Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu, děkuji

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Tokamak
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 19 kvě 2006 13:58
Kontaktovat uživatele:

Prosím o kontrolu logu, děkuji

#1 Příspěvek od Tokamak »

Dobrý den,
Nedávno jsem nainstaloval soubor Bio-Protection Solution MC3000U (kterým jsem chtěl zprovoznit čtečku otisků prstů...).. Nefungovalo mi to, tak jsem to odstranil přes Ovládací panely/Programy a funkce... Nyní se mi při každém spuštění windows spustí zároveň tento program, který nemůžu najít v procesech (není ani v Programech a funkcích), prosím o radu, jak se tohoto programu zbavit, děkuji.

Vkládám log RSIT

Logfile of random's system information tool 1.06 (written by random/random)
Run by Grayhoof at 2010-01-31 20:19:00
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 122 GB (83%) free of 148 GB
Total RAM: 2046 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:19:20, on 31.1.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\PLFSetI.exe
C:\Program Files\COMODO\Firewall\cfp.exe
D:\Fingerprint\PdtWzd.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
D:\ICQ\ICQ7.0\ICQ.exe
C:\Program Files\Acer\Acer VCM\AcerVCM.exe
C:\Users\Grayhoof\AppData\Local\Temp\RtkBtMnt.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Acer\Acer VCM\acp2HID.exe
C:\Windows\system32\Taskmgr.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
D:\Total Uninstall 5\Tu.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Grayhoof\Desktop\download\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Grayhoof.exe
D:\FINGERPRINT\FPLaunch.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://cs.intl.acer.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [eAudio] "C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [ZPdtWzdVitaKey MC3000] "D:\FINGERPRINT\PdtWzd.exe" show
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [ICQ] "D:\ICQ\ICQ7.0\ICQ.exe" silent loginmode=4
O4 - Global Startup: Acer VCM.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - D:\FINGERPRINT\PwdBank.exe
O9 - Extra 'Tools' menuitem: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - D:\FINGERPRINT\PwdBank.exe
O9 - Extra button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - D:\ICQ\ICQ7.0\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - D:\ICQ\ICQ7.0\ICQ.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O20 - AppInit_DLLs: C:\Windows\System32\guard32.dll
O20 - Winlogon Notify: AWinNotifyVitaKey MC3000 - D:\FINGERPRINT\WinNotify.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V7 (AdobeActiveFileMonitor7.0) - Unknown owner - D:\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe (file missing)
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe

--
End of file - 7167 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [2008-03-04 142896]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-04-04 1037608]
"ePower_DMC"=C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe [2008-03-11 397312]
"eDataSecurity Loader"=C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe [2008-03-04 526896]
"eAudio"=C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe [2008-03-07 544768]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-03-11 5296128]
"Skytel"=C:\Windows\Skytel.exe [2007-11-20 1826816]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2008-04-23 13535776]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2008-04-23 92704]
"WarReg_PopUp"=C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe [2008-01-29 303104]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2007-10-03 178712]
"PLFSetI"=C:\Windows\PLFSetI.exe [2007-10-23 200704]
"COMODO Firewall Pro"=C:\Program Files\COMODO\Firewall\cfp.exe [2009-01-25 1797880]
"NeroFilterCheck"=C:\Windows\system32\NeroCheck.exe [2001-07-09 155648]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-01-28 2757512]
"ZPdtWzdVitaKey MC3000"=D:\FINGERPRINT\PdtWzd.exe [2010-01-31 3870208]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"ICQ"=D:\ICQ\ICQ7.0\ICQ.exe [2010-01-12 133368]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Acer VCM.lnk - C:\Program Files\Acer\Acer VCM\AcerVCM.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\Windows\System32\guard32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AWinNotifyVitaKey MC3000]
D:\FINGERPRINT\WinNotify.dll [2010-01-31 2869760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSfsu.exe"="C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSfsu.exe:*:Enabled:eDSfsu"
"C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\encryption.exe"="C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\encryption.exe:*:Enabled:encryption"
"C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\decryption.exe"="C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\decryption.exe:*:Enabled:decryption"
"C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSMgr.exe"="C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSMgr.exe:*:Enabled:eDSMgr"
"C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStbmngr.exe"="C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStbmngr.exe:*:Enabled:eDStbmngr"
"C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64\eDSfsu.exe"="C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64\eDSfsu.exe:*:Enabled:eDSfsu"
"C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64\encryption.exe"="C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64\encryption.exe:*:Enabled:encryption"
"C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64\decryption.exe"="C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64\decryption.exe:*:Enabled:decryption"
"C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64\eDSMgr.exe"="C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64\eDSMgr.exe:*:Enabled:eDSMgr"
"C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64\eDStbmngr.exe"="C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64\eDStbmngr.exe:*:Enabled:eDStbmngr"
"C:\Users\Grayhoof\Downloads\Wolfenstein.2009-Razor1911\Wolfenstein.2009-Razor1911\Wolf2-Patch.exe"="C:\Users\Grayhoof\Downloads\Wolfenstein.2009-Razor1911\Wolfenstein.2009-Razor1911\Wolf2-Patch.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\Users\Grayhoof\Downloads\Wolfenstein.2009-Razor1911\Wolfenstein.2009-Razor1911\Crack+Patch\Wolf2-Patch.exe"="C:\Users\Grayhoof\Downloads\Wolfenstein.2009-Razor1911\Wolfenstein.2009-Razor1911\Crack+Patch\Wolf2-Patch.exe:*:Enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 months======

2010-01-31 19:28:31 ----SHD---- C:\Config.Msi
2010-01-31 19:06:29 ----D---- C:\ProgramData\Martau
2010-01-31 18:57:41 ----A---- C:\ComboFix.txt
2010-01-31 18:56:41 ----SHD---- C:\$RECYCLE.BIN
2010-01-31 18:23:38 ----A---- C:\Windows\zip.exe
2010-01-31 18:23:38 ----A---- C:\Windows\SWREG.exe
2010-01-31 18:23:38 ----A---- C:\Windows\PEV.exe
2010-01-31 18:23:38 ----A---- C:\Windows\NIRCMD.exe
2010-01-31 18:23:38 ----A---- C:\Windows\MBR.exe
2010-01-31 18:23:37 ----A---- C:\Windows\SWSC.exe
2010-01-31 18:23:37 ----A---- C:\Windows\sed.exe
2010-01-31 18:23:37 ----A---- C:\Windows\grep.exe
2010-01-31 18:23:03 ----D---- C:\Windows\ERDNT
2010-01-31 18:21:07 ----D---- C:\ComboFix
2010-01-31 18:20:57 ----AD---- C:\Qoobox
2010-01-31 18:20:40 ----A---- C:\Windows\SWXCACLS.exe
2010-01-31 17:59:52 ----D---- C:\Program Files\OpenOffice.org 3
2010-01-31 17:46:26 ----A---- C:\Windows\system32\VMC3KAPI.dll
2010-01-31 17:46:26 ----A---- C:\Windows\system32\VCryptAPI.dll
2010-01-31 17:46:24 ----A---- C:\Windows\system32\ShlCmd.exe
2010-01-31 17:44:45 ----D---- C:\ProgramData\UIB
2010-01-31 17:44:18 ----D---- C:\Program Files\ICQ6Toolbar
2010-01-31 17:43:13 ----D---- C:\Users\Grayhoof\AppData\Roaming\ICQ
2010-01-31 17:38:57 ----D---- C:\Program Files\WinRAR
2010-01-31 17:01:05 ----A---- C:\Windows\system32\aswBoot.exe
2010-01-31 17:00:59 ----D---- C:\ProgramData\Alwil Software
2010-01-31 13:15:18 ----A---- C:\Users\Grayhoof\AppData\Roaming\acervcmtmp.ini
2010-01-31 12:40:43 ----D---- C:\Users\Grayhoof\AppData\Roaming\Intel
2010-01-31 12:40:42 ----D---- C:\ProgramData\Roaming
2010-01-31 12:39:45 ----D---- C:\Program Files\Cisco
2010-01-31 12:39:42 ----D---- C:\Program Files\Common Files\Intel
2010-01-31 12:39:41 ----D---- C:\ProgramData\Intel
2010-01-31 12:38:32 ----DC---- C:\Windows\system32\DRVSTORE
2010-01-31 12:30:36 ----D---- C:\Program Files\Common Files\Windows Live
2010-01-31 11:42:23 ----D---- C:\Program Files\Microsoft Games
2010-01-31 01:24:49 ----D---- C:\Program Files\Astroburn Toolbar
2010-01-31 01:24:47 ----D---- C:\Program Files\Astroburn Lite
2010-01-31 01:24:34 ----D---- C:\Users\Grayhoof\AppData\Roaming\Astroburn Lite
2010-01-31 01:24:29 ----D---- C:\ProgramData\Astroburn Lite
2010-01-31 01:01:03 ----D---- C:\Program Files\DAEMON Tools Lite
2010-01-30 12:39:21 ----D---- C:\Users\Grayhoof\AppData\Roaming\Opera
2010-01-28 22:37:01 ----D---- C:\ProgramData\VistaCodecs
2010-01-27 22:40:12 ----D---- C:\ProgramData\Adobe Systems
2010-01-27 22:31:05 ----D---- C:\Program Files\Common Files\Adobe Systems Shared
2010-01-22 22:19:18 ----A---- C:\Windows\system32\mshtml.dll
2010-01-22 22:19:17 ----A---- C:\Windows\system32\ieframe.dll
2010-01-22 22:19:15 ----A---- C:\Windows\system32\iertutil.dll
2010-01-22 22:19:14 ----A---- C:\Windows\system32\wininet.dll
2010-01-22 22:19:14 ----A---- C:\Windows\system32\urlmon.dll
2010-01-22 22:19:14 ----A---- C:\Windows\system32\occache.dll
2010-01-22 22:19:14 ----A---- C:\Windows\system32\msfeeds.dll
2010-01-22 22:19:13 ----A---- C:\Windows\system32\ieui.dll
2010-01-22 22:19:13 ----A---- C:\Windows\system32\iepeers.dll
2010-01-22 22:19:13 ----A---- C:\Windows\system32\iedkcs32.dll
2010-01-22 22:19:12 ----A---- C:\Windows\system32\msfeedssync.exe
2010-01-22 22:19:12 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-01-22 22:19:12 ----A---- C:\Windows\system32\jsproxy.dll
2010-01-22 22:19:12 ----A---- C:\Windows\system32\ieUnatt.exe
2010-01-22 22:19:12 ----A---- C:\Windows\system32\iesysprep.dll
2010-01-22 22:19:12 ----A---- C:\Windows\system32\iesetup.dll
2010-01-22 22:19:12 ----A---- C:\Windows\system32\iernonce.dll
2010-01-22 22:19:12 ----A---- C:\Windows\system32\ie4uinit.exe
2010-01-16 22:36:16 ----D---- C:\ProgramData\Pinnacle Studio Ultimate
2010-01-15 15:59:08 ----D---- C:\ProgramData\Pinnacle
2010-01-13 16:25:21 ----A---- C:\Windows\IsUninst.exe
2010-01-13 15:25:20 ----A---- C:\Windows\system32\t2embed.dll
2010-01-13 15:25:20 ----A---- C:\Windows\system32\fontsub.dll

======List of files/folders modified in the last 1 months======

2010-01-31 20:19:09 ----D---- C:\Windows\Temp
2010-01-31 20:09:22 ----SHD---- C:\System Volume Information
2010-01-31 19:52:36 ----D---- C:\Program Files\Acer GameZone
2010-01-31 19:52:33 ----D---- C:\ProgramData
2010-01-31 19:42:33 ----SHD---- C:\Windows\Installer
2010-01-31 19:42:32 ----D---- C:\Program Files\Common Files
2010-01-31 19:42:31 ----D---- C:\Windows
2010-01-31 19:40:19 ----D---- C:\Program Files\Common Files\microsoft shared
2010-01-31 19:40:13 ----RD---- C:\Program Files
2010-01-31 19:39:32 ----D---- C:\Windows\Microsoft.NET
2010-01-31 19:39:23 ----RSD---- C:\Windows\assembly
2010-01-31 19:37:10 ----D---- C:\ProgramData\McAfee
2010-01-31 19:26:38 ----D---- C:\Windows\System32
2010-01-31 19:26:00 ----D---- C:\Windows\winsxs
2010-01-31 19:02:22 ----D---- C:\Windows\system32\catroot
2010-01-31 19:02:22 ----D---- C:\Windows\inf
2010-01-31 19:02:21 ----D---- C:\Windows\system32\drivers
2010-01-31 18:51:49 ----A---- C:\Windows\system.ini
2010-01-31 18:39:51 ----D---- C:\Windows\system32\config
2010-01-31 18:39:51 ----D---- C:\Boot
2010-01-31 18:37:48 ----RSD---- C:\Windows\Fonts
2010-01-31 18:32:51 ----D---- C:\Windows\AppPatch
2010-01-31 18:20:45 ----D---- C:\Windows\Prefetch
2010-01-31 18:06:32 ----D---- C:\Windows\system32\Tasks
2010-01-31 18:05:08 ----SD---- C:\Users\Grayhoof\AppData\Roaming\Microsoft
2010-01-31 17:44:18 ----D---- C:\Program Files\Mozilla Firefox
2010-01-31 17:44:14 ----HD---- C:\Program Files\InstallShield Installation Information
2010-01-31 17:44:07 ----D---- C:\ProgramData\ICQ
2010-01-31 17:43:28 ----D---- C:\Users\Grayhoof\AppData\Roaming\WinRAR
2010-01-31 17:35:28 ----D---- C:\Temp
2010-01-31 17:26:00 ----D---- C:\Program Files\Acer
2010-01-31 17:00:59 ----D---- C:\Program Files\Alwil Software
2010-01-31 16:58:44 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-01-31 12:39:41 ----D---- C:\Program Files\Intel
2010-01-31 12:37:44 ----SD---- C:\ProgramData\Microsoft
2010-01-31 01:01:51 ----D---- C:\Users\Grayhoof\AppData\Roaming\uTorrent
2010-01-31 01:00:39 ----D---- C:\ProgramData\DAEMON Tools Lite
2010-01-30 23:42:48 ----D---- C:\Windows\system32\catroot2
2010-01-30 23:30:07 ----D---- C:\Windows\Tasks
2010-01-30 23:30:07 ----D---- C:\ProgramData\Google
2010-01-30 23:30:07 ----D---- C:\Program Files\Google
2010-01-30 23:29:25 ----D---- C:\Program Files\Common Files\Adobe
2010-01-30 23:29:24 ----D---- C:\Windows\system32\Adobe
2010-01-30 23:27:34 ----D---- C:\Program Files\Cyberlink
2010-01-30 23:27:34 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
2010-01-30 23:23:30 ----D---- C:\Program Files\Adobe
2010-01-30 23:12:23 ----D---- C:\ProgramData\CyberLink
2010-01-30 23:08:02 ----D---- C:\Users\Grayhoof\AppData\Roaming\Adobe
2010-01-30 22:59:14 ----D---- C:\ProgramData\Adobe
2010-01-30 22:49:09 ----D---- C:\Program Files\GRETECH
2010-01-30 22:43:43 ----D---- C:\ProgramData\Skype
2010-01-30 22:29:48 ----D---- C:\Program Files\Common Files\System
2010-01-30 22:29:41 ----D---- C:\Windows\ShellNew
2010-01-30 22:26:39 ----D---- C:\Program Files\NewTech Infosystems
2010-01-30 12:42:27 ----D---- C:\Windows\Logs
2010-01-29 00:31:53 ----A---- C:\Windows\NeroDigital.ini
2010-01-27 02:01:21 ----D---- C:\Program Files\Internet Explorer
2010-01-23 09:49:05 ----D---- C:\Windows\system32\migration
2010-01-20 19:11:57 ----D---- C:\Users\Grayhoof\AppData\Roaming\skypePM
2010-01-14 11:12:06 ----N---- C:\Windows\system32\MpSigStub.exe
2010-01-14 01:06:48 ----D---- C:\Program Files\Windows Mail
2010-01-10 01:12:53 ----RD---- C:\Users
2010-01-05 01:17:46 ----N---- C:\Windows\system32\mrt.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2010-01-28 23376]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2010-01-28 163280]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2010-01-28 46672]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver; C:\Windows\System32\DRIVERS\cmdguard.sys [2009-01-25 99344]
R1 cmdHlp;COMODO Firewall Pro Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2009-01-25 25104]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2010-01-28 19024]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2010-01-28 51792]
R2 int15;int15; \??\C:\Windows\system32\drivers\int15.sys [2007-01-26 69632]
R2 PSDNServ;PSDNServ; C:\Windows\system32\DRIVERS\PSDNServ.sys [2008-03-04 16944]
R2 psdvdisk;PSDVdisk; C:\Windows\system32\DRIVERS\PSDVdisk.sys [2008-03-04 60464]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-02-29 1202560]
R3 CmBatt;Ovladač baterie Microsoft ACPI Control Method Battery; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-01-25 17480]
R3 Inspect;Comodo Firewall Network Driver; C:\Windows\system32\DRIVERS\inspect.sys [2008-10-11 73232]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-03-11 2077080]
R3 itecir;ITECIR Infrared Receiver; C:\Windows\system32\DRIVERS\itecir.sys [2007-12-18 54784]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1E60x86.sys [2009-08-05 48640]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw5v32.sys [2008-11-17 3668480]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-04-23 7446400]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-04-04 196784]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
R3 vfs101x;vfs101x; C:\Windows\system32\drivers\vfs101x.sys [2008-04-22 40752]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
S1 DritekPortIO;Dritek General Port I/O; \??\D:\LAUNCH~1\DPortIO.sys []
S3 adusbser;AnyDATA USB Device for Legacy Serial Communication; C:\Windows\system32\DRIVERS\adusbser.sys []
S3 aov23djj;aov23djj; C:\Windows\system32\drivers\aov23djj.sys []
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
S3 BthPort;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-04-11 507904]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-04-11 29696]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2007-03-29 79664]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2007-02-27 81200]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2007-02-27 16432]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MarvinBus;Pinnacle Marvin Bus; C:\Windows\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 NETw4v32;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw4v32.sys [2008-01-08 2554368]
S3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2008-01-30 14848]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
S3 wip0204;Wippien Network Adapter 2.4; C:\Windows\system32\DRIVERS\wip0204.sys [2008-12-30 23480]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2007-12-11 12800]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 cmdAgent;COMODO Firewall Pro Helper Service; C:\Program Files\COMODO\Firewall\cmdagent.exe [2009-01-25 618232]
R2 eDataSecurity Service;eDataSecurity Service; C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [2008-03-04 500784]
R2 ETService;Empowering Technology Service; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [2008-03-21 24576]
R2 EvtEng;Intel® PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2008-10-16 860160]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2007-10-03 358936]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
R2 MobilityService;MobilityService; C:\Acer\Mobility Center\MobilityService.exe [2007-12-06 110592]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-04-23 196608]
R2 RegSrvc;Intel® PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2008-10-16 466944]
R2 RS_Service;Raw Socket Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [2008-01-10 233472]
S2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7; D:\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe []
S2 MySQL;MySQL; C:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld --defaults-file=C:\Program Files\MySQL\MySQL Server 5.1\my.ini MySQL []
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2010-01-27 72704]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-08-11 651720]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119395
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu, děkuji

#2 Příspěvek od Rudy »

Podle návodu: http://www.viry.cz/forum/viewtopic.php?f=15&t=2791 odstraňte ručně jeho registry klíče.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Tokamak
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 19 kvě 2006 13:58
Kontaktovat uživatele:

Re: Prosím o kontrolu logu, děkuji

#3 Příspěvek od Tokamak »

děkuji

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119395
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu, děkuji

#4 Příspěvek od Rudy »

Nemáte zač!
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět