Zavirovaný počítač - nereaguje po startu Win
Napsal: 26 srp 2016 12:03
Dobrý den,
mám tu počítač známého. Po spuštění Win7 počítač přestane reagovat explorer.exe, cmd, nic.
V nouzovém režimu ale ano. Projel jsem ho tedy ComboFixem a posílám log. Děkuji za případné rady.
Pozn.: Eset Service byla vypnutá a pro jistotu jsem ji ještě disabloval, přesto ComboFix upozornil, že je aktivní, zvláštní. Žádný proces ani služba od esetu neběžela.
mám tu počítač známého. Po spuštění Win7 počítač přestane reagovat explorer.exe, cmd, nic.
V nouzovém režimu ale ano. Projel jsem ho tedy ComboFixem a posílám log. Děkuji za případné rady.
Pozn.: Eset Service byla vypnutá a pro jistotu jsem ji ještě disabloval, přesto ComboFix upozornil, že je aktivní, zvláštní. Žádný proces ani služba od esetu neběžela.
Kód: Vybrat vše
ComboFix 16-08-21.02 - uzivatel 26.08.2016 11:47:04.1.4 - x64 NETWORK
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4094.3452 [GMT 2:00]
Spuštěný z: c:\users\uzivatel\Downloads\ComboFix.exe
AV: ESET Smart Security 8.0 *Enabled/Outdated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
FW: ESET Personální firewall *Disabled* {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
SP: ESET Smart Security 8.0 *Enabled/Outdated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\msdownld.tmp
c:\windows\security\Database\tmp.edb
c:\windows\SysWow64\DEBUG.log
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2016-07-26 do 2016-08-26 )))))))))))))))))))))))))))))))
.
.
2016-08-26 09:51 . 2016-08-26 09:51 -------- d-----w- c:\users\Default\AppData\Local\temp
2016-08-26 09:26 . 2016-08-17 18:54 11847048 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1983A01D-E2E6-41A0-8B4F-0A57ED7D2E33}\mpengine.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-07-02 09:21 . 2016-07-02 09:21 678560 ----a-w- c:\windows\SysWow64\%InstallDir%speclean.new
2016-06-21 13:54 . 2014-11-20 12:01 142482544 ----a-w- c:\windows\system32\MRT.exe
2016-06-13 17:31 . 2010-11-21 03:27 484008 ----a-w- c:\windows\system32\MpSigStub.exe
2016-06-06 16:58 . 2016-06-19 14:47 41704 ----a-w- c:\windows\system32\CompatTelRunner.exe
2016-06-06 16:50 . 2016-06-19 14:47 1204224 ----a-w- c:\windows\system32\aeinv.dll
2016-06-03 13:05 . 2016-06-19 14:47 1413120 ----a-w- c:\windows\system32\appraiser.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2016-08-05 8894680]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-09-12 959176]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2016-04-01 596504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfp.sys [x]
R1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]
R1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R2 KMSServerService;KMS Server Service;c:\windows\KMSServerService\KMS Server Service.exe ;c:\windows\KMSServerService\KMS Server Service.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [x]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys;c:\windows\SYSNATIVE\DRIVERS\EpfwLWF.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr QWAVE wcncsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2016-06-18 04:10 1245848 ----a-w- c:\program files (x86)\Google\Chrome\Application\51.0.2704.103\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2016-08-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-20 15:50]
.
2016-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-11-20 03:19]
.
2016-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore1d042054c2282f.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-11-20 03:19]
.
2016-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore1d0923d7e33b332.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-11-20 03:19]
.
2016-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore1d0c16c8ff2140f.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-11-20 03:19]
.
2016-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore1d0e39bebe23df1.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-11-20 03:19]
.
2016-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore1d0f09c57c83b39.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-11-20 03:19]
.
2016-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore1d12e8cb89588fe.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-11-20 03:19]
.
2016-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore1d15b78dd24c479.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-11-20 03:19]
.
2016-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore1d16404778c78b2.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-11-20 03:19]
.
2016-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore1d1ab7ea310f834.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-11-20 03:19]
.
2016-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-11-20 03:19]
.
2016-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA1d0420556323b7.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-11-20 03:19]
.
2016-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA1d0923d7ed80bea.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-11-20 03:19]
.
2016-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA1d0c16c90aeb012.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-11-20 03:19]
.
2016-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA1d0e39bec7371e2.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-11-20 03:19]
.
2016-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA1d0f09c58596f2a.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-11-20 03:19]
.
2016-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA1d12e8cb92e6fdb.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-11-20 03:19]
.
2016-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA1d15b78dde4bbe9.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-11-20 03:19]
.
2016-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA1d164047830d16a.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-11-20 03:19]
.
2016-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA1d1ab7ea3c6dd5e.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-11-20 03:19]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-08-19 1796056]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 108144]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2014-10-01 5595336]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-06-11 12503184]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 62.240.163.170 8.8.8.8 8.8.8.8 192.168.10.1
FF - ProfilePath - c:\users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\tnb48x37.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{11111111-1111-1111-1111-110611341129} - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_189_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_189_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_189_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_189_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_189.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.15"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_189.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_189.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_189.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2016-08-26 11:53:10
ComboFix-quarantined-files.txt 2016-08-26 09:53
.
Před spuštěním: Volných bajtů: 406 571 810 816
Po spuštění: Volných bajtů: 406 205 448 192
.
- - End Of File - - 091B85410D4442C1E24C302641DFD9D2
A36C5E4F47E84449FF07ED3517B43A31