Spomaleny pocitac, vysoke CPU a Memory
Napsal: 02 bře 2013 01:13
Dobry vecer,
Po tyzdni som si vsimol ze Win7 pracuje o dost horsie ako pred tyzdnom. Neviem co sa stalo ale mam pocit ze nieco nieje v poriadku s procesmi a servismi. Hravam pravidelne zopar hier(online) ako Diablo 3/Warcraft 3 dota atd. ale pocitac ide zposledneho. Hry sekaju a je to utrpenie hrat. (kludne prilozim aj printscreen z task managera plus performance) podla mna Hroza ak je pocitac v klude..
Nechal som zbehnut Malwarebytes Anti-Malware ale nic vyrazne nenasiel. Tak isto som nechal zbehnut aj combofix ale zmena/zlepsenie neprichadza. Dosli mi uz vsetky napady a neviem kam dalej. Prosim vas o radu a pomoc. Dakujem Vam za ochotu. (prikladam log z combofix)
{ComboFix 13-03-01.01 - Tomo . 03. 2013 0:32.1.2 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1250.421.1033.18.2047.684 [GMT 1:00]
Running from: j:\users\Tomo\Downloads\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
AV: Microsoft Security Essentials *Enabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
SP: Microsoft Security Essentials *Enabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
j:\users\Otec\iperf.exe
j:\users\Otec\wireshark-win32-1.4.3.exe
j:\users\Tomo\AppData\Roaming\x-video-converter-ultimate.exe
j:\windows\security\Database\tmp.edb
.
.
((((((((((((((((((((((((( Files Created from 2013-02-01 to 2013-03-01 )))))))))))))))))))))))))))))))
.
.
2013-03-01 23:44 . 2013-03-01 23:44 -------- d-----w- j:\users\Otec\AppData\Local\temp
2013-03-01 23:44 . 2013-03-01 23:45 -------- d-----w- j:\users\Tomo\AppData\Local\temp
2013-03-01 23:44 . 2013-03-01 23:44 -------- d-----w- j:\users\Default\AppData\Local\temp
2013-03-01 23:21 . 2013-03-01 23:21 29904 ----a-w- j:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1251BC78-2F9F-4F95-83F6-2BFB644D6E31}\MpKsl8259866c.sys
2013-03-01 23:05 . 2012-12-14 15:49 21104 ----a-w- j:\windows\system32\drivers\mbam.sys
2013-03-01 22:36 . 2013-03-01 22:36 -------- d-----w- j:\program files\Common Files\Adobe
2013-03-01 22:32 . 2013-03-01 22:32 861088 ----a-w- j:\windows\system32\npDeployJava1.dll
2013-03-01 22:32 . 2013-03-01 22:32 94112 ----a-w- j:\windows\system32\WindowsAccessBridge.dll
2013-03-01 22:14 . 2013-02-08 00:45 6954968 ----a-w- j:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1251BC78-2F9F-4F95-83F6-2BFB644D6E31}\mpengine.dll
2013-03-01 21:58 . 2013-02-08 00:45 6954968 ----a-w- j:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-03-01 20:48 . 2013-03-01 20:48 -------- d-----w- j:\users\Tomo\AppData\Roaming\Malwarebytes
2013-03-01 20:48 . 2013-03-01 20:48 -------- d-----w- j:\programdata\Malwarebytes
2013-03-01 20:48 . 2013-03-01 23:05 -------- d-----w- j:\program files\Malwarebytes' Anti-Malware
2013-02-22 15:00 . 2013-02-22 15:00 -------- d-----w- j:\programdata\Origin
2013-02-14 08:43 . 2013-01-04 03:00 2347008 ----a-w- j:\windows\system32\win32k.sys
2013-02-14 08:43 . 2013-01-05 05:00 3967848 ----a-w- j:\windows\system32\ntkrnlpa.exe
2013-02-14 08:43 . 2013-01-05 05:00 3913064 ----a-w- j:\windows\system32\ntoskrnl.exe
2013-02-14 08:43 . 2013-01-03 05:05 1293672 ----a-w- j:\windows\system32\drivers\tcpip.sys
2013-02-14 08:43 . 2013-01-03 05:04 187752 ----a-w- j:\windows\system32\drivers\FWPKCLNT.SYS
2013-02-14 08:43 . 2013-01-04 04:50 169984 ----a-w- j:\windows\system32\winsrv.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-01 23:15 . 2012-04-09 14:41 691568 ----a-w- j:\windows\system32\FlashPlayerApp.exe
2013-03-01 23:15 . 2011-05-17 19:16 71024 ----a-w- j:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-01 22:32 . 2011-01-26 12:55 782240 ----a-w- j:\windows\system32\deployJava1.dll
2013-01-30 10:53 . 2010-07-08 10:55 232336 ------w- j:\windows\system32\MpSigStub.exe
2013-01-02 10:51 . 2013-01-02 10:51 74752 ----a-w- j:\windows\system32\RegisterIEPKEYs.exe
2013-01-02 10:51 . 2013-01-02 10:51 161792 ----a-w- j:\windows\system32\msls31.dll
2013-01-02 10:51 . 2013-01-02 10:51 110592 ----a-w- j:\windows\system32\IEAdvpack.dll
2013-01-02 10:51 . 2013-01-02 10:51 86528 ----a-w- j:\windows\system32\iesysprep.dll
2013-01-02 10:51 . 2013-01-02 10:51 76800 ----a-w- j:\windows\system32\SetIEInstalledDate.exe
2013-01-02 10:51 . 2013-01-02 10:51 74752 ----a-w- j:\windows\system32\iesetup.dll
2013-01-02 10:51 . 2013-01-02 10:51 63488 ----a-w- j:\windows\system32\tdc.ocx
2013-01-02 10:51 . 2013-01-02 10:51 48640 ----a-w- j:\windows\system32\mshtmler.dll
2013-01-02 10:51 . 2013-01-02 10:51 367104 ----a-w- j:\windows\system32\html.iec
2013-01-02 10:51 . 2013-01-02 10:51 35840 ----a-w- j:\windows\system32\imgutil.dll
2013-01-02 10:51 . 2013-01-02 10:51 23552 ----a-w- j:\windows\system32\licmgr10.dll
2013-01-02 10:51 . 2013-01-02 10:51 152064 ----a-w- j:\windows\system32\wextract.exe
2013-01-02 10:51 . 2013-01-02 10:51 150528 ----a-w- j:\windows\system32\iexpress.exe
2013-01-02 10:51 . 2013-01-02 10:51 11776 ----a-w- j:\windows\system32\mshta.exe
2013-01-02 10:51 . 2013-01-02 10:51 101888 ----a-w- j:\windows\system32\admparse.dll
2012-12-19 20:50 . 2012-09-28 02:22 5630200 ----a-w- j:\windows\system32\atiumdag.dll
2012-12-19 20:47 . 2012-12-19 20:47 9647104 ----a-w- j:\windows\system32\drivers\atikmdag.sys
2012-12-19 20:22 . 2012-12-19 20:22 58880 ----a-w- j:\windows\system32\coinst_9.012.dll
2012-12-19 20:19 . 2012-12-19 20:19 163840 ----a-w- j:\windows\system32\atiapfxx.exe
2012-12-19 20:18 . 2012-12-19 20:18 46080 ----a-w- j:\windows\system32\aticalrt.dll
2012-12-19 20:17 . 2012-12-19 20:17 44032 ----a-w- j:\windows\system32\aticalcl.dll
2012-12-19 20:13 . 2012-12-19 20:13 13703168 ----a-w- j:\windows\system32\aticaldd.dll
2012-12-19 20:12 . 2012-12-19 20:12 18982400 ----a-w- j:\windows\system32\atioglxx.dll
2012-12-19 20:09 . 2011-05-25 03:07 960512 ----a-w- j:\windows\system32\aticfx32.dll
2012-12-19 20:06 . 2011-05-25 02:58 6681088 ----a-w- j:\windows\system32\atidxx32.dll
2012-12-19 19:57 . 2012-09-28 01:39 442368 ----a-w- j:\windows\system32\atidemgy.dll
2012-12-19 19:56 . 2012-12-19 19:56 482304 ----a-w- j:\windows\system32\atieclxx.exe
2012-12-19 19:55 . 2012-12-19 19:55 219136 ----a-w- j:\windows\system32\atiesrxx.exe
2012-12-19 19:54 . 2012-12-19 19:54 163840 ----a-w- j:\windows\system32\atitmmxx.dll
2012-12-19 19:54 . 2012-12-19 19:54 20992 ----a-w- j:\windows\system32\atimuixx.dll
2012-12-19 19:54 . 2012-12-19 19:54 43520 ----a-w- j:\windows\system32\ati2edxx.dll
2012-12-19 19:44 . 2012-09-28 01:22 4162048 ----a-w- j:\windows\system32\atiumdva.dll
2012-12-19 19:33 . 2012-12-19 19:33 56832 ----a-w- j:\windows\system32\atimpc32.dll
2012-12-19 19:33 . 2012-12-19 19:33 56832 ----a-w- j:\windows\system32\amdpcom32.dll
2012-12-19 19:33 . 2012-09-28 01:13 421888 ----a-w- j:\windows\system32\atiadlxx.dll
2012-12-19 19:33 . 2012-12-19 19:33 14848 ----a-w- j:\windows\system32\atiglpxx.dll
2012-12-19 19:33 . 2012-12-19 19:33 33280 ----a-w- j:\windows\system32\atigktxx.dll
2012-12-19 19:32 . 2012-12-19 19:32 442368 ----a-w- j:\windows\system32\drivers\atikmpag.sys
2012-12-19 19:31 . 2011-05-25 02:24 109568 ----a-w- j:\windows\system32\atiuxpag.dll
2012-12-19 19:30 . 2012-06-11 16:24 83968 ----a-w- j:\windows\system32\atiu9pag.dll
2012-12-19 19:30 . 2012-12-19 19:30 53248 ----a-w- j:\windows\system32\drivers\ati2erec.dll
2012-12-19 14:45 . 2012-12-19 14:45 180224 ----a-w- j:\windows\system32\clinfo.exe
2012-12-19 14:44 . 2012-12-19 14:44 65536 ----a-w- j:\windows\system32\OpenVideo.dll
2012-12-19 14:44 . 2012-12-19 14:44 56320 ----a-w- j:\windows\system32\OVDecode.dll
2012-12-19 14:38 . 2012-12-19 14:38 28732928 ----a-w- j:\windows\system32\amdocl.dll
2012-12-19 14:34 . 2012-12-19 14:34 50176 ----a-w- j:\windows\system32\OpenCL.dll
2012-12-16 14:54 . 2010-10-13 18:38 138032 ----a-w- j:\windows\system32\drivers\PnkBstrK.sys
2012-12-16 14:54 . 2010-10-13 18:40 281688 ----a-w- j:\windows\system32\PnkBstrB.xtr
2012-12-16 14:54 . 2010-10-13 18:37 281688 ----a-w- j:\windows\system32\PnkBstrB.exe
2012-12-16 14:13 . 2012-12-20 19:22 295424 ----a-w- j:\windows\system32\atmfd.dll
2012-12-16 14:13 . 2012-12-20 19:22 34304 ----a-w- j:\windows\system32\atmlib.dll
2012-12-12 22:41 . 2010-10-13 18:37 281688 ----a-w- j:\windows\system32\PnkBstrB.ex0
2012-12-07 12:26 . 2013-01-09 18:39 308736 ----a-w- j:\windows\system32\Wpc.dll
2012-12-07 12:20 . 2013-01-09 18:39 2576384 ----a-w- j:\windows\system32\gameux.dll
2012-12-07 10:46 . 2013-01-09 18:39 43520 ----a-w- j:\windows\system32\csrr.rs
2012-12-07 10:46 . 2013-01-09 18:39 30720 ----a-w- j:\windows\system32\usk.rs
2012-12-07 10:46 . 2013-01-09 18:39 45568 ----a-w- j:\windows\system32\oflc-nz.rs
2012-12-07 10:46 . 2013-01-09 18:39 44544 ----a-w- j:\windows\system32\pegibbfc.rs
2012-12-07 10:46 . 2013-01-09 18:39 20480 ----a-w- j:\windows\system32\pegi-pt.rs
2012-12-07 10:46 . 2013-01-09 18:38 23552 ----a-w- j:\windows\system32\oflc.rs
2012-12-07 10:46 . 2013-01-09 18:38 20480 ----a-w- j:\windows\system32\pegi-fi.rs
2012-12-07 10:46 . 2013-01-09 18:39 46592 ----a-w- j:\windows\system32\fpb.rs
2012-12-07 10:46 . 2013-01-09 18:39 20480 ----a-w- j:\windows\system32\pegi.rs
2012-12-07 10:46 . 2013-01-09 18:39 21504 ----a-w- j:\windows\system32\grb.rs
2012-12-07 10:46 . 2013-01-09 18:39 40960 ----a-w- j:\windows\system32\cob-au.rs
2012-12-07 10:46 . 2013-01-09 18:39 15360 ----a-w- j:\windows\system32\djctq.rs
2012-12-07 10:46 . 2013-01-09 18:38 55296 ----a-w- j:\windows\system32\cero.rs
2012-12-07 10:46 . 2013-01-09 18:38 51712 ----a-w- j:\windows\system32\esrb.rs
2012-12-04 12:18 . 2010-10-13 18:37 76888 ----a-w- j:\windows\system32\PnkBstrA.exe
2013-02-08 11:13 . 2013-02-08 11:12 262552 ----a-w- j:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{1dad3af3-ef2f-4f64-ac4b-11789189fcb6}]
2012-06-11 14:22 1307728 ----a-w- j:\program files\Microsoft\BingBar\7.1.391.0\BingExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="j:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"Steam"="j:\program files\Steam2\Steam.exe" [2013-02-25 1602984]
"HydraVisionDesktopManager"="j:\program files\ATI Technologies\HydraVision\HydraDM.exe" [2011-10-03 393216]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="j:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"Easy-PrintToolBox"="j:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-14 409600]
"CanonMyPrinter"="j:\program files\Canon\MyPrinter\BJMyPrt.exe" [2011-07-19 2567272]
"RIMBBLaunchAgent.exe"="j:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-02-18 79192]
"MSC"="j:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 947176]
"LogMeIn Hamachi Ui"="j:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-12-10 2254768]
"StartCCC"="j:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-12-19 642808]
"SunJavaUpdateSched"="j:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes Anti-Malware"="j:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-12-14 512360]
.
j:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - j:\program files\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248]
VPN Client.lnk - j:\windows\Installer\{14FCFE7C-AB86-428A-9D2E-BFB6F5A7AA6E}\Icon3E5562ED7.ico [2010-11-15 6144]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 BBSvc;BingBar Service;j:\program files\Microsoft\BingBar\7.1.391.0\BBSvc.exe [x]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;j:\program files\Lavasoft\Ad-Aware\AAWService.exe [x]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;j:\windows\system32\Drivers\ssadadb.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);j:\windows\system32\DRIVERS\ssudbus.sys [x]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;j:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;j:\program files\McAfee Security Scan\3.0.318\McCHSvc.exe [x]
S0 Lbd;Lbd;j:\windows\system32\DRIVERS\Lbd.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;j:\windows\system32\atiesrxx.exe [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;j:\program files\LogMeIn Hamachi\hamachi-2.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;j:\windows\system32\drivers\AtihdW73.sys [x]
S3 BBUpdate;BBUpdate;j:\program files\Microsoft\BingBar\7.1.391.0\SeaPort.exe [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MPKSL8259866C
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
GPSvcGroup REG_MULTI_SZ GPSvc
.
Contents of the 'Scheduled Tasks' folder
.
2013-03-01 j:\windows\Tasks\Adobe Flash Player Updater.job
- j:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-09 23:15]
.
2013-03-01 j:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- j:\program files\Google\Update\GoogleUpdate.exe [2010-11-21 12:51]
.
2013-03-01 j:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- j:\program files\Google\Update\GoogleUpdate.exe [2010-11-21 12:51]
.
2013-02-23 j:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-143793042-2127241793-3012379221-1000Core.job
- j:\users\Tomo\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-12 12:51]
.
2013-03-01 j:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-143793042-2127241793-3012379221-1000UA.job
- j:\users\Tomo\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-12 12:51]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.daemon-search.com/startpage
uDefault_Search_URL = hxxp://search.qip.ru
uSearchAssistant = hxxp://search.qip.ru/ie
IE: E&xportovať do programu Microsoft Excel - j:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - j:\users\Tomo\AppData\Roaming\Mozilla\Firefox\Profiles\xkka63rz.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://google.sk/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=827316&p=
FF - prefs.js: network.proxy.type - 0
FF - ExtSQL: 2013-01-02 11:33; bkmrksync@nokia.com; j:\program files\Nokia\Nokia PC Suite 7\bkmrksync
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{9CB65206-89C4-402c-BA80-02D8C59F9B1D} - j:\program files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-03-02 00:49:03
ComboFix-quarantined-files.txt 2013-03-01 23:49
ComboFix2.txt 2008-09-09 20:59
.
Pre-Run: 41 943 089 152 bytes free
Post-Run: 49 343 336 448 bytes free
.
- - End Of File - - 06B706917ED17946087D33147C5BAAFF}
Dakujem
Po tyzdni som si vsimol ze Win7 pracuje o dost horsie ako pred tyzdnom. Neviem co sa stalo ale mam pocit ze nieco nieje v poriadku s procesmi a servismi. Hravam pravidelne zopar hier(online) ako Diablo 3/Warcraft 3 dota atd. ale pocitac ide zposledneho. Hry sekaju a je to utrpenie hrat. (kludne prilozim aj printscreen z task managera plus performance) podla mna Hroza ak je pocitac v klude..
Nechal som zbehnut Malwarebytes Anti-Malware ale nic vyrazne nenasiel. Tak isto som nechal zbehnut aj combofix ale zmena/zlepsenie neprichadza. Dosli mi uz vsetky napady a neviem kam dalej. Prosim vas o radu a pomoc. Dakujem Vam za ochotu. (prikladam log z combofix)
{ComboFix 13-03-01.01 - Tomo . 03. 2013 0:32.1.2 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1250.421.1033.18.2047.684 [GMT 1:00]
Running from: j:\users\Tomo\Downloads\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
AV: Microsoft Security Essentials *Enabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
SP: Microsoft Security Essentials *Enabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
j:\users\Otec\iperf.exe
j:\users\Otec\wireshark-win32-1.4.3.exe
j:\users\Tomo\AppData\Roaming\x-video-converter-ultimate.exe
j:\windows\security\Database\tmp.edb
.
.
((((((((((((((((((((((((( Files Created from 2013-02-01 to 2013-03-01 )))))))))))))))))))))))))))))))
.
.
2013-03-01 23:44 . 2013-03-01 23:44 -------- d-----w- j:\users\Otec\AppData\Local\temp
2013-03-01 23:44 . 2013-03-01 23:45 -------- d-----w- j:\users\Tomo\AppData\Local\temp
2013-03-01 23:44 . 2013-03-01 23:44 -------- d-----w- j:\users\Default\AppData\Local\temp
2013-03-01 23:21 . 2013-03-01 23:21 29904 ----a-w- j:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1251BC78-2F9F-4F95-83F6-2BFB644D6E31}\MpKsl8259866c.sys
2013-03-01 23:05 . 2012-12-14 15:49 21104 ----a-w- j:\windows\system32\drivers\mbam.sys
2013-03-01 22:36 . 2013-03-01 22:36 -------- d-----w- j:\program files\Common Files\Adobe
2013-03-01 22:32 . 2013-03-01 22:32 861088 ----a-w- j:\windows\system32\npDeployJava1.dll
2013-03-01 22:32 . 2013-03-01 22:32 94112 ----a-w- j:\windows\system32\WindowsAccessBridge.dll
2013-03-01 22:14 . 2013-02-08 00:45 6954968 ----a-w- j:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1251BC78-2F9F-4F95-83F6-2BFB644D6E31}\mpengine.dll
2013-03-01 21:58 . 2013-02-08 00:45 6954968 ----a-w- j:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-03-01 20:48 . 2013-03-01 20:48 -------- d-----w- j:\users\Tomo\AppData\Roaming\Malwarebytes
2013-03-01 20:48 . 2013-03-01 20:48 -------- d-----w- j:\programdata\Malwarebytes
2013-03-01 20:48 . 2013-03-01 23:05 -------- d-----w- j:\program files\Malwarebytes' Anti-Malware
2013-02-22 15:00 . 2013-02-22 15:00 -------- d-----w- j:\programdata\Origin
2013-02-14 08:43 . 2013-01-04 03:00 2347008 ----a-w- j:\windows\system32\win32k.sys
2013-02-14 08:43 . 2013-01-05 05:00 3967848 ----a-w- j:\windows\system32\ntkrnlpa.exe
2013-02-14 08:43 . 2013-01-05 05:00 3913064 ----a-w- j:\windows\system32\ntoskrnl.exe
2013-02-14 08:43 . 2013-01-03 05:05 1293672 ----a-w- j:\windows\system32\drivers\tcpip.sys
2013-02-14 08:43 . 2013-01-03 05:04 187752 ----a-w- j:\windows\system32\drivers\FWPKCLNT.SYS
2013-02-14 08:43 . 2013-01-04 04:50 169984 ----a-w- j:\windows\system32\winsrv.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-01 23:15 . 2012-04-09 14:41 691568 ----a-w- j:\windows\system32\FlashPlayerApp.exe
2013-03-01 23:15 . 2011-05-17 19:16 71024 ----a-w- j:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-01 22:32 . 2011-01-26 12:55 782240 ----a-w- j:\windows\system32\deployJava1.dll
2013-01-30 10:53 . 2010-07-08 10:55 232336 ------w- j:\windows\system32\MpSigStub.exe
2013-01-02 10:51 . 2013-01-02 10:51 74752 ----a-w- j:\windows\system32\RegisterIEPKEYs.exe
2013-01-02 10:51 . 2013-01-02 10:51 161792 ----a-w- j:\windows\system32\msls31.dll
2013-01-02 10:51 . 2013-01-02 10:51 110592 ----a-w- j:\windows\system32\IEAdvpack.dll
2013-01-02 10:51 . 2013-01-02 10:51 86528 ----a-w- j:\windows\system32\iesysprep.dll
2013-01-02 10:51 . 2013-01-02 10:51 76800 ----a-w- j:\windows\system32\SetIEInstalledDate.exe
2013-01-02 10:51 . 2013-01-02 10:51 74752 ----a-w- j:\windows\system32\iesetup.dll
2013-01-02 10:51 . 2013-01-02 10:51 63488 ----a-w- j:\windows\system32\tdc.ocx
2013-01-02 10:51 . 2013-01-02 10:51 48640 ----a-w- j:\windows\system32\mshtmler.dll
2013-01-02 10:51 . 2013-01-02 10:51 367104 ----a-w- j:\windows\system32\html.iec
2013-01-02 10:51 . 2013-01-02 10:51 35840 ----a-w- j:\windows\system32\imgutil.dll
2013-01-02 10:51 . 2013-01-02 10:51 23552 ----a-w- j:\windows\system32\licmgr10.dll
2013-01-02 10:51 . 2013-01-02 10:51 152064 ----a-w- j:\windows\system32\wextract.exe
2013-01-02 10:51 . 2013-01-02 10:51 150528 ----a-w- j:\windows\system32\iexpress.exe
2013-01-02 10:51 . 2013-01-02 10:51 11776 ----a-w- j:\windows\system32\mshta.exe
2013-01-02 10:51 . 2013-01-02 10:51 101888 ----a-w- j:\windows\system32\admparse.dll
2012-12-19 20:50 . 2012-09-28 02:22 5630200 ----a-w- j:\windows\system32\atiumdag.dll
2012-12-19 20:47 . 2012-12-19 20:47 9647104 ----a-w- j:\windows\system32\drivers\atikmdag.sys
2012-12-19 20:22 . 2012-12-19 20:22 58880 ----a-w- j:\windows\system32\coinst_9.012.dll
2012-12-19 20:19 . 2012-12-19 20:19 163840 ----a-w- j:\windows\system32\atiapfxx.exe
2012-12-19 20:18 . 2012-12-19 20:18 46080 ----a-w- j:\windows\system32\aticalrt.dll
2012-12-19 20:17 . 2012-12-19 20:17 44032 ----a-w- j:\windows\system32\aticalcl.dll
2012-12-19 20:13 . 2012-12-19 20:13 13703168 ----a-w- j:\windows\system32\aticaldd.dll
2012-12-19 20:12 . 2012-12-19 20:12 18982400 ----a-w- j:\windows\system32\atioglxx.dll
2012-12-19 20:09 . 2011-05-25 03:07 960512 ----a-w- j:\windows\system32\aticfx32.dll
2012-12-19 20:06 . 2011-05-25 02:58 6681088 ----a-w- j:\windows\system32\atidxx32.dll
2012-12-19 19:57 . 2012-09-28 01:39 442368 ----a-w- j:\windows\system32\atidemgy.dll
2012-12-19 19:56 . 2012-12-19 19:56 482304 ----a-w- j:\windows\system32\atieclxx.exe
2012-12-19 19:55 . 2012-12-19 19:55 219136 ----a-w- j:\windows\system32\atiesrxx.exe
2012-12-19 19:54 . 2012-12-19 19:54 163840 ----a-w- j:\windows\system32\atitmmxx.dll
2012-12-19 19:54 . 2012-12-19 19:54 20992 ----a-w- j:\windows\system32\atimuixx.dll
2012-12-19 19:54 . 2012-12-19 19:54 43520 ----a-w- j:\windows\system32\ati2edxx.dll
2012-12-19 19:44 . 2012-09-28 01:22 4162048 ----a-w- j:\windows\system32\atiumdva.dll
2012-12-19 19:33 . 2012-12-19 19:33 56832 ----a-w- j:\windows\system32\atimpc32.dll
2012-12-19 19:33 . 2012-12-19 19:33 56832 ----a-w- j:\windows\system32\amdpcom32.dll
2012-12-19 19:33 . 2012-09-28 01:13 421888 ----a-w- j:\windows\system32\atiadlxx.dll
2012-12-19 19:33 . 2012-12-19 19:33 14848 ----a-w- j:\windows\system32\atiglpxx.dll
2012-12-19 19:33 . 2012-12-19 19:33 33280 ----a-w- j:\windows\system32\atigktxx.dll
2012-12-19 19:32 . 2012-12-19 19:32 442368 ----a-w- j:\windows\system32\drivers\atikmpag.sys
2012-12-19 19:31 . 2011-05-25 02:24 109568 ----a-w- j:\windows\system32\atiuxpag.dll
2012-12-19 19:30 . 2012-06-11 16:24 83968 ----a-w- j:\windows\system32\atiu9pag.dll
2012-12-19 19:30 . 2012-12-19 19:30 53248 ----a-w- j:\windows\system32\drivers\ati2erec.dll
2012-12-19 14:45 . 2012-12-19 14:45 180224 ----a-w- j:\windows\system32\clinfo.exe
2012-12-19 14:44 . 2012-12-19 14:44 65536 ----a-w- j:\windows\system32\OpenVideo.dll
2012-12-19 14:44 . 2012-12-19 14:44 56320 ----a-w- j:\windows\system32\OVDecode.dll
2012-12-19 14:38 . 2012-12-19 14:38 28732928 ----a-w- j:\windows\system32\amdocl.dll
2012-12-19 14:34 . 2012-12-19 14:34 50176 ----a-w- j:\windows\system32\OpenCL.dll
2012-12-16 14:54 . 2010-10-13 18:38 138032 ----a-w- j:\windows\system32\drivers\PnkBstrK.sys
2012-12-16 14:54 . 2010-10-13 18:40 281688 ----a-w- j:\windows\system32\PnkBstrB.xtr
2012-12-16 14:54 . 2010-10-13 18:37 281688 ----a-w- j:\windows\system32\PnkBstrB.exe
2012-12-16 14:13 . 2012-12-20 19:22 295424 ----a-w- j:\windows\system32\atmfd.dll
2012-12-16 14:13 . 2012-12-20 19:22 34304 ----a-w- j:\windows\system32\atmlib.dll
2012-12-12 22:41 . 2010-10-13 18:37 281688 ----a-w- j:\windows\system32\PnkBstrB.ex0
2012-12-07 12:26 . 2013-01-09 18:39 308736 ----a-w- j:\windows\system32\Wpc.dll
2012-12-07 12:20 . 2013-01-09 18:39 2576384 ----a-w- j:\windows\system32\gameux.dll
2012-12-07 10:46 . 2013-01-09 18:39 43520 ----a-w- j:\windows\system32\csrr.rs
2012-12-07 10:46 . 2013-01-09 18:39 30720 ----a-w- j:\windows\system32\usk.rs
2012-12-07 10:46 . 2013-01-09 18:39 45568 ----a-w- j:\windows\system32\oflc-nz.rs
2012-12-07 10:46 . 2013-01-09 18:39 44544 ----a-w- j:\windows\system32\pegibbfc.rs
2012-12-07 10:46 . 2013-01-09 18:39 20480 ----a-w- j:\windows\system32\pegi-pt.rs
2012-12-07 10:46 . 2013-01-09 18:38 23552 ----a-w- j:\windows\system32\oflc.rs
2012-12-07 10:46 . 2013-01-09 18:38 20480 ----a-w- j:\windows\system32\pegi-fi.rs
2012-12-07 10:46 . 2013-01-09 18:39 46592 ----a-w- j:\windows\system32\fpb.rs
2012-12-07 10:46 . 2013-01-09 18:39 20480 ----a-w- j:\windows\system32\pegi.rs
2012-12-07 10:46 . 2013-01-09 18:39 21504 ----a-w- j:\windows\system32\grb.rs
2012-12-07 10:46 . 2013-01-09 18:39 40960 ----a-w- j:\windows\system32\cob-au.rs
2012-12-07 10:46 . 2013-01-09 18:39 15360 ----a-w- j:\windows\system32\djctq.rs
2012-12-07 10:46 . 2013-01-09 18:38 55296 ----a-w- j:\windows\system32\cero.rs
2012-12-07 10:46 . 2013-01-09 18:38 51712 ----a-w- j:\windows\system32\esrb.rs
2012-12-04 12:18 . 2010-10-13 18:37 76888 ----a-w- j:\windows\system32\PnkBstrA.exe
2013-02-08 11:13 . 2013-02-08 11:12 262552 ----a-w- j:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{1dad3af3-ef2f-4f64-ac4b-11789189fcb6}]
2012-06-11 14:22 1307728 ----a-w- j:\program files\Microsoft\BingBar\7.1.391.0\BingExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="j:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"Steam"="j:\program files\Steam2\Steam.exe" [2013-02-25 1602984]
"HydraVisionDesktopManager"="j:\program files\ATI Technologies\HydraVision\HydraDM.exe" [2011-10-03 393216]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="j:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"Easy-PrintToolBox"="j:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-14 409600]
"CanonMyPrinter"="j:\program files\Canon\MyPrinter\BJMyPrt.exe" [2011-07-19 2567272]
"RIMBBLaunchAgent.exe"="j:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-02-18 79192]
"MSC"="j:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 947176]
"LogMeIn Hamachi Ui"="j:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-12-10 2254768]
"StartCCC"="j:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-12-19 642808]
"SunJavaUpdateSched"="j:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes Anti-Malware"="j:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-12-14 512360]
.
j:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - j:\program files\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248]
VPN Client.lnk - j:\windows\Installer\{14FCFE7C-AB86-428A-9D2E-BFB6F5A7AA6E}\Icon3E5562ED7.ico [2010-11-15 6144]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 BBSvc;BingBar Service;j:\program files\Microsoft\BingBar\7.1.391.0\BBSvc.exe [x]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;j:\program files\Lavasoft\Ad-Aware\AAWService.exe [x]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;j:\windows\system32\Drivers\ssadadb.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);j:\windows\system32\DRIVERS\ssudbus.sys [x]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;j:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;j:\program files\McAfee Security Scan\3.0.318\McCHSvc.exe [x]
S0 Lbd;Lbd;j:\windows\system32\DRIVERS\Lbd.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;j:\windows\system32\atiesrxx.exe [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;j:\program files\LogMeIn Hamachi\hamachi-2.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;j:\windows\system32\drivers\AtihdW73.sys [x]
S3 BBUpdate;BBUpdate;j:\program files\Microsoft\BingBar\7.1.391.0\SeaPort.exe [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MPKSL8259866C
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
GPSvcGroup REG_MULTI_SZ GPSvc
.
Contents of the 'Scheduled Tasks' folder
.
2013-03-01 j:\windows\Tasks\Adobe Flash Player Updater.job
- j:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-09 23:15]
.
2013-03-01 j:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- j:\program files\Google\Update\GoogleUpdate.exe [2010-11-21 12:51]
.
2013-03-01 j:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- j:\program files\Google\Update\GoogleUpdate.exe [2010-11-21 12:51]
.
2013-02-23 j:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-143793042-2127241793-3012379221-1000Core.job
- j:\users\Tomo\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-12 12:51]
.
2013-03-01 j:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-143793042-2127241793-3012379221-1000UA.job
- j:\users\Tomo\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-12 12:51]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.daemon-search.com/startpage
uDefault_Search_URL = hxxp://search.qip.ru
uSearchAssistant = hxxp://search.qip.ru/ie
IE: E&xportovať do programu Microsoft Excel - j:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - j:\users\Tomo\AppData\Roaming\Mozilla\Firefox\Profiles\xkka63rz.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://google.sk/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=827316&p=
FF - prefs.js: network.proxy.type - 0
FF - ExtSQL: 2013-01-02 11:33; bkmrksync@nokia.com; j:\program files\Nokia\Nokia PC Suite 7\bkmrksync
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{9CB65206-89C4-402c-BA80-02D8C59F9B1D} - j:\program files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-03-02 00:49:03
ComboFix-quarantined-files.txt 2013-03-01 23:49
ComboFix2.txt 2008-09-09 20:59
.
Pre-Run: 41 943 089 152 bytes free
Post-Run: 49 343 336 448 bytes free
.
- - End Of File - - 06B706917ED17946087D33147C5BAAFF}
Dakujem