Bojim se, ze ma zavirovany notebook.
Napsal: 30 bře 2017 17:56
Zdravim,
prosim o pomoc. Mam funkcni NOD32-nic nenasel, zapnuty win firewall.
Kdyz notas neni na internetu je rychlost normalni, jakmile se pripojim yacne mrznout a celkem cile komunikuje na tehle adresach:
103.5.140.18:53
http://www.ipgeek.co/103.5.140.18
103.5.140.11:67
Spusteni RSIT skoncilo s chybou, vkladam log z DDS, snad bude stacit.
Moc dekuji ya pomoc.
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 11.0.9600.17689
Run by maimai at 18:39:11 on 2017-03-30
Microsoft Windows 7 Starter 6.1.7601.1.1252.1.1033.18.1014.201 [GMT 2:00]
.
AV: ESET NOD32 Antivirus 10.0.390.0 *Enabled/Updated* {EC1D6F37-E411-475A-DF50-12FF7FE4AC70}
SP: ESET NOD32 Antivirus 10.0.390.0 *Enabled/Updated* {577C8ED3-C22B-48D4-E5E0-298D0463E6CD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ================
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\windows\System32\spoolsv.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\System32\AsusService.exe
C:\Program Files\CheckPoint\SSL Network Extender\slimsvc.exe
C:\windows\system32\crypserv.exe
c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\Program Files\NetLimiter 2 Monitor\nlsvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\windows\system32\taskhost.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\NetLimiter 2 Monitor\NLClient.exe
C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\windows\system32\igfxsrvc.exe
C:\Program Files\processexplorer\procexp.exe
C:\Program Files\totalcmd\TOTALCMD.EXE
C:\windows\system32\taskeng.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\windows\system32\NOTEPAD.EXE
C:\Program Files\SeaMonkey\seamonkey.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files\wakan\wakan.exe
C:\windows\system32\taskmgr.exe
C:\windows\system32\conhost.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\System32\svchost.exe -k HPZ12
C:\windows\System32\svchost.exe -k HPZ12
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://asus.msn.com
BHO: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL
uRun: [CCleaner Monitoring] "c:\program files\ccleaner\CCleaner.exe" /MONITOR
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [Eee Docking] c:\program files\asus\eee docking\Eee Docking.exe autorun
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [ASUSPRP] c:\program files\asus\aprp\APRP.EXE
mRun: [SynAsusAcpi] c:\program files\synaptics\syntp\SynAsusAcpi.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\procex~1.lnk - c:\program files\processexplorer\procexp.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\totalc~1.lnk - c:\program files\totalcmd\TOTALCMD.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:255
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
TCP: NameServer = 103.5.140.18 103.5.140.19
TCP: Interfaces\{61A0E461-29CD-460E-947A-510EC7882C39} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{875AABA7-06D2-470B-9E19-3CBF1AE66A27} : DHCPNameServer = 103.5.140.18 103.5.140.19
TCP: Interfaces\{875AABA7-06D2-470B-9E19-3CBF1AE66A27}\072776E2165627F6D266275656 : DHCPNameServer = 193.179.211.28 80.188.91.29
TCP: Interfaces\{875AABA7-06D2-470B-9E19-3CBF1AE66A27}\2457666616C6F6D274D293146303 : DHCPNameServer = 192.168.10.1
TCP: Interfaces\{875AABA7-06D2-470B-9E19-3CBF1AE66A27}\25F4F4D4 : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{875AABA7-06D2-470B-9E19-3CBF1AE66A27}\35753513461697 : DHCPNameServer = 101.110.25.155 101.110.10.155
TCP: Interfaces\{875AABA7-06D2-470B-9E19-3CBF1AE66A27}\4595E435B41402C4944502B414651425E414 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{875AABA7-06D2-470B-9E19-3CBF1AE66A27}\E264255454F57596D26496F50514353505F42545 : DHCPNameServer = 101.110.25.155 101.110.10.155
TCP: Interfaces\{CFF24251-2894-4565-A5C7-4592B7A9FBF8} : NameServer = 217.77.165.81 217.77.161.131
TCP: Interfaces\{CFF24251-2894-4565-A5C7-4592B7A9FBF8} : DHCPNameServer = 217.77.165.81 217.77.161.131
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [2010-6-28 11520]
.
=============== Created Last 30 ================
.
2017-03-30 16:20:08 -------- d-----w- c:\program files\trend micro
.
==================== Find3M ====================
.
2017-03-27 20:20:59 62528 ----a-w- c:\windows\system32\drivers\epfwwfpr.sys
2017-03-27 20:20:59 140984 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2017-03-27 20:20:58 113544 ----a-w- c:\windows\system32\drivers\eamonm.sys
.
============= FINISH: 18:43:36.14 ===============
prosim o pomoc. Mam funkcni NOD32-nic nenasel, zapnuty win firewall.
Kdyz notas neni na internetu je rychlost normalni, jakmile se pripojim yacne mrznout a celkem cile komunikuje na tehle adresach:
103.5.140.18:53
http://www.ipgeek.co/103.5.140.18
103.5.140.11:67
Spusteni RSIT skoncilo s chybou, vkladam log z DDS, snad bude stacit.
Moc dekuji ya pomoc.
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 11.0.9600.17689
Run by maimai at 18:39:11 on 2017-03-30
Microsoft Windows 7 Starter 6.1.7601.1.1252.1.1033.18.1014.201 [GMT 2:00]
.
AV: ESET NOD32 Antivirus 10.0.390.0 *Enabled/Updated* {EC1D6F37-E411-475A-DF50-12FF7FE4AC70}
SP: ESET NOD32 Antivirus 10.0.390.0 *Enabled/Updated* {577C8ED3-C22B-48D4-E5E0-298D0463E6CD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ================
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\windows\System32\spoolsv.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\System32\AsusService.exe
C:\Program Files\CheckPoint\SSL Network Extender\slimsvc.exe
C:\windows\system32\crypserv.exe
c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\Program Files\NetLimiter 2 Monitor\nlsvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\windows\system32\taskhost.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\NetLimiter 2 Monitor\NLClient.exe
C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\windows\system32\igfxsrvc.exe
C:\Program Files\processexplorer\procexp.exe
C:\Program Files\totalcmd\TOTALCMD.EXE
C:\windows\system32\taskeng.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\windows\system32\NOTEPAD.EXE
C:\Program Files\SeaMonkey\seamonkey.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files\wakan\wakan.exe
C:\windows\system32\taskmgr.exe
C:\windows\system32\conhost.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\System32\svchost.exe -k HPZ12
C:\windows\System32\svchost.exe -k HPZ12
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://asus.msn.com
BHO: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL
uRun: [CCleaner Monitoring] "c:\program files\ccleaner\CCleaner.exe" /MONITOR
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [Eee Docking] c:\program files\asus\eee docking\Eee Docking.exe autorun
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [ASUSPRP] c:\program files\asus\aprp\APRP.EXE
mRun: [SynAsusAcpi] c:\program files\synaptics\syntp\SynAsusAcpi.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\procex~1.lnk - c:\program files\processexplorer\procexp.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\totalc~1.lnk - c:\program files\totalcmd\TOTALCMD.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:255
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
TCP: NameServer = 103.5.140.18 103.5.140.19
TCP: Interfaces\{61A0E461-29CD-460E-947A-510EC7882C39} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{875AABA7-06D2-470B-9E19-3CBF1AE66A27} : DHCPNameServer = 103.5.140.18 103.5.140.19
TCP: Interfaces\{875AABA7-06D2-470B-9E19-3CBF1AE66A27}\072776E2165627F6D266275656 : DHCPNameServer = 193.179.211.28 80.188.91.29
TCP: Interfaces\{875AABA7-06D2-470B-9E19-3CBF1AE66A27}\2457666616C6F6D274D293146303 : DHCPNameServer = 192.168.10.1
TCP: Interfaces\{875AABA7-06D2-470B-9E19-3CBF1AE66A27}\25F4F4D4 : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{875AABA7-06D2-470B-9E19-3CBF1AE66A27}\35753513461697 : DHCPNameServer = 101.110.25.155 101.110.10.155
TCP: Interfaces\{875AABA7-06D2-470B-9E19-3CBF1AE66A27}\4595E435B41402C4944502B414651425E414 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{875AABA7-06D2-470B-9E19-3CBF1AE66A27}\E264255454F57596D26496F50514353505F42545 : DHCPNameServer = 101.110.25.155 101.110.10.155
TCP: Interfaces\{CFF24251-2894-4565-A5C7-4592B7A9FBF8} : NameServer = 217.77.165.81 217.77.161.131
TCP: Interfaces\{CFF24251-2894-4565-A5C7-4592B7A9FBF8} : DHCPNameServer = 217.77.165.81 217.77.161.131
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [2010-6-28 11520]
.
=============== Created Last 30 ================
.
2017-03-30 16:20:08 -------- d-----w- c:\program files\trend micro
.
==================== Find3M ====================
.
2017-03-27 20:20:59 62528 ----a-w- c:\windows\system32\drivers\epfwwfpr.sys
2017-03-27 20:20:59 140984 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2017-03-27 20:20:58 113544 ----a-w- c:\windows\system32\drivers\eamonm.sys
.
============= FINISH: 18:43:36.14 ===============