Stránka 1 z 2

problem pri najizdezdeni winXp

Napsal: 12 led 2014 13:11
od 69pavel
Dobry den,
popisi svuj problem,kdyz zapnu PC tak PC normalne nabiha ,celkem rychle do chvile kdy se objevi obrazovka s vyberem uzivatelu a v momente kdy kliknu na prihlaseni uzivatele tak mi naskoci tapeta win a ted se PC jakoby zabrzdi a nekdy trva i 2-3 minuty nekdy i vice nez nabehnou ikony,v minulosti jsem pomoci programu Malwarebytes a superantispyware odstranil tyto nakazy Spyware PWS(umisteno v -systemvolumeinformation/restore na oddilech C;D;G)
Riskware.toolo.HCK(umisteno-systemvolumeinformation_restore na oddilu G)
Trojan.agent/genNullo(short)
Trojan.agent/gen-kazy

programy infekce odstranily presunem do karanteny,presto se mi to nezda normalni aby to tak najizdelo,pc jsem nechal zkontrolovat online skenerem na F-secure,vysledek negativni,pote test avastu po restartu,vysledek negativni a pak jeste provedena kontrola pomoci avast rescueCD taky negativni.
pro doplneni pouzivam legalni system WinXP home edition,predtim zadne problemy nebyly
predem diky za pomoc

Re: problem pri najizdezdeni winXp

Napsal: 12 led 2014 14:42
od 69pavel
porad se mi nedari udelat log z programu FRST, pri skenovani to spadne a vyhodi chybovou hlasku,co stim aby to slo oskenovat??? verzi mam v poradku,overeno pres vasi utilitu na zjisteni OS tak nevi mco delam spatne


Obrázek




EDIT: i kdyz to porad pada pri skenovani nejaky txt log to napsalo jestli to bude dostacujici nevim,snad je celej

LOG:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-01-2014
Ran by Pavlik (administrator) on DOMA-A8CA6F655C on 12-01-2014 17:36:03
Running from C:\Documents and Settings\Pavlik\Plocha
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore.exe
(Acronis) C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Skype Technologies S.A.) C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
() C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Alcor Micro Corp.) C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe
(Acronis) C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
(Acronis) C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
(Acronis) C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
(Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Nokia) C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe
(BitTorrent, Inc.) C:\Documents and Settings\Pavlik\Data aplikací\uTorrent\utorrent.exe
(ZONER software) C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTray.exe
(Nokia) C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2012-11-29] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [ATICustomerCare] - C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe [311296 2010-05-04] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [NeroFilterCheck] - C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [153136 2007-03-01] (Nero AG)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2013-12-29] (AVAST Software)
HKLM\...\Run: [RTHDCPL] - C:\Windows\RTHDCPL.EXE [20145368 2013-10-04] (Realtek Semiconductor Corp.)
HKLM\...\Run: [AmIcoSinglun] - C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe [279320 2013-07-12] (Alcor Micro Corp.)
HKLM\...\Run: [TrueImageMonitor.exe] - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2615688 2008-03-06] (Acronis)
HKLM\...\Run: [AcronisTimounterMonitor] - C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [910744 2008-03-06] (Acronis)
HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [140568 2008-03-06] (Acronis)
HKLM\...\Run: [OSSelectorReinstall] - C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe [2225208 2007-03-15] ()
Winlogon\Notify\AtiExtEvent: C:\Windows\system32\Ati2evxx.dll (ATI Technologies Inc.)
HKCU\...\Run: [AlcoholAutomount] - C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [33120 2010-08-20] (Alcohol Soft Development Team)
HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-02-19] (Google Inc.)
HKCU\...\Run: [NokiaSuite.exe] - C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe [1090912 2013-10-02] (Nokia)
HKCU\...\Run: [uTorrent] - C:\Documents and Settings\Pavlik\Data aplikací\uTorrent\utorrent.exe [393728 2013-10-10] (BitTorrent, Inc.)
HKCU\...\Run: [Zoner Photo Studio Autoupdate] - C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE [774168 2013-02-18] (ZONER software)
HKCU\...\Run: [GUDelayStartup] - C:\Program Files\Glary Utilities 4\StartupManager.exe [37152 2014-01-06] (Glarysoft Ltd)
HKCU\...\Policies\Explorer: [NoInstrumentation] 1
HKU\Honza\...\Run: [NokiaSuite.exe] - C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe [ 2013-10-02] (Nokia)
Lsa: [Authentication Packages] msv1_0 relog_ap

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll ()
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll ()
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU - &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\Windows\system32\SHELL32.dll (Microsoft Corporation)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftup ... 1039521859
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [115440 2013-05-07] (SuperAdBlocker.com)
Tcpip\Parameters: [DhcpNameServer] 10.157.255.1 10.157.255.2

Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/
CHR Plugin: (Shockwave Flash) - C:\Documents and Settings\Pavlik\Local Settings\Data aplikac\u00ED\Google\Chrome\User Data\PepperFlash\11.6.602.167\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Skype Click to Call) - C:\Documents and Settings\Pavlik\Local Settings\Data aplikac\u00ED\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.6.0.11664_0\npSkypeChromePlugin.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Microsoft\u00AE DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Microsoft\u00AE DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U13) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Nokia Suite Enabler Plugin) - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
CHR Plugin: (VLC Web Plugin) - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Windows Presentation Foundation) - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Shockwave for Director) - C:\WINDOWS\system32\Adobe\Director\np32dsw_1200112.dll No File
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_168.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.130.20) - C:\WINDOWS\system32\npDeployJava1.dll No File
CHR Extension: (Candy) - C:\Documents and Settings\Pavlik\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\fiejadjmcgacmocgeegodfhligbpecdg\1.0_0 [2013-02-20]
CHR Extension: (avast! Online Security) - C:\Documents and Settings\Pavlik\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2011.70_0 [2014-01-07]
CHR Extension: (Skype Click to Call) - C:\Documents and Settings\Pavlik\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.13.0.13771_0 [2013-10-18]
CHR Extension: (Google Wallet) - C:\Documents and Settings\Pavlik\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 [2013-12-29]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-10-09]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

========================== Services (Whitelisted) =================

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [119056 2013-05-23] (SUPERAntiSpyware.com)
R2 AcrSch2Svc; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [427288 2008-03-06] (Acronis)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-29] (AVAST Software)
S3 DfSdkS; C:\Program Files\Ashampoo\Ashampoo WinOptimizer 9\DfsdkS.exe [406016 2009-08-24] (mst software GmbH, Germany)
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2013-10-08] (Oracle Corporation)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 Skype C2C Service; C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
S2 StarWindServiceAE; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software)
R2 TryAndDecideService; C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe [495936 2008-03-06] ()

==================== Drivers (Whitelisted) ====================

S3 Ambfilt; C:\Windows\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative)
S3 asusgsb; C:\Windows\System32\drivers\asusgsb.sys [12416 2009-02-17] (ASUSTeK Computer Inc.)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [67824 2013-12-29] (AVAST Software)
R1 AswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [54832 2013-12-29] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49944 2013-10-31] ()
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [775952 2013-12-29] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [410528 2013-12-29] (AVAST Software)
R1 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57672 2013-12-29] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [180248 2013-12-29] ()
R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdXP3.sys [103040 2012-05-14] (Advanced Micro Devices)
R0 BootDefragDriver; C:\Windows\System32\drivers\BootDefragDriver.sys [13504 2014-01-06] (Glarysoft Ltd)
S3 CCDECODE; C:\Windows\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-02-20] (DT Soft Ltd)
R2 EIO_XP; C:\WINDOWS\system32\drivers\EIO_XP.sys [14336 2009-07-30] (ASUSTeK Computer Inc.)
S3 ETD; C:\Windows\System32\DRIVERS\ETD.sys [314632 2013-10-24] (ELAN Microelectronics Corp.)
R3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [56352 2013-10-24] (HP)
R3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [22928 2013-10-24] (HP)
R3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [28000 2013-10-24] (HP)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
S3 Monfilt; C:\Windows\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.)
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SCDEmu; C:\Windows\System32\Drivers\SCDEmu.sys [113608 2013-04-15] (Power Software Ltd)
R0 tdrpman; C:\Windows\System32\DRIVERS\tdrpman.sys [368480 2013-12-07] (Acronis)
R2 tifsfilter; C:\Windows\System32\DRIVERS\tifsfilt.sys [44384 2013-12-07] (Acronis)
U3 a9uhkr9q; C:\Windows\System32\Drivers\a9uhkr9q.sys [0 ] (Microsoft Corporation)
U3 avbbr020; C:\Windows\System32\Drivers\avbbr020.sys [0 ] (Microsoft Corporation)
R1 AFD; \SystemRoot\System32\drivers\afd.sys [x]
S3 ApfiltrService; system32\DRIVERS\Apfiltr.sys [x]
R0 sptd; \SystemRoot\System32\Drivers\sptd.sys [x]
R1 VgaSave; \SystemRoot\System32\drivers\vga.sys [x]
S3 Video3D; System32\Drivers\Video3D32.sys [x]
U1 WS2IFSL;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-12 17:36 - 2014-01-12 17:36 - 00016652 _____ C:\Documents and Settings\Pavlik\Plocha\FRST.txt
2014-01-12 14:39 - 2014-01-12 14:57 - 00029696 _____ C:\Documents and Settings\Pavlik\Local Settings\Data aplikací\MSGBOX.EXE
2014-01-12 14:39 - 2014-01-12 14:39 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Pavlik\Plocha\FRSTLauncher.exe
2014-01-12 14:36 - 2014-01-12 14:36 - 00000000 ____D C:\FRST
2014-01-12 14:35 - 2014-01-12 14:35 - 01219584 _____ (Farbar) C:\Documents and Settings\Pavlik\Plocha\FRST.exe
2014-01-09 10:09 - 2014-01-09 10:09 - 00000794 _____ C:\Documents and Settings\All Users\Nabídka Start\Programy\Glary Utilities 4.lnk
2014-01-09 10:09 - 2014-01-06 04:28 - 00013504 _____ (Glarysoft Ltd) C:\WINDOWS\system32\Drivers\BootDefragDriver.sys
2014-01-06 20:16 - 2014-01-06 20:16 - 00165996 _____ C:\WINDOWS\system32\config\aswrc1389035791.rcr
2014-01-06 19:08 - 2014-01-06 19:08 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Adobe
2014-01-06 19:08 - 2014-01-06 19:08 - 00000000 ____D C:\Documents and Settings\Administrator\Data aplikací\Adobe
2014-01-04 22:42 - 2014-01-04 22:42 - 00000000 ____D C:\Documents and Settings\NetworkService\Data aplikací\Acronis
2013-12-29 22:01 - 2013-12-29 22:15 - 00001024 _____ C:\WINDOWS\system32\AutoPartNt.let
2013-12-29 21:52 - 2013-12-29 21:52 - 00000934 _____ C:\Documents and Settings\Pavlik\Plocha\AIDA64 Business Edition.lnk
2013-12-29 21:52 - 2013-12-29 21:52 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\FinalWire
2013-12-29 21:41 - 2013-12-29 21:52 - 00000000 ____D C:\Program Files\FinalWire
2013-12-29 21:36 - 2014-01-12 07:37 - 00000318 _____ C:\WINDOWS\Tasks\GlaryInitialize 4.job
2013-12-29 21:36 - 2014-01-09 10:09 - 00000788 _____ C:\Documents and Settings\All Users\Plocha\Glary Utilities 4.lnk
2013-12-29 21:36 - 2014-01-06 09:38 - 00101664 _____ (Glarysoft Ltd) C:\WINDOWS\system32\BootDefrag.exe
2013-12-29 21:36 - 2013-12-29 21:36 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Glary Utilities 4
2013-12-29 21:35 - 2014-01-09 10:09 - 00000000 ____D C:\Program Files\Glary Utilities 4
2013-12-29 21:34 - 2013-12-29 21:37 - 00000000 ____D C:\Program Files\Glary Utilities 3
2013-12-29 21:34 - 2013-12-29 21:34 - 00000126 _____ C:\Documents and Settings\Pavlik\Local Settings\Data aplikací\fusioncache.dat
2013-12-29 21:31 - 2013-12-29 21:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2808679$
2013-12-29 21:16 - 2013-12-29 21:16 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2904266$
2013-12-29 21:16 - 2013-12-29 21:16 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2898715$
2013-12-29 21:06 - 2013-12-29 21:06 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2893984$
2013-12-29 21:06 - 2013-12-29 21:06 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2893294$
2013-12-29 21:06 - 2013-12-29 21:06 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2892075$
2013-12-29 17:26 - 2014-01-06 20:12 - 00000000 ____D C:\Documents and Settings\Pavlik

==================== One Month Modified Files and Folders =======

2014-01-12 17:36 - 2014-01-12 17:36 - 00016652 _____ C:\Documents and Settings\Pavlik\Plocha\FRST.txt
2014-01-12 17:36 - 2013-02-17 11:07 - 00000000 ____D C:\Documents and Settings\Pavlik\Data aplikací\uTorrent
2014-01-12 17:36 - 2013-02-16 16:15 - 00000466 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{E5DBF983-2779-4738-B623-6ECECF873FF2}.job
2014-01-12 17:36 - 2013-02-16 15:22 - 00000000 ____D C:\Documents and Settings\Pavlik\Plocha
2014-01-12 17:34 - 2013-02-19 15:39 - 00000000 ____D C:\Documents and Settings\Pavlik\Plocha\OPRAVA COMPU
2014-01-12 17:24 - 2013-02-16 16:00 - 00000468 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{715B3559-FF94-4902-AD0E-10C89802A9EA}.job
2014-01-12 17:19 - 2013-11-18 10:34 - 00000000 ____D C:\Program Files\ScreenshotCaptor
2014-01-12 16:50 - 2013-02-17 11:48 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-01-12 16:39 - 2013-02-16 16:01 - 00000940 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-12 14:59 - 2013-02-20 09:52 - 00000262 _____ C:\WINDOWS\wiadebug.log
2014-01-12 14:57 - 2014-01-12 14:39 - 00029696 _____ C:\Documents and Settings\Pavlik\Local Settings\Data aplikací\MSGBOX.EXE
2014-01-12 14:57 - 2013-02-16 15:22 - 00000000 ___HD C:\Documents and Settings\Pavlik\Local Settings\Data aplikací
2014-01-12 14:39 - 2014-01-12 14:39 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Pavlik\Plocha\FRSTLauncher.exe
2014-01-12 14:39 - 2013-02-16 16:02 - 00001324 _____ C:\WINDOWS\system32\d3d9caps.dat
2014-01-12 14:39 - 2013-02-16 15:21 - 00032532 _____ C:\WINDOWS\SchedLgU.Txt
2014-01-12 14:36 - 2014-01-12 14:36 - 00000000 ____D C:\FRST
2014-01-12 14:35 - 2014-01-12 14:35 - 01219584 _____ (Farbar) C:\Documents and Settings\Pavlik\Plocha\FRST.exe
2014-01-12 14:21 - 2013-02-20 09:50 - 01334119 _____ C:\WINDOWS\WindowsUpdate.log
2014-01-12 07:52 - 2013-02-16 16:25 - 00000364 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2014-01-12 07:41 - 2013-02-16 14:53 - 00759006 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2014-01-12 07:37 - 2013-12-29 21:36 - 00000318 _____ C:\WINDOWS\Tasks\GlaryInitialize 4.job
2014-01-12 07:36 - 2013-04-17 09:02 - 00000274 _____ C:\WINDOWS\Tasks\RMAutoUpdate.job
2014-01-12 07:36 - 2013-02-20 09:52 - 00000049 _____ C:\WINDOWS\wiaservc.log
2014-01-12 07:36 - 2013-02-16 16:01 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-12 07:36 - 2013-02-16 15:22 - 00000000 ___HD C:\Documents and Settings\Pavlik\Šablony
2014-01-12 07:36 - 2013-02-16 15:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2014-01-12 07:36 - 2006-03-02 13:00 - 00012598 _____ C:\WINDOWS\system32\wpa.dbl
2014-01-11 22:26 - 2013-02-16 19:26 - 00131072 _____ C:\WINDOWS\system32\config\ACEEvent.evt
2014-01-11 22:26 - 2013-02-16 15:22 - 00000178 ___SH C:\Documents and Settings\Pavlik\ntuser.ini
2014-01-11 19:52 - 2013-04-17 09:02 - 00000274 _____ C:\WINDOWS\Tasks\RMSchedule.job
2014-01-11 17:49 - 2013-05-06 18:57 - 00000000 ____D C:\Documents and Settings\Pavlik\Data aplikací\vlc
2014-01-10 20:02 - 2013-02-20 07:59 - 00000000 ____D C:\Documents and Settings\Pavlik\Data aplikací\Media Player Classic
2014-01-09 10:09 - 2014-01-09 10:09 - 00000794 _____ C:\Documents and Settings\All Users\Nabídka Start\Programy\Glary Utilities 4.lnk
2014-01-09 10:09 - 2013-12-29 21:36 - 00000788 _____ C:\Documents and Settings\All Users\Plocha\Glary Utilities 4.lnk
2014-01-09 10:09 - 2013-12-29 21:35 - 00000000 ____D C:\Program Files\Glary Utilities 4
2014-01-09 10:09 - 2013-02-16 14:53 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2014-01-07 14:20 - 2013-02-16 16:01 - 00000000 ____D C:\Documents and Settings\Pavlik\Local Settings\Data aplikací\Google
2014-01-06 20:16 - 2014-01-06 20:16 - 00165996 _____ C:\WINDOWS\system32\config\aswrc1389035791.rcr
2014-01-06 20:12 - 2013-12-29 17:26 - 00000000 ____D C:\Documents and Settings\Pavlik
2014-01-06 20:12 - 2013-02-20 09:45 - 00000000 ____D C:\Documents and Settings\Administrator
2014-01-06 20:12 - 2013-02-16 16:11 - 00000000 ____D C:\Documents and Settings\Honza
2014-01-06 20:12 - 2013-02-16 15:21 - 00000000 __SHD C:\Documents and Settings\LocalService
2014-01-06 20:12 - 2013-02-16 14:44 - 00000000 __SHD C:\Documents and Settings\NetworkService
2014-01-06 19:09 - 2013-02-20 09:45 - 00000178 ___SH C:\Documents and Settings\Administrator\ntuser.ini
2014-01-06 19:08 - 2014-01-06 19:08 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Adobe
2014-01-06 19:08 - 2014-01-06 19:08 - 00000000 ____D C:\Documents and Settings\Administrator\Data aplikací\Adobe
2014-01-06 19:08 - 2013-02-20 09:45 - 00000000 __RHD C:\Documents and Settings\Administrator\Data aplikací
2014-01-06 19:08 - 2013-02-20 09:45 - 00000000 ___HD C:\Documents and Settings\Administrator\Local Settings\Data aplikací
2014-01-06 09:38 - 2013-12-29 21:36 - 00101664 _____ (Glarysoft Ltd) C:\WINDOWS\system32\BootDefrag.exe
2014-01-06 04:28 - 2014-01-09 10:09 - 00013504 _____ (Glarysoft Ltd) C:\WINDOWS\system32\Drivers\BootDefragDriver.sys
2014-01-04 22:42 - 2014-01-04 22:42 - 00000000 ____D C:\Documents and Settings\NetworkService\Data aplikací\Acronis
2014-01-04 22:42 - 2013-02-16 14:44 - 00000000 ____D C:\Documents and Settings\NetworkService\Data aplikací
2014-01-04 17:37 - 2013-07-11 06:21 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850851$
2014-01-04 17:07 - 2013-02-16 14:46 - 00000000 ____D C:\WINDOWS\Driver Cache
2014-01-04 12:21 - 2013-02-16 16:31 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\DriverGenius
2014-01-04 12:11 - 2013-02-20 10:10 - 00000000 ____D C:\Program Files\CCleaner
2014-01-04 10:37 - 2013-05-26 07:21 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-12-29 22:29 - 2013-02-16 19:20 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-12-29 22:15 - 2013-12-29 22:01 - 00001024 _____ C:\WINDOWS\system32\AutoPartNt.let
2013-12-29 22:14 - 2013-12-06 04:24 - 01390730 _____ (Acronis) C:\WINDOWS\system32\AutoPartNt.exe
2013-12-29 22:01 - 2013-10-24 07:55 - 00380991 _____ C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-S-1-5-21-1935655697-606747145-1801674531-1004-0.dat
2013-12-29 22:01 - 2013-02-19 23:31 - 00230734 _____ C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-System.dat
2013-12-29 21:52 - 2013-12-29 21:52 - 00000934 _____ C:\Documents and Settings\Pavlik\Plocha\AIDA64 Business Edition.lnk
2013-12-29 21:52 - 2013-12-29 21:52 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\FinalWire
2013-12-29 21:52 - 2013-12-29 21:41 - 00000000 ____D C:\Program Files\FinalWire
2013-12-29 21:47 - 2013-02-19 13:57 - 00000000 ____D C:\Documents and Settings\Pavlik\Nabídka Start\Programy\PC Translator
2013-12-29 21:37 - 2013-12-29 21:34 - 00000000 ____D C:\Program Files\Glary Utilities 3
2013-12-29 21:37 - 2013-08-07 06:31 - 00000075 _____ C:\DiskDefrag.log
2013-12-29 21:37 - 2013-02-20 09:27 - 00000000 ____D C:\Documents and Settings\Pavlik\Data aplikací\GlarySoft
2013-12-29 21:36 - 2013-12-29 21:36 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Glary Utilities 4
2013-12-29 21:36 - 2013-02-16 14:53 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2013-12-29 21:34 - 2013-12-29 21:34 - 00000126 _____ C:\Documents and Settings\Pavlik\Local Settings\Data aplikací\fusioncache.dat
2013-12-29 21:31 - 2013-12-29 21:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2808679$
2013-12-29 21:27 - 2013-02-16 14:39 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy\Nástroje pro správu
2013-12-29 21:26 - 2013-02-16 14:39 - 00000000 ____D C:\WINDOWS\Registration
2013-12-29 21:18 - 2013-02-16 14:52 - 00218448 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-12-29 21:16 - 2013-12-29 21:16 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2904266$
2013-12-29 21:16 - 2013-12-29 21:16 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2898715$
2013-12-29 21:16 - 2013-02-16 15:56 - 00019306 _____ C:\WINDOWS\system32\TZLog.log
2013-12-29 21:16 - 2013-02-16 15:54 - 00000000 ____D C:\WINDOWS\ie8updates
2013-12-29 21:15 - 2013-07-15 12:10 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-12-29 21:10 - 2013-02-17 10:08 - 00000000 ____D C:\Documents and Settings\Pavlik\Nabídka Start\Programy
2013-12-29 21:06 - 2013-12-29 21:06 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2893984$
2013-12-29 21:06 - 2013-12-29 21:06 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2893294$
2013-12-29 21:06 - 2013-12-29 21:06 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2892075$
2013-12-29 21:06 - 2013-02-16 15:52 - 88123800 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-12-29 20:50 - 2013-02-17 11:48 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2013-12-29 20:50 - 2013-02-17 11:48 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2013-12-29 19:52 - 2013-03-24 08:38 - 00180248 _____ C:\WINDOWS\system32\Drivers\aswVmm.sys
2013-12-29 19:52 - 2013-03-24 08:38 - 00067824 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2013-12-29 19:52 - 2013-02-16 16:25 - 00775952 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2013-12-29 19:52 - 2013-02-16 16:25 - 00410528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsp.sys
2013-12-29 19:52 - 2013-02-16 16:25 - 00057672 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys
2013-12-29 19:52 - 2013-02-16 16:25 - 00054832 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
2013-12-29 19:52 - 2013-02-16 16:25 - 00001762 _____ C:\Documents and Settings\All Users\Plocha\avast! Free Antivirus.lnk
2013-12-29 19:52 - 2013-02-16 16:24 - 00270240 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2013-12-29 19:52 - 2013-02-16 16:24 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2013-12-29 19:34 - 2013-02-16 15:33 - 00012540 _____ C:\WINDOWS\system32\wpa.bak
2013-12-29 19:32 - 2013-02-16 15:34 - 00005208 _____ C:\WINDOWS\system32\pid.PNF
2013-12-29 19:29 - 2013-05-24 05:14 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Google Drive

Some content of TEMP:
====================
C:\Documents and Settings\Honza\Local Settings\Temp\jre-7u45-windows-i586-iftw.exe
C:\Documents and Settings\Honza\Local Settings\Temp\NEventMessages.dll
C:\Documents and Settings\Honza\Local Settings\Temp\NOSEventMessages.dll
C:\Documents and Settings\Pavlik\Local Settings\Temp\NEventMessages.dll
C:\Documents and Settings\Pavlik\Local Settings\Temp\NOSEventMessages.dll


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe
[2008-04-14 07:52] - [2008-04-14 07:52] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1

C:\Windows\System32\winlogon.exe
[2008-04-14 07:52] - [2008-04-14 07:52] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea

C:\Windows\System32\svchost.exe
[2008-04-14 07:52] - [2008-04-14 07:52] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93

C:\Windows\System32\services.exe
[2008-04-14 07:52] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7

C:\Windows\System32\User32.dll
[2008-04-14 07:52] - [2008-04-14 07:52] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53

C:\Windows\System32\userinit.exe
[2008-04-14 07:52] - [2008-04-14 07:52] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239

C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys
[2008-04-14 06:42] - [2008-04-14 06:42] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1


==================== End Of Log ============================

Re: problem pri najizdezdeni winXp

Napsal: 13 led 2014 18:19
od Roli
Zdravím, pokud nepůjde FRST klidně použij RSIT.

To zdlouhavé spouštění normální není, nejdříve kouknem na šmejdy a pak na hardware.


Stáhni a spusť HJT

v okně které se ti otevře klikni na Do a system scan and save a logfile.

Proběhne sken a log který na Tebe vypadne mi sem nakopíruj.


Stáhni a ulož na plochu AdwCleaner,

ukonči všechny programy včetně prohlížeče a dvojklikem spusť,

objeví se okno kde vlevo nahoře klikni na Scan.

Po té proběhne sken a po jeho skončení klikni na Report a to co na Tebe vypadne mi sem zkopíruj.

Re: problem pri najizdezdeni winXp

Napsal: 13 led 2014 20:22
od 69pavel
zdravim,v prve rade predem dekuji za vasi ochotu a tady je je log z hijacktis

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:20:46, on 13.1.2014
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe
C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O3 - Toolbar: avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AmIcoSinglun] "C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe"
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [OSSelectorReinstall] C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [NokiaSuite.exe] C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe -tray
O4 - HKCU\..\Run: [uTorrent] "C:\Documents and Settings\Pavlik\Data aplikací\uTorrent\utorrent.exe"
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE
O4 - HKCU\..\Run: [GUDelayStartup] C:\Program Files\Glary Utilities 4\StartupManager.exe -delayrun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 1025107067
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 1039521859
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - C:\Program Files\Ashampoo\Ashampoo WinOptimizer 9\DfsdkS.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe

--
End of file - 12822 bytes

Re: problem pri najizdezdeni winXp

Napsal: 13 led 2014 20:25
od 69pavel
log z adwcleaner

# AdwCleaner v3.017 - Report created 13/01/2014 at 20:23:08
# Updated 12/01/2014 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Pavlik - DOMA-A8CA6F655C
# Running from : C:\Documents and Settings\Pavlik\Plocha\adwcleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Found C:\Documents and Settings\All Users\Data aplikací\boost_interprocess
Folder Found C:\Documents and Settings\Pavlik\Data aplikací\driver-soft
Folder Found C:\Documents and Settings\Pavlik\Data aplikací\registry mechanic
Folder Found C:\Documents and Settings\Pavlik\Local Settings\Data aplikací\apn
Folder Found C:\Program Files\driver-soft

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\APN PIP
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : HKCU\Software\Softonic
Key Found : HKLM\SOFTWARE\Classes\CLSID\{059EACC2-1ABE-49E8-928D-DC8BD355B7A9}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{4C836512-BB70-11D2-A5A7-00105A9C91C6}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6FDBBC21-E399-4542-B4CE-86326E1F0727}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7B878FD4-8F19-46DB-94B1-4CABFF80679C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{8BA495EF-6CD5-413A-8AEF-483631B98C4F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{8C71E394-2E6F-452A-AB7D-C17E78307083}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{BADB1512-759C-4792-A18A-DD6BDC4E1991}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DB797690-40E0-11D2-9BD5-0060082AE372}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E54FBC83-9028-45AC-A5B9-D5DA828E59C2}
Key Found : HKLM\SOFTWARE\Classes\driverscanner
Key Found : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Found : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{633AA60B-C339-46C3-951F-047F9822C473}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9156C8F9-B397-4DEF-8AC5-5966221A134A}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A8E5842E-102B-4289-9D57-3B3F5B5E15D3}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{DB797681-40E0-11D2-9BD5-0060082AE372}
Key Found : HKLM\Software\Driver-Soft
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
Key Found : HKLM\Software\PIP
Key Found : HKLM\Software\Uniblue

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702


-\\ Google Chrome v31.0.1650.63

[ File : C:\Documents and Settings\Pavlik\Local Settings\Data aplikací\Google\Chrome\User Data\Default\preferences ]


[ File : C:\Documents and Settings\Honza\Local Settings\Data aplikací\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [3419 octets] - [13/01/2014 20:23:08]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [3479 octets] ##########

Re: problem pri najizdezdeni winXp

Napsal: 14 led 2014 20:41
od Roli
V HJT fixni :

O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll
O3 - Toolbar: avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [NokiaSuite.exe] C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe -tray
O4 - HKCU\..\Run: [uTorrent] "C:\Documents and Settings\Pavlik\Data aplikací\uTorrent\utorrent.exe"
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)


Fix znamená že spustíš HJT Obrázek jako admin

v okně které se ti otevře klikneš na Do a system scan only

v dalším okně najdeš řádky které jsem ti vypsal,

vedle nich je čtvereček do kterého uděláš zatržítko,

pak klikneš na Fix checked které je vlevo dole,

program se ti zeptá zda opravdu ANO s tím samozřejmě souhlasíš a je hotovo.


Přes Start >> Spustit >> napiš - services.msc >> OK. Najdi službu :

Služba Google Update (gupdate)

Služba Google Update (gupdatem)

Google Software Updater

NBService

NMIndexingService


dvojklikem se otevře karta kde nejprve službu zastav tlačítkem Zastavit u položky Typ spouštění vyber Zakázáno a klik na OK.


V Naplánovaných úkolech zakaž Google Update bude to tam několikrát.


Znovu spusť AdwCleaner ale tentokrát klikni na Clean,

proběhne restart PC kdy dojde ke smazání nepořádku.

Po té mi sem zase zkopíruj Report.


Smaž nepotřebné soubory

pomocí CCleaneru

návod :

Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš

Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)

čištění registru je třeba několikrát zopakovat !

Nástroje - tady lze odinstalovat programy, upravit co se spustí po Startu systému a obnovit systém


Stáhni a ulož na plochu ComboFix,

spusť aplikaci jako Administrátor a povol instalaci Konzole pro zotavení - Recovery Console.

Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,

pak ještě jednou klik na ANO a už to jede.

Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.

Při skenovaní může být PC i restartováno nelekat se.

Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,

protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.

Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt

(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.


V případě nejasností je ZDE obrázkový návod.

Re: problem pri najizdezdeni winXp

Napsal: 14 led 2014 21:20
od 69pavel
zati mjsem vse udelal ale ted si nevim rady ,kde najdu ty naplanovane ulohy abych zakazal ten googleupdate

Re: problem pri najizdezdeni winXp

Napsal: 14 led 2014 21:30
od Roli
69pavel píše:zati mjsem vse udelal ale ted si nevim rady ,kde najdu ty naplanovane ulohy abych zakazal ten googleupdate
Start >> Všechny programy >> Příslušenství >> Systémové nástroje >> Naplánované úkoly :wink:

Re: problem pri najizdezdeni winXp

Napsal: 14 led 2014 21:31
od 69pavel
jj,diky, uz jsem ztoho nejak zmateny
log z adwcleaneru

# AdwCleaner v3.017 - Report created 14/01/2014 at 21:41:32
# Updated 12/01/2014 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Pavlik - DOMA-A8CA6F655C
# Running from : C:\Documents and Settings\Pavlik\Plocha\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Documents and Settings\All Users\Data aplikací\boost_interprocess
Folder Deleted : C:\Program Files\driver-soft
Folder Deleted : C:\Documents and Settings\Pavlik\Local Settings\Data aplikací\apn
Folder Deleted : C:\Documents and Settings\Pavlik\Data aplikací\driver-soft
Folder Deleted : C:\Documents and Settings\Pavlik\Data aplikací\registry mechanic

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\driverscanner
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{059EACC2-1ABE-49E8-928D-DC8BD355B7A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4C836512-BB70-11D2-A5A7-00105A9C91C6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6FDBBC21-E399-4542-B4CE-86326E1F0727}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7B878FD4-8F19-46DB-94B1-4CABFF80679C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8BA495EF-6CD5-413A-8AEF-483631B98C4F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8C71E394-2E6F-452A-AB7D-C17E78307083}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BADB1512-759C-4792-A18A-DD6BDC4E1991}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DB797690-40E0-11D2-9BD5-0060082AE372}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E54FBC83-9028-45AC-A5B9-D5DA828E59C2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{633AA60B-C339-46C3-951F-047F9822C473}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9156C8F9-B397-4DEF-8AC5-5966221A134A}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A8E5842E-102B-4289-9D57-3B3F5B5E15D3}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DB797681-40E0-11D2-9BD5-0060082AE372}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\Software\Driver-Soft
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\Software\Uniblue
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702


-\\ Google Chrome v31.0.1650.63

[ File : C:\Documents and Settings\Pavlik\Local Settings\Data aplikací\Google\Chrome\User Data\Default\preferences ]


[ File : C:\Documents and Settings\Honza\Local Settings\Data aplikací\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [3559 octets] - [13/01/2014 20:23:08]
AdwCleaner[R1].txt - [3408 octets] - [14/01/2014 21:29:51]
AdwCleaner[R2].txt - [3527 octets] - [14/01/2014 21:40:07]
AdwCleaner[S0].txt - [358 octets] - [14/01/2014 21:32:32]
AdwCleaner[S1].txt - [3522 octets] - [14/01/2014 21:41:32]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [3582 octets] ##########

Re: problem pri najizdezdeni winXp

Napsal: 14 led 2014 21:43
od Roli
69pavel píše:jj,diky, uz jsem ztoho nejak zmateny
A to se teprve rozjíždíme :lol:

Re: problem pri najizdezdeni winXp

Napsal: 14 led 2014 22:05
od 69pavel
log z combofixu
ComboFix 14-01-14.02 - Pavlik 14.01.2014 21:55:58.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2047.1377 [GMT 1:00]
Spuštěný z: c:\documents and settings\Pavlik\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Pavlik\Local Settings\Data aplikací\MSGBOX.EXE
c:\program files\update.exe
c:\windows\system32\SET356.tmp
c:\windows\system32\SET35B.tmp
c:\windows\system32\TZLog.log
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-12-14 do 2014-01-14 )))))))))))))))))))))))))))))))
.
.
2014-01-14 07:37 . 2014-01-14 07:37 -------- d-----w- c:\program files\My Lockbox
2014-01-14 07:37 . 2011-06-03 22:59 51760 ----a-w- c:\windows\system32\drivers\FSPFltd2.sys
2014-01-13 19:23 . 2014-01-14 20:41 -------- d-----w- C:\AdwCleaner
2014-01-13 19:19 . 2014-01-13 19:19 -------- d-----w- c:\program files\Trend Micro
2014-01-12 13:36 . 2014-01-12 13:36 -------- d-----w- C:\FRST
2014-01-09 09:09 . 2014-01-06 03:28 13504 ----a-w- c:\windows\system32\drivers\BootDefragDriver.sys
2013-12-29 20:41 . 2013-12-29 20:52 -------- d-----w- c:\program files\FinalWire
2013-12-29 20:36 . 2013-12-29 20:36 -------- d-----w- C:\ProgramData
2013-12-29 20:36 . 2014-01-06 08:38 101664 ----a-w- c:\windows\system32\BootDefrag.exe
2013-12-29 20:35 . 2014-01-14 06:02 -------- d-----w- c:\program files\Glary Utilities 4
2013-12-29 20:34 . 2013-12-29 20:37 -------- d-----w- c:\program files\Glary Utilities 3
2013-12-29 20:26 . 2013-12-29 20:26 -------- d-----w- c:\windows\system32\URTTEMP
2013-12-29 16:26 . 2013-12-29 16:27 -------- d-----w- C:\Documents and Settings
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-29 21:14 . 2013-12-06 03:24 1390730 ----a-w- c:\windows\system32\AutoPartNt.exe
2013-12-29 19:50 . 2013-02-17 10:48 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-12-29 19:50 . 2013-02-17 10:48 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-12-29 18:52 . 2013-03-24 07:38 180248 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-12-29 18:52 . 2013-03-24 07:38 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-12-29 18:52 . 2013-02-16 15:25 410528 ----a-w- c:\windows\system32\drivers\aswsp.sys
2013-12-29 18:52 . 2013-02-16 15:25 57672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-12-29 18:52 . 2013-02-16 15:25 54832 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2013-12-29 18:52 . 2013-02-16 15:25 775952 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-12-29 18:52 . 2013-02-16 15:24 43152 ----a-w- c:\windows\avastSS.scr
2013-12-29 18:52 . 2013-02-16 15:24 270240 ----a-w- c:\windows\system32\aswBoot.exe
2013-12-07 18:29 . 2013-02-17 06:43 44384 ----a-w- c:\windows\system32\drivers\tifsfilt.sys
2013-12-07 18:29 . 2013-02-17 06:43 441760 ----a-w- c:\windows\system32\drivers\timntr.sys
2013-12-07 18:29 . 2013-02-17 06:43 129248 ----a-w- c:\windows\system32\drivers\snapman.sys
2013-12-07 18:29 . 2013-02-17 06:43 368480 ----a-w- c:\windows\system32\drivers\tdrpman.sys
2013-12-03 10:33 . 2008-04-13 22:50 361600 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-11-13 03:00 . 2008-04-14 06:51 150528 ----a-w- c:\windows\system32\imagehlp.dll
2013-11-10 06:11 . 2013-11-10 06:11 386464 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\TPWinPrn.dll
2013-11-10 06:08 . 2013-11-10 06:08 51200 ----a-w- c:\windows\system32\wmerrenu.dll
2013-11-10 06:08 . 2013-11-10 06:08 63088 ----a-w- c:\windows\system32\vsocklib.dll
2013-11-10 06:08 . 2013-11-10 06:08 16496 ----a-w- c:\windows\system32\vmx_mode.dll
2013-11-10 06:08 . 2013-11-10 06:08 1544048 ----a-w- c:\windows\system32\vmx_fb.dll
2013-11-10 06:08 . 2013-11-10 06:08 3181680 ----a-w- c:\windows\system32\vmwogl32.dll
2013-11-10 06:07 . 2013-11-10 06:07 90224 ----a-w- c:\windows\system32\VMUpgradeAtShutdownWXP.dll
2013-11-10 06:07 . 2013-11-10 06:07 50800 ----a-w- c:\windows\system32\vmhgfs.dll
2013-11-10 06:07 . 2013-11-10 06:07 34416 ----a-w- c:\windows\system32\vmGuestLibJava.dll
2013-11-10 06:07 . 2013-11-10 06:07 53360 ----a-w- c:\windows\system32\vmGuestLib.dll
2013-11-10 06:07 . 2013-11-10 06:07 111912 ----a-w- c:\windows\system32\TPVMW32.dll
2013-11-10 06:07 . 2013-11-10 06:07 9072 ----a-w- c:\windows\system32\TPVMMonUIjpn.dll
2013-11-10 06:07 . 2013-11-10 06:07 9064 ----a-w- c:\windows\system32\TPVMMonUIdeu.dll
2013-11-10 06:07 . 2013-11-10 06:07 79176 ----a-w- c:\windows\system32\TPVMMonUI.dll
2013-11-10 06:07 . 2013-11-10 06:07 9576 ----a-w- c:\windows\system32\TPVMMonjpn.dll
2013-11-10 06:07 . 2013-11-10 06:07 23904 ----a-w- c:\windows\system32\TPVMMondeu.dll
2013-11-10 06:07 . 2013-11-10 06:07 316736 ----a-w- c:\windows\system32\TPVMMon.dll
2013-11-10 06:07 . 2013-11-10 06:07 484192 ----a-w- c:\windows\system32\TPSvc.dll
2013-11-10 06:07 . 2013-11-10 06:07 144664 ----a-w- c:\windows\system32\tprdpw32.dll
2013-11-10 06:07 . 2013-11-10 06:07 30000 ----a-w- c:\windows\system32\drivers\vmxnet.sys
2013-11-10 06:07 . 2013-11-10 06:07 102256 ----a-w- c:\windows\system32\drivers\vmx_svga.sys
2013-11-10 06:06 . 2013-11-10 06:06 17968 ----a-w- c:\windows\system32\drivers\vmscsi.sys
2013-11-10 06:06 . 2013-11-10 06:06 11440 ----a-w- c:\windows\system32\drivers\vmmouse.sys
2013-11-10 06:06 . 2013-11-10 06:06 143344 ----a-w- c:\windows\system32\drivers\vmhgfs.sys
2013-11-10 06:06 . 2013-11-10 06:06 98928 ----a-w- c:\windows\system32\drivers\vmci.sys
2013-11-10 06:06 . 2013-11-10 06:06 35328 ----a-w- c:\windows\system32\drivers\pcntpci5.sys
2013-11-10 06:06 . 2013-11-10 06:06 10624 ----a-w- c:\windows\system32\drivers\gameenum.sys
2013-11-10 06:06 . 2013-11-10 06:06 40704 ----a-w- c:\windows\system32\drivers\es1371mp.sys
2013-11-10 06:06 . 2013-11-10 06:06 10240 ----a-w- c:\windows\system32\drivers\compbatt.sys
2013-11-10 06:06 . 2013-11-10 06:06 13952 ----a-w- c:\windows\system32\drivers\CmBatt.sys
2013-11-10 06:06 . 2013-11-10 06:06 14208 ----a-w- c:\windows\system32\drivers\battc.sys
2013-11-10 06:06 . 2013-11-10 06:06 42368 ----a-w- c:\windows\system32\drivers\AGP440.SYS
2013-11-07 05:38 . 2008-04-14 06:51 591360 ----a-w- c:\windows\system32\rpcrt4.dll
2013-11-06 01:36 . 2008-05-05 06:25 7168 ----a-w- c:\windows\system32\xpsp4res.dll
2013-11-05 18:47 . 2013-02-16 18:11 5589720 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
2013-10-31 07:06 . 2013-03-24 07:38 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-10-30 02:51 . 2008-04-14 05:45 1879040 ----a-w- c:\windows\system32\win32k.sys
2013-10-29 07:45 . 2008-04-14 06:52 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2013-10-29 07:45 . 2008-04-14 06:52 920064 ----a-w- c:\windows\system32\wininet.dll
2013-10-29 07:45 . 2008-04-14 06:51 43520 ----a-w- c:\windows\system32\licmgr10.dll
2013-10-29 07:45 . 2008-04-14 06:51 18944 ----a-w- c:\windows\system32\corpol.dll
2013-10-29 00:45 . 2008-04-14 05:50 385024 ----a-w- c:\windows\system32\html.iec
2013-10-24 06:54 . 2013-02-16 18:23 495616 ----a-w- c:\windows\system32\atiok3x2.dll
2013-10-24 06:54 . 2013-02-16 18:23 24064 ----a-w- c:\windows\system32\ativcoxx.dll
2013-10-24 06:54 . 2013-02-16 18:23 2380672 ----a-w- c:\windows\system32\ativvaxx.dll
2013-10-24 06:54 . 2013-02-16 18:23 212992 ----a-w- c:\windows\system32\atipdlxx.dll
2013-10-24 06:54 . 2013-02-16 18:23 18964480 ----a-w- c:\windows\system32\atioglxx.dll
2013-10-24 06:54 . 2013-02-16 18:23 17408 ----a-w- c:\windows\system32\atitvo32.dll
2013-10-24 06:54 . 2013-02-16 18:23 163840 ----a-w- c:\windows\system32\Oemdspif.dll
2013-10-24 06:54 . 2013-02-16 18:23 929792 ----a-w- c:\windows\system32\atikvmag.dll
2013-10-24 06:54 . 2013-02-16 18:23 71192 ----a-w- c:\windows\system32\atimpc32.dll
2013-10-24 06:54 . 2013-02-16 18:23 71192 ----a-w- c:\windows\system32\amdpcom32.dll
2013-10-24 06:54 . 2013-02-16 18:23 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2013-10-24 06:54 . 2013-02-16 18:23 4844064 ----a-w- c:\windows\system32\ati3duag.dll
2013-10-24 06:54 . 2013-02-16 18:23 45056 ----a-w- c:\windows\system32\ATIODCLI.exe
2013-10-24 06:54 . 2013-02-16 18:23 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2013-10-24 06:54 . 2013-02-16 18:23 307200 ----a-w- c:\windows\system32\atiiiexx.dll
2013-10-24 06:54 . 2013-02-16 18:23 294912 ----a-w- c:\windows\system32\ATIODE.exe
2013-10-24 06:54 . 2013-02-16 18:23 245760 ----a-w- c:\windows\system32\atiadlxx.dll
2013-10-24 06:54 . 2013-02-16 18:23 163840 ----a-w- c:\windows\system32\atiapfxx.exe
2013-10-24 06:54 . 2013-02-16 18:23 118784 ----a-w- c:\windows\system32\atibtmon.exe
2013-10-24 06:54 . 2013-02-16 18:23 6850048 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2013-10-24 06:54 . 2013-02-16 18:23 643072 ----a-w- c:\windows\system32\ati2evxx.exe
2013-10-24 06:54 . 2013-02-16 18:23 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2013-10-24 06:54 . 2013-02-16 18:23 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2013-10-24 06:54 . 2013-02-16 18:23 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2013-10-24 06:54 . 2013-02-16 18:23 192512 ----a-w- c:\windows\system32\ati2evxx.dll
2013-10-24 06:54 . 2013-02-16 18:23 663552 ----a-w- c:\windows\system32\ati2cqag.dll
2013-10-24 06:54 . 2013-02-16 18:23 306176 ----a-w- c:\windows\system32\ati2dvag.dll
2013-10-24 06:22 . 2005-10-28 00:24 28000 ----a-w- c:\windows\system32\drivers\HPZius12.sys
2013-10-24 06:22 . 2005-10-28 00:23 293152 ----a-w- c:\windows\system32\HPZc3212.dll
2013-10-24 06:22 . 2013-02-17 09:24 56352 ----a-w- c:\windows\system32\drivers\HPZid412.sys
2013-10-24 06:22 . 2013-02-17 09:24 22928 ----a-w- c:\windows\system32\drivers\HPZipr12.sys
2013-10-24 06:17 . 2013-10-24 06:17 314632 ----a-w- c:\windows\system32\drivers\ETD.sys
2013-10-24 06:09 . 2013-02-18 16:19 1461992 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
2013-10-23 23:45 . 2008-04-14 06:51 172032 ----a-w- c:\windows\system32\scrrun.dll
2008-02-14 12:23 . 2008-02-14 12:23 231944 ----a-w- c:\program files\gwflash.exe
2007-09-21 17:42 . 2007-09-21 17:42 19008 ----a-w- c:\program files\markfun.a64
2007-08-21 17:49 . 2007-08-21 17:49 125504 ----a-w- c:\program files\MarkFunDrv.dll
2007-08-21 17:49 . 2007-08-21 17:49 17912 ----a-w- c:\program files\markfun.w32
2007-04-04 16:35 . 2007-04-04 16:35 207680 ----a-w- c:\program files\updateutility.exe
2007-03-02 02:48 . 2007-03-02 02:48 240448 ----a-w- c:\program files\gwf32.exe
2006-11-23 21:47 . 2006-11-23 21:47 207680 ----a-w- c:\program files\BIOS_Run.exe
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2013-12-03 . CBEEBEB899E31EF52B962CB31FC8CA5C . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB2509553$\tcpip.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-12-29 18:52 259464 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2013-12-06 14:47 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-12-06 14:47 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-12-06 14:47 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2013-12-06 14:47 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2013-12-06 14:47 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2013-12-06 14:47 579024 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" [2010-08-20 33120]
"GUDelayStartup"="c:\program files\Glary Utilities 4\StartupManager.exe" [2014-01-06 37152]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-11-29 98304]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2013-12-29 3764024]
"RTHDCPL"="RTHDCPL.EXE" [2013-10-04 20145368]
"AmIcoSinglun"="c:\program files\AmIcoSingLun\AmIcoSinglun.exe" [2013-07-12 279320]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2008-03-06 2615688]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2008-03-06 910744]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2008-03-06 140568]
"OSSelectorReinstall"="c:\program files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe" [2007-03-15 2225208]
"mylbx"="c:\program files\My Lockbox\mylbx.exe" [2013-10-28 2289952]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2013-05-07 115440]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\persistentroutes]
"195.137.182.212,255.255.255.255,10.1.1.14,1"=""
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\TopCD\\Traktor 3\\farm2012.dll"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\ICQ7M\\ICQ.exe"=
"c:\\Program Files\\GIGABYTE\\@BIOS\\update.exe"=
"c:\\Program Files\\gwflash.exe"=
"c:\\Documents and Settings\\Pavlik\\Data aplikací\\uTorrent\\utorrent.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Vzdálená správa systému Windows
.
R0 aswRvrt;avast! Revert;c:\windows\system32\drivers\aswRvrt.sys [24.3.2013 8:38 49944]
R0 aswVmm;avast! VM Monitor;c:\windows\system32\drivers\aswVmm.sys [24.3.2013 8:38 180248]
R0 BootDefragDriver;BootDefragDriver;c:\windows\system32\drivers\BootDefragDriver.sys [9.1.2014 10:09 13504]
R0 FSProFilter2;FSPro File Filter 2;c:\windows\system32\drivers\FSPFltd2.sys [14.1.2014 8:37 51760]
R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys --> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [16.2.2013 16:25 775952]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswsp.sys [16.2.2013 16:25 410528]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [22.7.2011 17:27 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12.7.2011 22:55 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [23.5.2013 21:11 119056]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [24.3.2013 8:38 67824]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [16.2.2013 19:23 103040]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [20.2.2013 8:10 242240]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [20.2.2013 9:59 22856]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [17.2.2013 13:10 47360]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [20.2.2013 9:59 701512]
S2 Skype C2C Service;Skype C2C Service;c:\documents and settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [9.10.2013 9:58 3275136]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [7.2.2013 13:24 161384]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [17.2.2013 7:38 1691480]
S3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 9\DfSdkS.exe [17.2.2013 13:06 406016]
S3 ETD;Dell Touchpad;c:\windows\system32\drivers\ETD.sys [24.10.2013 7:17 314632]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [10.5.2013 5:37 137600]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [10.5.2013 5:37 8576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-12-05 20:36 1210320 ----a-w- c:\program files\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-01-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-17 19:50]
.
2014-01-14 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2013-02-16 18:52]
.
2014-01-14 c:\windows\Tasks\GlaryInitialize 4.job
- c:\program files\Glary Utilities 4\Initialize.exe [2014-01-06 08:37]
.
2014-01-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-02-16 15:01]
.
2014-01-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-02-16 15:01]
.
2014-01-14 c:\windows\Tasks\User_Feed_Synchronization-{715B3559-FF94-4902-AD0E-10C89802A9EA}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
2014-01-14 c:\windows\Tasks\User_Feed_Synchronization-{E5DBF983-2779-4738-B623-6ECECF873FF2}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - c:\program files\ICQ7M\ICQ.exe
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
TCP: DhcpNameServer = 10.157.255.1 10.157.255.2
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
SafeBoot-WudfPf
SafeBoot-WudfRd
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-01-14 22:02
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1412)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
- - - - - - - > 'lsass.exe'(1468)
c:\windows\system32\relog_ap.dll
.
Celkový čas: 2014-01-14 22:04:21
ComboFix-quarantined-files.txt 2014-01-14 21:04
.
Před spuštěním: Volných bajtů: 75 901 521 920
Po spuštění: Volných bajtů: 77 319 061 504
.
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 8C9147250212569E00E8B206C69DB9EE
A1D51EB7C81D922D77F0DE7BE8922627

Re: problem pri najizdezdeni winXp

Napsal: 15 led 2014 18:13
od Roli
Než budeme pokračovat tohle :

c:\windows\system32\drivers\tcpip.sys

c:\windows\$hf_mig$\KB2509553\SP3QFE\tcpip.sys

c:\windows\system32\dllcache\tcpip.sys

c:\windows\$NtUninstallKB2509553$\tcpip.sys

postupně otestuj na VIRUSTOTAL

(po načtení stránky klikni na tlačítko Procházet - Choose File, najdi cestu k výše zmíněnému souboru

nebo tam výše zmíněný text nakopíruj a klikni na tlačítko Odeslat soubor - Scan It!

trvá to okolo deseti minut pak mi sem zkopíruj link, to je ten řádek nahoře v prohlížeči)

Pokud ti to napíše že soubor již byl testován nech Otestovat znovu - Reanalyse.


Stáhni a spusť OTMoveIt

do levého okna aplikace pod Paste Instructions for Items to be Moved zkopíruj tento text:

Kód: Vybrat vše

:processes
explorer.exe       

:files 
C:\*.tmp
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

:commands
[purity]
[emptytemp]
[start explorer]
klikni na MoveIt! a v pravém zeleném okně aplikace se Ti objeví info o provedene akci, obsah okna zkopíruj sem,

pokud aplikace bude požadovat restart, klikni na YES

v tom případě sem chci zkopírovat obsah logu uloženého na C:\_OTMoveIt\MovedFiles\

Re: problem pri najizdezdeni winXp

Napsal: 15 led 2014 20:15
od 69pavel
zdravim,jdu na to testovani

prvni soubor odkaz https://www.virustotal.com/cs/file/41f7 ... /analysis/

druhy-
https://www.virustotal.com/cs/file/fa50 ... /analysis/

treti-
nenasel jsem ,i kdyz mam zobrazene skryte slozky a koncove pripony

ctvrty-
https://www.virustotal.com/cs/file/0130 ... /analysis/


EDIT: tak ted nastal problem stmi programem,udelal jsem jak jste napsal a po spusteni se pc jakoby zamrazilo,ikony a lista zmizela,zustalo jen okno programu a konec,pc zamrzne,po 15 minutach jsem ho natvrdo restartoval nebot nic jineho stim neslo delat,log se nevytvoril.

Re: problem pri najizdezdeni winXp

Napsal: 16 led 2014 20:21
od Roli
69pavel píše:........., po 15 minutach jsem ho natvrdo restartoval nebot nic jineho stim neslo delat,log se nevytvoril.
V pohodě tak to neřeš, byla to jen zbytečnost.

Znovu spusť OTMoveIt a nahoře v aplikaci klini na CleanUP!

tímto po sobě uklidí.


Přes Start >> Spustit zkopíruj do okna:

ComboFix /Uninstall

a stiskni Enter

To odinstaluje ComboFix a smaže s ním související soubory a složky


Použij T-Cleaner, který smaže případné zbytky po aplikacích které jsme použili.

Jen před jeho stažením a při použití stopni antivir, protože ho muže detekovat jako vir ale není tomu tak.


Pak dej vědět jaký je stav PC.

Re: problem pri najizdezdeni winXp

Napsal: 16 led 2014 21:22
od 69pavel
tak jsem udelal co jste psal akorat ten otmove smazal i ten combofix,kdyz jsem ho totiz pak chtel pres ten prikaz radek spustit tak vypsal chybu a na plose uz ikona combofixu nebyla. zkousel jsem nekolikrat vypnout pc a pri najizdeni je to porad stejne, tak nevim,nemuze to delat treba nektery soft,i kdyz uz jsem skusil vypnout ten antimalware,superantispyware, vysledek porad stejny,na uzivateli se to zamrazi a pak nabehne

jeste u toho tcleanu to chtelo smazat nejakou slozku pro zalohu registru tak jsem zmacknul ano,neudelal jsem neco spatne?