Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

kontrola logu, děkuji

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
subaru
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 25 lis 2006 21:31

kontrola logu, děkuji

#1 Příspěvek od subaru »

Prosím o kontrolu logu, něco mi zas dusí PC. Díky moc
dávám sem log po projetí PC CCleanerem.


Logfile of random's system information tool 1.08 (written by random/random)
Run by Správce at 2010-12-29 22:24:08
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 56 GB (18%) free of 305 GB
Total RAM: 4094 MB (69% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:24:12, on 29.12.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18999)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Správce.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.www.daemon-search.com/default
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Správce\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Správce\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-21-3968299894-954384744-379159808-1003\..\Run: [AlcoholAutomount] "C:\Program Files (x86)\Alcohol Soft\Alcohol 120\axcmd.exe" /automount (User 'Pavel')
O4 - HKUS\S-1-5-21-3968299894-954384744-379159808-1003\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (User 'Pavel')
O4 - HKUS\S-1-5-21-3968299894-954384744-379159808-1003\..\Run: [Notes] (User 'Pavel')
O4 - Startup: hamachi.lnk = C:\Program Files (x86)\Hamachi\hamachi.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files (x86)\QIP\qip.exe (HKCU)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Firewall (AntiVirFirewallService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Backbone Service (BBDemon) - Dassault Systemes - C:\Program Files (x86)\Dassault Systemes\B16\intel_a\code\bin\CATSysDemon.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files (x86)\GIGABYTE\GEST\GSvr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version4\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7538 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\Program Files (x86)\Dassault Systemes\B16\intel_a\code\bin\CATSysDemon.exe" -service
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version4\TeamViewer_Service.exe" -service
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe /Embedding
taskeng.exe {50E34ABA-104C-4B52-BDC9-E5B30EFA53F3}
"C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE"
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\nvvsvc.exe -session
taskeng.exe {1B789713-BF1F-4256-ACEA-AD26BD4B7E8E}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Windows\RAVCpl64.exe"
"C:\Windows\ehome\ehtray.exe"
C:\Windows\ehome\ehmsas.exe -Embedding
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\Pavel\Desktop\NoINST\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Users\Správce\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2009-07-14 150768]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-04-12 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Windows\RAVCpl64.exe [2007-09-19 5426688]
"Skytel"=C:\Windows\Skytel.exe [2007-08-03 1826816]
"PAC7302_Monitor"=C:\Windows\PixArt\PAC7302\Monitor.exe [2006-11-03 319488]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-10 1555968]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2010-05-19 2736128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"=C:\Windows\RaidTool\xInsIDE.exe [2007-03-20 36864]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

C:\Users\Správce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
hamachi.lnk - C:\Program Files (x86)\Hamachi\hamachi.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.scr - open - "C:\Windows\system32\notepad.exe" "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2010-12-29 21:21:25 ----D---- C:\rsit
2010-12-24 23:14:21 ----D---- C:\Program Files (x86)\Hamachi
2010-12-24 23:14:21 ----A---- C:\Windows\system32\drivers\hamachi.sys
2010-12-20 19:12:55 ----D---- C:\Program Files (x86)\MSECache
2010-12-17 16:35:41 ----D---- C:\ProgramData\vsosdk
2010-12-15 16:02:07 ----A---- C:\Windows\SYSWOW64\drivers\ssmdrv.sys
2010-12-15 16:02:07 ----A---- C:\Windows\system32\drivers\avgntflt.sys
2010-12-15 16:02:07 ----A---- C:\Windows\system32\drivers\avfwot.sys
2010-12-15 16:02:07 ----A---- C:\Windows\system32\drivers\avfwim.sys
2010-12-15 16:02:06 ----D---- C:\Program Files (x86)\Avira
2010-12-15 13:54:23 ----A---- C:\Windows\tcpip.txt
2010-12-15 11:37:08 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2010-12-15 11:37:08 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2010-12-15 11:37:08 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2010-12-15 11:37:08 ----A---- C:\Windows\system32\fontsub.dll
2010-12-15 11:37:08 ----A---- C:\Windows\system32\atmlib.dll
2010-12-15 11:37:08 ----A---- C:\Windows\system32\atmfd.dll
2010-12-15 11:37:05 ----A---- C:\Windows\system32\win32k.sys
2010-12-15 11:37:04 ----A---- C:\Windows\system32\consent.exe
2010-12-15 11:37:03 ----A---- C:\Windows\system32\mshtml.dll
2010-12-15 11:37:02 ----A---- C:\Windows\system32\ieframe.dll
2010-12-15 11:37:01 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2010-12-15 11:37:01 ----A---- C:\Windows\system32\mstime.dll
2010-12-15 11:37:01 ----A---- C:\Windows\system32\iertutil.dll
2010-12-15 11:37:00 ----A---- C:\Windows\SYSWOW64\mstime.dll
2010-12-15 11:37:00 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2010-12-15 11:37:00 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2010-12-15 11:36:59 ----A---- C:\Windows\SYSWOW64\wininet.dll
2010-12-15 11:36:59 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2010-12-15 11:36:59 ----A---- C:\Windows\SYSWOW64\occache.dll
2010-12-15 11:36:59 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2010-12-15 11:36:59 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2010-12-15 11:36:59 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2010-12-15 11:36:59 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2010-12-15 11:36:59 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2010-12-15 11:36:59 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2010-12-15 11:36:59 ----A---- C:\Windows\SYSWOW64\ieui.dll
2010-12-15 11:36:59 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2010-12-15 11:36:59 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2010-12-15 11:36:59 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2010-12-15 11:36:59 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2010-12-15 11:36:59 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2010-12-15 11:36:59 ----A---- C:\Windows\SYSWOW64\ie4uinit.exe
2010-12-15 11:36:59 ----A---- C:\Windows\system32\wininet.dll
2010-12-15 11:36:59 ----A---- C:\Windows\system32\urlmon.dll
2010-12-15 11:36:59 ----A---- C:\Windows\system32\occache.dll
2010-12-15 11:36:59 ----A---- C:\Windows\system32\mshtmled.dll
2010-12-15 11:36:59 ----A---- C:\Windows\system32\msfeedssync.exe
2010-12-15 11:36:59 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-12-15 11:36:59 ----A---- C:\Windows\system32\msfeeds.dll
2010-12-15 11:36:59 ----A---- C:\Windows\system32\licmgr10.dll
2010-12-15 11:36:59 ----A---- C:\Windows\system32\jsproxy.dll
2010-12-15 11:36:59 ----A---- C:\Windows\system32\ieUnatt.exe
2010-12-15 11:36:59 ----A---- C:\Windows\system32\ieui.dll
2010-12-15 11:36:59 ----A---- C:\Windows\system32\iesysprep.dll
2010-12-15 11:36:59 ----A---- C:\Windows\system32\iesetup.dll
2010-12-15 11:36:59 ----A---- C:\Windows\system32\iernonce.dll
2010-12-15 11:36:59 ----A---- C:\Windows\system32\iepeers.dll
2010-12-15 11:36:59 ----A---- C:\Windows\system32\iedkcs32.dll
2010-12-15 11:36:58 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2010-12-15 11:36:58 ----A---- C:\Windows\system32\ie4uinit.exe
2010-12-15 11:36:53 ----A---- C:\Windows\SYSWOW64\tzres.dll
2010-12-15 11:36:53 ----A---- C:\Windows\system32\tzres.dll
2010-12-15 11:36:50 ----A---- C:\Windows\system32\schedsvc.dll
2010-12-15 11:36:49 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2010-12-15 11:36:49 ----A---- C:\Windows\SYSWOW64\taskeng.exe
2010-12-15 11:36:49 ----A---- C:\Windows\SYSWOW64\taskcomp.dll
2010-12-15 11:36:49 ----A---- C:\Windows\system32\wmicmiplugin.dll
2010-12-15 11:36:49 ----A---- C:\Windows\system32\taskschd.dll
2010-12-15 11:36:49 ----A---- C:\Windows\system32\taskeng.exe
2010-12-15 11:36:49 ----A---- C:\Windows\system32\taskcomp.dll
2010-12-15 11:09:54 ----SHD---- C:\$RECYCLE.BIN
2010-12-15 10:32:02 ----D---- C:\Windows\temp
2010-12-15 10:32:01 ----A---- C:\ComboFix.txt
2010-12-15 10:24:08 ----A---- C:\Windows\zip.exe
2010-12-15 10:24:08 ----A---- C:\Windows\SWSC.exe
2010-12-15 10:24:08 ----A---- C:\Windows\SWREG.exe
2010-12-15 10:24:08 ----A---- C:\Windows\sed.exe
2010-12-15 10:24:08 ----A---- C:\Windows\PEV.exe
2010-12-15 10:24:08 ----A---- C:\Windows\NIRCMD.exe
2010-12-15 10:24:08 ----A---- C:\Windows\MBR.exe
2010-12-15 10:24:08 ----A---- C:\Windows\grep.exe
2010-12-15 10:24:04 ----D---- C:\Windows\ERDNT
2010-12-15 10:24:03 ----D---- C:\ComboFix
2010-12-15 10:23:36 ----D---- C:\Qoobox
2010-12-15 10:23:22 ----A---- C:\Windows\SWXCACLS.exe
2010-12-13 13:32:34 ----D---- C:\Users\Správce\AppData\Roaming\Malwarebytes
2010-12-13 13:32:04 ----D---- C:\ProgramData\Malwarebytes
2010-12-13 13:32:01 ----A---- C:\Windows\system32\drivers\mbam.sys
2010-12-13 09:19:01 ----D---- C:\Program Files\trend micro

======List of files/folders modified in the last 1 months======

2010-12-29 22:18:26 ----D---- C:\Windows\System32
2010-12-29 22:18:26 ----D---- C:\Windows\inf
2010-12-29 22:18:26 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-12-29 22:05:17 ----D---- C:\Windows\system32\catroot2
2010-12-29 22:01:40 ----D---- C:\Windows\Prefetch
2010-12-29 20:51:35 ----AD---- C:\Windows
2010-12-29 20:27:46 ----D---- C:\Windows\system32\drivers
2010-12-29 20:26:10 ----D---- C:\Windows\system32\catroot
2010-12-29 20:00:12 ----SHD---- C:\System Volume Information
2010-12-29 17:46:19 ----D---- C:\Users\Správce\AppData\Roaming\Hamachi
2010-12-27 15:43:18 ----D---- C:\Program Files (x86)\Codemasters
2010-12-27 15:42:58 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2010-12-27 15:41:58 ----D---- C:\Users\Správce\AppData\Roaming\InstallShield
2010-12-27 15:39:24 ----SHD---- C:\Windows\Installer
2010-12-27 15:39:23 ----RD---- C:\Program Files (x86)
2010-12-26 21:30:58 ----D---- C:\Program Files (x86)\FreeRapid-0.83u1
2010-12-20 19:13:39 ----D---- C:\Windows\winsxs
2010-12-20 19:13:11 ----D---- C:\Program Files (x86)\Microsoft Office
2010-12-17 16:35:41 ----D---- C:\ProgramData
2010-12-16 08:43:35 ----D---- C:\Windows\rescache
2010-12-16 08:26:42 ----D---- C:\Windows\SysWOW64
2010-12-16 08:26:41 ----D---- C:\Program Files\Windows Mail
2010-12-16 08:26:41 ----D---- C:\Program Files\Internet Explorer
2010-12-16 08:26:41 ----D---- C:\Program Files (x86)\Windows Mail
2010-12-16 08:26:41 ----D---- C:\Program Files (x86)\Internet Explorer
2010-12-16 08:26:40 ----D---- C:\Windows\SYSWOW64\migration
2010-12-16 08:26:40 ----D---- C:\Windows\system32\migration
2010-12-16 08:26:39 ----D---- C:\Windows\SYSWOW64\cs-CZ
2010-12-16 08:26:39 ----D---- C:\Windows\system32\cs-CZ
2010-12-16 01:36:23 ----A---- C:\Windows\system32\mrt.exe
2010-12-15 16:47:24 ----D---- C:\Windows\SYSWOW64\drivers
2010-12-15 16:02:06 ----D---- C:\ProgramData\Avira
2010-12-15 10:31:11 ----D---- C:\Windows\Tasks
2010-12-15 10:30:40 ----A---- C:\Windows\system.ini
2010-12-15 10:28:00 ----D---- C:\Windows\AppPatch
2010-12-15 10:28:00 ----D---- C:\Program Files\Common Files
2010-12-15 10:28:00 ----D---- C:\Program Files (x86)\Common Files
2010-12-14 00:23:08 ----D---- C:\Windows\pss
2010-12-13 14:25:23 ----D---- C:\ProgramData\Spybot - Search & Destroy
2010-12-13 09:19:01 ----RD---- C:\Program Files
2010-12-12 10:41:57 ----D---- C:\Users\Správce\AppData\Roaming\DAEMON Tools Lite
2010-12-09 12:44:09 ----D---- C:\Windows\system32\wbem
2010-12-09 12:43:23 ----D---- C:\Windows\system32\spool
2010-12-09 12:43:23 ----D---- C:\Windows\system32\CodeIntegrity
2010-12-09 12:43:23 ----D---- C:\Windows\registration
2010-12-09 12:09:12 ----SD---- C:\Users\Správce\AppData\Roaming\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2007-09-29 91648]
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2007-02-07 14104]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-18 834544]
R1 avfwot;avfwot; C:\Windows\system32\DRIVERS\avfwot.sys [2010-12-15 121672]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2008-07-21 32200]
R1 LUMDriver;LUMDriver; \??\C:\Windows\system32\drivers\LUMDriver.sys [2008-01-02 24848]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2010-12-15 74880]
R3 AnyDVD;AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [2008-08-01 113088]
R3 avfwim;AvFw Packet Filter Miniport; C:\Windows\system32\DRIVERS\avfwim.sys [2009-02-24 87552]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2007-09-19 1221912]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2010-04-03 13807976]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2008-09-07 82816]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh64.sys [2010-03-04 321568]
S1 HWiNFO32;HWiNFO32 Kernel Driver; \??\C:\Users\SPRVCE~1\AppData\Local\Temp\HWiNFO64A.SYS []
S2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2008-12-11 211456]
S2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2008-12-11 35328]
S3 a9lmw767;a9lmw767; C:\Windows\system32\drivers\a9lmw767.sys []
S3 as22bd6t;as22bd6t; C:\Windows\system32\drivers\as22bd6t.sys []
S3 athrusb;Atheros Wireless LAN USB device driver; C:\Windows\system32\DRIVERS\athrxusb.sys [2008-07-29 1075712]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2006-11-02 6144]
S3 ET5Drv;ET5Drv; \??\C:\Windows\ET5Drv.sys [2007-10-16 36416]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2010-01-21 20544]
S3 GPU-Z;GPU-Z; C:\Windows\system32\drivers\GPU-Z.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2010-12-24 33344]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 273920]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-18 11008]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 7040]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 6656]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-18 7936]
S3 pfc;Padus ASPI Shell; C:\Windows\system32\drivers\pfc.sys []
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-18 168704]
S3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2008-07-17 35328]
S3 WinRing0_1_2_0;WinRing0_1_2_0; \??\C:\Users\Pavel\Desktop\NoINST\RealTemp_340\WinRing0x64.sys [2008-07-26 14544]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-18 108544]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirFirewallService;Avira Firewall; C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe [2010-12-15 388865]
R2 AntiVirMailService;Avira AntiVir MailGuard; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe [2010-12-15 194817]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2010-12-15 185089]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2010-12-15 108289]
R2 AntiVirWebService;Avira AntiVir WebGuard; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [2010-12-15 434945]
R2 BBDemon;Backbone Service; C:\Program Files (x86)\Dassault Systemes\B16\intel_a\code\bin\CATSysDemon.exe [2005-09-06 35840]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2010-05-19 73728]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-04-03 159336]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2010-05-13 75064]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 TeamViewer4;TeamViewer 4; C:\Program Files (x86)\TeamViewer\Version4\TeamViewer_Service.exe [2009-05-06 185640]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2008-09-08 85096]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-18 27648]
S3 GEST Service;GEST Service for program management.; C:\Program Files (x86)\GIGABYTE\GEST\GSvr.exe [2007-12-14 47624]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 PerfHost;@%systemroot%\sysWow64\perfhost.exe,-2; C:\Windows\SysWow64\perfhost.exe [2008-01-18 19968]
S3 WPFFontCache_v0400;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]

-----------------EOF-----------------

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: kontrola logu, děkuji

#2 Příspěvek od Roli »

Zdravím, tohle fixni v HJT :

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.www.daemon-search.com/default
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Správce\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe


HJT najdeš zde :

C:\Program Files\trend micro\Správce.exe


Fix znamená že spustíš HJT Obrázek jako admin

v okně které se ti otevře klikneš na Do a system scan only

v dalším okně najdeš řádky které jsem ti vypsal,

vedle nich je čtvereček do kterého uděláš zatržítko,

pak klikneš na Fix checked které je vlevo dole,

program se ti zeptá zda opravdu ANO s tím samozřejmě souhlasíš a je hotovo.


Smaž nepotřebné soubory

pomocí CCleaneru

návod :

Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš

Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)

čištění registru je třeba několikrát zopakovat !

Nástroje - tady lze odinstalovat programy, upravit co se spustí po Startu systému a obnovit systém


Stáhni a ulož na plochu ComboFix,

spusť aplikaci jako Administrátor a povol instalaci Konzole pro zotavení - Recovery Console.

Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,

pak ještě jednou klik na ANO a už to jede.

Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.

Při skenovaní může být PC i restartováno nelekat se.

Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,

protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.

Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt

(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Odpovědět