Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

mrzne PC

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
rivers2
Návštěvník
Návštěvník
Příspěvky: 178
Registrován: 10 led 2009 15:21

mrzne PC

#1 Příspěvek od rivers2 »

poprosím o kontrolu logu. zacal mi mrznut pc. dakujem


Logfile of random's system information tool 1.06 (written by random/random)
Run by Jozo at 2010-01-29 23:41:12
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 7 GB (37%) free of 19 GB
Total RAM: 3070 MB (82% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:41:20, on 29. 1. 2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\IObit\IObit Security 360\IS360srv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\IncrediMail\bin\ImApp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
F:\rapidshare\programy\RSIT_2.exe
C:\Program Files\trend micro\Jozo.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.zoznam.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\WINDOWS\system32\dvmurl.dll
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Prevziať cez IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Prevziať cez IDM všetky prepojenia - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Prevziať obsah FLV cez IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastaviť prekladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Preložiť &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Preložiť &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O13 - Gopher Prefix:
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IS360service - IObit - C:\Program Files\IObit\IObit Security 360\IS360srv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 11605 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDMIEHlprObj Class - C:\Program Files\Internet Download Manager\IDMIECC.dll [2009-09-09 173488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2007-11-06 322880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}]
PC Tools Browser Guard BHO - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll [2009-11-10 395216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll [2009-12-12 503808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-12-12 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-12-12 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2007-11-06 542016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll [2009-12-12 503808]
{472734EA-242A-422B-ADF8-83D1E48CC825} - PC Tools Browser Guard - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll [2009-11-10 395216]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-02-13 16857600]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-10-14 49152]
"hpqSRMon"=C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [2007-08-22 80896]
"Logitech Hardware Abstraction Layer"=C:\WINDOWS\KHALMNPR.EXE [2008-02-29 76304]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"PDVD8LanguageShortcut"=C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe [2007-12-14 50472]
"BDRegion"=C:\Program Files\Cyberlink\Shared Files\brs.exe [2008-05-19 91432]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-11-20 12669544]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2009-11-20 110184]
"Kernel and Hardware Abstraction Layer"=C:\WINDOWS\KHALMNPR.EXE [2008-02-29 76304]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"IDMan"=C:\Program Files\Internet Download Manager\IDMan.exe [2009-09-10 3118512]
"IncrediMail"=C:\Program Files\IncrediMail\bin\IncMail.exe [2008-07-24 243072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"TuneUp.ProgramStatisticsSvc"=2
"TuneUp.Defrag"=3

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll [2008-05-02 72208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2009-06-04 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoResolveTrack"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoResolveTrack"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\IncrediMail\bin\IncMail.exe"="C:\Program Files\IncrediMail\bin\IncMail.exe:*:Enabled:IncrediMail"
"C:\Program Files\IncrediMail\bin\ImpCnt.exe"="C:\Program Files\IncrediMail\bin\ImpCnt.exe:*:Enabled:IncrediMail"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\IncrediMail\bin\ImLc.exe"="C:\Program Files\IncrediMail\bin\ImLc.exe:*:Enabled:IncrediMail"
"B:\hry\hra\Data\ra3_1.0.game"="B:\hry\hra\Data\ra3_1.0.game:*:Enabled:Command & Conquer™ Red Alert™ 3"
"C:\Program Files\IncrediMail\bin\ImApp.exe"="C:\Program Files\IncrediMail\bin\ImApp.exe:*:Enabled:IncrediMail"
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"

======List of files/folders created in the last 1 months======

2010-01-29 21:12:09 ----A---- C:\WINDOWS\system32\BtCoreIf.dll
2010-01-29 20:02:43 ----D---- C:\Program Files\IncrediMail
2010-01-29 19:39:03 ----D---- C:\Documents and Settings\Jozo\Data aplikací\Logitech
2010-01-29 19:37:46 ----A---- C:\WINDOWS\system32\KemXML.dll
2010-01-29 19:37:46 ----A---- C:\WINDOWS\system32\KemWnd.dll
2010-01-29 19:37:46 ----A---- C:\WINDOWS\system32\KemUtil.dll
2010-01-29 19:37:46 ----A---- C:\WINDOWS\system32\kemutb.dll
2010-01-29 19:37:23 ----D---- C:\Documents and Settings\All Users\Data aplikací\Logitech
2010-01-29 19:34:02 ----D---- C:\Program Files\GameShadow
2010-01-28 09:56:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\WinZip
2010-01-28 09:56:38 ----D---- C:\Program Files\WinZip
2010-01-24 20:55:15 ----D---- C:\Documents and Settings\Jozo\Data aplikací\Red Alert 3
2010-01-24 20:54:04 ----RHD---- C:\Documents and Settings\Jozo\Data aplikací\SecuROM
2010-01-20 18:05:48 ----D---- C:\Documents and Settings\All Users\Data aplikací\Firefly Studios
2010-01-20 18:03:51 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2010-01-16 20:53:00 ----D---- C:\Documents and Settings\Jozo\Data aplikací\Uniblue
2010-01-16 20:52:55 ----D---- C:\Program Files\Uniblue
2010-01-14 00:04:32 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-01-14 00:04:20 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-01-13 20:12:05 ----SHD---- C:\WINDOWS\ftpcache
2010-01-13 20:08:55 ----A---- C:\WINDOWS\game.ini
2010-01-12 13:07:14 ----D---- C:\Documents and Settings\All Users\Data aplikací\LogiShrd
2010-01-12 13:03:19 ----D---- C:\Program Files\Common Files\Logishrd
2010-01-11 00:20:45 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2010-01-11 00:20:44 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2010-01-11 00:20:44 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2010-01-11 00:20:43 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2010-01-11 00:20:42 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2010-01-11 00:20:42 ----A---- C:\WINDOWS\system32\d3dx10_42.dll
2010-01-11 00:20:41 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2010-01-05 17:00:50 ----D---- C:\rsit
2010-01-05 16:24:01 ----D---- C:\Documents and Settings\All Users\Data aplikací\Paradox Interactive
2010-01-05 16:04:48 ----D---- C:\Program Files\Microsoft Bootvis

======List of files/folders modified in the last 1 months======

2010-01-29 23:41:14 ----D---- C:\Program Files\trend micro
2010-01-29 23:40:38 ----D---- C:\WINDOWS\Temp
2010-01-29 23:40:32 ----D---- C:\WINDOWS\system32\CatRoot2
2010-01-29 23:39:14 ----D---- C:\Program Files\Mozilla Firefox
2010-01-29 23:38:01 ----D---- C:\Documents and Settings\Jozo\Data aplikací\DMCache
2010-01-29 23:36:58 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2010-01-29 22:58:46 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-29 22:44:00 ----D---- C:\WINDOWS
2010-01-29 22:43:58 ----SHD---- C:\WINDOWS\Installer
2010-01-29 22:43:58 ----HD---- C:\WINDOWS\inf
2010-01-29 22:43:58 ----D---- C:\WINDOWS\system32\dllcache
2010-01-29 22:43:57 ----HD---- C:\Config.Msi
2010-01-29 22:43:57 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-01-29 22:43:57 ----D---- C:\WINDOWS\system32\drivers
2010-01-29 22:43:57 ----D---- C:\WINDOWS\system32
2010-01-29 22:43:57 ----D---- C:\Program Files\Common Files\Logitech
2010-01-29 22:43:53 ----HD---- C:\Program Files\InstallShield Installation Information
2010-01-29 22:43:48 ----RD---- C:\Program Files
2010-01-29 22:43:48 ----D---- C:\Program Files\Logitech
2010-01-29 22:43:46 ----RSD---- C:\WINDOWS\Fonts
2010-01-29 22:14:48 ----D---- C:\WINDOWS\system32\Restore
2010-01-29 20:15:09 ----D---- C:\Program Files\Internet Download Manager
2010-01-29 17:48:21 ----D---- C:\Program Files\Spyware Doctor
2010-01-26 19:06:57 ----D---- C:\Documents and Settings\Jozo\Data aplikací\IDM
2010-01-24 20:44:02 ----D---- C:\WINDOWS\system32\DirectX
2010-01-23 00:25:36 ----D---- C:\Program Files\Internet Explorer
2010-01-23 00:25:16 ----D---- C:\WINDOWS\ie8updates
2010-01-23 00:25:02 ----HD---- C:\WINDOWS\$hf_mig$
2010-01-21 21:07:48 ----D---- C:\WINDOWS\Prefetch
2010-01-21 12:23:26 ----D---- C:\Program Files\Unlocker
2010-01-20 18:00:35 ----D---- C:\WINDOWS\Downloaded Installations
2010-01-20 18:00:14 ----RSD---- C:\WINDOWS\assembly
2010-01-19 10:48:33 ----D---- C:\WINDOWS\system32\config
2010-01-16 20:48:56 ----D---- C:\WINDOWS\Debug
2010-01-16 20:48:55 ----D---- C:\WINDOWS\Minidump
2010-01-14 09:18:32 ----SD---- C:\Documents and Settings\Jozo\Data aplikací\Microsoft
2010-01-14 08:10:41 ----D---- C:\WINDOWS\AppPatch
2010-01-14 00:05:12 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-01-13 22:31:06 ----A---- C:\WINDOWS\TRNCOM.INI
2010-01-13 20:20:18 ----A---- C:\WINDOWS\system32\PnkBstrA.exe
2010-01-13 20:20:06 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2010-01-12 22:21:14 ----D---- C:\Program Files\Smarty Uninstaller Pro
2010-01-12 13:03:19 ----D---- C:\Program Files\Common Files
2010-01-05 17:59:58 ----ASH---- C:\boot.ini
2010-01-05 17:59:58 ----A---- C:\WINDOWS\win.ini
2010-01-05 17:59:58 ----A---- C:\WINDOWS\system.ini
2010-01-05 17:15:11 ----SHD---- C:\System Volume Information
2010-01-05 16:18:37 ----D---- C:\WINDOWS\WinSxS
2010-01-05 16:09:52 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-01-05 01:17:46 ----A---- C:\WINDOWS\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2008-11-02 56572]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}; \??\C:\Program Files\CyberLink\PowerDVD8\000.fcl []
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-12-12 56816]
R2 LBeepKE;LBeepKE; C:\WINDOWS\System32\Drivers\LBeepKE.sys [2007-01-23 10640]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2009-06-04 60800]
R3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys []
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-11-01 49920]
R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-11-01 16496]
R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2007-11-01 21568]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-02-14 4676096]
R3 L8042Kbd;Logitech SetPoint Keyboard Driver; C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys [2008-02-29 20240]
R3 L8042mou;SetPoint PS/2 Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\L8042mou.Sys [2008-02-29 63120]
R3 LMouKE;SetPoint Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouKE.Sys [2008-02-29 79120]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2009-06-04 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-11-21 10235968]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-12-18 47360]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-01-03 105856]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 ayrwbk1a;ayrwbk1a; C:\WINDOWS\system32\drivers\ayrwbk1a.sys []
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2008-05-07 17536]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2008-05-07 20864]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2009-12-24 10368]
S3 slabbus;CP2101 USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\slabbus.sys [2004-03-11 52384]
S3 TVICHW32;TVICHW32; \??\C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS []
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2008-06-06 8064]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2008-05-07 8064]
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-15 82688]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
R2 Browser Defender Update Service;Browser Defender Update Service; C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe [2009-11-10 112592]
R2 GEST Service;GEST Service for program management.; C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe [2008-07-18 80392]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 IS360service;IS360service; C:\Program Files\IObit\IObit Security 360\IS360srv.exe [2009-09-02 305936]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-12-12 153376]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-11-20 154216]
R2 O&O Defrag;O&O Defrag; C:\WINDOWS\system32\oodag.exe [2007-05-11 1050120]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2010-01-13 66872]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe [2008-05-02 121360]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 sdAuxService;PC Tools Auxiliary Service; C:\Program Files\Spyware Doctor\pctsAuxs.exe [2009-10-30 359624]
S3 sdCoreService;PC Tools Security Service; C:\Program Files\Spyware Doctor\pctsSvc.exe [2009-11-06 1141712]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-08-07 575488]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\WINDOWS\System32\TuneUpDefragService.exe [2009-12-12 360192]
S4 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service; C:\WINDOWS\System32\TUProgSt.exe [2009-12-12 603904]

-----------------EOF-----------------

meteorolog
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 308
Registrován: 07 led 2007 15:20
Bydliště: Pardubice

Re: mrzne PC

#2 Příspěvek od meteorolog »

Dobrý den :)

pošlete ještě log z Combofix

Stáhneme na plochu, ukončíme všechna aktivní okna a spustíme ComboFix - http://download.bleepingcomputer.com/sUBs/ComboFix.exe
- Po spuštění potvrdíme podmínky užití
- Dále postupujeme dle pokynů, během aplikování ComboFixu neklikejte do zobrazujících se oken
- Po dokončení skenování, trvajícího maximálně 10 minut, by měl program vytvořit log - C:\ComboFix.txt
- ComboFix je třeba spustit pod účtem s právy administrátora
"Život je život, louka je louka, koukneš se do trávy – a vidíš brouka."

"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)

rivers2
Návštěvník
Návštěvník
Příspěvky: 178
Registrován: 10 led 2009 15:21

Re: mrzne PC

#3 Příspěvek od rivers2 »

ComboFix 10-01-29.09 - Jozo . 01. 2010 20:40:31.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1029.18.3070.2609 [GMT 1:00]
Running from: f:\rapidshare\programy\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\uninstall.exe

.
((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-30 )))))))))))))))))))))))))))))))
.

2010-01-29 20:12 . 2008-05-02 01:38 301656 ----a-w- c:\windows\system32\BtCoreIf.dll
2010-01-29 19:29 . 2007-01-23 14:44 10640 ----a-w- c:\windows\system32\drivers\LBeepKE.sys
2010-01-29 19:02 . 2010-01-29 21:43 -------- d-----w- c:\program files\IncrediMail
2010-01-29 18:37 . 2008-05-02 01:40 84496 ----a-w- c:\windows\system32\KemXML.dll
2010-01-29 18:37 . 2008-05-02 01:40 117264 ----a-w- c:\windows\system32\KemWnd.dll
2010-01-29 18:37 . 2008-05-02 01:39 145936 ----a-w- c:\windows\system32\KemUtil.dll
2010-01-29 18:37 . 2008-05-02 01:39 170512 ----a-w- c:\windows\system32\kemutb.dll
2010-01-29 18:34 . 2010-01-29 21:43 -------- d-----w- c:\program files\GameShadow
2010-01-21 09:45 . 2008-04-13 21:09 7552 ----a-w- c:\windows\system32\drivers\MSKSSRV.sys
2010-01-21 09:45 . 2008-04-13 21:09 7552 ----a-w- c:\windows\system32\dllcache\mskssrv.sys
2010-01-20 17:03 . 2010-01-24 19:54 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-01-16 19:52 . 2010-01-16 19:52 -------- d-----w- c:\program files\Uniblue
2010-01-13 19:12 . 2010-01-13 19:12 -------- d-sh--w- c:\windows\ftpcache
2010-01-13 15:16 . 2010-01-13 15:16 -------- d-----w- c:\documents and settings\LocalService\Plocha
2010-01-13 08:13 . 2009-11-21 16:03 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
2010-01-12 12:03 . 2010-01-29 21:43 -------- d-----w- c:\program files\Common Files\Logishrd
2010-01-10 23:20 . 2009-09-04 16:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2010-01-10 23:20 . 2009-09-04 16:44 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2010-01-10 23:20 . 2009-09-04 16:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2010-01-10 23:20 . 2009-09-04 16:29 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2010-01-10 23:20 . 2009-09-04 16:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2010-01-10 23:20 . 2009-09-04 16:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2010-01-10 23:20 . 2009-09-04 16:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2010-01-05 16:00 . 2010-01-05 21:37 -------- d-----w- C:\rsit
2010-01-05 15:04 . 2010-01-05 15:09 -------- d-----w- c:\program files\Microsoft Bootvis

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-30 19:12 . 2009-12-10 21:39 16608 ----a-w- c:\windows\gdrv.sys
2010-01-30 06:25 . 2009-12-27 18:06 -------- d-----w- c:\program files\Internet Download Manager
2010-01-29 22:41 . 2009-12-12 11:47 -------- d-----w- c:\program files\trend micro
2010-01-29 21:43 . 2009-12-11 09:31 -------- d-----w- c:\program files\Common Files\Logitech
2010-01-29 21:43 . 2009-12-10 21:40 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-29 21:43 . 2009-12-11 09:31 -------- d-----w- c:\program files\Logitech
2010-01-29 16:48 . 2009-12-13 13:40 -------- d-----w- c:\program files\Spyware Doctor
2010-01-21 11:23 . 2009-12-12 21:17 -------- d-----w- c:\program files\Unlocker
2010-01-13 19:20 . 2009-12-17 22:25 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-01-13 19:20 . 2009-12-17 22:25 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-01-13 19:20 . 2009-12-17 22:25 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-01-12 21:21 . 2009-12-12 19:56 -------- d-----w- c:\program files\Smarty Uninstaller Pro
2010-01-05 15:09 . 2001-10-25 12:00 78856 ----a-w- c:\windows\system32\perfc005.dat
2010-01-05 15:09 . 2001-10-25 12:00 431770 ----a-w- c:\windows\system32\perfh005.dat
2009-12-24 14:55 . 2009-12-24 14:55 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2009-12-24 14:55 . 2009-12-24 14:55 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-12-24 14:52 . 2009-12-24 14:52 -------- d-----w- c:\program files\Common Files\PCSuite
2009-12-24 14:52 . 2009-12-24 14:52 -------- d-----w- c:\program files\Common Files\Nokia
2009-12-24 14:52 . 2009-12-24 14:52 -------- d-----w- c:\program files\Nokia
2009-12-24 14:52 . 2009-12-24 14:52 -------- d-----w- c:\program files\DIFX
2009-12-24 14:52 . 2009-12-24 14:52 -------- d-----w- c:\program files\PC Connectivity Solution
2009-12-24 13:42 . 2009-12-24 13:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-24 12:11 . 2009-12-24 12:11 -------- d-----w- c:\program files\iFoxSoft
2009-12-24 12:10 . 2009-12-10 21:40 -------- d-----w- c:\program files\Common Files\InstallShield
2009-12-24 10:53 . 2009-12-24 10:53 -------- d-----w- c:\program files\Common Files\Ulead Systems
2009-12-23 23:27 . 2009-12-23 23:27 -------- d-----w- c:\program files\Common Files\ACD Systems
2009-12-23 23:27 . 2009-12-23 23:27 -------- d-----w- c:\program files\ACD Systems
2009-12-23 23:27 . 2009-12-23 23:27 10368 ----a-w- c:\windows\system32\drivers\pfc.sys
2009-12-21 19:08 . 2009-06-04 12:06 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-19 09:18 . 2009-12-19 09:18 -------- d-----w- c:\program files\Reference Assemblies
2009-12-18 17:28 . 2009-12-18 17:28 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-12-18 14:14 . 2009-12-17 22:25 794408 ----a-w- c:\windows\system32\pbsvc.exe
2009-12-18 08:05 . 2009-12-18 08:05 -------- d-----w- c:\program files\Yamicsoft
2009-12-17 20:08 . 2009-12-17 20:08 662 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2009-12-17 19:56 . 2009-12-17 19:56 -------- d-----w- c:\program files\Alcohol Soft
2009-12-17 19:52 . 2009-12-17 19:52 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-12-17 19:18 . 2009-12-17 19:18 -------- d-----w- c:\program files\PowerISO
2009-12-16 08:04 . 2009-12-16 08:04 -------- d-----w- c:\program files\IObit
2009-12-14 19:17 . 2009-12-14 19:17 -------- d-----w- c:\program files\Common Files\Common Share
2009-12-14 19:17 . 2009-12-14 19:17 -------- d-----w- c:\program files\OJOsoft
2009-12-14 19:08 . 2009-12-14 19:08 -------- d-----w- c:\program files\OO Software
2009-12-14 13:54 . 2009-12-14 13:52 -------- d-----w- c:\program files\NVIDIA Corporation
2009-12-14 13:53 . 2009-12-14 13:53 -------- d-----w- c:\program files\AGEIA Technologies
2009-12-14 13:53 . 2009-12-14 13:53 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-12-14 13:42 . 2009-12-14 13:42 -------- d-----w- c:\program files\Driver-Soft
2009-12-14 13:06 . 2009-12-14 13:06 23600 ----a-w- c:\windows\system32\drivers\TVICHW32.SYS
2009-12-13 19:05 . 2009-12-13 19:05 -------- d-----w- c:\program files\microsoft frontpage
2009-12-13 13:42 . 2009-12-13 13:40 -------- d-----w- c:\program files\Common Files\PC Tools
2009-12-13 12:38 . 2009-12-11 09:11 -------- d-----w- c:\program files\Microsoft Works
2009-12-12 23:07 . 2009-12-12 23:07 -------- d-----w- c:\program files\CCleaner
2009-12-12 22:32 . 2009-12-12 22:28 353576 ----a-w- c:\windows\system32\msvcr71.dll
2009-12-12 22:32 . 2009-12-12 22:28 29480 ----a-w- c:\windows\system32\msxml3a.dll
2009-12-12 22:32 . 2007-10-19 19:37 505128 ----a-w- c:\windows\system32\msvcp71.dll
2009-12-12 22:30 . 2009-12-12 22:29 -------- d-----w- c:\program files\CyberLink
2009-12-12 22:30 . 2009-12-12 22:30 -------- d-----w- c:\program files\Common Files\CyberLink
2009-12-12 21:50 . 2009-12-12 21:49 -------- d-----w- c:\program files\Nero
2009-12-12 21:50 . 2009-12-12 21:49 -------- d-----w- c:\program files\Common Files\Nero
2009-12-12 20:20 . 2009-12-12 20:19 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-12 20:19 . 2009-12-12 20:19 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-12-12 20:18 . 2009-12-12 20:18 -------- d-----w- c:\program files\McAfee Security Scan
2009-12-12 20:17 . 2009-12-12 20:17 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-12 20:16 . 2009-12-12 20:16 -------- d-----w- c:\program files\Java
2009-12-12 20:14 . 2009-12-12 20:12 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-12-12 20:13 . 2009-12-12 20:13 603904 ----a-w- c:\windows\system32\TUProgSt.exe
2009-12-12 20:13 . 2009-12-12 20:13 360192 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-12-12 09:51 . 2009-12-10 20:24 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-12-12 09:51 . 2009-12-10 20:24 2426 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2009-12-12 09:49 . 2009-12-10 20:25 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2009-12-12 09:07 . 2009-12-10 21:54 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-11 09:45 . 2009-12-11 09:45 0 ----a-w- c:\windows\nsreg.dat
2009-12-11 09:35 . 2009-12-11 09:35 -------- d-----w- c:\program files\Sony
2009-12-11 09:33 . 2009-12-11 09:33 127034 ------r- c:\windows\bwUnin-8.1.1.50-8876480SL.exe
2009-12-11 09:25 . 2009-12-11 09:13 164918 ----a-w- c:\windows\hpoins21.dat
2009-12-11 09:24 . 2009-12-11 09:15 -------- d-----w- c:\program files\HP
2009-12-11 09:17 . 2009-12-11 09:17 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-12-11 09:16 . 2009-12-11 09:16 -------- d-----w- c:\program files\Common Files\HP
2009-12-11 09:11 . 2009-12-11 09:11 -------- d-----w- c:\program files\MSBuild
2009-12-10 21:54 . 2009-12-10 21:54 -------- d-----w- c:\program files\Avira
2009-12-10 21:46 . 2009-12-10 21:43 -------- d-----w- c:\program files\Realtek
2009-12-10 21:43 . 2009-12-10 21:43 315392 ----a-w- c:\windows\HideWin.exe
2009-12-10 21:40 . 2009-12-10 21:40 -------- d-----w- c:\program files\Intel
2009-12-10 21:40 . 2009-12-10 21:40 -------- d-----w- c:\program files\Browser Configuration Utility
2009-12-10 21:40 . 2009-12-10 21:40 -------- d-----w- c:\program files\GIGABYTE
2009-12-10 20:22 . 2009-12-10 20:22 21812 ----a-w- c:\windows\system32\emptyregdb.dat
2009-12-10 20:21 . 2009-12-10 20:21 -------- d-----w- c:\program files\Windows Media Connect 2
2009-12-03 15:14 . 2009-12-24 13:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-03 15:13 . 2009-12-24 13:42 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-21 16:03 . 2008-04-14 06:51 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-20 19:32 . 2009-11-20 19:32 278120 ----a-w- c:\windows\system32\nvmccs.dll
2009-11-19 20:42 . 2009-12-10 21:47 592488 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-11-10 09:28 . 2009-12-13 13:41 149456 ----a-w- c:\windows\SGDetectionTool.dll
2009-11-10 09:28 . 2009-12-13 13:41 165840 ----a-w- c:\windows\PCTBDRes.dll
2009-11-10 09:28 . 2009-12-13 13:41 1640400 ----a-w- c:\windows\PCTBDCore.dll
2009-11-10 09:26 . 2009-12-13 13:41 767952 ----a-w- c:\windows\BDTSupport.dll
2009-11-09 10:20 . 2009-12-13 13:40 207792 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-11-02 13:03 . 2009-12-10 21:40 53248 ----a-w- c:\windows\system32\CSVer.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-09-10 3118512]
"IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2008-07-24 243072]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 16857600]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"PDVD8LanguageShortcut"="c:\program files\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 50472]
"BDRegion"="c:\program files\Cyberlink\Shared Files\brs.exe" [2008-05-19 91432]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-11-20 12669544]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-11-20 110184]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2009-06-04 128512]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2010-1-29 67128]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-1-29 805392]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 ----a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 05:52 1695232 ------w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"TuneUp.ProgramStatisticsSvc"=2 (0x2)
"TuneUp.Defrag"=3 (0x3)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
"Uniblue RegistryBooster 2"=c:\program files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"RemoteControl8"="c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe"
"OODefragTray"=c:\windows\system32\oodtray.exe
"PWRISOVM.EXE"=c:\program files\PowerISO\PWRISOVM.EXE
"Ulead AutoDetector"=c:\program files\Common Files\Ulead Systems\AutoDetector\Monitor.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImLc.exe"=
"b:\\hry\\hra\\Data\\ra3_1.0.game"=
"c:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [13. 12. 2009 14:40 207792]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\000.fcl [7. 10. 2008 20:31 61424]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [10. 12. 2009 23:19 108289]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [13. 12. 2009 14:41 112592]
R2 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\EnergySaver\GSvr.exe [10. 12. 2009 22:40 80392]
R2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [16. 12. 2009 9:04 305936]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [29. 1. 2010 20:29 10640]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [17. 12. 2009 20:52 721904]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [13. 12. 2009 14:40 359624]
S3 TVICHW32;TVICHW32;c:\windows\system32\drivers\TVICHW32.SYS [14. 12. 2009 14:06 23600]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2010-01-30 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-11 20:36]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.zoznam.sk/
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Prevziať cez IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: Prevziať cez IDM všetky prepojenia - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Prevziať obsah FLV cez IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
.
- - - - ORPHANS REMOVED - - - -

AddRemove-SLABCOMM - c:\windows\system32\uninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-30 20:44
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,78,31,32,7b,e2,18,09,4f,96,37,77,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,78,31,32,7b,e2,18,09,4f,96,37,77,\

[HKEY_USERS\S-1-5-21-602162358-1844823847-1801674531-1003\Software\SecuROM\License information*]
"datasecu"=hex:c2,76,ca,39,7e,34,7d,00,fc,d8,a7,d0,ed,d0,20,6c,b5,ca,fe,4d,b7,
48,ed,1a,95,ad,47,15,e9,54,86,18,f5,49,70,50,59,f0,c5,29,bc,c0,34,c4,b8,bb,\
"rkeysecu"=hex:6f,87,86,a9,0d,e5,06,9b,23,24,08,98,64,f9,fb,a2

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="FE415AC885615106FC264A69EC69265379ADD0DF64A67B521B2627082EC18165D94467EF0BBBF90BEF44240D16D1FA9A9B1CD181F1F9FA8EBC3F7B754771B5692CEFD0F60CD1DB217E2379F924BF901FFBF143D7CFA03DC9FD9B13E75F6A322A0D1BFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6171C11EC38DE3DFEBC9E127BECC74C5D575E7D6A3B9808A896EAD1782DA13007589296FC990F544947F5E7E8B78AFB40DAEC10ECC5D4DB6B576FC488EE07F468EA56F0266232AC45CBE290100557E890F59B1BB03329C6C86EFD7E1E09235E101AF4268045EB903724AA1B40358EED93F59D290435F4272D3A961D84BF478FADF75C8CAD088C2E343448B40C2D9A65E4AD1A5F0EF3E29E55202C60969A7E92C418ED1F5D34181825602AB21A1621097074AC0C0DD8D031D406AA2DC86680D5AD14FEF8D6964645C513330A27DFF37878A4661DCF9453C613D76D8D1DB23FAA9207D9DE7440068EA73ABBD6023B9EB5131CCA28BA1AAE2CCA0747ADAED35DC4F4933C35A38675332FC50FD68D205E2BA9BE51E2C79F5F120906FA5EA9E1B2BFA7DD5A0568826AD6162DE96DC0C6A4A2FAF1E72C01A0130C334B4215D039CA17538DD8FD57916C7E68E881A1A82E964C97216C0287DC2B92FD544BE9F77AE42EF14F50719BD3B89387777B9E62190EB9653B338890D73F0375A0351A898874C7D5D5D055F2AF3FE6A659F2B2A28D97639F32060863579A9C77B29686028B211021D2DB432F4EA5A9CF9578D030D4F6A4517C1E6CDC67BA05B693783473714793CB816779B81CC4F1DFB48D10667C9FBDDF952FC4EBD6D244BB4D574D8269F5C2229D5D5908C9A6B907462AACB358BBD0FDFB59C59639C7C55FF0A31CE7E7EFF343661B692BCD8EE04BD8B7039C7EA965B6B137C6F366365BD0114393F1232DDF23A2F2D2C561EE29038417983948F968E73ED34431776C3893C60F47021A59A48A1AACE38D8172395E621B91B1D3F128C32B2FDE0E4CEAF5FCAB54718C0BD34393990010CBEDF29BDA8F093B48838CD64E88BE585E0AE9103A62D26D1C7BB0212F719B6AE0AC03BDCDAE1E824FFDF50E63E8681A8A94D366470BC1BDCB3237879F76A22F3D07E67262E4887C2D2C8FC7AF610930109AC7BEF84F47074EBBE2257F812A3AE70B17EF145B6ADEDD3D7064B40DF1497E8817C0755B04106A69E109B76EBB0FFA083FD132BF5C0471A3DFA6498CE43BF9124879B75D85C8F54D1AAA0A1FD6D2249340156344E7EB0A945EB4957F9B7C3AAE16588D0A5340E0C1226209F76CCF2788AF1D9F1F8DB8DF0A1A1D198FC1A80D9AEFB29B19E42C2CE144ED9DE06274D882D42F3488BFB13D447BCCA565F6805153F740D645A8E4EB0D02ED03461451A462"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(856)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
Completion time: 2010-01-30 20:45:45
ComboFix-quarantined-files.txt 2010-01-30 19:45

Pre-Run: 7 417 249 792
Post-Run: 7 539 478 528

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - A7F6B7C7C21A5930FC22C8BB70F58E6E

meteorolog
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 308
Registrován: 07 led 2007 15:20
Bydliště: Pardubice

Re: mrzne PC

#4 Příspěvek od meteorolog »

log vypadá v pořádku, tak to trochu pročistíme :)

použijte http://sweb.cz/Marinus/T-Cleaner.exe - pro potvrzení stiskněte vždy klávesu A nebo Enter (utilita může být označena antivirem jako vir - po použití ji smažte)

potom CCleaner - položky Čistič a Registry - čištění opakujte do odstranění všech problémů

a nakonec ATF Cleaner - http://www.atribune.org/ccount/click.php?id=1:

po spuštění staženého souboru se objeví okno:

Obrázek

zatrhněte Select All, klikněte na Empty Selected a Exit

stejným způsobem vymažte případně cache Firefoxu a Opery :-)

restartujte PC
"Život je život, louka je louka, koukneš se do trávy – a vidíš brouka."

"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)

rivers2
Návštěvník
Návštěvník
Příspěvky: 178
Registrován: 10 led 2009 15:21

Re: mrzne PC

#5 Příspěvek od rivers2 »

O.K. Ďakujem

meteorolog
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 308
Registrován: 07 led 2007 15:20
Bydliště: Pardubice

Re: mrzne PC

#6 Příspěvek od meteorolog »

nemáte zač :-)
"Život je život, louka je louka, koukneš se do trávy – a vidíš brouka."

"Neodpovídej tupci na jeho tupost, aby ses mu sám nezačal podobat. Odpověz tupci na jeho tupost, aby si přestal moudrý připadat...."
(Přísloví krále Šalomouna)

Odpovědět