----a-w- h:\windows\system32\drivers\aswSP.sys
2012-10-30 22:51 . 2012-05-21 16:50 738504 ----a-w- h:\windows\system32\drivers\aswSnx.sys
2012-10-30 22:51 . 2012-05-21 16:50 54232 ----a-w- h:\windows\system32\drivers\aswTdi.sys
2012-10-30 22:51 . 2012-05-21 16:50 35928 ----a-w- h:\windows\system32\drivers\aswRdr.sys
2012-10-30 22:51 . 2012-05-21 16:50 97608 ----a-w- h:\windows\system32\drivers\aswmon2.sys
2012-10-30 22:51 . 2012-05-21 16:50 89752 ----a-w- h:\windows\system32\drivers\aswmon.sys
2012-10-30 22:51 . 2012-05-21 16:50 21256 ----a-w- h:\windows\system32\drivers\aswFsBlk.sys
2012-10-30 22:51 . 2012-05-21 16:50 25256 ----a-w- h:\windows\system32\drivers\aavmker4.sys
2012-10-30 22:51 . 2012-05-21 16:50 41224 ----a-w- h:\windows\avastSS.scr
2012-10-30 22:50 . 2012-05-21 16:50 227648 ----a-w- h:\windows\system32\aswBoot.exe
2012-10-28 16:33 . 2012-10-03 20:36 13024 ----a-w- h:\windows\system32\drivers\SWDUMon.sys
2012-10-08 22:00 . 2012-05-10 18:07 696760 ----a-w- h:\windows\system32\FlashPlayerApp.exe
2012-10-08 22:00 . 2011-09-21 22:05 73656 ----a-w- h:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-29 18:54 . 2012-05-21 17:03 22856 ----a-w- h:\windows\system32\drivers\mbam.sys
2012-08-30 19:10 . 2012-10-03 20:50 888168 ----a-w- h:\windows\system32\nvdispgenco32.dll
2012-08-30 19:10 . 2012-10-03 20:50 5947392 ----a-w- h:\windows\system32\nvopencl.dll
2012-08-30 19:10 . 2011-09-14 16:06 1009512 ----a-w- h:\windows\system32\nvdispco32.dll
2012-08-30 19:10 . 2010-08-09 20:40 2578792 ----a-w- h:\windows\system32\nvcuvid.dll
2012-08-30 19:10 . 2010-08-09 20:40 19103744 ----a-w- h:\windows\system32\nvoglnt.dll
2012-08-30 19:10 . 2010-08-09 20:40 1866088 ----a-w- h:\windows\system32\nvcuvenc.dll
2012-08-30 19:10 . 2010-08-09 20:39 7446528 ----a-w- h:\windows\system32\nvcuda.dll
2012-08-30 19:10 . 2010-08-09 20:39 2376704 ----a-w- h:\windows\system32\nvapi.dll
2012-08-30 19:10 . 2010-08-09 20:39 17551360 ----a-w- h:\windows\system32\nvcompiler.dll
2012-08-30 19:10 . 2009-03-29 13:22 12555680 ----a-w- h:\windows\system32\drivers\nv4_mini.sys
2012-08-30 19:10 . 2008-04-14 03:21 4494208 ----a-w- h:\windows\system32\nv4_disp.dll
2012-08-30 16:49 . 2010-07-09 14:24 253952 ----a-w- h:\windows\system32\nvrsth.dll
2012-08-30 16:49 . 2010-07-09 14:24 335872 ----a-w- h:\windows\system32\nvrshe.dll
2012-08-30 16:49 . 2010-07-09 14:24 274432 ----a-w- h:\windows\system32\nvrsnl.dll
2012-08-30 16:49 . 2010-07-09 14:24 249856 ----a-w- h:\windows\system32\nvrsfi.dll
2012-08-30 16:49 . 2010-07-09 14:24 253952 ----a-w- h:\windows\system32\nvrsno.dll
2012-08-30 16:49 . 2010-07-09 14:24 274432 ----a-w- h:\windows\system32\nvrspt.dll
2012-08-30 16:49 . 2010-07-09 14:24 274432 ----a-w- h:\windows\system32\nvrsesm.dll
2012-08-30 16:49 . 2010-07-09 14:24 282624 ----a-w- h:\windows\system32\nvrsit.dll
2012-08-30 16:49 . 2010-07-09 14:24 253952 ----a-w- h:\windows\system32\nvrssv.dll
2012-08-30 16:49 . 2010-07-09 14:24 286720 ----a-w- h:\windows\system32\nvrsfr.dll
2012-08-30 16:49 . 2010-07-09 14:24 258048 ----a-w- h:\windows\system32\nvrssk.dll
2012-08-30 16:49 . 2010-07-09 14:24 126976 ----a-w- h:\windows\system32\nvrszht.dll
2012-08-30 16:49 . 2010-07-09 14:24 253952 ----a-w- h:\windows\system32\nvrsda.dll
2012-08-30 16:49 . 2010-07-09 14:24 270336 ----a-w- h:\windows\system32\nvrsptb.dll
2012-08-30 16:49 . 2010-07-09 14:24 282624 ----a-w- h:\windows\system32\nvrsel.dll
2012-08-30 16:49 . 2010-07-09 14:24 270336 ----a-w- h:\windows\system32\nvrsru.dll
2012-08-30 16:49 . 2010-07-09 14:24 258048 ----a-w- h:\windows\system32\nvrstr.dll
2012-08-30 16:49 . 2010-07-09 14:24 335872 ----a-w- h:\windows\system32\nvrsar.dll
2012-08-30 16:49 . 2010-07-09 14:24 262144 ----a-w- h:\windows\system32\nvrshu.dll
2012-08-30 16:49 . 2010-07-09 14:24 249856 ----a-w- h:\windows\system32\nvrseng.dll
2012-08-30 16:49 . 2010-07-09 14:24 229376 ----a-w- h:\windows\system32\nvrszhc.dll
2012-08-30 16:49 . 2010-07-09 14:24 274432 ----a-w- h:\windows\system32\nvrsja.dll
2012-08-30 16:49 . 2010-07-09 14:24 266240 ----a-w- h:\windows\system32\nvrsko.dll
2012-08-30 16:49 . 2010-07-09 14:24 258048 ----a-w- h:\windows\system32\nvrssl.dll
2012-08-30 16:49 . 2010-07-09 14:24 258048 ----a-w- h:\windows\system32\nvrspl.dll
2012-08-30 16:49 . 2010-07-09 14:24 282624 ----a-w- h:\windows\system32\nvrses.dll
2012-08-30 16:49 . 2010-07-09 14:24 278528 ----a-w- h:\windows\system32\nvrsde.dll
2012-08-30 16:49 . 2010-07-09 14:24 249856 ----a-w- h:\windows\system32\nvrscs.dll
2012-08-30 16:44 . 2010-07-09 14:24 54272 ----a-w- h:\windows\system32\nvwddi.dll
2012-08-30 16:43 . 2010-07-09 14:24 164200 ----a-w- h:\windows\system32\nvsvc32.exe
2012-08-30 16:43 . 2010-07-09 14:24 15512424 ----a-w- h:\windows\system32\nvcpl.dll
2012-08-30 16:43 . 2010-07-09 14:24 108392 ----a-w- h:\windows\system32\nvmctray.dll
2012-08-30 16:43 . 2010-07-09 14:24 143720 ----a-w- h:\windows\system32\nvcolor.exe
2012-09-07 12:11 . 2012-09-07 12:11 266720 ----a-w- h:\program files\mozilla firefox\components\browsercomps.dll
2009-04-07 18:52 . 2012-09-07 12:11 28672 ----a-w- h:\program files\mozilla firefox\components\GooglePlusVideosXPCOM.dll
2008-10-19 09:58 . 2012-09-07 12:11 49152 ----a-w- h:\program files\mozilla firefox\components\SiteVacuumXPCOM.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 121528 ----a-w- h:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="h:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
"NvMediaCenter"="NvMCTray.dll" [2012-08-30 108392]
"NvCplDaemon"="h:\windows\system32\NvCpl.dll" [2012-08-30 15512424]
"RTHDCPL"="RTHDCPL.EXE" [2000-01-01 20065936]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "h:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- h:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-07-27 20:51 919008 ----a-w- h:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2012-03-28 06:34 116648 ----atw- h:\documents and settings\Kukemale\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mouseElf]
2006-02-27 04:47 471166 ----a-w- h:\progra~1\GAMING~1\MouseElf.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrintDisp]
2011-01-03 01:29 976896 ----a-w- h:\windows\system32\PrintDisp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"f:\\Program Files\\StrongDC++\\StrongDC.exe"=
"f:\\Program Files\\StrongDC++ 222\\StrongDC.exe"=
"f:\\Program Files\\1uTorrent\\uTorrent.exe"=
"h:\\Program Files\\totalcmd\\TOTALCMD.EXE"=
"h:\\Program Files\\Gigabyte\\ET5Pro\\update.exe"=
"h:\\Games\\Quake III\\quake3.exe"=
"e:\\________Games Install\\Tom Clancy's H.A.W.X\\HAWX.exe"=
"e:\\________Games Install\\Counter-Strike 1.6\\hl.exe"=
"h:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"h:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"h:\\Program Files\\Skype\\Phone\\Skype.exe"=
"e:\\________Games Install\\DiRT2\\dirt2_game.exe"=
"e:\\________Games Install\\World_of_Tanks\\WorldOfTanks.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1033:TCP"= 1033:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R0 a347scsi;a347scsi;h:\windows\system32\drivers\a347scsi.sys [21.8.2010 22:30 5248]
R1 aswSnx;aswSnx;h:\windows\system32\drivers\aswSnx.sys [21.5.2012 17:50 738504]
R1 aswSP;aswSP;h:\windows\system32\drivers\aswSP.sys [21.5.2012 17:50 361032]
R1 SASDIFSV;SASDIFSV;h:\program files\SUPERAntiSpyware\sasdifsv.sys [22.7.2011 17:27 12880]
R1 SASKUTIL;SASKUTIL;h:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12.7.2011 22:55 67664]
R2 !SASCORE;SAS Core Service;h:\program files\SUPERAntiSpyware\SASCore.exe [12.8.2011 0:38 116608]
R2 acedrv11;acedrv11;h:\windows\system32\drivers\acedrv11.sys [19.1.2009 19:31 277544]
R2 aswFsBlk;aswFsBlk;h:\windows\system32\drivers\aswFsBlk.sys [21.5.2012 17:50 21256]
R2 Dokan;Dokan;h:\windows\system32\drivers\dokan.sys [10.1.2011 13:50 91904]
R2 Printer Control;Printer Control;h:\windows\system32\PrintCtrl.exe [3.6.2012 20:00 65536]
R2 RtNdPt5x;Realtek NDIS Protocol Driver;h:\windows\system32\drivers\RtNdPt5x.sys [10.8.2010 20:31 22016]
S1 SBRE;SBRE;\??\h:\windows\system32\drivers\SBREdrv.sys --> h:\windows\system32\drivers\SBREdrv.sys [?]
S2 AODService;AODService;h:\program files\AMD\OverDrive\AODAssist.exe [25.5.2011 21:54 136616]
S2 DokanMounter;DokanMounter;h:\program files\Dokan\DokanLibrary\mounter.exe [10.1.2011 13:50 25088]
S3 Ambfilt;Ambfilt;h:\windows\system32\drivers\Ambfilt.sys [30.3.2009 19:00 1691480]
S3 cpuz129;cpuz129;\??\h:\docume~1\Kukemale\LOCALS~1\Temp\cpuz_x32.sys --> h:\docume~1\Kukemale\LOCALS~1\Temp\cpuz_x32.sys [?]
S3 genmcmnUSB;USB Scroll Mouse Driver;h:\windows\system32\drivers\gflmouhid.sys [13.10.2012 18:21 7808]
S3 hid7906;hid7906;h:\windows\system32\drivers\hid7906.sys [6.9.2010 20:22 53921]
S3 Rockusb;Driver for Emgeton Cult M1;h:\windows\system32\drivers\rockusb.sys [27.2.2012 22:49 44528]
S3 RTLTEAMING;Realtek Intermediate Driver for Ethernet Extended Features;h:\windows\system32\drivers\RTLTEAMING.SYS [10.8.2010 20:31 29440]
S3 RTLVLAN;Realtek VLAN Intermediate Driver;h:\windows\system32\drivers\RTLVLAN.SYS [10.8.2010 20:31 17536]
S3 SWDUMon;SWDUMon;h:\windows\system32\drivers\SWDUMon.sys [3.10.2012 21:36 13024]
.
--- Ostatní služby/ovladače v paměti ---
.
*Deregistered* - sptd
.
Obsah adresáře 'Naplánované úlohy'
.
2012-11-20 h:\windows\Tasks\Adobe Flash Player Updater.job
- h:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-10 22:00]
.
2012-11-20 h:\windows\Tasks\avast! Emergency Update.job
- h:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2012-07-03 22:50]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://eu.ask.com/?l=dis&o=14597
uInternet Settings,ProxyOverride = <local>
IE: E&xportovat do aplikace Microsoft Excel - h:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - h:\documents and settings\Kukemale\Data aplikací\Mozilla\Firefox\Profiles\5o6geqr1.default\
FF - ExtSQL: !HIDDEN! 2009-09-02 20:12; {20a82645-c095-46ed-80e3-08825760534b}; h:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - ExtSQL: !HIDDEN! 2010-01-27 21:14; xmlfiller@software602.cz; h:\program files\Mozilla Firefox\extensions\xmlfiller@software602.cz
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-20 23:58
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-448539723-1993962763-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:c8,38,ac,ae,4e,59,35,37,23,8a,af,b0,76,0d,01,41,4c,ec,ce,ee,bd,0c,f3,
cc,9b,cd,c1,d2,e0,9e,ca,2a,0d,e6,eb,88,2d,50,ba,6d,88,ea,7f,af,2f,09,a3,b1,\
"??"=hex:72,c9,9d,87,c6,85,85,b7,bb,54,4b,10,f4,22,b9,80
.
[HKEY_USERS\S-1-5-21-448539723-1993962763-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:8e,00,a1,e1,86,86,07,e3,6c,8a,e0,fe,7e,91,9d,35,a6,c0,0c,e1,5e,
cd,19,2e,ea,45,55,8f,32,f5,32,4e,32,df,56,be,30,68,69,80,92,c1,2c,07,40,f2,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@h:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="h:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(860)
h:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
- - - - - - - > 'explorer.exe'(2480)
h:\windows\system32\msi.dll
h:\windows\system32\webcheck.dll
h:\windows\system32\WPDShServiceObj.dll
h:\windows\system32\PortableDeviceTypes.dll
h:\windows\system32\PortableDeviceApi.dll
.
Celkový čas: 2012-11-20 23:59:43
ComboFix-quarantined-files.txt 2012-11-20 22:59
ComboFix2.txt 2012-11-20 19:50
.
Před spuštěním: 6 342 918 144
Po spuštění: 6 322 016 256
.
- - End Of File - - B9EFE706C5E046F41345867BC805CD8E

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: prosím o kontrolu

#8 Příspěvek od Roli »

Přes Start >> Spustit zkopíruj do okna:

ComboFix /Uninstall

a stiskni Enter

To odinstaluje ComboFix a smaže s ním související soubory a složky.


Použij T-Cleaner, který smaže případné zbytky po aplikacích které jsme použili.

Jen před jeho stažením a při použití stopni antivir, protože ho muže detekovat jako vir ale není tomu tak.


Pak dej vědět jaký je stav PC.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Kukemale
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 21 srp 2010 11:51

Re: prosím o kontrolu

#9 Příspěvek od Kukemale »

...tak to jede jak má. :thumbsup:
Díky za tvůj čas a hlavně za tvoji pomoc.

Kde my by jsme bez vás byly .....
.....asi v :205:

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: prosím o kontrolu

#10 Příspěvek od Roli »

Bezva, není zač a :closed:
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Zamčeno