Stránka 1 z 3

Spomalený PC, zase

Napsal: 23 led 2013 19:09
od Patho
Tak, bohužiaľ sa obracám po pár hodinách opäť o pomoc.
Riešil som s vyosek tento problém http://forum.viry.cz/viewtopic.php?f=13&t=127486 a považoval som to za úspešne vyriešenú vec.
Po uprataní vecí s T-Cleaner,OTC,TFC,CcCleaner a odinštalovaní ComboFix sa všetko zdalo v poriadku, PC nebol spomalený, úplne v poriadku šlo všetko. Bol som rád, počítač naozaj bežal ako pred tým. No, teraz sa to zase vrátilo. NOD nevyhadzuje nič ako včera. Ale PC je viac spomalenejší, po pár pokusoch som sa aspoň dostal sem na forum, všetky stránky načítava strašne dlho a počas toho prestane reagovať mozilla. Ešte v tej minulej téme, keď sa zdalo, že už to je dobré som písal že idem pustiť ESET, ale ten zostál stáť na jednej položke niekde v strede kontroly asi hodinu a pol, následne som to zrušil a dal kontrolovať znova, ale opať to zostalo na jednej položke s ktorej sa to vôbec nepohlo ďalej. (druhý krát som už tak dlho nečakal či sa pohne ďalej)
Nerozumiem ako sa to mohlo od poobedia, čo som sem napísal takto zmeniť, a pritom som ani nič nerobil,bol som iba na nete ale nič nekopíroval do PC ani nič nesťahoval.
Budem rád za akúkoľvek pomoc.

Re: Spomalený PC, zase

Napsal: 25 led 2013 15:27
od Patho
Včera som skúšal ESET znova, stále je to rovnaké. Dojde to tak do 49% a zostane to tak, kontroluje to stále jednu vec, tú jednu vec kontroluje cca hodinu a pol a posunulo sa to na ďalšiu, takto pomalý to išlo, vždy sa to tak zasekne. Odvtedy som stále nič nesťahoval ani nedával do PC. Internet je spomalený tiež stále rovnako. Stránky načítava dlho a počas toho mozilla prestae reagovať(chrome som neskúšal, strašne som zvyknutý na firefox :/ ). A keď je na niakom forume youtube tak ho takto načítava http://s1.postimage.org/kflxpaukv/Bez_n_zvu.jpg a tak po 5 minútach sa tam objavý.

Už som písal vtedy, že po prvom probléme keď som poodstraňoval programy, ktoré mi poradil vyosek išiel PC normálne, zmenilo sa to všetku k večeru, vtedy som sem napísal 2 krát.

Je tu možnosť, že som spravil niečo zle keď som to odstraňoval? Nerozumiem, čo sa mohlo stať, že sa to znova zmenilo tak ako to bolo :/
Prosím Vás o pomoc. Je ešte prosím niaka šanca niečo spraviť?

Re: Spomalený PC, zase

Napsal: 25 led 2013 15:53
od Patho
Pridávam log z RSIT. Púšťalo mi to tiež viac ako 5 minút, odbehol som počas čakania tak neviem presne. Ale pri otvorení niakeho priečinku(tento počítač, dokumenty) je všetko v poriadku, okno nabehne ihneď, ale ako pri pustení RSIT, 5 minút nič a až potom to nabehlo.

Logfile of random's system information tool 1.06 (written by random/random)
Run by Patho at 2013-01-25 15:49:35
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 61 GB (40%) free of 153 GB
Total RAM: 2047 MB (67% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:50:16, on 25. 1. 2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Icon7\iConfig for Gamers\hid.exe
C:\Windows\PixArt\Pac7302\Monitor.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Icon7\iConfig for Gamers\Tray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\mobsync.exe
C:\PathoDisc\Downloads\RSIT.exe
C:\Program Files\trend micro\Patho.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [iConfigg] "C:\Program Files\Icon7\iConfig for Gamers\hid.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\Windows\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 4351 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-01-17 3855520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-08-06 6265376]
"iConfigg"=C:\Program Files\Icon7\iConfig for Gamers\hid.exe [2008-03-25 266240]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]
"PAC7302_Monitor"=C:\Windows\PixArt\PAC7302\Monitor.exe [2006-11-03 319488]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-11-16 2054360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======List of files/folders created in the last 1 months======

2013-01-25 15:38:43 ----D---- C:\rsit
2013-01-23 14:50:09 ----D---- C:\CFLog
2013-01-23 13:55:43 ----SHD---- C:\$RECYCLE.BIN
2013-01-23 13:16:31 ----D---- C:\Windows\temp
2013-01-22 17:51:21 ----D---- C:\Windows\erdnt
2013-01-22 15:51:56 ----D---- C:\Program Files\trend micro
2013-01-21 14:20:48 ----D---- C:\Program Files\Mozilla Firefox
2013-01-17 19:56:00 ----D---- C:\Users\Patho\AppData\Roaming\dclogs
2013-01-15 15:17:56 ----A---- C:\Windows\system32\mshtml.dll
2013-01-09 13:23:39 ----A---- C:\Windows\system32\ncrypt.dll
2013-01-09 13:23:37 ----A---- C:\Windows\system32\shlwapi.dll
2013-01-09 13:23:36 ----A---- C:\Windows\system32\msxml6.dll
2012-12-26 14:47:47 ----D---- C:\Program Files\BP DOWNLOADER

======List of files/folders modified in the last 1 months======

2013-01-25 15:46:53 ----D---- C:\Windows\system32\WDI
2013-01-25 15:06:01 ----SHD---- C:\System Volume Information
2013-01-24 17:34:57 ----D---- C:\Windows\System32
2013-01-24 17:33:54 ----D---- C:\Users\Patho\AppData\Roaming\Skype
2013-01-23 18:02:08 ----D---- C:\Windows
2013-01-23 18:01:55 ----D---- C:\Windows\inf
2013-01-23 16:24:44 ----D---- C:\Users\Patho\AppData\Roaming\Winamp
2013-01-23 14:14:27 ----D---- C:\Windows\SoftwareDistribution
2013-01-23 14:12:41 ----D---- C:\Users\Patho\AppData\Roaming\uTorrent
2013-01-23 14:12:41 ----D---- C:\Users\Patho\AppData\Roaming\Media Player Classic
2013-01-23 14:12:41 ----D---- C:\Users\Patho\AppData\Roaming\DAEMON Tools Lite
2013-01-23 14:12:40 ----D---- C:\Windows\Logs
2013-01-23 14:12:40 ----D---- C:\Windows\Debug
2013-01-23 14:11:10 ----D---- C:\Windows\Minidump
2013-01-23 13:14:35 ----A---- C:\Windows\system.ini
2013-01-23 13:12:12 ----D---- C:\Windows\system32\drivers
2013-01-23 13:12:12 ----D---- C:\Windows\AppPatch
2013-01-23 13:12:11 ----D---- C:\Program Files\Common Files
2013-01-22 20:51:42 ----RD---- C:\PathoDisc
2013-01-22 16:45:04 ----SHD---- C:\Windows\Installer
2013-01-22 16:41:45 ----RD---- C:\Program Files
2013-01-22 13:30:20 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-01-21 15:13:00 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-01-18 10:43:38 ----D---- C:\ProgramData
2013-01-15 20:39:09 ----D---- C:\Windows\winsxs
2013-01-15 15:15:41 ----D---- C:\Windows\system32\catroot
2013-01-14 18:21:39 ----SD---- C:\Users\Patho\AppData\Roaming\Microsoft
2013-01-12 21:18:20 ----D---- C:\Windows\system32\catroot2
2013-01-11 14:43:03 ----D---- C:\Windows\Prefetch
2013-01-10 18:44:05 ----D---- C:\Windows\Microsoft.NET
2013-01-10 18:43:37 ----RSD---- C:\Windows\assembly
2013-01-10 16:33:54 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2013-01-10 16:10:25 ----D---- C:\ProgramData\Microsoft Help
2013-01-10 15:54:20 ----A---- C:\Windows\system32\mrt.exe
2013-01-07 13:29:41 ----D---- C:\Users\Patho\AppData\Roaming\Mp3tag
2012-12-27 12:42:34 ----D---- C:\Program Files\OpenOffice.org 3
2012-12-26 13:44:40 ----D---- C:\ProgramData\PMB Files

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-08-08 232512]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-11-16 108792]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\Windows\system32\drivers\sp_rsdrv2.sys [2011-08-08 142592]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2011-08-23 281760]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-11-16 116520]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2009-12-18 95896]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2011-08-23 25888]
R3 Afc;PPdus ASPI Shell; C:\Windows\system32\drivers\Afc.sys [2005-02-23 11776]
R3 Icon7Fltr;Icon7 Gaming Laser Mouse; C:\Windows\system32\drivers\Icon7ms.sys [2008-03-19 10112]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-08-06 2164248]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2006-10-18 7680]
R3 NVENETFD;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2008-03-26 1048480]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2012-10-10 10837352]
R3 PAC7302;PAC7302 VGA USB Camera; C:\Windows\system32\DRIVERS\PAC7302.SYS [2007-06-14 457856]
R3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136]
S3 adqnz0pr;adqnz0pr; C:\Windows\system32\drivers\adqnz0pr.sys []
S3 ALSysIO;ALSysIO; \??\C:\Users\Patho\AppData\Local\Temp\ALSysIO.sys []
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files\Garena Classic\safedrv.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 XDva391;XDva391; \??\C:\Windows\system32\XDva391.sys []
S3 XDva401;XDva401; \??\C:\Windows\system32\XDva401.sys []
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-11-16 735960]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-05-03 118784]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2012-01-07 75136]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2011-08-08 496128]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-11-09 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-10 251400]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-11-16 20680]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-01-21 115608]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\system32\GameMon.des [2011-08-07 3804120]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WPFFontCache_v0400;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]

-----------------EOF-----------------

Re: Spomalený PC, zase

Napsal: 28 led 2013 20:20
od Patho
Dobrý večer,
Po 6 dňoch sa nič nezmenilo, je to stále tak isto spomalené, prosím Vás, dalo by sa ešte niečo spraviť?

Vopred veľmi, veľmi pekne ďakujem za akúkoľvek pomoc, ba či len odpoveď na môj problém.

Re: Spomalený PC, zase

Napsal: 29 led 2013 10:09
od Márty84
Zdravim :)

:arrow: Udelejte !!!kompletni!!! kontrolu s MBAM http://forum.viry.cz/viewtopic.php?f=29&t=115222 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce


:arrow: Stahnete crystal disk info http://www.slunecnice.cz/sw/crystaldiskinfo/
Nainstalujte (pozor na pripadne doplnky, ty odmitnete zrusenim zatrzitka) a spustte jako spravce. Za chvili se zobrazi vysledek.
Kliknete nahore na napis Úpravy a pak na napis Kopírovat. To co se zkopiruje (ulozi se to do pameti) mi sem vlozte

Re: Spomalený PC, zase

Napsal: 29 led 2013 18:05
od Patho
Ďakujem za odpoveď.

MBAM:

Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.70.0.1100
www.malwarebytes.org

Verze: v2013.01.29.06

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 7.0.6002.18005
Patho :: PATHO-PC [administrátor]

Ochrana: Povolena

29. 1. 2013 16:34:31
MBAM-log-2013-01-29 (18-00-52).txt

Typ: Kompletní kontrola (C:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 371191
Uplynulý čas: 1 hodin, 26 minut, 9 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 1
C:\Users\Patho\AppData\Roaming\dclogs (Stolen.Data) -> Nebyla provedena žádná instrukce.

Nalezené soubory: 4
C:\Users\Patho\AppData\Roaming\dclogs\2013-01-17-5.dc (Stolen.Data) -> Nebyla provedena žádná instrukce.
C:\Users\Patho\AppData\Roaming\dclogs\2013-01-18-6.dc (Stolen.Data) -> Nebyla provedena žádná instrukce.
C:\Users\Patho\AppData\Roaming\dclogs\2013-01-21-2.dc (Stolen.Data) -> Nebyla provedena žádná instrukce.
C:\Users\Patho\AppData\Roaming\dclogs\2013-01-22-3.dc (Stolen.Data) -> Nebyla provedena žádná instrukce.

(konec)

CrystalDiskInfo:

----------------------------------------------------------------------------
CrystalDiskInfo 5.3.1 (C) 2008-2013 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows Vista Home Premium Edition SP2 [6.0 Build 6002] (x86)
Date : 2013/01/29 18:05:17

-- Controller Map ----------------------------------------------------------
+ Standard Dual Channel PCI IDE Controller [ATA]
- IDE Channel (0)
- IDE Channel (1)
+ NVIDIA nForce Serial ATA Controller [ATA]
- ExcelSto r Technology SCSI Disk Device
- Optiarc DVD RW AD-5200S SCSI CdRom Device
+ AQ983BF1 IDE Controller [SCSI]
- WBM 6Z8LIBCT SCSI CdRom Device
- Microsoft iSCSI Initiator [SCSI]

-- Disk List ---------------------------------------------------------------
(1) ExcelStor Technology J8160S : 160,0 GB [0/2/0, sm]

----------------------------------------------------------------------------
(1) ExcelStor Technology J8160S
----------------------------------------------------------------------------
Model : ExcelStor Technology J8160S
Firmware : P22OABEA
Serial Number : PVF904Q4C5X6UB
Disk Size : 160,0 GB (8,4/137,4/160,0)
Buffer Size : 7376 KB
Queue Depth : 32
# of Sectors : 312581808
Rotation Rate : Unknown
Interface : Serial ATA
Major Version : ATA/ATAPI-7
Minor Version : ATA/ATAPI-7 T13 1532D version 1
Transfer Mode : SATA/300
Power On Hours : 12503 hours
Power On Count : 2404 count
Temparature : 45 C (113 F)
Health Status : Good
Features : S.M.A.R.T., APM, AAM, 48bit LBA, NCQ
APM Level : 0000h [OFF]
AAM Level : 80FEh [OFF]

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 100 100 _16 000000000001 Read Error Rate
02 100 100 _50 000000000000 Throughput Performance
03 134 134 _24 000300910099 Spin-Up Time
04 100 100 __0 000000000967 Start/Stop Count
05 100 100 __5 000000000000 Reallocated Sectors Count
07 100 100 _67 000000000000 Seek Error Rate
08 100 100 _20 000000000000 Seek Time Performance
09 _99 _99 __0 0000000030D7 Power-On Hours
0A 100 100 _60 000000000000 Spin Retry Count
0C 100 100 __0 000000000964 Power Cycle Count
C0 _98 _98 __0 000000000A0E Power-off Retract Count
C1 _98 _98 __0 000000000A0E Load/Unload Cycle Count
C2 133 133 __0 003A000F002D Temperature
C4 100 100 __0 000000000000 Reallocation Event Count
C5 100 100 __0 000000000000 Current Pending Sector Count
C6 100 100 __0 000000000000 Uncorrectable Sector Count
C7 200 253 __0 000000000000 UltraDMA CRC Error Count

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 045A 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 2020 2020 2020 5056 4639 3034 5134 4335 5836 5542
020: 0003 39A1 0034 5032 324F 4142 4541 4578 6365 6C53
030: 746F 7220 5465 6368 6E6F 6C6F 6779 204A 3831 3630
040: 5320 2020 2020 2020 2020 2020 2020 8010 0000 2F00
050: 4000 0200 0200 0007 3FFF 0010 003F FC10 00FB 0110
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 001F 0706 0000 005E 0040
080: 00FC 001A 346B 7FE9 4773 3469 BC01 4763 407F 001E
090: 0000 0000 FFFE 0000 80FE 0008 00CA 00F9 2710 0000
100: 9EB0 12A1 0000 0000 00CA 0000 0000 5A87 0000 0000
110: 0000 0000 0000 0000 0000 0000 0000 0000 0000 4010
120: 4010 0000 0000 0000 0000 0000 0000 0000 0009 000B
130: 0000 0000 2982 0DB1 FE20 0001 4000 0404 0000 0000
140: 0000 5DFF 27B7 11EA 0300 0280 3F7F 00C0 0040 2A00
150: 8000 0000 434E 5942 0000 AC02 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 003F 0000 0000 0000
210: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
220: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 D9A5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 0B 00 64 64 01 00 00 00 00 00 00 02 05
010: 00 64 64 00 00 00 00 00 00 00 03 07 00 86 86 99
020: 00 91 00 03 00 00 04 12 00 64 64 67 09 00 00 00
030: 00 00 05 33 00 64 64 00 00 00 00 00 00 00 07 0B
040: 00 64 64 00 00 00 00 00 00 00 08 05 00 64 64 00
050: 00 00 00 00 00 00 09 12 00 63 63 D7 30 00 00 00
060: 00 00 0A 13 00 64 64 00 00 00 00 00 00 00 0C 32
070: 00 64 64 64 09 00 00 00 00 00 C0 32 00 62 62 0E
080: 0A 00 00 00 00 00 C1 12 00 62 62 0E 0A 00 00 00
090: 00 00 C2 02 00 85 85 2D 00 0F 00 3A 00 00 C4 32
0A0: 00 64 64 00 00 00 00 00 00 00 C5 22 00 64 64 00
0B0: 00 00 00 00 00 00 C6 08 00 64 64 00 00 00 00 00
0C0: 00 00 C7 0A 00 C8 FD 00 00 00 00 00 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 31 0B 01 5B
170: 03 00 01 00 01 30 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 A5

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 10 00 00 00 00 00 00 00 00 00 00 02 32
010: 00 00 00 00 00 00 00 00 00 00 03 18 00 00 00 00
020: 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 00
030: 00 00 05 05 00 00 00 00 00 00 00 00 00 00 07 43
040: 00 00 00 00 00 00 00 00 00 00 08 14 00 00 00 00
050: 00 00 00 00 00 00 09 00 00 00 00 00 00 00 00 00
060: 00 00 0A 3C 00 00 00 00 00 00 00 00 00 00 0C 00
070: 00 00 00 00 00 00 00 00 00 00 C0 00 00 00 00 00
080: 00 00 00 00 00 00 C1 00 00 00 00 00 00 00 00 00
090: 00 00 C2 00 00 00 00 00 00 00 00 00 00 00 C4 00
0A0: 00 00 00 00 00 00 00 00 00 00 C5 00 00 00 00 00
0B0: 00 00 00 00 00 00 C6 00 00 00 00 00 00 00 00 00
0C0: 00 00 C7 00 00 00 00 00 00 00 00 00 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 68

Re: Spomalený PC, zase

Napsal: 30 led 2013 01:28
od Márty84
:arrow: Nalezy nechte odstrnit.


:arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe , ulozte ho na plochu, kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Probehne kratoucky testik a pak se zpristupni vpravo nahore tlacitko Prohledat. Na to kliknete a probehne dalsi test.
Po dokonceni kliknete na napis Zprava a objevi se log. Ten mi sem vlozte

Re: Spomalený PC, zase

Napsal: 30 led 2013 17:42
od Patho
Tak, dal som MBAM znova aby som ich odstránil a našlo ich 5, nie 4 ako včera... odstránil som všetky, ale pridávam ešte aj tento 2. MBAM log:

Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.70.0.1100
www.malwarebytes.org

Verze: v2013.01.30.04

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 7.0.6002.18005
Patho :: PATHO-PC [administrátor]

Ochrana: Povolena

30. 1. 2013 15:36:36
gdfgdg.txt

Typ: Kompletní kontrola (C:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 371963
Uplynulý čas: 1 hodin, 55 minut, 23 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 1
C:\Users\Patho\AppData\Roaming\dclogs (Stolen.Data) -> Nebyla provedena žádná instrukce.

Nalezené soubory: 4
C:\Users\Patho\AppData\Roaming\dclogs\2013-01-17-5.dc (Stolen.Data) -> Nebyla provedena žádná instrukce.
C:\Users\Patho\AppData\Roaming\dclogs\2013-01-18-6.dc (Stolen.Data) -> Nebyla provedena žádná instrukce.
C:\Users\Patho\AppData\Roaming\dclogs\2013-01-21-2.dc (Stolen.Data) -> Nebyla provedena žádná instrukce.
C:\Users\Patho\AppData\Roaming\dclogs\2013-01-22-3.dc (Stolen.Data) -> Nebyla provedena žádná instrukce.

(konec)




RogueKiller:

RogueKiller V8.4.3 [Jan 27 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.geekstogo.com/forum/files/fi ... guekiller/
Webové stránky : http://tigzy.geekstogo.com/roguekiller.php
: http://tigzyrk.blogspot.com/

Operační systém : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Spuštěno v : Normální režim
Uživatel : Patho [Práva správce]
Mód : Kontrola -- Datum : 01/30/2013 17:41:10
| ARK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 7 ¤¤¤
[HJPOL] HKCU\[...]\System : disableregistrytools (0) -> NALEZENO
[HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ] HKCU\[...]\System : EnableLUA (0) -> NALEZENO
[HJ DESK] HKCU\[...]\ClassicStartMenu : {59031A47-3F72-44A7-89C5-5595FE6B30EE} (1) -> NALEZENO
[HJ DESK] HKCU\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO] ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts

127.0.0.1 localhost


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: ExcelSto r Technology SCSI Disk Device +++++
--- User ---
[MBR] 6820a220b2670968eacd70a833460fe4
[BSP] 65d158aceda0aa8ef5b83d3febb7cf89 : Windows Vista MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 152625 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Dokončeno : << RKreport[1]_S_01302013_02d1741.txt >>
RKreport[1]_S_01302013_02d1741.txt

Re: Spomalený PC, zase

Napsal: 30 led 2013 18:01
od Márty84
OK, pokud je vsechno pryc, je to dobre.


:arrow: Znovu spustte RogueKiller jako spravce (pokud jste ho jeste nezavrel/a, rovnou kliknete na napis Smazat)
Probehne kratoucky testik a pak se zpristupni vpravo nahore tlacitko Prohledat. Na to kliknete a probehne dalsi test.
Po dokonceni kliknete na napis Smazat.
Pak kliknete na napis Zprava a objevi se log. Ten mi sem vlozte.
Pak kliknete na napis Oprava Host a Zprava.
Objevi se dalsi log. I ten mi sem vlozte.

Re: Spomalený PC, zase

Napsal: 30 led 2013 18:25
od Patho
log 1. smazanie:

RogueKiller V8.4.3 [Jan 27 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.geekstogo.com/forum/files/fi ... guekiller/
Webové stránky : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operačný systém : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Spustené v : Normálny režim
Užívateľ : Patho [Práva Správcu]
Režim : Odebrať -- Dátum : 01/30/2013 18:23:44
| ARK || MBR |

¤¤¤ Škodlivé procesy : 0 ¤¤¤

¤¤¤ Záznamy Registrov : 7 ¤¤¤
[HJPOL] HKCU\[...]\System : disableregistrytools (0) -> VYMAZANÉ
[HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> VYMAZANÉ
[HJ] HKCU\[...]\System : EnableLUA (0) -> NAHRADENÉ (1)
[HJ DESK] HKCU\[...]\ClassicStartMenu : {59031A47-3F72-44A7-89C5-5595FE6B30EE} (1) -> NAHRADENÉ (0)
[HJ DESK] HKCU\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRADENÉ (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRADENÉ (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRADENÉ (0)

¤¤¤ Zvláštne súbory / Adresáre: ¤¤¤

¤¤¤ Ovládač : [NAHRATÉ] ¤¤¤
IRP[IRP_MJ_CREATE] : \SystemRoot\System32\drivers\mountmgr.sys -> HOOKED ([MAJOR] Unknown @ 0x851E81E8)
IRP[IRP_MJ_CLOSE] : \SystemRoot\System32\drivers\mountmgr.sys -> HOOKED ([MAJOR] Unknown @ 0x851E81E8)
IRP[IRP_MJ_DEVICE_CONTROL] : \SystemRoot\System32\drivers\mountmgr.sys -> HOOKED ([MAJOR] Unknown @ 0x851E81E8)
IRP[IRP_MJ_INTERNAL_DEVICE_CONTROL] : \SystemRoot\System32\drivers\mountmgr.sys -> HOOKED ([MAJOR] Unknown @ 0x851E81E8)
IRP[IRP_MJ_POWER] : \SystemRoot\System32\drivers\mountmgr.sys -> HOOKED ([MAJOR] Unknown @ 0x851E81E8)
IRP[IRP_MJ_SYSTEM_CONTROL] : \SystemRoot\System32\drivers\mountmgr.sys -> HOOKED ([MAJOR] Unknown @ 0x851E81E8)
IRP[IRP_MJ_PNP] : \SystemRoot\System32\drivers\mountmgr.sys -> HOOKED ([MAJOR] Unknown @ 0x851E81E8)

¤¤¤ Súbor HOSTS: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts

127.0.0.1 localhost


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: ExcelSto r Technology SCSI Disk Device +++++
--- User ---
[MBR] 6820a220b2670968eacd70a833460fe4
[BSP] 65d158aceda0aa8ef5b83d3febb7cf89 : Windows Vista MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 152625 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Dokončené : << RKreport[3]_D_01302013_02d1823.txt >>
RKreport[1]_S_01302013_02d1741.txt ; RKreport[2]_S_01302013_02d1823.txt ; RKreport[3]_D_01302013_02d1823.txt





log 2. oprava host:

RogueKiller V8.4.3 [Jan 27 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.geekstogo.com/forum/files/fi ... guekiller/
Webové stránky : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operačný systém : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Spustené v : Normálny režim
Užívateľ : Patho [Práva Správcu]
Režim : Oprava HOSTS -- Dátum : 01/30/2013 18:25:03
| ARK || MBR |

¤¤¤ Škodlivé procesy : 0 ¤¤¤

¤¤¤ Záznamy Registrov : 0 ¤¤¤

¤¤¤ Ovládač : [NAHRATÉ] ¤¤¤

¤¤¤ Súbor HOSTS: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts

127.0.0.1 localhost


¤¤¤ Resetovaný HOSTS: ¤¤¤
127.0.0.1 localhost

Dokončené : << RKreport[4]_H_01302013_02d1825.txt >>
RKreport[1]_S_01302013_02d1741.txt ; RKreport[2]_S_01302013_02d1823.txt ; RKreport[3]_D_01302013_02d1823.txt ; RKreport[4]_H_01302013_02d1825.txt

Re: Spomalený PC, zase

Napsal: 30 led 2013 19:45
od Márty84
:arrow: Stahnete MBRScan http://eric71.geekstogo.com/tools/MbrScan.exe , ulozte ho na plochu a spustte jako spravce.
Kliknete na Report
Za chvili vyskoci log s nazvem MBRScan.txt, ten mi sem zkopirujte.

Re: Spomalený PC, zase

Napsal: 30 led 2013 20:04
od Patho
Ešte pri tom RogueKiller som sa prvý krát unáhlil a pustil to prvý krát so spusteným skype, keď sa spustil RogueKiller tak po chvíli naskočila modrá win obrazovka.


Kód: Vybrat vše

MBRScan v1.1.1

OS             : Windows Vista Service Pack 2 (32 bit)
PROCESSOR      : x86 Family 15 Model 107 Stepping 2, AuthenticAMD
BOOT           : Normal Boot
DATE           : 2013/01/30 (ISO 8601) at 19:56:37
________________________________________________________________________________

DISK           : Device\Harddisk0\DR0 __ExcelSto r Technology (P22O)
BUS_TYPE       : (0x06)  F-ATA
USE_PIO        : YES
MAX_TRANSFER   : 128 Kb
ALIGNMENT_MASK : word aligned
________________________________________________________________________________

Device\Harddisk0\DR0	149.1 Go  [Fixed] ==> Unknown MBR Code . ==> PARTITION TABLE FAKED !!

MBR_MD5   : 1E2AF499088CCEB5109E921D88B03706
MBR_SHA1  : EF7D3153FDC2104997AD1B78FF88A821EE894671

Device\Harddisk0\Partition1	149.0 Go  	0x07 NTFS / HPFS __ BOOTABLE __
Device\Harddisk0\Partition2	1.25 To  	0x2C 0x2C 
Device\Harddisk0\Partition3	1.62 To  	0x3A 0x3A 
Device\Harddisk0\Partition4	1.41 To  	0x37 0x37 
________________________________________________________________________________

############################### Additional scan ################################

DRIVER  : C:\Windows\System32\Drivers\sptd.sys => LOCKED!
ADDRESS : 0x8060C000
SIZE    : 1.09 Mo

DRIVER  : C:\Windows\System32\Drivers\dump_diskdump.sys => Invisible on the disk
ADDRESS : 0x90398000
SIZE    : 40.0 Ko

DRIVER  : C:\Windows\System32\Drivers\dump_nvstor32.sys => Invisible on the disk
ADDRESS : 0x903A2000
SIZE    : 144.0 Ko

DRIVER  : C:\Windows\system32\drivers\TrueSight.sys => Invisible on the disk
ADDRESS : 0x9F59B000
SIZE    : 16.0 Ko

BCD EmsSettings {0CE4991B-E6B3-4B16-B23C-5E0D9250E5D9} => BcdLibraryBoolean_EmsEnabled (16000020)

SystemStartOptions : /NOEXECUTE=OPTIN

________________________________________________________________________________

_____FAKED   \Device\Harddisk0\DR0  

0x00000000   96 6C 0B 9B AB E3 5C 9D 84 B2 2A F9 A9 5E 40 18   .l..«ã\..²*ù©^@.
0x00000010   BE 8E 04 07 92 2B 40 D3 A1 05 7A 5C AC 23 A7 D6   ¾....+@Ó¡.z\¬#§Ö
0x00000020   48 1E CB D7 6E BE 79 01 4B DA 76 B8 A5 E4 E4 A8   H.Ë×n¾y.KÚv¸¥ää¨
0x00000030   2F B1 E8 56 C4 EB 2A 57 4B 58 B8 5E 8F 49 BE 73   /±èVÄë*WKX¸^.I¾s
0x00000040   32 50 02 67 85 32 A3 20 18 69 87 22 39 1C 57 39   2P.g.2£ .i."9.W9
0x00000050   BE 22 CE B2 F0 1F 3E 24 D6 BC 9D 2F BB 33 8A 58   ¾"βð.>$Ö¼./»3.X
0x00000060   EA 35 10 DB AA 87 7A 77 64 7B EB 07 C0 D2 B8 74   ê5.Ûª.zwd{ë.ÀÒ¸t
0x00000070   14 27 69 05 21 46 B3 C2 61 8A ED 3B 7B 01 93 95   .'i.!F³Âa.í;{...
0x00000080   EB 99 93 4C 4E 1E 51 46 C0 2B 0F 6B 90 05 A4 8D   ë..LN.QFÀ+.k..¤.
0x00000090   D4 ED B2 5C 42 50 7D 10 D8 3A 78 1C 47 BF D8 B8   Ôí²\BP}.Ø:x.G¿Ø¸
0x000000A0   5B A2 04 D2 7E 67 93 67 03 4A 6C FC ED B2 71 72   [¢.Ò~g.g.Jlüí²qr
0x000000B0   65 BE 92 2F DD F9 0F 2A 8D 91 B9 A9 DF 57 09 73   e¾./Ýù.*..¹©ßW.s
0x000000C0   D3 12 1A C3 2A 84 EE B2 7A D3 DE FC 53 99 E9 3C   Ó..Ã*.î²zÓÞüS.é<
0x000000D0   8D B6 C2 8A 86 4B 59 40 30 83 C6 8E 8E 96 0B 1A   .¶Â..KY@0.Æ.....
0x000000E0   83 47 BE 8E AC 5D 7C 0A 31 4D 71 0D F3 1C 0A 79   .G¾.¬]|.1Mq.ó..y
0x000000F0   67 80 1B 0E 63 FB 68 46 E3 94 B6 8F F1 27 12 D5   g...cûhFã.¶.ñ'.Õ
0x00000100   96 79 93 C6 EE 41 BA 77 B4 6B 9B CD 90 D3 81 BD   .y.ÆîAºw´k.Í.Ó.½
0x00000110   F9 20 65 81 4F 6E 1E 06 3D 93 72 AB F7 74 CB 6F   ù e.On..=.r«÷tËo
0x00000120   2D CB 7B B1 E6 4D 61 BD 40 61 26 E8 38 BE 54 9E   -Ë{±æMa½@a&è8¾T.
0x00000130   DC A5 F1 FC 16 6A 54 2E 14 E3 F9 DE B9 CF EA 16   Ü¥ñü.jT..ãùÞ¹Ïê.
0x00000140   F1 21 0D 61 1B 3B 44 FF 1A 62 0C DB 85 39 69 D3   ñ!.a.;D..b.Û.9iÓ
0x00000150   AA 21 D3 5D 91 54 96 18 5D 15 F5 D5 28 40 50 80   ª!Ó].T..].õÕ(@P.
0x00000160   EF 68 C2 CF 32 96 76 D9 3F F5 14 57 EF F9 16 7C   ïhÂÏ2.vÙ?õ.Wïù.|
0x00000170   84 3A D7 75 73 9F BB DB 74 01 EE 8E 56 D1 A1 86   .:×us.»Ût.î.VÑ¡.
0x00000180   21 BA CB 03 96 22 3E 6D A7 3C 69 AC 13 8C A2 43   !ºË..">m§<i¬..¢C
0x00000190   2A 20 9E E1 18 76 52 82 65 59 B3 75 11 60 DD 73   * .á.vR.eY³u.`Ýs
0x000001A0   2B 47 DF 0E 03 F5 31 2C 84 F2 50 07 EF 21 87 CE   +Gß..õ1,.òP.ï!.Î
0x000001B0   B0 EC 8C 18 80 81 61 23 5B 83 EB 16 B5 15 D3 78   °ì....a#[.ë.µ.Óx
0x000001C0   B8 8C 5A E7 07 6E 70 A6 A1 BE 35 AB 25 8B 22 C9   ¸.Zç.np¦¡¾5«%."É
0x000001D0   E5 1F 2C 6D D6 66 EA 98 02 90 04 88 C8 9F 8F 2F   å.,mÖfê.....È../
0x000001E0   4D C1 3A 95 6C A2 1B 43 50 D1 A6 DD 7A CF 05 CF   MÁ:.l¢.CPѦÝzÏ.Ï
0x000001F0   C6 FB 37 33 84 F5 30 20 4B 0E 18 9A 9E B4 66 AF   Æû73.õ0 K....´f¯

__ORIGINAL   \Device\Harddisk0\DR0  

0x00000000   33 C0 8E D0 BC 00 7C 8E C0 8E D8 BE 00 7C BF 00   3À.м.|.À.ؾ.|¿.
0x00000010   06 B9 00 02 FC F3 A4 50 68 1C 06 CB FB B9 04 00   .¹..üó¤Ph..Ëû¹..
0x00000020   BD BE 07 80 7E 00 00 7C 0B 0F 85 10 01 83 C5 10   ½¾..~..|......Å.
0x00000030   E2 F1 CD 18 88 56 00 55 C6 46 11 05 C6 46 10 00   âñÍ..V.UÆF..ÆF..
0x00000040   B4 41 BB AA 55 CD 13 5D 72 0F 81 FB 55 AA 75 09   ´A»ªUÍ.]r..ûUªu.
0x00000050   F7 C1 01 00 74 03 FE 46 10 66 60 80 7E 10 00 74   ÷Á..t.þF.f`.~..t
0x00000060   26 66 68 00 00 00 00 66 FF 76 08 68 00 00 68 00   &fh....f.v.h..h.
0x00000070   7C 68 01 00 68 10 00 B4 42 8A 56 00 8B F4 CD 13   |h..h..´B.V..ôÍ.
0x00000080   9F 83 C4 10 9E EB 14 B8 01 02 BB 00 7C 8A 56 00   ..Ä..ë.¸..».|.V.
0x00000090   8A 76 01 8A 4E 02 8A 6E 03 CD 13 66 61 73 1E FE   .v..N..n.Í.fas.þ
0x000000A0   4E 11 0F 85 0C 00 80 7E 00 80 0F 84 8A 00 B2 80   N......~......².
0x000000B0   EB 82 55 32 E4 8A 56 00 CD 13 5D EB 9C 81 3E FE   ë.U2ä.V.Í.]ë..>þ
0x000000C0   7D 55 AA 75 6E FF 76 00 E8 8A 00 0F 85 15 00 B0   }Uªun.v.è......°
0x000000D0   D1 E6 64 E8 7F 00 B0 DF E6 60 E8 78 00 B0 FF E6   Ñædè..°ßæ`èx.°.æ
0x000000E0   64 E8 71 00 B8 00 BB CD 1A 66 23 C0 75 3B 66 81   dèq.¸.»Í.f#Àu;f.
0x000000F0   FB 54 43 50 41 75 32 81 F9 02 01 72 2C 66 68 07   ûTCPAu2.ù..r,fh.
0x00000100   BB 00 00 66 68 00 02 00 00 66 68 08 00 00 00 66   »..fh....fh....f
0x00000110   53 66 53 66 55 66 68 00 00 00 00 66 68 00 7C 00   SfSfUfh....fh.|.
0x00000120   00 66 61 68 00 00 07 CD 1A 5A 32 F6 EA 00 7C 00   .fah...Í.Z2öê.|.
0x00000130   00 CD 18 A0 B7 07 EB 08 A0 B6 07 EB 03 A0 B5 07   .Í..·.ë..¶.ë..µ.
0x00000140   32 E4 05 00 07 8B F0 AC 3C 00 74 FC BB 07 00 B4   2ä....ð¬<.tü»..´
0x00000150   0E CD 10 EB F2 2B C9 E4 64 EB 00 24 02 E0 F8 24   .Í.ëò+Éädë.$.àø$
0x00000160   02 C3 49 6E 76 61 6C 69 64 20 70 61 72 74 69 74   .ÃInvalid partit
0x00000170   69 6F 6E 20 74 61 62 6C 65 00 45 72 72 6F 72 20   ion table.Error 
0x00000180   6C 6F 61 64 69 6E 67 20 6F 70 65 72 61 74 69 6E   loading operatin
0x00000190   67 20 73 79 73 74 65 6D 00 4D 69 73 73 69 6E 67   g system.Missing
0x000001A0   20 6F 70 65 72 61 74 69 6E 67 20 73 79 73 74 65    operating syste
0x000001B0   6D 00 00 00 00 62 7A 99 B8 D8 BE C5 00 00 80 20   m....bz.¸Ø¾Å... 
0x000001C0   21 00 07 FE FF FF 00 08 00 00 00 88 A1 12 00 00   !..þ........¡...
0x000001D0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001E0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................
0x000001F0   00 00 00 00 00 00 00 00 00 00 00 00 00 00 55 AA   ..............Uª

Re: Spomalený PC, zase

Napsal: 31 led 2013 02:56
od Márty84
Dejte novy log z RSIT

Re: Spomalený PC, zase

Napsal: 31 led 2013 15:28
od Patho
Logfile of random's system information tool 1.09 (written by random/random)
Run by Patho at 2013-01-31 15:27:23
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 60 GB (39%) free of 153 GB
Total RAM: 2047 MB (52% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:27:36, on 31. 1. 2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Icon7\iConfig for Gamers\hid.exe
C:\Windows\PixArt\Pac7302\Monitor.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Icon7\iConfig for Gamers\Tray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Windows\system32\SearchFilterHost.exe
C:\PathoDisc\Downloads\RSIT.exe
C:\Program Files\trend micro\Patho.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [iConfigg] "C:\Program Files\Icon7\iConfig for Gamers\hid.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\Windows\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 4915 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Patho\AppData\Roaming\Mozilla\Firefox\Profiles\wbe64pft.default

prefs.js - "browser.startup.homepage" - "http://www.google.sk/"

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.5.502.146 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
nppdf32.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-01-17 3855520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-08-06 6265376]
"iConfigg"=C:\Program Files\Icon7\iConfig for Gamers\hid.exe [2008-03-25 266240]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]
"PAC7302_Monitor"=C:\Windows\PixArt\PAC7302\Monitor.exe [2006-11-03 319488]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-11-16 2054360]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2013-01-08 18705664]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv

======List of files/folders created in the last 1 month======

2013-01-30 15:36:23 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2013-01-29 16:25:15 ----D---- C:\Users\Patho\AppData\Roaming\Malwarebytes
2013-01-29 16:25:08 ----D---- C:\ProgramData\Malwarebytes
2013-01-29 16:25:06 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2013-01-29 16:25:06 ----A---- C:\Windows\system32\drivers\mbam.sys
2013-01-29 15:29:38 ----D---- C:\Program Files\Common Files\Skype
2013-01-25 15:38:43 ----D---- C:\rsit
2013-01-23 14:50:09 ----D---- C:\CFLog
2013-01-23 13:55:43 ----SHD---- C:\$RECYCLE.BIN
2013-01-23 13:16:31 ----D---- C:\Windows\temp
2013-01-22 17:51:21 ----D---- C:\Windows\erdnt
2013-01-22 15:51:56 ----D---- C:\Program Files\trend micro
2013-01-21 14:20:48 ----D---- C:\Program Files\Mozilla Firefox
2013-01-15 15:17:56 ----A---- C:\Windows\system32\mshtml.dll
2013-01-09 13:24:22 ----A---- C:\Windows\system32\win32k.sys
2013-01-09 13:23:39 ----A---- C:\Windows\system32\ncrypt.dll
2013-01-09 13:23:37 ----A---- C:\Windows\system32\shlwapi.dll
2013-01-09 13:23:36 ----A---- C:\Windows\system32\msxml6.dll

======List of files/folders modified in the last 1 month======

2013-01-31 15:03:43 ----D---- C:\Windows\system32\catroot2
2013-01-31 15:03:11 ----D---- C:\Users\Patho\AppData\Roaming\Skype
2013-01-30 18:25:55 ----D---- C:\Windows\system32\drivers
2013-01-30 18:19:21 ----D---- C:\Windows\Minidump
2013-01-30 18:19:17 ----D---- C:\Windows
2013-01-30 17:47:05 ----D---- C:\Windows\System32
2013-01-29 16:25:08 ----D---- C:\ProgramData
2013-01-29 16:25:06 ----RD---- C:\Program Files
2013-01-29 15:42:34 ----SHD---- C:\System Volume Information
2013-01-29 15:30:56 ----SHD---- C:\Windows\Installer
2013-01-29 15:30:56 ----D---- C:\ProgramData\Skype
2013-01-29 15:29:38 ----RD---- C:\Program Files\Skype
2013-01-29 15:29:38 ----D---- C:\Program Files\Common Files
2013-01-25 15:46:53 ----D---- C:\Windows\system32\WDI
2013-01-23 18:01:55 ----D---- C:\Windows\inf
2013-01-23 16:24:44 ----D---- C:\Users\Patho\AppData\Roaming\Winamp
2013-01-23 14:14:27 ----D---- C:\Windows\SoftwareDistribution
2013-01-23 14:12:41 ----D---- C:\Users\Patho\AppData\Roaming\uTorrent
2013-01-23 14:12:41 ----D---- C:\Users\Patho\AppData\Roaming\Media Player Classic
2013-01-23 14:12:41 ----D---- C:\Users\Patho\AppData\Roaming\DAEMON Tools Lite
2013-01-23 14:12:40 ----D---- C:\Windows\Logs
2013-01-23 14:12:40 ----D---- C:\Windows\Debug
2013-01-23 13:14:35 ----A---- C:\Windows\system.ini
2013-01-23 13:12:12 ----D---- C:\Windows\AppPatch
2013-01-22 20:51:42 ----RD---- C:\PathoDisc
2013-01-22 20:44:12 ----D---- C:\Windows\system32\drivers\etc
2013-01-22 13:30:20 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-01-21 15:13:00 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-01-15 20:39:09 ----D---- C:\Windows\winsxs
2013-01-15 15:15:41 ----D---- C:\Windows\system32\catroot
2013-01-14 18:21:39 ----SD---- C:\Users\Patho\AppData\Roaming\Microsoft
2013-01-11 14:43:03 ----D---- C:\Windows\Prefetch
2013-01-10 18:44:05 ----D---- C:\Windows\Microsoft.NET
2013-01-10 18:43:37 ----RSD---- C:\Windows\assembly
2013-01-10 16:33:54 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2013-01-10 16:10:25 ----D---- C:\ProgramData\Microsoft Help
2013-01-10 15:54:20 ----A---- C:\Windows\system32\mrt.exe
2013-01-07 13:29:41 ----D---- C:\Users\Patho\AppData\Roaming\Mp3tag

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 nvstor32;nvstor32; C:\Windows\system32\DRIVERS\nvstor32.sys [2008-01-26 140832]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-11-04 443448]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-08-08 232512]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-11-16 108792]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\Windows\system32\drivers\sp_rsdrv2.sys [2011-08-08 142592]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2011-08-23 281760]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-11-16 116520]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2009-12-18 95896]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2011-08-23 25888]
R3 Afc;PPdus ASPI Shell; C:\Windows\system32\drivers\Afc.sys [2005-02-23 11776]
R3 Icon7Fltr;Icon7 Gaming Laser Mouse; C:\Windows\system32\drivers\Icon7ms.sys [2008-03-19 10112]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-08-06 2164248]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2006-10-18 7680]
R3 NVENETFD;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2008-03-26 1048480]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2012-10-10 10837352]
R3 PAC7302;PAC7302 VGA USB Camera; C:\Windows\system32\DRIVERS\PAC7302.SYS [2007-06-14 457856]
R3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136]
S3 a2s0q3wy;a2s0q3wy; C:\Windows\system32\drivers\a2s0q3wy.sys []
S3 ALSysIO;ALSysIO; \??\C:\Users\Patho\AppData\Local\Temp\ALSysIO.sys []
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files\Garena Classic\safedrv.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2012-12-14 21104]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [2013-01-30 40776]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 XDva391;XDva391; \??\C:\Windows\system32\XDva391.sys []
S3 XDva401;XDva401; \??\C:\Windows\system32\XDva401.sys []
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-11-16 735960]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-05-03 118784]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2012-01-07 75136]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2011-08-08 496128]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344]
S2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-01-08 161536]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-10 251400]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-11-16 20680]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-01-21 115608]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\system32\GameMon.des [2011-08-07 3804120]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WPFFontCache_v0400;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]

-----------------EOF-----------------

Re: Spomalený PC, zase

Napsal: 31 led 2013 19:09
od Márty84
Nemam dobre zprvy. Vypada to na peknou potvoru.


:arrow: Postupujte podle navodu kolegy
vyosek píše: :arrow: Stahnete si TDSSKiller http://support.kaspersky.com/downloads/ ... killer.exe
  • Kliknete na volbu Change parametrs
  • V okne Additional Option zakliknete vsechny moznosti
  • Kliknete na OK
  • Utilite prikazte, at skenuje - klik na Start Scan
  • Po dokonceni skenu se objevi okno, zkontrolujte, zda-li je vsude moznost Skip
  • Pokud moznost Skip nebude primarne nastavena, prekliknete ji na Skip
  • Pokud mate vsude Skip, kliknete na Continue
  • Na disku, kde mate Windows (obvykle c:\) ve tvaru TDSSKiller.nejaka cisilka _log.txt bude log - jeho obsah sem vlozte