Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Zpomalení PC při startupu, winesm32.exe

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
zaxic
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 07 bře 2010 15:14

Zpomalení PC při startupu, winesm32.exe

#1 Příspěvek od zaxic »

Zdravim,
27.2 sem pracoval normálně na svém PC, vše bylo dobré, pak najednou mi Avast hlásil viry ve složce C:\WINDOWS\system32\drivers ..
Do truhly sem přesunul asi 75 souborů s příponou .sys a jeden soubor fjhdyfhsn.bat, tak sem pak ještě projel PC antispywarem a avastem a už nic..
Obrázek
Pak se to sáme stalo 3.3 to sem přesunul do truhly jen 7 souboru jeden z nich byl s příponou .tmp.
Když sem další den zapnul počítač tak se mi zasekl při startu asi na 10 minut a potom se vše rozjelo..Avast mi hned našel vir winesm32.exe ve složce Po spuštění, tak sem ho přesunul to truhly projel sem pak počítač ještě MBAM a našel našel nějakou havět tak sem jí dal do karantény.
Obrázek
Jenže PC se pořád při startu zasekává a já nevim co s tim a nejde mi HAMACHI, a zvuk, i nějaká ta hra a třeba když zapojim mobil do PC tak se nic neděje.( takže budu asi muset přeinstalovat ovladače)

Zde log z RSIT
Logfile of random's system information tool 1.06 (written by random/random)
Run by Jakub Žert at 2010-03-07 15:34:48
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 2 GB (2%) free of 100 GB
Total RAM: 3327 MB (69% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:34:57, on 7.3.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
D:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
D:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Rainlendar2\Rainlendar2.exe
D:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files\GIGABYTE\Gamer HUD\HUD.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Xfire\Xfire.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\Alwil Software\Avast4\ashChest.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Jakub Žert\Plocha\RSIT.exe
C:\Program Files\trend micro\Jakub Žert.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O1 - Hosts: 216.107.250.194 nprotect.lineage2.com
O1 - Hosts: 81.0.254.162 L2authd.Lineage2.com
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - D:\Program Files\FlashGet\jccatch.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Rainlendar2] D:\Program Files\Rainlendar2\Rainlendar2.exe
O4 - HKCU\..\Run: [QIP2005] D:\Program Files\QIP\qip.exe
O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "D:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ashDisp.lnk = C:\Program Files\Alwil Software\Avast4\ashDisp.exe
O4 - Startup: GIGABYTE Gamer HUD.lnk = C:\Program Files\GIGABYTE\Gamer HUD\HUD.exe
O4 - Startup: HD ADeck.lnk = C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
O4 - Startup: SpywareTerminatorShield.lnk = C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
O4 - Startup: Xfire.lnk = D:\Program Files\Xfire\Xfire.exe
O8 - Extra context menu item: &Stáhnout &vše FlashGetem - D:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Stáhnout FlashGetem - D:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: Download all with Free Download Manager - file://D:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://D:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://D:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://D:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NMSAccessU - Unknown owner - D:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - D:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 10033 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2009-03-04 1194496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}]
FGCatchUrl - D:\Program Files\FlashGet\jccatch.dll [2007-06-29 94308]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-17 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-03-17 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler lišta - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2009-03-04 1194496]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe [2008-08-15 30003200]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-03-24 13524992]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-03-24 86016]
"ISUSPM Startup"=C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe [2006-05-16 213936]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2006-05-16 86960]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-11-25 81000]
"CHotkey"=C:\WINDOWS\mHotkey.exe [2003-09-16 514048]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-17 148888]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"Monitor"=C:\WINDOWS\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-05-16 213936]
"MSConfig"=C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe [2008-04-14 171008]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2009-07-17 2173440]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"QuickTime Task"=D:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-01-07 1394000]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2010-01-07 429392]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2008-04-23 22058792]
"Rainlendar2"=D:\Program Files\Rainlendar2\Rainlendar2.exe [2009-08-22 5148672]
"QIP2005"=D:\Program Files\QIP\qip.exe [2009-08-13 3276288]
"Sony Ericsson PC Suite"=D:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe [2009-09-24 434176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
D:\Program Files\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RGSC]
D:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe [2009-07-24 306088]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
D:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe [2006-11-24 487424]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
D:\Program Files\Steam\Steam.exe [2009-08-24 1217784]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\READER~1.0\Reader\READER~1.EXE [2008-01-11 39792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Synchronizer.lnk]
C:\PROGRA~1\Adobe\READER~1.0\Reader\ADOBEC~1.EXE [2007-05-11 738968]

C:\Documents and Settings\Jakub Žert\Nabídka Start\Programy\Po spuštění
ashDisp.lnk - C:\Program Files\Alwil Software\Avast4\ashDisp.exe
GIGABYTE Gamer HUD.lnk - C:\Program Files\GIGABYTE\Gamer HUD\HUD.exe
HD ADeck.lnk - C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
SpywareTerminatorShield.lnk - C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
Xfire.lnk - D:\Program Files\Xfire\Xfire.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=
scecli
scecli

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=177
"DisableLocalUserRun"=1
"DisableLocalUserRunOnce"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"DisableLocalMachineRun"=
"DisableLocalMachineRunOnce"=
"DisableLocalUserRun"=
"DisableLocalUserRunOnce"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\QIP\qip.exe"="D:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"D:\Program Files\TmNationsForever\TmForever.exe"="D:\Program Files\TmNationsForever\TmForever.exe:*:Enabled:TmForever"
"D:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe"="D:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"D:\Program Files\TmUnitedForever\TmForever.exe"="D:\Program Files\TmUnitedForever\TmForever.exe:*:Enabled:TmForever"
"C:\Documents and Settings\Jakub Žert\temp\TeamViewer\Version4\TeamViewer.exe"="C:\Documents and Settings\Jakub Žert\temp\TeamViewer\Version4\TeamViewer.exe:*:Enabled:TeamViewer Remote Control Application"
"D:\Program Files\Rockstar Games\GTA San Andreas\gta_sa.exe"="D:\Program Files\Rockstar Games\GTA San Andreas\gta_sa.exe:*:Enabled:Play GTA San Andreas"
"D:\Program Files\Rockstar Games\GTA San Andreas\samp.exe"="D:\Program Files\Rockstar Games\GTA San Andreas\samp.exe:*:Enabled:San Andreas Multiplayer"
"D:\Program Files\HLSW\hlsw.exe"="D:\Program Files\HLSW\hlsw.exe:*:Enabled:hlsw"
"D:\Program Files\ICQ6.5\ICQ.exe"="D:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Program Files\Blitzkrieg 2\EXE\bin\GAME.EXE"="D:\Program Files\Blitzkrieg 2\EXE\bin\GAME.EXE:*:Enabled:Blitzkrieg 2"
"D:\Program Files\FlashGet\flashget.exe"="D:\Program Files\FlashGet\flashget.exe:*:Enabled:Flashget"
"C:\Documents and Settings\Jakub Žert\Plocha\l2phx-dist\l2phx.exe"="C:\Documents and Settings\Jakub Žert\Plocha\l2phx-dist\l2phx.exe:*:Enabled:l2phx"
"C:\Documents and Settings\Jakub Žert\Plocha\l2_phx(2)\infinita\l2phx.exe"="C:\Documents and Settings\Jakub Žert\Plocha\l2_phx(2)\infinita\l2phx.exe:*:Enabled:l2phx"
"C:\Documents and Settings\Jakub Žert\Plocha\l2 hack\l2phx english\l2phx.exe"="C:\Documents and Settings\Jakub Žert\Plocha\l2 hack\l2phx english\l2phx.exe:*:Enabled:l2phx"
"D:\Program Files\Techland\Xpand Rally\xpandrally.exe"="D:\Program Files\Techland\Xpand Rally\xpandrally.exe:*:Enabled:XpandRally"
"D:\Program Files\Lineage II CT2.3\LineageII.exe"="D:\Program Files\Lineage II CT2.3\LineageII.exe:*:Enabled:Play Lineage II PTS"
"D:\Program Files\Counter-Strike Source\hl2.exe"="D:\Program Files\Counter-Strike Source\hl2.exe:*:Enabled:hl2"
"D:\Program Files\Valvesoftware\The Orange Box\team fortress 2\hl2.exe"="D:\Program Files\Valvesoftware\The Orange Box\team fortress 2\hl2.exe:*:Enabled:hl2"
"D:\Program Files\Counter-Strike\hl.exe"="D:\Program Files\Counter-Strike\hl.exe:*:Enabled:Half-Life Launcher"
"D:\Program Files\Counter-Strike\hltv.exe"="D:\Program Files\Counter-Strike\hltv.exe:*:Enabled:HLTV Launcher"
"C:\Program Files\Reallusion\CrazyTalk for Skype\CT4Skype.exe"="C:\Program Files\Reallusion\CrazyTalk for Skype\CT4Skype.exe:*:Enabled:CrazyTalk"
"D:\Program Files\Free Download Manager\fdm.exe"="D:\Program Files\Free Download Manager\fdm.exe:*:Enabled:fdm"
"D:\Program Files\Air Conflicts\ac.exe"="D:\Program Files\Air Conflicts\ac.exe:*:Enabled:ac"
"D:\Program Files\Xfire\Xfire.exe"="D:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire"
"D:\Program Files\Firefly Studios\Stronghold Legends\StrongholdLegends.exe"="D:\Program Files\Firefly Studios\Stronghold Legends\StrongholdLegends.exe:*:Enabled:Stronghold Legends"
"D:\Program Files\Flagship Studios\Hellgate London\Launcher.exe"="D:\Program Files\Flagship Studios\Hellgate London\Launcher.exe:*:Enabled:Hellgate: London"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"D:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe"="D:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"D:\Program Files\Ubisoft\Far Cry 2\bin\FarCry2.exe"="D:\Program Files\Ubisoft\Far Cry 2\bin\FarCry2.exe:*:Enabled:Far Cry 2"
"D:\Program Files\Ubisoft\Far Cry 2\bin\FC2Launcher.exe"="D:\Program Files\Ubisoft\Far Cry 2\bin\FC2Launcher.exe:*:Enabled:Far Cry 2 Updater"
"D:\Program Files\Ubisoft\Far Cry 2\bin\FC2Editor.exe"="D:\Program Files\Ubisoft\Far Cry 2\bin\FC2Editor.exe:*:Enabled:Editor"
"D:\Program Files\Ubisoft\Crytek\Far Cry\Bin32\FarCry.exe"="D:\Program Files\Ubisoft\Crytek\Far Cry\Bin32\FarCry.exe:*:Enabled:Far Cry"
"D:\Program Files\Activision\Prototype\prototypef.exe"="D:\Program Files\Activision\Prototype\prototypef.exe:*:Enabled:Prototype(TM)"
"D:\Program Files\Team17\Worms 2\Frontend.exe"="D:\Program Files\Team17\Worms 2\Frontend.exe:*:Enabled:Worms 2 Frontend"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"D:\Program Files\Xfire\dppm_source.exe"="D:\Program Files\Xfire\dppm_source.exe:*:Enabled:Dyyno P2P Source Application"
"D:\Program Files\Hamachi\hamachi.exe"="D:\Program Files\Hamachi\hamachi.exe:*:Enabled:Hamachi"
"D:\Program Files\Activision\Call of Duty - World at War\CoDWaW_LANFixed.exe"="D:\Program Files\Activision\Call of Duty - World at War\CoDWaW_LANFixed.exe:*:Enabled:Call of Duty(R): World at War Campaign/Coop"
"D:\Program Files\Team17\Worms World Party\wwp.exe"="D:\Program Files\Team17\Worms World Party\wwp.exe:*:Enabled:Worms World Party"
"C:\Documents and Settings\Jakub Žert\Plocha\Worms World Party\WWP\wwp.exe"="C:\Documents and Settings\Jakub Žert\Plocha\Worms World Party\WWP\wwp.exe:*:Enabled:Worms World Party"
"D:\Program Files\Worms World Party\WWP\wwp.exe"="D:\Program Files\Worms World Party\WWP\wwp.exe:*:Enabled:Worms World Party"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"D:\Program Files\Activision\Call of Duty - World at War\CoDWaW_LANFixed1.4.exe"="D:\Program Files\Activision\Call of Duty - World at War\CoDWaW_LANFixed1.4.exe:*:Enabled:Call of Duty(R): World at War Campaign/Coop"
"D:\Program Files\left 4 Dead\left4dead.exe"="D:\Program Files\left 4 Dead\left4dead.exe:*:Enabled:left4dead"
"C:\Documents and Settings\Jakub Žert\Plocha\l4d_launcher_oger_v1.3_32.exe"="C:\Documents and Settings\Jakub Žert\Plocha\l4d_launcher_oger_v1.3_32.exe:*:Enabled:l4d_launcher_oger_v1.3_32"
"D:\Program Files\Garena\Garena.exe"="D:\Program Files\Garena\Garena.exe:*:Enabled:Garena"
"D:\Program Files\Killing Floor\System\KillingFloor.exe"="D:\Program Files\Killing Floor\System\KillingFloor.exe:*:Enabled:KillingFloor"
"D:\Program Files\Killing Floor LAN\System\KillingFloor.exe"="D:\Program Files\Killing Floor LAN\System\KillingFloor.exe:*:Enabled:KillingFloor"
"D:\SOUBORY\Demigod\Demigod\RoTaM.De\game\bin\Demigod.exe"="D:\SOUBORY\Demigod\Demigod\RoTaM.De\game\bin\Demigod.exe:*:Enabled:Demigod Application"
"D:\Program Files\Activision\Call of Duty - World at War\CoDWaW-lanfix 1.5.exe"="D:\Program Files\Activision\Call of Duty - World at War\CoDWaW-lanfix 1.5.exe:*:Enabled:Call of Duty(R): World at War Campaign/Coop"
"D:\Program Files\jazz2\Jazz2.exe"="D:\Program Files\jazz2\Jazz2.exe:*:Enabled:Jazz2"
"C:\Documents and Settings\Jakub Žert\Local Settings\Temp\Rar$EX00.157\jazz2\Jazz2.exe"="C:\Documents and Settings\Jakub Žert\Local Settings\Temp\Rar$EX00.157\jazz2\Jazz2.exe:*:Enabled:Jazz Jackrabbit 2"
"D:\Program Files\Activision\Call of Duty - World at War\server.exe"="D:\Program Files\Activision\Call of Duty - World at War\server.exe:*:Enabled:Call of Duty(R): World at War Multiplayer"
"D:\Program Files\Activision\Call of Duty - World at War\CoD 5 1.5 Privat Client Patch.exe"="D:\Program Files\Activision\Call of Duty - World at War\CoD 5 1.5 Privat Client Patch.exe:*:Enabled:CoD 5 1.5 Privat Client Patch"
"D:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe"="D:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:*:Enabled:Rockstar Games Social Club"
"C:\Program Files\Microsoft Games for Windows - LIVE\Client\GFWLive.exe"="C:\Program Files\Microsoft Games for Windows - LIVE\Client\GFWLive.exe:*:Enabled:Games for Windows - LIVE"
"D:\Program Files\Rockstar Games\Grand Theft Auto IV\GTAIV.exe"="D:\Program Files\Rockstar Games\Grand Theft Auto IV\GTAIV.exe:*:Enabled:GTAIV"
"D:\Program Files\Wolfenstein\Wolf2MP.exe"="D:\Program Files\Wolfenstein\Wolf2MP.exe:*:Enabled:Wolfenstein MP"
"D:\Program Files\Wolfenstein\Wolf2MPLite.exe"="D:\Program Files\Wolfenstein\Wolf2MPLite.exe:*:Enabled:Wolfenstein MP"
"D:\Program Files\n2n Gui\n2ngui.exe"="D:\Program Files\n2n Gui\n2ngui.exe:*:Enabled:n2n Gui"
"D:\Program Files\Wippien\Wippien.exe"="D:\Program Files\Wippien\Wippien.exe:*:Enabled:Wippien"
"D:\Program Files\LAN On Internet\LANOnInternet.exe"="D:\Program Files\LAN On Internet\LANOnInternet.exe:*:Enabled:lanoninternet.exe"
"C:\Documents and Settings\Jakub Žert\Local Settings\Temp\Rar$EX00.875\lanoverip-server-0.1.2-win32\lanoipserveur.exe"="C:\Documents and Settings\Jakub Žert\Local Settings\Temp\Rar$EX00.875\lanoverip-server-0.1.2-win32\lanoipserveur.exe:*:Enabled:lanoipserveur"
"D:\Program Files\Call of Duty\CoDMP.exe"="D:\Program Files\Call of Duty\CoDMP.exe:*:Enabled:CoDMP"
"D:\Program Files\Activision\Call of Duty - World at War\sp_tool.exe"="D:\Program Files\Activision\Call of Duty - World at War\sp_tool.exe:*:Enabled:Call of Duty(R): World at War Campaign/Coop"
"D:\Program Files\Touchstone\Turok\Binaries\TurokGame.exe"="D:\Program Files\Touchstone\Turok\Binaries\TurokGame.exe:*:Enabled:Turok"
"D:\Program Files\Activision\Wolfenstein\MP\Wolf2MP.exe"="D:\Program Files\Activision\Wolfenstein\MP\Wolf2MP.exe:*:Enabled:Wolfenstein(TM) "
"D:\Program Files\Activision\Wolfenstein\MP\Wolf2MPLite.exe"="D:\Program Files\Activision\Wolfenstein\MP\Wolf2MPLite.exe:*:Enabled:Wolfenstein(TM) "
"D:\Program Files\Bethesda Softworks\Fallout 3\Fallout3.exe"="D:\Program Files\Bethesda Softworks\Fallout 3\Fallout3.exe:*:Disabled:Fallout3"
"D:\Program Files\Ubisoft\Tom Clancy's H.A.W.X\HAWX.exe"="D:\Program Files\Ubisoft\Tom Clancy's H.A.W.X\HAWX.exe:*:Enabled:Tom Clancy's H.A.W.X"
"D:\Program Files\Ubisoft\Tom Clancy's H.A.W.X\HAWX_dx10.exe"="D:\Program Files\Ubisoft\Tom Clancy's H.A.W.X\HAWX_dx10.exe:*:Enabled:Tom Clancy's H.A.W.X"
"D:\Program Files\Codemasters\GRID\GRID.exe"="D:\Program Files\Codemasters\GRID\GRID.exe:*:Enabled:GRID Executable"
"D:\Program Files\Codemasters\FUEL\FUEL.exe"="D:\Program Files\Codemasters\FUEL\FUEL.exe:*:Enabled:FUEL"
"D:\Program Files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe"="D:\Program Files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. - Shadow of Chernobyl (CLI)"
"D:\Program Files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe"="D:\Program Files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. - Shadow of Chernobyl (SRV)"
"D:\Program Files\Activision\Call of Duty - World at War\CoDWaW.exe"="D:\Program Files\Activision\Call of Duty - World at War\CoDWaW.exe:*:Enabled:Call of Duty(R) - World at War(TM) "
"D:\Program Files\Activision\Call of Duty - World at War\CoDWaWmp.exe"="D:\Program Files\Activision\Call of Duty - World at War\CoDWaWmp.exe:*:Enabled:Call of Duty(R) - World at War(TM) "
"D:\Program Files\Activision\Call of Duty - World at War\CodWaw_LANFixed 1.6.exe"="D:\Program Files\Activision\Call of Duty - World at War\CodWaw_LANFixed 1.6.exe:*:Enabled:Call of Duty(R): World at War Campaign/Coop"
"D:\Program Files\Miranda IM\miranda32.exe"="D:\Program Files\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"C:\games\Guitar Hero III\GH3.exe"="C:\games\Guitar Hero III\GH3.exe:*:Enabled:Guitar Hero III"
"D:\Program Files\Firefly Studios\Stronghold Crusader\Stronghold Crusader.exe"="D:\Program Files\Firefly Studios\Stronghold Crusader\Stronghold Crusader.exe:*:Enabled:Stronghold Crusader"
"D:\SOUBORY\Worms Armageddon - New Edition\wa.exe"="D:\SOUBORY\Worms Armageddon - New Edition\wa.exe:*:Enabled:Worms Armageddon"
"D:\Program Files\Worms Armageddon - New Edition\wa.exe"="D:\Program Files\Worms Armageddon - New Edition\wa.exe:*:Enabled:Worms Armageddon"
"C:\WINDOWS\Downloaded Program Files\ijjiOptimizer.exe"="C:\WINDOWS\Downloaded Program Files\ijjiOptimizer.exe:*:Enabled:ijjiOptimizer.exe"
"D:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp-cracked.exe"="D:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp-cracked.exe:*:Enabled:iw3mp-cracked"
"D:\Program Files\2K Games\Gearbox Software\Borderlands\Binaries\Borderlands.exe"="D:\Program Files\2K Games\Gearbox Software\Borderlands\Binaries\Borderlands.exe:*:Enabled:Borderlands"
"D:\Program Files\left 4 dead 2\left4dead2.exe"="D:\Program Files\left 4 dead 2\left4dead2.exe:*:Enabled:left4dead2"
"D:\Program Files\left 4 dead 2\srcds.exe"="D:\Program Files\left 4 dead 2\srcds.exe:*:Enabled:srcds"
"D:\Program Files\[PSY] Garrys Mod 11(1.o.o.5)\hl2.exe"="D:\Program Files\[PSY] Garrys Mod 11(1.o.o.5)\hl2.exe:*:Enabled:hl2"
"D:\Program Files\PBX Telecom\PBX TV\pbxtv.exe"="D:\Program Files\PBX Telecom\PBX TV\pbxtv.exe:*:Enabled:pbxtv"
"D:\Program Files\Heroes of Newerth\hon.exe"="D:\Program Files\Heroes of Newerth\hon.exe:*:Enabled:Heroes of Newerth"
"D:\Program Files\EA Games\Mirror's Edge\Binaries\MirrorsEdge.exe"="D:\Program Files\EA Games\Mirror's Edge\Binaries\MirrorsEdge.exe:*:Enabled:Mirror's Edge™"
"C:\Program Files\Java\jre6\launch4j-tmp\frd.exe"="C:\Program Files\Java\jre6\launch4j-tmp\frd.exe:*:Enabled:Java(TM) Platform SE binary"
"D:\Program Files\Electronic Arts\Dead Space\Dead Space.exe"="D:\Program Files\Electronic Arts\Dead Space\Dead Space.exe:*:Enabled:Dead Space ™"
"D:\SOUBORY\Demigod\game\bin\Demigod.exe"="D:\SOUBORY\Demigod\game\bin\Demigod.exe:*:Enabled:Demigod.exe"
"D:\Program Files\ICQ7.0\ICQ.exe"="D:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"D:\Program Files\ICQ7.0\aolload.exe"="D:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Program Files\ICQ7.0\ICQ.exe"="D:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"D:\Program Files\ICQ7.0\aolload.exe"="D:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"

======List of files/folders created in the last 1 months======

2010-03-07 03:46:48 ----D---- C:\rsit
2010-03-07 02:49:53 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-03-04 17:21:57 ----SHD---- C:\WINDOWS\CSC
2010-03-04 17:00:43 ----D---- C:\Documents and Settings\Jakub Žert\Data aplikací\Malwarebytes
2010-03-04 17:00:38 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-03-04 17:00:37 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-02-28 13:41:18 ----D---- C:\Program Files\Common Files\DirectX
2010-02-28 12:37:18 ----D---- C:\Program Files\Common Files\Akamai
2010-02-26 16:43:34 ----D---- C:\Documents and Settings\All Users\Data aplikací\id Software
2010-02-21 22:51:49 ----D---- C:\Documents and Settings\Jakub Žert\Data aplikací\LolClient.F24C99354F615F3BAB18AE7B93E3F9B9E8784FA6.1
2010-02-21 21:33:10 ----A---- C:\WINDOWS\tv_viewer.ini
2010-02-21 21:31:38 ----D---- C:\CZD_Config
2010-02-21 21:29:37 ----D---- C:\Documents and Settings\Jakub Žert\Data aplikací\MMToolz
2010-02-21 18:20:41 ----D---- C:\Program Files\Common Files\Adobe AIR
2010-02-19 21:04:24 ----D---- C:\Documents and Settings\Jakub Žert\Data aplikací\Broken Rules
2010-02-14 05:06:27 ----D---- C:\Documents and Settings\All Users\Data aplikací\Chit Chat For FaceBook
2010-02-11 04:16:10 ----A---- C:\WINDOWS\system32\xfcodec.dll
2010-02-09 22:23:27 ----D---- C:\Documents and Settings\Jakub Žert\Data aplikací\TS3Client
2010-02-09 15:06:21 ----D---- C:\Documents and Settings\Jakub Žert\Data aplikací\Mikrotik

======List of files/folders modified in the last 1 months======

2010-03-07 15:34:49 ----D---- C:\Program Files\trend micro
2010-03-07 15:17:30 ----D---- C:\WINDOWS\Prefetch
2010-03-07 11:36:42 ----D---- C:\WINDOWS\Temp
2010-03-07 04:57:26 ----D---- C:\Program Files\Mozilla Firefox
2010-03-07 04:57:14 ----D---- C:\WINDOWS
2010-03-07 04:56:23 ----SHD---- C:\WINDOWS\Installer
2010-03-07 04:55:52 ----SHD---- C:\Config.Msi
2010-03-07 04:55:27 ----D---- C:\Program Files\Common Files\Adobe
2010-03-07 04:55:27 ----D---- C:\Program Files\Common Files
2010-03-07 04:53:02 ----D---- C:\Documents and Settings\Jakub Žert\Data aplikací\Adobe
2010-03-07 04:52:04 ----D---- C:\Program Files\Adobe
2010-03-07 04:51:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-03-07 04:44:10 ----D---- C:\Documents and Settings\Jakub Žert\Data aplikací\Spyware Terminator
2010-03-07 04:41:49 ----D---- C:\Program Files\NCSoft
2010-03-07 04:40:46 ----D---- C:\Program Files\Sony Online Entertainment
2010-03-07 04:40:20 ----D---- C:\Program Files\Screaming Bee
2010-03-07 04:00:07 ----D---- C:\Program Files\Spyware Terminator
2010-03-07 03:12:50 ----D---- C:\Documents and Settings\Jakub Žert\Data aplikací\Skype
2010-03-05 18:32:57 ----SHD---- C:\RECYCLER
2010-03-05 16:49:20 ----A---- C:\WINDOWS\win.ini
2010-03-05 02:20:41 ----D---- C:\WINDOWS\system32\CatRoot2
2010-03-05 01:26:40 ----D---- C:\Documents and Settings\Jakub Žert\Data aplikací\Hamachi
2010-03-05 01:26:19 ----D---- C:\temp
2010-03-05 01:24:16 ----D---- C:\WINDOWS\system32\drivers
2010-03-05 00:58:36 ----RSH---- C:\boot.ini
2010-03-05 00:58:36 ----A---- C:\WINDOWS\system.ini
2010-03-05 00:24:22 ----D---- C:\Documents and Settings\Jakub Žert\Data aplikací\skypePM
2010-03-04 23:57:07 ----D---- C:\WINDOWS\My Video Downloader
2010-03-04 23:57:07 ----D---- C:\WINDOWS\addins
2010-03-04 22:11:11 ----D---- C:\Downloads
2010-03-04 18:23:22 ----D---- C:\WINDOWS\system32
2010-03-04 17:56:02 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-04 17:41:37 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-03-04 17:00:37 ----RD---- C:\Program Files
2010-03-03 20:00:43 ----D---- C:\Documents and Settings\Jakub Žert\Data aplikací\ICQ
2010-03-03 18:28:30 ----D---- C:\WINDOWS\WinSxS
2010-03-03 16:13:50 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-03-02 20:33:34 ----D---- C:\Documents and Settings\Jakub Žert\Data aplikací\Free Download Manager
2010-03-01 00:45:25 ----D---- C:\DVDVideoSoft
2010-02-28 22:13:28 ----D---- C:\Documents and Settings
2010-02-28 03:14:06 ----D---- C:\Program Files\WinClamAVShield
2010-02-28 01:46:31 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2010-02-27 23:37:34 ----D---- C:\Documents and Settings\Jakub Žert\Data aplikací\vlc
2010-02-27 23:06:52 ----D---- C:\Documents and Settings\Jakub Žert\Data aplikací\dvdcss
2010-02-27 01:38:28 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2010-02-27 01:29:26 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-26 20:21:10 ----HD---- C:\Program Files\InstallShield Installation Information
2010-02-26 16:43:35 ----A---- C:\WINDOWS\system32\PnkBstrA.exe
2010-02-26 16:43:35 ----A---- C:\WINDOWS\system32\pbsvc.exe
2010-02-22 23:11:47 ----D---- C:\Documents and Settings\Jakub Žert\Data aplikací\HLSW
2010-02-21 18:21:19 ----HD---- C:\WINDOWS\inf
2010-02-21 18:21:19 ----D---- C:\WINDOWS\system32\DirectX

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
R1 AmdPPM;Ovladač procesoru HwPState AMD; C:\WINDOWS\system32\DRIVERS\AmdPPM.sys [2007-04-16 33792]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2004-09-03 54368]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 Tcpip6;Ovladač protokolu Microsoft IPv6; C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2008-04-13 225664]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.3.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2009-03-04 20747]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-11-25 94160]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 monfilt;monfilt; C:\WINDOWS\system32\drivers\monfilt.sys [2008-02-14 1389056]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-15 5810]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-03-24 6547872]
R3 NVR0Dev;NVR0Dev; \??\C:\WINDOWS\nvoclock.sys []
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-07-01 108800]
R3 SCREAMINGBDRIVER;Screaming Bee Audio; C:\WINDOWS\system32\drivers\ScreamingBAudio.sys [2009-11-26 34384]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\WINDOWS\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
R3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-13 12288]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\WINDOWS\system32\drivers\viahduaa.sys [2008-07-25 845184]
S3 aaj6h2ai;aaj6h2ai; C:\WINDOWS\system32\drivers\aaj6h2ai.sys []
S3 npkcrypt;npkcrypt; \??\D:\Program Files\Lineage II\system\npkcrypt.sys []
S3 npkycryp;npkycryp; \??\D:\Program Files\Lineage II\system\npkycryp.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 6to4;Pomocná služba protokolu IPv6; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 Akamai;Akamai NetSession Interface; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-03-17 152984]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2009-07-20 935208]
R2 NMSAccessU;NMSAccessU; D:\Program Files\CDBurnerXP\NMSAccessU.exe [2009-07-13 71096]
R2 nTuneService;nTune Service; C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe [2007-09-04 131072]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-03-24 155716]
R2 OMSI download service;Sony Ericsson OMSI download service; D:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2010-02-26 75064]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2010-02-28 215104]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2009-07-17 487424]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MSSQLServerADHelper;MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [2002-12-17 66112]
S3 npggsvc;nProtect GameGuard Service; C:\WINDOWS\system32\GameMon.des [2009-07-22 3240876]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2003-04-04 77824]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Zpomalení PC při startupu, winesm32.exe

#2 Příspěvek od Caroprd111 »

Zdravím :)

Na logu se pracuje, prosím o strpení.
Obrázek

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Zpomalení PC při startupu, winesm32.exe

#3 Příspěvek od Caroprd111 »

Zazálohujte si důležitá data :!:


Obrázek Můžete mi sem vložit výpis všech nakažených souborů :???:



Obrázek Stáhněte a uložte, nejlépe na plochu http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Obrázek Vypněte všechny rezidentní bezpečnostní programy - firewally, antiviry, antispywary

Obrázek Spusťte aplikaci pod účtem s oprávněním Administrátora (Správce), ihned po startu se zobrází stránka s licenčnímy podmínkami, pokračujte stisknutím tlačítka "Ano"

Obrázek Dále postupujte dle pokynů, během scanu nespouštějte jiné aplikace a neklikejte do zobrazujícího se okna :!:

Obrázek Scan by měl trvat okolo 5 - 10 minut, po dokončení Combofix zobrazí log C:\ComboFix.txt , který sem vložte.

Obrázek Během skenování může být počítač restartován.
Obrázek

zaxic
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 07 bře 2010 15:14

Re: Zpomalení PC při startupu, winesm32.exe

#4 Příspěvek od zaxic »

zde je seznam infikovaných souborů
Obrázek
jdu na ten ComboFix

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Zpomalení PC při startupu, winesm32.exe

#5 Příspěvek od Caroprd111 »

OK :)
Obrázek

zaxic
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 07 bře 2010 15:14

Re: Zpomalení PC při startupu, winesm32.exe

#6 Příspěvek od zaxic »

zde je ten log

ComboFix 10-03-06.07 - Jakub Žert 07.03.2010 16:22:40.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3327.2737 [GMT 1:00]
Spuštěný z: c:\documents and settings\Jakub Žert\Plocha\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100307-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Data aplikací\hpe6A.dll
c:\documents and settings\All Users\Data aplikací\hpeAE.dll
c:\documents and settings\All Users\Data aplikací\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Data aplikací\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Jakub ¦ert\Dokumenty\cc_20090608_171247.reg
c:\documents and settings\Jakub ¦ert\Dokumenty\cc_20090711_152804.reg
c:\documents and settings\Jakub ¦ert\Dokumenty\cc_20090716_221109.reg
c:\documents and settings\Jakub ¦ert\Dokumenty\cc_20090803_211041.reg
c:\documents and settings\Jakub ¦ert\Dokumenty\cc_20090830_021204.reg
c:\documents and settings\Jakub ¦ert\Dokumenty\cc_20091028_224721.reg
c:\documents and settings\Jakub ¦ert\Dokumenty\cc_20091208_155707.reg
c:\documents and settings\Jakub ¦ert\Dokumenty\cc_20100207_000502.reg
c:\documents and settings\Jakub ¦ert\Dokumenty\cc_20100214_035015.reg
c:\documents and settings\Jakub ¦ert\Dokumenty\cc_20100214_040332.reg
c:\documents and settings\Jakub ¦ert\Dokumenty\cc_20100304_174220.reg
c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\INSTALL.LOG
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\program files\WinPCap\Uninstall.exe
C:\STF1A1.tmp
c:\windows\f96ac0e5-19d2-42c5-8f68-eb7a99861769.ocx
c:\windows\system32\_000126_.tmp.dll
c:\windows\system32\_004495_.tmp.dll
c:\windows\system32\_004496_.tmp.dll
c:\windows\system32\_004497_.tmp.dll
c:\windows\system32\_004498_.tmp.dll
c:\windows\system32\_004505_.tmp.dll
c:\windows\system32\_004506_.tmp.dll
c:\windows\system32\_004507_.tmp.dll
c:\windows\system32\_004508_.tmp.dll
c:\windows\system32\_004510_.tmp.dll
c:\windows\system32\_004511_.tmp.dll
c:\windows\system32\_004514_.tmp.dll
c:\windows\system32\_004515_.tmp.dll
c:\windows\system32\_004517_.tmp.dll
c:\windows\system32\_004518_.tmp.dll
c:\windows\system32\_004519_.tmp.dll
c:\windows\system32\_004521_.tmp.dll
c:\windows\system32\_004523_.tmp.dll
c:\windows\system32\_004524_.tmp.dll
c:\windows\system32\_004525_.tmp.dll
c:\windows\system32\_004529_.tmp.dll
c:\windows\system32\_004530_.tmp.dll
c:\windows\system32\_004532_.tmp.dll
c:\windows\system32\_004535_.tmp.dll
c:\windows\system32\_004537_.tmp.dll
c:\windows\system32\_004539_.tmp.dll
c:\windows\system32\_004540_.tmp.dll
c:\windows\system32\_004541_.tmp.dll
c:\windows\system32\_004544_.tmp.dll
c:\windows\system32\_004545_.tmp.dll
c:\windows\system32\_004546_.tmp.dll
c:\windows\system32\_004547_.tmp.dll
c:\windows\system32\_004548_.tmp.dll
c:\windows\system32\_004553_.tmp.dll
c:\windows\system32\_004555_.tmp.dll
c:\windows\system32\2d2ca2ce-704a-428c-8cbe-0736b29190aa.dll
c:\windows\system32\drivers\npf.sys
c:\windows\system32\ieuinit.inf
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\Thumbs.db
c:\windows\system32\vbzlib1.dll
c:\windows\system32\wpcap.dll
D:\install.exe

----- BITS: Možné infikované stránky -----

hxxp://download.xbox.com:80
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NPF


((((((((((((((((((((((((( Soubory vytvořené od 2010-02-07 do 2010-03-07 )))))))))))))))))))))))))))))))
.

2010-03-07 02:46 . 2010-03-07 02:47 -------- d-----w- C:\rsit
2010-03-04 17:23 . 2010-03-04 17:23 -------- d-s---w- c:\documents and settings\Administrator\UserData
2010-03-04 17:23 . 2010-03-04 17:23 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-03-04 17:23 . 2010-03-04 17:23 552 ----a-w- c:\windows\system32\d3d8caps.dat
2010-03-04 16:00 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-04 16:00 . 2010-03-04 16:00 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-04 16:00 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-03 14:51 . 2010-03-05 00:05 17480 ----a-w- c:\windows\system32\drivers\hamachi.sys
2010-02-28 21:13 . 2010-02-28 21:13 -------- d-----w- c:\documents and settings\Jakub ?ert
2010-02-28 12:41 . 2010-02-28 12:41 -------- d-----w- c:\program files\Common Files\DirectX
2010-02-28 11:37 . 2010-03-07 15:26 -------- d-----w- c:\program files\Common Files\Akamai
2010-02-27 00:26 . 2008-04-13 23:10 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2010-02-27 00:26 . 2008-04-13 23:11 8576 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2010-02-27 00:26 . 2008-04-13 23:11 8192 ----a-w- c:\windows\system32\drivers\changer.sys
2010-02-21 20:31 . 2010-02-21 20:31 -------- d-----w- C:\CZD_Config
2010-02-21 17:20 . 2010-02-21 17:22 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-02-19 20:04 . 2010-02-19 20:04 4096 ----a-w- c:\windows\d3dx.dat
2010-02-11 03:16 . 2010-02-11 03:16 41872 ----a-w- c:\windows\system32\xfcodec.dll
2010-02-06 22:59 . 2004-05-29 16:53 82896 ------w- c:\windows\system32\KickCom2.dll
2010-02-06 22:59 . 2004-05-29 16:52 91072 ------w- c:\windows\system32\RoseCo2.dll
2010-02-06 22:59 . 2003-07-24 09:24 237568 ----a-w- c:\windows\system32\demoover.exe
2010-02-06 22:59 . 2002-01-05 12:48 974848 ------w- c:\windows\system32\mfc70.dll
2010-02-06 21:08 . 2010-02-28 02:14 -------- d-----w- c:\program files\WinClamAVShield

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-07 14:34 . 2009-07-18 17:56 -------- d-----w- c:\program files\trend micro
2010-03-07 03:55 . 2009-03-04 20:45 -------- d-----w- c:\program files\Common Files\Adobe
2010-03-07 03:41 . 2009-10-21 14:03 -------- d-----w- c:\program files\NCSoft
2010-03-07 03:40 . 2009-07-27 23:41 -------- d-----w- c:\program files\Sony Online Entertainment
2010-03-07 03:40 . 2009-11-30 17:46 -------- d-----w- c:\program files\Screaming Bee
2010-03-07 03:00 . 2009-03-11 20:49 -------- d-----w- c:\program files\Spyware Terminator
2010-03-04 16:56 . 2001-10-25 14:00 91540 ----a-w- c:\windows\system32\perfc005.dat
2010-03-04 16:56 . 2001-10-25 14:00 458476 ----a-w- c:\windows\system32\perfh005.dat
2010-03-03 15:13 . 2009-03-04 20:53 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-28 00:46 . 2009-03-08 20:17 215104 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-02-28 00:43 . 2009-03-08 20:17 138576 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-02-26 19:21 . 2009-03-04 19:56 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-26 15:43 . 2009-05-31 20:52 2373712 ----a-w- c:\windows\system32\pbsvc.exe
2010-02-26 15:43 . 2009-03-08 20:16 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-01-31 02:33 . 2010-01-31 02:33 249856 ------w- c:\windows\Setup1.exe
2010-01-31 02:33 . 2010-01-31 02:33 73216 ----a-w- c:\windows\ST6UNST.EXE
2010-01-21 22:42 . 2009-03-15 23:46 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2010-01-21 18:28 . 2010-01-21 18:28 -------- d-----w- c:\program files\Avanquest update
2010-01-21 18:20 . 2010-01-21 18:20 -------- d-----w- c:\program files\Common Files\Sony Shared
2010-01-21 18:17 . 2010-01-21 18:17 -------- d-----w- c:\program files\Common Files\Apple
2010-01-17 22:06 . 2010-01-17 22:06 -------- d-----w- c:\program files\NVIDIA Corporation
2010-01-17 22:05 . 2010-01-17 22:05 -------- d-----w- c:\program files\NVIDIA nTune Performance Application
2010-01-09 19:59 . 2010-01-09 19:59 -------- d-----w- c:\program files\Common Files\reFX
2010-01-07 17:46 . 2009-06-25 19:00 -------- d-----w- c:\program files\Vstplugins
2009-12-28 19:35 . 2009-12-28 19:32 24 --sha-w- c:\windows\SAE39192B.tmp
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-04-23 22058792]
"Rainlendar2"="d:\program files\Rainlendar2\Rainlendar2.exe" [2009-08-22 5148672]
"QIP2005"="d:\program files\QIP\qip.exe" [2009-08-13 3276288]
"Sony Ericsson PC Suite"="d:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2009-09-24 434176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2008-08-15 30003200]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-03-24 13524992]
"nwiz"="nwiz.exe" [2008-03-24 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-03-24 86016]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 213936]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-05-16 86960]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"CHotkey"="mHotkey.exe" [2003-09-16 514048]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-17 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-05-16 213936]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2009-07-17 2173440]
"QuickTime Task"="d:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Jakub ¦ert\Nabˇdka Start\Programy\Po spuçtŘnˇ\
ashDisp.lnk - c:\program files\Alwil Software\Avast4\ashDisp.exe [2009-3-4 81000]
GIGABYTE Gamer HUD.lnk - c:\program files\GIGABYTE\Gamer HUD\HUD.exe [2008-4-10 1907712]
HD ADeck.lnk - c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe [2009-3-4 30003200]
SpywareTerminatorShield.lnk - c:\program files\Spyware Terminator\SpywareTerminatorShield.Exe [2009-3-11 2173440]
Xfire.lnk - d:\program files\Xfire\Xfire.exe [2010-2-11 3207056]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 ----a-w- d:\program files\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RGSC]
2009-07-24 20:26 306088 ----a-w- d:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
2006-11-24 00:06 487424 ----a-r- d:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2009-08-24 22:52 1217784 ----a-w- d:\program files\Steam\Steam.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\QIP\\qip.exe"=
"d:\\Program Files\\TmNationsForever\\TmForever.exe"=
"d:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"c:\\Documents and Settings\\Jakub Žert\\temp\\TeamViewer\\Version4\\TeamViewer.exe"=
"d:\\Program Files\\Rockstar Games\\GTA San Andreas\\gta_sa.exe"=
"d:\\Program Files\\Rockstar Games\\GTA San Andreas\\samp.exe"=
"d:\\Program Files\\HLSW\\hlsw.exe"=
"d:\\Program Files\\ICQ6.5\\ICQ.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\FlashGet\\flashget.exe"=
"d:\\Program Files\\Lineage II CT2.3\\LineageII.exe"=
"d:\\Program Files\\Counter-Strike Source\\hl2.exe"=
"d:\\Program Files\\Counter-Strike\\hl.exe"=
"d:\\Program Files\\Counter-Strike\\hltv.exe"=
"c:\\Program Files\\Reallusion\\CrazyTalk for Skype\\CT4Skype.exe"=
"d:\\Program Files\\Free Download Manager\\fdm.exe"=
"d:\\Program Files\\Xfire\\Xfire.exe"=
"d:\\Program Files\\Firefly Studios\\Stronghold Legends\\StrongholdLegends.exe"=
"d:\\Program Files\\Flagship Studios\\Hellgate London\\Launcher.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"d:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"d:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"d:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"d:\\Program Files\\Activision\\Prototype\\prototypef.exe"=
"d:\\Program Files\\Team17\\Worms 2\\Frontend.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"d:\\Program Files\\Hamachi\\hamachi.exe"=
"d:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW_LANFixed.exe"=
"d:\\Program Files\\Team17\\Worms World Party\\wwp.exe"=
"d:\\Program Files\\Worms World Party\\WWP\\wwp.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"d:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW_LANFixed1.4.exe"=
"d:\\Program Files\\left 4 Dead\\left4dead.exe"=
"d:\\Program Files\\Killing Floor LAN\\System\\KillingFloor.exe"=
"d:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW-lanfix 1.5.exe"=
"d:\\Program Files\\jazz2\\Jazz2.exe"=
"d:\\Program Files\\Activision\\Call of Duty - World at War\\server.exe"=
"d:\\Program Files\\Activision\\Call of Duty - World at War\\CoD 5 1.5 Privat Client Patch.exe"=
"d:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"c:\\Program Files\\Microsoft Games for Windows - LIVE\\Client\\GFWLive.exe"=
"d:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\GTAIV.exe"=
"d:\\Program Files\\Wolfenstein\\Wolf2MP.exe"=
"d:\\Program Files\\Wolfenstein\\Wolf2MPLite.exe"=
"d:\\Program Files\\Activision\\Call of Duty - World at War\\sp_tool.exe"=
"d:\\Program Files\\Activision\\Wolfenstein\\MP\\Wolf2MP.exe"=
"d:\\Program Files\\Activision\\Wolfenstein\\MP\\Wolf2MPLite.exe"=
"d:\\Program Files\\Bethesda Softworks\\Fallout 3\\Fallout3.exe"=
"d:\\Program Files\\Ubisoft\\Tom Clancy's H.A.W.X\\HAWX.exe"=
"d:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"d:\\Program Files\\Codemasters\\FUEL\\FUEL.exe"=
"d:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"d:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"d:\\Program Files\\Activision\\Call of Duty - World at War\\CodWaw_LANFixed 1.6.exe"=
"c:\\games\\Guitar Hero III\\GH3.exe"=
"d:\\Program Files\\Firefly Studios\\Stronghold Crusader\\Stronghold Crusader.exe"=
"d:\\Program Files\\Worms Armageddon - New Edition\\wa.exe"=
"c:\\WINDOWS\\Downloaded Program Files\\ijjiOptimizer.exe"=
"d:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp-cracked.exe"=
"d:\\Program Files\\2K Games\\Gearbox Software\\Borderlands\\Binaries\\Borderlands.exe"=
"d:\\Program Files\\left 4 dead 2\\left4dead2.exe"=
"d:\\Program Files\\left 4 dead 2\\srcds.exe"=
"d:\\Program Files\\[PSY] Garrys Mod 11(1.o.o.5)\\hl2.exe"=
"d:\\Program Files\\Heroes of Newerth\\hon.exe"=
"d:\\Program Files\\EA Games\\Mirror's Edge\\Binaries\\MirrorsEdge.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\frd.exe"=
"d:\\Program Files\\Electronic Arts\\Dead Space\\Dead Space.exe"=
"d:\\Program Files\\ICQ7.0\\ICQ.exe"=
"d:\\Program Files\\ICQ7.0\\aolload.exe"=
"d:\\Program Files\\Demigod\\bin\\Demigod.exe"=
"d:\\Program Files\\Opera\\opera.exe"=
"d:\\Program Files\\Savage 2 - A Tortured Soul\\savage2.exe"=
"c:\\Program Files\\DsNET Corp\\aTube Catcher 1.0\\smh.exe"=
"d:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"d:\\Riot Games\\League of Legends\\air\\LolClient.exe"=
"d:\\Riot Games\\League of Legends\\game\\League of Legends.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
"8375:TCP"= 8375:TCP:League of Legends Launcher
"8375:UDP"= 8375:UDP:League of Legends Launcher
"6979:TCP"= 6979:TCP:League of Legends Launcher
"6979:UDP"= 6979:UDP:League of Legends Launcher
"8376:TCP"= 8376:TCP:League of Legends Launcher
"8376:UDP"= 8376:UDP:League of Legends Launcher
"1034:TCP"= 1034:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 0 (0x0)

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [26.3.2009 0:20 721904]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [4.3.2009 21:30 114768]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [11.3.2009 21:49 142592]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [17.8.2004 14:49 14336]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4.3.2009 21:30 20560]
R2 OMSI download service;Sony Ericsson OMSI download service;d:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [21.1.2010 19:28 90112]
R3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [24.8.2007 16:44 34384]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [21.1.2010 19:29 27632]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [4.3.2009 20:57 845184]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 npkycryp;npkycryp;\??\d:\program files\Lineage II\system\npkycryp.sys --> d:\program files\Lineage II\system\npkycryp.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Connection Wizard,ShellNext = iexplore
IE: &Stáhnout &vše FlashGetem - d:\program files\FlashGet\jc_all.htm
IE: &Stáhnout FlashGetem - d:\program files\FlashGet\jc_link.htm
IE: Crawler Search - tbr:iemenu
IE: Download all with Free Download Manager - file://d:\program files\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://d:\program files\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://d:\program files\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://d:\program files\Free Download Manager\dllink.htm
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
FF - ProfilePath - c:\documents and settings\Jakub Žert\Data aplikací\Mozilla\Firefox\Profiles\abwjo3qb.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2304157&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2304157&q=
FF - component: c:\documents and settings\Jakub Žert\Data aplikací\Mozilla\Firefox\Profiles\abwjo3qb.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Jakub Žert\Data aplikací\Mozilla\Firefox\Profiles\abwjo3qb.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\RadioWMPCore.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF - plugin: d:\program files\Opera\program\plugins\npdsplay.dll
FF - plugin: d:\program files\Opera\program\plugins\npqtplugin.dll
FF - plugin: d:\program files\Opera\program\plugins\npqtplugin2.dll
FF - plugin: d:\program files\Opera\program\plugins\NPSWF32.dll
FF - plugin: d:\program files\Opera\program\plugins\npwmsdrm.dll
FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin.dll
FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin2.dll

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

AddRemove-WinPcapInst - c:\program files\WinPcap\Uninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-07 16:27
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll prosync1.sys sfsync02.sys atapi.sys spcy.sys >>UNKNOWN [0x8AF37938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba8ecf28
\Driver\ACPI -> ACPI.sys @ 0xba666cb8
\Driver\atapi -> prosync1.sys @ 0xbadb06c1
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Realtek RTL8168C(P)/8111C(P) PCI-E Gigabit Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xba4d3bb0
PacketIndicateHandler -> NDIS.sys @ 0xba4e0a21
SendHandler -> NDIS.sys @ 0xba4be87b
user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-117609710-1409082233-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:ac,5f,9f,59,23,af,df,f5,a8,7d,e6,0d,a5,4c,14,28,19,0a,54,91,ca,e8,0a,
69,d2,42,7d,10,9b,e1,53,c6,e0,4b,dd,76,de,c2,6c,05,23,9d,20,79,6c,f8,52,cb,\
"??"=hex:48,62,76,40,43,ca,74,e8,a6,ce,1d,09,25,e4,61,ea

[HKEY_USERS\S-1-5-21-117609710-1409082233-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:f4,fb,a4,28,13,27,bc,6b,6c,ed,18,87,2e,2a,8a,b0,8d,28,d4,e1,d3,
86,1b,55,64,53,79,b0,a7,55,5a,c9,20,13,cf,52,aa,6d,23,12,76,00,07,f7,dd,3c,\
"rkeysecu"=hex:ea,2a,46,cc,5b,40,09,b1,5b,68,52,d0,56,b3,01,54
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'Explorer.EXE'(3032)
c:\windows\system32\msi.dll
d:\program files\Xfire\xfire_toucan_41445.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
d:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\windows\mHotkey.exe
c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe
.
**************************************************************************
.
Celkový čas: 2010-03-07 16:31:02 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-03-07 15:31

Před spuštěním: 2 004 828 160
Po spuštění: 1 857 757 184

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - D66BE672A581287A0F1A44E91ABDBD7F

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Zpomalení PC při startupu, winesm32.exe

#7 Příspěvek od Caroprd111 »

Než se podívám na log, tak Vás o něco poprosím.

Všechny soubory z karantény obnovte do nějaké složky, zazipujte a někam, uložte. Odkaz mi pošlete Soukromou zprávou.

Děkuji. :)
Obrázek

zaxic
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 07 bře 2010 15:14

Re: Zpomalení PC při startupu, winesm32.exe

#8 Příspěvek od zaxic »

a chcete i ty soubory z MBAM? nebo jen z Avastu ?

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Zpomalení PC při startupu, winesm32.exe

#9 Příspěvek od Caroprd111 »

Stačily by z Avastu, ale pokud můžete, tak tam přihoďte i MBAM. :)
Obrázek

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Zpomalení PC při startupu, winesm32.exe

#10 Příspěvek od Caroprd111 »

Obrázek Odinstalujte všechny emulátory virtuálních mechanik.

Obrázek Stáhněte SPTD http://www.duplexsecure.com/en/downloads
  • Vyberte verzi podle svého operačního systému (64 & 32b). Uložte na plochu a spusťte.
  • zvolte možnost Uninstall a restartujte PC.


Obrázek Stáhněte MBR na plochu http://www2.gmer.net/mbr/mbr.exe

Obrázek Start > Spustit (Win + R)
  • Vyskočí okénko, zkopírujte do něj:

Kód: Vybrat vše

"%userprofile%\plocha\mbr" -t
  • Klikněte na OK
  • Vytvoří se log s názvem mbr.log, vložte ho sem.


Obrázek Dejte log z Gmer http://www.viry.cz/forum/viewtopic.php?f=29&t=62878
Obrázek

zaxic
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 07 bře 2010 15:14

Re: Zpomalení PC při startupu, winesm32.exe

#11 Příspěvek od zaxic »

No tak sem udelal log z MBR potom ten prvni z Gmer a pak sem dal delat ten druhy a chvily to neco delalo ale pak najednou to probliklo a videl sem tusim BSOD.. tak ted nevim jestli to mam zkusit znova..

zaxic
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 07 bře 2010 15:14

Re: Zpomalení PC při startupu, winesm32.exe

#12 Příspěvek od zaxic »

tady sou ty logy
log z mbr

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll prosync1.sys sfsync02.sys atapi.sys pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK

a zde prvni log zGmer

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-03-07 18:30:26
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\JAKUBE~1\LOCALS~1\Temp\fgpoqfow.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

---- EOF - GMER 1.0.15 ----


a ten druhy log teda nemam protoze byla ta BSOD tak jestli to mam zkusit znova? .. jen Gmer? ..

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Zpomalení PC při startupu, winesm32.exe

#13 Příspěvek od Caroprd111 »

Ano, Gmer spusťte znovu. :)
Obrázek

zaxic
Návštěvník
Návštěvník
Příspěvky: 29
Registrován: 07 bře 2010 15:14

Re: Zpomalení PC při startupu, winesm32.exe

#14 Příspěvek od zaxic »

takže log 2


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-07 21:32:12
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\JAKUBE~1\LOCALS~1\Temp\fgpoqfow.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB34766B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xB3476574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xB3476A52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB347614C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xB347664E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xB347608C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xB34760F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB347676E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB347672E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xB34768AE]

---- Kernel code sections - GMER 1.0.15 ----

.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB5EF0360, 0x37192D, 0xE8000020]
init C:\WINDOWS\system32\drivers\monfilt.sys entry point in "init" section [0xB3805280]

---- User code sections - GMER 1.0.15 ----

.text D:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[1252] USER32.dll!DefWindowProcA + 11A 7E37C298 7 Bytes JMP 10031D10 D:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
.text D:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[1252] USER32.dll!SetWindowRgn + 2BD 7E37E7E5 7 Bytes JMP 10031C80 D:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)
.text D:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe[1252] USER32.dll!SetClipboardData + 19D 7E38113B 7 Bytes JMP 10031CF0 D:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\NewUI.dll (New UI/Avanquest Software)

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\WINDOWS\system32\services.exe[740] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003D0002
IAT C:\WINDOWS\system32\services.exe[740] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003D0000

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\prodrv06 \Device\ProDrv06 E1BFC778
Device \Driver\atapi \Device\Ide\IdePort0 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort1 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort2 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort3 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\prohlp02 \Device\ProHlp02 E10100D8

AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x6F 0x2C 0xAC 0xCE ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x7D 0x30 0xCB 0xF4 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xD5 0x7F 0x9D 0x32 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x79 0x71 0xEE 0xE1 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xC2 0x8C 0x9D 0xEC ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x04 0xB8 0x80 0x2B ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 D:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x7D 0x30 0xCB 0xF4 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x16 0x01 0xA2 0xF2 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x2B 0x9A 0xCC 0xA9 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xC2 0x8C 0x9D 0xEC ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x04 0xB8 0x80 0x2B ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 D:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x7D 0x30 0xCB 0xF4 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x5A 0x92 0xFD 0x41 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x2B 0x9A 0xCC 0xA9 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xC2 0x8C 0x9D 0xEC ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x04 0xB8 0x80 0x2B ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x6F 0x2C 0xAC 0xCE ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x7D 0x30 0xCB 0xF4 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xD5 0x7F 0x9D 0x32 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x79 0x71 0xEE 0xE1 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xC2 0x8C 0x9D 0xEC ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x04 0xB8 0x80 0x2B ...

---- EOF - GMER 1.0.15 ----

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Zpomalení PC při startupu, winesm32.exe

#15 Příspěvek od Caroprd111 »

Jak to vypadá s PC :???:
Obrázek

Odpovědět