Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

PROSIM O KONTROLU RSTI -LOG

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Pravnik1
4. Stupeň Varování
Příspěvky: 74
Registrován: 05 kvě 2010 14:54

PROSIM O KONTROLU RSTI -LOG

#1 Příspěvek od Pravnik1 »

Logfile of random's system information tool 1.06 (written by random/random)
Run by Andread at 2010-05-05 17:01:45
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 471 MB (7%) free of 7 GB
Total RAM: 239 MB (26% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:02:30, on 5.5.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\sistray.EXE
C:\WINDOWS\system32\khooker.exe
C:\WINDOWS\soundman.exe
C:\WINDOWS\LTSMMSG.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Documents and Settings\Andread\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Andread\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Andread\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Andread\My Documents\Downloads\RSIT.exe
C:\Program Files\trend micro\Andread.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\system32\khooker.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\sisUSBrg.exe
O4 - HKLM\..\Run: [SoundMan] soundman.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Andread\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 3846491457
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 3846614834
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 4219 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1060284298-854245398-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1060284298-854245398-1003UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SiS Tray"=C:\WINDOWS\system32\sistray.EXE [2002-05-09 303104]
"SiS KHooker"=C:\WINDOWS\system32\khooker.exe [2002-01-25 290816]
"SiSUSBRG"=C:\WINDOWS\sisUSBrg.exe [2002-04-25 32768]
"SoundMan"=C:\WINDOWS\soundman.exe [2002-04-18 46592]
"LTSMMSG"=C:\WINDOWS\LTSMMSG.exe [2002-06-01 141880]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-02-06 2021400]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"Google Update"=C:\Documents and Settings\Andread\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-01 136176]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-05-05 17:01:53 ----D---- C:\Program Files\trend micro
2010-05-05 17:01:45 ----D---- C:\rsit
2010-05-05 15:35:35 ----A---- C:\WINDOWS\system32\lsdelete.exe
2010-05-05 15:35:24 ----AH---- C:\aaw7boot.cmd
2010-05-05 14:41:33 ----HDC---- C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-05-05 14:35:59 ----D---- C:\Program Files\Lavasoft
2010-05-05 14:35:58 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2010-05-05 14:24:06 ----A---- C:\WINDOWS\imsins.BAK
2010-05-05 13:13:42 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-05-05 13:13:42 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2010-05-04 16:00:41 ----D---- C:\WINDOWS\Minidump
2010-05-04 15:44:06 ----D---- C:\Documents and Settings\Andread\Application Data\WinRAR
2010-05-04 15:43:15 ----D---- C:\Program Files\WinRAR
2010-05-04 12:39:21 ----D---- C:\Documents and Settings\Andread\Application Data\Uniblue
2010-05-04 12:38:43 ----D---- C:\WINDOWS\SxsCaPendDel
2010-05-04 12:33:00 ----D---- C:\Documents and Settings\Andread\Application Data\BSplayer Pro
2010-05-04 12:32:35 ----D---- C:\Program Files\Webteh
2010-05-03 13:29:42 ----D---- C:\Program Files\QuickTime
2010-04-30 22:10:22 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2010-04-30 22:10:13 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2010-04-30 22:09:25 ----D---- C:\WINDOWS\Logs
2010-04-30 22:02:17 ----D---- C:\Program Files\The KMPlayer
2010-04-30 15:38:38 ----D---- C:\Documents and Settings\Andread\Application Data\Mozilla
2010-04-30 15:38:37 ----D---- C:\Documents and Settings\Andread\Application Data\Thunderbird

======List of files/folders modified in the last 1 months======

2010-05-05 17:01:54 ----D---- C:\WINDOWS\Temp
2010-05-05 17:01:53 ----RD---- C:\Program Files
2010-05-05 15:58:42 ----SD---- C:\WINDOWS\Tasks
2010-05-05 15:35:35 ----D---- C:\WINDOWS\system32
2010-05-05 15:30:07 ----D---- C:\WINDOWS\system32\CatRoot2
2010-05-05 14:52:17 ----D---- C:\WINDOWS
2010-05-05 14:45:04 ----D---- C:\WINDOWS\system32\drivers
2010-05-05 14:44:09 ----HD---- C:\WINDOWS\inf
2010-05-05 14:44:01 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-05-05 14:43:56 ----D---- C:\WINDOWS\security
2010-05-05 14:42:37 ----SHD---- C:\WINDOWS\Installer
2010-05-05 14:42:26 ----D---- C:\WINDOWS\WinSxS
2010-05-05 14:26:28 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-05-05 14:25:18 ----D---- C:\WINDOWS\system32\inetsrv
2010-05-05 13:06:57 ----D---- C:\Program Files\Common Files
2010-05-05 12:22:57 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-05-04 17:05:56 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-05-04 16:46:28 ----D---- C:\Program Files\CCleaner
2010-05-04 16:25:44 ----D---- C:\WINDOWS\system32\config
2010-05-03 13:31:19 ----D---- C:\Program Files\Internet Explorer
2010-05-03 11:02:35 ----SD---- C:\Documents and Settings\Andread\Application Data\Microsoft
2010-05-01 20:48:35 ----D---- C:\WINDOWS\Help
2010-05-01 20:48:35 ----D---- C:\Program Files\Windows Media Player
2010-05-01 19:28:40 ----A---- C:\WINDOWS\WINCMD.INI
2010-05-01 19:27:43 ----D---- C:\WINDOWS\ie7updates
2010-05-01 19:26:12 ----D---- C:\WINDOWS\WBEM
2010-05-01 19:26:12 ----D---- C:\WINDOWS\system32\en-us
2010-05-01 19:26:11 ----D---- C:\WINDOWS\Media
2010-04-30 22:10:44 ----D---- C:\WINDOWS\system32\DirectX
2010-04-30 22:08:09 ----D---- C:\WINDOWS\Prefetch
2010-04-30 21:43:07 ----D---- C:\Program Files\ESET
2010-04-30 15:58:08 ----D---- C:\Program Files\soundbase
2010-04-30 15:48:37 ----HD---- C:\WINDOWS\$hf_mig$
2010-04-30 12:38:44 ----D---- C:\Documents and Settings\Andread\Application Data\Adobe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-02-06 106208]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2009-02-06 93336]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R1 SiSkp;SiSkp; C:\WINDOWS\system32\drivers\srvkp.sys [2002-04-02 5760]
R2 Aspi32;Aspi32; C:\WINDOWS\system32\drivers\Aspi32.sys [1999-09-10 25244]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-02-06 113448]
R2 STEC3;STEC3; \??\C:\WINDOWS\system32\STEC3.sys []
R3 ALCXWDM;Service for Avance AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2002-04-18 305100]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-14 13952]
R3 LucentSoftModem;Lucent Technologies Soft Modem; C:\WINDOWS\system32\DRIVERS\LTSM.sys [2002-08-02 816043]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2009-03-25 130432]
R3 SiS315;SiS315; C:\WINDOWS\system32\DRIVERS\sisgrp.sys [2002-05-15 194176]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-14 17152]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-02-06 727720]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2010-02-04 1228208]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2001-02-23 270336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-02-06 20680]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ServiceLayer;ServiceLayer; C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe [2008-11-11 620544]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13493
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: PROSIM O KONTROLU RSTI -LOG

#2 Příspěvek od Caroprd111 »

Zdravím :)

Nezakládejte prosím duplicitní témata, pokračujte zde: http://www.viry.cz/forum/viewtopic.php?f=13&t=100780

Moderátory prosím o :lock:
Obrázek

Zamčeno