problémy při startu, prosím o kontrolu logu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

rychlik
nováček
Příspěvky: 49
Registrován: srpen 12
Pohlaví: Muž
Stav:
Offline

Re: problémy při startu, prosím o kontrolu logu

Příspěvekod rychlik » 15 srp 2012 21:26

MiLiNess jsem psal, ale zatím bez odezvy.

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43064
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: problémy při startu, prosím o kontrolu logu

Příspěvekod jaro3 » 16 srp 2012 14:41

On se určitě , já mám plno ve virech a on je na to mistr.

Stáhni si zde soubor:
http://leteckaposta.cz/933774860
Rozbal a vyjmi ho ze složky a samotný soubor vlož do C:\
Bude tedy zde:
C:\i8042prt.sys


Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:

Kód: Vybrat vše

ClearJavaCache::

KillAll::
FCOPY::
C:\i8042prt.sys | c:\windows\system32\drivers\i8042prt.sys


Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

rychlik
nováček
Příspěvky: 49
Registrován: srpen 12
Pohlaví: Muž
Stav:
Offline

Re: problémy při startu, prosím o kontrolu logu

Příspěvekod rychlik » 17 srp 2012 00:02

Provedeno, opět jsem to musel dělat v nouzovém režimu.
Log z ComboFix:


ComboFix 12-08-16.01 - Administrator 16.08.2012 23:27:54.5.2 - x86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1790.1416 [GMT 2:00]
Spuštěný z: c:\documents and settings\KarolÝna\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\KarolÝna\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\drivers\i8042prt.sys . . . chybí !!
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-16 do 2012-08-16 )))))))))))))))))))))))))))))))
.
.
2012-08-16 20:38 . 2012-08-16 20:38 -------- d-----w- C:\i8042prt
2012-08-15 18:57 . 2012-08-15 18:57 -------- d-----w- c:\program files\CrystalDiskInfo
2012-08-15 17:24 . 2012-08-15 17:25 -------- d-----w- c:\documents and settings\Administrator
2012-08-12 19:53 . 2012-08-12 19:55 -------- d-----w- c:\program files\WhoCrashed
2012-08-12 05:14 . 2012-06-02 13:18 214256 ----a-w- c:\windows\system32\muweb.dll
2012-08-11 21:30 . 2012-08-11 21:30 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2012-08-11 21:30 . 2012-08-11 21:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-08-11 21:30 . 2012-07-03 11:46 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-11 19:39 . 2012-08-11 19:39 -------- d-----w- c:\documents and settings\All Users\Data aplikací\GFI Software
2012-08-06 14:12 . 2012-08-06 14:12 -------- d-----w- c:\program files\Common Files\Java
2012-08-06 14:11 . 2012-08-06 14:11 -------- d-----w- c:\program files\Oracle
2012-07-30 22:08 . 2012-07-30 22:08 -------- d-----w- c:\program files\CCleaner
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-15 05:08 . 2012-04-05 06:26 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-15 05:08 . 2011-05-26 05:32 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-06 13:58 . 2008-04-14 12:00 78336 ----a-w- c:\windows\system32\browser.dll
2012-07-05 20:07 . 2012-05-10 17:04 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-07-05 20:06 . 2012-05-10 17:04 772544 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-07-05 20:06 . 2010-04-19 05:12 687544 ----a-w- c:\windows\system32\deployJava1.dll
2012-07-04 14:05 . 2009-03-28 11:58 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 18:22 . 2008-04-14 12:00 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-07-03 16:21 . 2009-03-28 12:41 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-07-03 16:21 . 2011-06-29 16:58 721000 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-07-03 16:21 . 2009-03-28 12:41 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-07-03 16:21 . 2009-03-28 12:41 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-07-03 16:21 . 2009-03-28 12:41 89624 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-07-03 16:21 . 2009-03-28 12:41 353688 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-07-03 16:21 . 2009-03-28 12:41 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-07-03 16:21 . 2009-03-28 12:41 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-07-03 16:21 . 2010-06-30 20:00 41224 ----a-w- c:\windows\avastSS.scr
2012-07-03 16:21 . 2009-03-28 12:41 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-07-02 17:38 . 2008-04-14 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-07-02 17:38 . 2008-04-14 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-07-02 17:38 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-07-02 12:05 . 2008-04-14 12:00 385024 ------w- c:\windows\system32\html.iec
2012-06-06 18:59 . 2012-06-06 18:59 1070152 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2012-06-05 15:49 . 2008-04-14 12:00 1372672 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:49 . 2008-04-14 12:00 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2008-04-14 12:00 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 13:19 . 2008-10-16 13:07 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2008-10-16 13:08 22552 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2009-03-28 12:00 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2009-03-28 12:00 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-02 13:19 . 2009-03-28 12:00 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2009-03-28 12:00 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2009-03-28 12:00 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 13:19 . 2008-10-16 13:09 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 13:19 . 2008-10-16 13:07 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 13:19 . 2008-10-16 13:07 18456 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2008-04-14 12:00 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 13:19 . 2009-03-28 12:00 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2009-03-28 12:00 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 13:19 . 2009-12-03 06:24 17648 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-06-02 13:18 . 2009-12-03 06:24 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-05-31 13:22 . 2008-04-14 12:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2012-05-29 07:38 . 2011-07-26 15:26 330240 ----a-w- c:\windows\MASetupCaller.dll
2012-07-28 16:44 . 2011-05-01 07:40 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-08-12_19.28.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-14 12:00 . 2012-07-02 17:38 67072 c:\windows\system32\mshtmled.dll
- 2008-04-14 12:00 . 2012-05-11 14:44 67072 c:\windows\system32\mshtmled.dll
+ 2007-08-13 17:54 . 2012-07-02 17:38 55296 c:\windows\system32\msfeedsbs.dll
- 2007-08-13 17:54 . 2012-05-11 14:44 55296 c:\windows\system32\msfeedsbs.dll
- 2008-04-14 12:00 . 2012-05-11 14:44 25600 c:\windows\system32\jsproxy.dll
+ 2008-04-14 12:00 . 2012-07-02 17:38 25600 c:\windows\system32\jsproxy.dll
- 2011-06-19 08:40 . 2012-05-11 14:44 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2011-06-19 08:40 . 2012-07-02 17:38 12800 c:\windows\system32\dllcache\xpshims.dll
- 2008-04-14 12:00 . 2012-05-11 14:44 67072 c:\windows\system32\dllcache\mshtmled.dll
+ 2008-04-14 12:00 . 2012-07-02 17:38 67072 c:\windows\system32\dllcache\mshtmled.dll
- 2009-03-28 13:06 . 2012-05-11 14:44 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2009-03-28 13:06 . 2012-07-02 17:38 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2008-04-14 12:00 . 2012-05-11 14:44 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2008-04-14 12:00 . 2012-07-02 17:38 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2008-04-14 12:00 . 2012-07-02 17:38 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2008-04-14 12:00 . 2012-05-11 14:44 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2008-04-14 12:00 . 2012-07-06 13:58 78336 c:\windows\system32\dllcache\browser.dll
+ 2009-03-28 15:05 . 2012-08-15 22:09 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
- 2009-03-28 15:05 . 2012-07-11 21:57 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
- 2009-03-28 15:05 . 2012-07-11 21:57 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-03-28 15:05 . 2012-08-15 22:09 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-03-28 15:05 . 2012-08-15 22:09 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
- 2009-03-28 15:05 . 2012-07-11 21:57 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
+ 2012-08-15 22:04 . 2012-05-11 14:44 12800 c:\windows\ie8updates\KB2722913-IE8\xpshims.dll
+ 2012-08-15 22:04 . 2012-05-11 14:44 67072 c:\windows\ie8updates\KB2722913-IE8\mshtmled.dll
+ 2012-08-15 22:04 . 2012-05-11 14:44 55296 c:\windows\ie8updates\KB2722913-IE8\msfeedsbs.dll
+ 2012-08-15 22:04 . 2012-05-11 14:44 43520 c:\windows\ie8updates\KB2722913-IE8\licmgr10.dll
+ 2012-08-15 22:04 . 2012-05-11 14:44 25600 c:\windows\ie8updates\KB2722913-IE8\jsproxy.dll
- 2008-04-14 12:00 . 2012-05-11 14:44 105984 c:\windows\system32\url.dll
+ 2008-04-14 12:00 . 2012-07-02 17:38 105984 c:\windows\system32\url.dll
- 2008-04-14 12:00 . 2012-05-11 14:44 206848 c:\windows\system32\occache.dll
+ 2008-04-14 12:00 . 2012-07-02 17:38 206848 c:\windows\system32\occache.dll
+ 2008-04-14 12:00 . 2012-07-06 13:58 337920 c:\windows\system32\netapi32.dll
+ 2008-04-14 12:00 . 2012-07-02 17:38 611840 c:\windows\system32\mstime.dll
- 2008-04-14 12:00 . 2012-05-11 14:44 611840 c:\windows\system32\mstime.dll
- 2007-08-13 17:54 . 2012-05-11 14:44 629760 c:\windows\system32\msfeeds.dll
+ 2007-08-13 17:54 . 2012-07-02 17:38 629760 c:\windows\system32\msfeeds.dll
+ 2012-08-15 05:08 . 2012-08-15 05:08 686792 c:\windows\system32\Macromed\Flash\FlashUtil32_11_3_300_271_Plugin.exe
+ 2012-08-14 22:08 . 2012-08-14 22:08 686792 c:\windows\system32\Macromed\Flash\FlashUtil32_11_3_300_271_ActiveX.exe
+ 2012-08-14 22:08 . 2012-08-14 22:08 466632 c:\windows\system32\Macromed\Flash\FlashUtil32_11_3_300_271_ActiveX.dll
- 2012-04-05 06:26 . 2012-08-04 22:08 250056 c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
+ 2012-04-05 06:26 . 2012-08-15 05:08 250056 c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
- 2008-04-14 12:00 . 2009-05-07 15:33 346624 c:\windows\system32\localspl.dll
+ 2008-04-14 12:00 . 2012-05-14 09:22 346624 c:\windows\system32\localspl.dll
+ 2008-04-14 12:00 . 2012-07-02 17:38 184320 c:\windows\system32\iepeers.dll
- 2008-04-14 12:00 . 2012-05-11 14:44 184320 c:\windows\system32\iepeers.dll
+ 2008-04-14 12:00 . 2012-07-02 17:38 387584 c:\windows\system32\iedkcs32.dll
- 2008-04-14 12:00 . 2012-05-11 14:44 387584 c:\windows\system32\iedkcs32.dll
+ 2008-04-14 12:00 . 2012-07-02 12:05 174080 c:\windows\system32\ie4uinit.exe
- 2008-04-14 12:00 . 2012-05-11 11:38 174080 c:\windows\system32\ie4uinit.exe
- 2009-03-28 12:51 . 2012-07-12 05:16 151584 c:\windows\system32\FNTCACHE.DAT
+ 2009-03-28 12:51 . 2012-08-16 05:02 151584 c:\windows\system32\FNTCACHE.DAT
- 2008-04-14 12:00 . 2012-05-16 15:09 916992 c:\windows\system32\dllcache\wininet.dll
+ 2008-04-14 12:00 . 2012-07-02 17:38 916992 c:\windows\system32\dllcache\wininet.dll
+ 2008-04-14 12:00 . 2012-07-02 17:38 105984 c:\windows\system32\dllcache\url.dll
- 2008-04-14 12:00 . 2012-05-11 14:44 105984 c:\windows\system32\dllcache\url.dll
+ 2009-03-28 11:58 . 2012-07-04 14:05 139784 c:\windows\system32\dllcache\rdpwd.sys
+ 2008-04-14 12:00 . 2012-07-02 17:38 206848 c:\windows\system32\dllcache\occache.dll
- 2008-04-14 12:00 . 2012-05-11 14:44 206848 c:\windows\system32\dllcache\occache.dll
+ 2008-04-14 12:00 . 2012-07-06 13:58 337920 c:\windows\system32\dllcache\netapi32.dll
+ 2008-04-14 12:00 . 2012-07-02 17:38 611840 c:\windows\system32\dllcache\mstime.dll
- 2008-04-14 12:00 . 2012-05-11 14:44 611840 c:\windows\system32\dllcache\mstime.dll
+ 2009-03-28 13:06 . 2012-07-02 17:38 629760 c:\windows\system32\dllcache\msfeeds.dll
- 2009-03-28 13:06 . 2012-05-11 14:44 629760 c:\windows\system32\dllcache\msfeeds.dll
- 2008-04-14 12:00 . 2009-05-07 15:33 346624 c:\windows\system32\dllcache\localspl.dll
+ 2008-04-14 12:00 . 2012-05-14 09:22 346624 c:\windows\system32\dllcache\localspl.dll
- 2012-06-13 05:02 . 2012-05-11 14:44 521728 c:\windows\system32\dllcache\jsdbgui.dll
+ 2012-06-13 05:02 . 2012-07-02 17:38 521728 c:\windows\system32\dllcache\jsdbgui.dll
- 2011-06-19 08:40 . 2012-05-11 14:44 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2011-06-19 08:40 . 2012-07-02 17:38 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2008-04-14 12:00 . 2012-07-02 17:38 184320 c:\windows\system32\dllcache\iepeers.dll
- 2008-04-14 12:00 . 2012-05-11 14:44 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2011-06-19 08:40 . 2012-07-02 17:38 743424 c:\windows\system32\dllcache\iedvtool.dll
- 2011-06-19 08:40 . 2012-05-11 14:44 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2008-04-14 12:00 . 2012-07-02 17:38 387584 c:\windows\system32\dllcache\iedkcs32.dll
- 2008-04-14 12:00 . 2012-05-11 14:44 387584 c:\windows\system32\dllcache\iedkcs32.dll
- 2008-04-14 12:00 . 2012-05-11 11:38 174080 c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-04-14 12:00 . 2012-07-02 12:05 174080 c:\windows\system32\dllcache\ie4uinit.exe
+ 2012-07-18 13:46 . 2012-07-18 13:46 593408 c:\windows\Installer\a84373.msp
- 2009-03-28 15:05 . 2012-07-11 21:57 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-03-28 15:05 . 2012-08-15 22:09 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-03-28 15:05 . 2012-08-15 22:09 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
- 2009-03-28 15:05 . 2012-07-11 21:57 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
- 2009-03-28 15:05 . 2012-07-11 21:57 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
+ 2009-03-28 15:05 . 2012-08-15 22:09 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
+ 2009-03-28 15:05 . 2012-08-15 22:09 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
- 2009-03-28 15:05 . 2012-07-11 21:57 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
+ 2011-06-23 08:54 . 2011-06-23 08:54 119160 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSCONV97.DLL
+ 2012-08-15 22:04 . 2012-05-16 15:09 916992 c:\windows\ie8updates\KB2722913-IE8\wininet.dll
+ 2012-08-15 22:04 . 2012-05-11 14:44 105984 c:\windows\ie8updates\KB2722913-IE8\url.dll
+ 2012-08-15 22:04 . 2010-07-05 13:13 391032 c:\windows\ie8updates\KB2722913-IE8\spuninst\updspapi.dll
+ 2012-08-15 22:04 . 2010-07-05 13:13 233848 c:\windows\ie8updates\KB2722913-IE8\spuninst\spuninst.exe
+ 2012-08-15 22:04 . 2012-05-11 14:44 206848 c:\windows\ie8updates\KB2722913-IE8\occache.dll
+ 2012-08-15 22:04 . 2012-05-11 14:44 611840 c:\windows\ie8updates\KB2722913-IE8\mstime.dll
+ 2012-08-15 22:04 . 2012-05-11 14:44 629760 c:\windows\ie8updates\KB2722913-IE8\msfeeds.dll
+ 2012-08-15 22:04 . 2012-05-11 14:44 521728 c:\windows\ie8updates\KB2722913-IE8\jsdbgui.dll
+ 2012-08-15 22:04 . 2012-05-11 14:44 247808 c:\windows\ie8updates\KB2722913-IE8\ieproxy.dll
+ 2012-08-15 22:04 . 2012-05-11 14:44 184320 c:\windows\ie8updates\KB2722913-IE8\iepeers.dll
+ 2012-08-15 22:04 . 2012-05-11 14:44 743424 c:\windows\ie8updates\KB2722913-IE8\iedvtool.dll
+ 2012-08-15 22:04 . 2012-05-11 14:44 387584 c:\windows\ie8updates\KB2722913-IE8\iedkcs32.dll
+ 2012-08-15 22:04 . 2012-05-11 11:38 174080 c:\windows\ie8updates\KB2722913-IE8\ie4uinit.exe
- 2008-04-14 12:00 . 2012-05-11 14:44 1212416 c:\windows\system32\urlmon.dll
+ 2008-04-14 12:00 . 2012-07-02 17:38 1212416 c:\windows\system32\urlmon.dll
+ 2008-04-14 12:00 . 2012-07-02 17:38 6008320 c:\windows\system32\mshtml.dll
+ 2012-08-15 05:08 . 2012-08-15 05:08 9465032 c:\windows\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll
- 2007-08-13 17:34 . 2012-05-11 14:44 2000384 c:\windows\system32\iertutil.dll
+ 2007-08-13 17:34 . 2012-07-02 17:38 2000384 c:\windows\system32\iertutil.dll
- 2008-04-14 12:00 . 2012-06-13 13:55 1866112 c:\windows\system32\dllcache\win32k.sys
+ 2008-04-14 12:00 . 2012-07-03 18:22 1866112 c:\windows\system32\dllcache\win32k.sys
- 2008-04-14 12:00 . 2012-05-11 14:44 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2008-04-14 12:00 . 2012-07-02 17:38 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2008-04-14 12:00 . 2012-07-02 17:38 6008320 c:\windows\system32\dllcache\mshtml.dll
- 2009-03-28 13:06 . 2012-05-11 14:44 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2009-03-28 13:06 . 2012-07-02 17:38 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2012-06-26 16:03 . 2012-06-26 16:03 3875840 c:\windows\Installer\a84397.msp
- 2009-03-28 15:05 . 2012-07-11 21:57 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-03-28 15:05 . 2012-08-15 22:09 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
+ 2012-08-15 22:04 . 2012-05-11 14:44 1212416 c:\windows\ie8updates\KB2722913-IE8\urlmon.dll
+ 2012-08-15 22:04 . 2012-05-11 14:44 6007808 c:\windows\ie8updates\KB2722913-IE8\mshtml.dll
+ 2012-08-15 22:04 . 2012-05-11 14:44 2000384 c:\windows\ie8updates\KB2722913-IE8\iertutil.dll
+ 2009-03-28 13:05 . 2012-08-15 22:06 59884088 c:\windows\system32\MRT.exe
- 2007-08-13 17:54 . 2012-05-11 18:14 11111424 c:\windows\system32\ieframe.dll
+ 2007-08-13 17:54 . 2012-07-02 21:08 11111424 c:\windows\system32\ieframe.dll
- 2009-03-28 13:06 . 2012-05-11 18:14 11111424 c:\windows\system32\dllcache\ieframe.dll
+ 2009-03-28 13:06 . 2012-07-02 21:08 11111424 c:\windows\system32\dllcache\ieframe.dll
+ 2012-07-25 14:59 . 2012-07-25 14:59 11032064 c:\windows\Installer\a84385.msp
+ 2012-07-18 13:53 . 2012-07-18 13:53 10937344 c:\windows\Installer\a84361.msp
+ 2011-08-03 18:53 . 2011-08-03 18:53 17324928 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\MSO.DLL
+ 2012-08-15 22:04 . 2012-05-11 18:14 11111424 c:\windows\ie8updates\KB2722913-IE8\ieframe.dll
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-07-03 16:21 121528 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GEST"="=" [X]
"RTHDCPL"="RTHDCPL.EXE" [2008-08-26 16851456]
"Lexmark 1200 Series"="c:\program files\Lexmark 1200 Series\lxczbmgr.exe" [2006-07-13 57344]
"pdfFactory Pro Dispatcher v1"="c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis1.exe" [2002-10-30 364544]
"FinePrint Dispatcher v4"="c:\windows\System32\spool\DRIVERS\W32X86\2\fpdisp4.exe" [1999-12-13 303104]
"LogitechCommunicationsManager"="c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [2006-06-26 497200]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam10\QuickCam10.exe" [2006-06-26 614960]
"LVCOMSX"="c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe" [2006-06-26 243248]
"WD Drive Manager"="c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe" [2008-07-24 450560]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2012-06-08 3521464]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-02-14 98304]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2003-8-29 499779]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-2-7 813584]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 11:28 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Documents and Settings\\Karolína\\temp\\TeamViewer3\\TeamViewer.exe"=
"d:\\Miloš\\World of Warcraft\\Launcher.exe"=
"d:\\Miloš\\World of Warcraft\\BackgroundDownloader.exe"=
"d:\\Miloš\\World of Warcraft\\WoW-3.1.2.9901-to-3.1.3.9947-enGB-downloader.exe"=
"d:\\Miloš\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enGB-downloader.exe"=
"d:\\Miloš\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enGB-downloader.exe"=
"d:\\Miloš\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-enGB-downloader.exe"=
"d:\\Miloš\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-enGB-downloader.exe"=
"c:\\Program Files\\THQ\\Dawn of War\\W40k.exe"=
"d:\\Miloš\\World of Warcraft\\WoW-x.x.x.x-4.0.0.12911-EU-Downloader.exe"=
"d:\\Miloš\\StarCraft II\\StarCraft II.exe"=
"d:\\Miloš\\StarCraft II\\Versions\\Base16939\\SC2.exe"=
"d:\\Miloš\\StarCraft II\\Versions\\Base17326\\SC2.exe"=
"c:\\WINDOWS\\system32\\SUPDSvc.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"d:\\Miloš\\StarCraft II\\Versions\\Base18574\\SC2.exe"=
"c:\\Program Files\\THQ\\Dawn of War - Soulstorm\\Soulstorm.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Documents and Settings\\All Users\\Data aplikací\\Battle.net\\Agent\\Agent.524\\Agent.exe"=
"c:\\Documents and Settings\\All Users\\Data aplikací\\Battle.net\\Agent\\Agent.954\\Agent.exe"=
"c:\\Program Files\\Opera\\pluginwrapper\\opera_plugin_wrapper.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"5985:TCP"= 5985:TCP:*:Disabled:Vzdálená správa systému Windows
.
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [29.6.2011 18:58 721000]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [28.3.2009 14:41 353688]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [28.3.2009 14:41 21256]
S2 dgdersvc;Device Error Recovery Service;c:\windows\system32\dgdersvc.exe [25.5.2010 8:44 95568]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [20.3.2010 23:29 233472]
S2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [7.2.2010 14:07 10384]
S2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [24.7.2008 15:22 102400]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [5.4.2012 8:26 250056]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [12.9.2011 17:05 30312]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [10.3.2012 21:45 100368]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [25.5.2010 8:44 18136]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [20.3.2010 23:29 36608]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [11.8.2012 23:30 22344]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [8.5.2012 12:22 113120]
S3 Samsung UPD Service;Samsung UPD Service;c:\windows\system32\SUPDSvc.exe [23.5.2011 20:48 131888]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\drivers\ss_bbus.sys [12.9.2011 17:05 98432]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\drivers\ss_bmdfl.sys [12.9.2011 17:05 14848]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\drivers\ss_bmdm.sys [12.9.2011 17:05 123648]
S3 ss_bserd;SAMSUNG USB Mobile Logging Driver;c:\windows\system32\drivers\ss_bserd.sys [12.9.2011 17:05 100224]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [12.9.2011 17:05 121064]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [12.9.2011 17:05 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [12.9.2011 17:05 136808]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\ssadserd.sys [12.9.2011 17:05 114280]
S4 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [11.8.2012 23:30 655944]
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 05:08]
.
2012-08-16 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\Alwil Software\Avast5\AvastEmUpdate.exe [2012-07-10 16:21]
.
.
------- Doplňkový sken -------
.
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Karolína\Data aplikací\Mozilla\Firefox\Profiles\3w0a7o4e.default\
FF - prefs.js: browser.startup.homepage - hxxp://kajinka.info/
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-16 23:41
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(216)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
Celkový čas: 2012-08-16 23:44:31
ComboFix-quarantined-files.txt 2012-08-16 21:44
ComboFix2.txt 2012-08-15 17:49
ComboFix3.txt 2012-08-12 19:32
.
Před spuštěním: Volných bajtů: 57 696 919 552
Po spuštění: Volných bajtů: 57 670 770 688
.
- - End Of File - - FFF3355D45394755C49507149C4B4B21

rychlik
nováček
Příspěvky: 49
Registrován: srpen 12
Pohlaví: Muž
Stav:
Offline

Re: problémy při startu, prosím o kontrolu logu

Příspěvekod rychlik » 17 srp 2012 00:03

čerstvý log z HJT:


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:59:32, on 16.8.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\dgdersvc.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis1.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\fpdisp4.exe
C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Logitech\QuickCam10\COCIManager.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Documents and Settings\Karolína\Plocha\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://kajinka.info/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\WINDOWS\system32\dvmurl.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [GEST] =
O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v1] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis1.exe
O4 - HKLM\..\Run: [FinePrint Dispatcher v4] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\fpdisp4.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
O4 - HKCU\..\Run: [KiesPDLR] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Device Error Recovery Service (dgdersvc) - Devguru Co., Ltd. - C:\WINDOWS\system32\dgdersvc.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Samsung UPD Service - Samsung Electronics CO., LTD. - C:\WINDOWS\system32\SUPDSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: WD Drive Manager Service (WDBtnMgrSvc.exe) - WDC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe

--
End of file - 10829 bytes

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43064
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: problémy při startu, prosím o kontrolu logu

Příspěvekod jaro3 » 17 srp 2012 10:03

Nainstaluj javu:
Java SE Runtime Environment 7

Klikni na Accept License Agreement
Vyber si OS (Windows nebo Windows x64, Offline Installation)
jre-7-windows-i586-p.exe nebo
jre-7-windows-x64.exe
Stáhni ( download) a nainstaluj.
Ostatní javy odeber v přidat/odebrat programy.

Ten script zopakuj s tímto:

Kód: Vybrat vše

KillAll::

FCOPY::
C:\i8042prt.sys | c:\windows\system32\drivers\i8042prt.sys
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

rychlik
nováček
Příspěvky: 49
Registrován: srpen 12
Pohlaví: Muž
Stav:
Offline

Re: problémy při startu, prosím o kontrolu logu

Příspěvekod rychlik » 17 srp 2012 19:39

tak jsem tedy ty Javy odinstaolval a nainstaloval tu odkazovanou, ovšem nevypadá to, že by to byla poslední verze (je to 7čka a poslední je 7 update 5)... Teď jdu na ten combofix

rychlik
nováček
Příspěvky: 49
Registrován: srpen 12
Pohlaví: Muž
Stav:
Offline

Re: problémy při startu, prosím o kontrolu logu

Příspěvekod rychlik » 17 srp 2012 20:13

hotovo

log z combofix:


ComboFix 12-08-16.01 - Administrator 17.08.2012 19:52:24.6.2 - x86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1790.1415 [GMT 2:00]
Spuštěný z: c:\documents and settings\KarolÝna\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\KarolÝna\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\drivers\i8042prt.sys . . . chybí !!
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-17 do 2012-08-17 )))))))))))))))))))))))))))))))
.
.
2012-08-17 17:37 . 2012-08-17 17:37 -------- d-----w- c:\program files\Common Files\Java
2012-08-17 17:34 . 2012-08-17 17:34 611224 ----a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2012-08-17 17:34 . 2012-08-17 17:34 128000 ----a-w- c:\windows\system32\javacpl.cpl
2012-08-17 17:34 . 2012-08-17 17:34 -------- d-----w- c:\program files\Java
2012-08-16 20:38 . 2012-08-16 20:38 -------- d-----w- C:\i8042prt
2012-08-15 18:57 . 2012-08-15 18:57 -------- d-----w- c:\program files\CrystalDiskInfo
2012-08-15 17:24 . 2012-08-15 17:25 -------- d-----w- c:\documents and settings\Administrator
2012-08-12 19:53 . 2012-08-12 19:55 -------- d-----w- c:\program files\WhoCrashed
2012-08-12 05:14 . 2012-06-02 13:18 214256 ----a-w- c:\windows\system32\muweb.dll
2012-08-11 21:30 . 2012-08-11 21:30 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2012-08-11 21:30 . 2012-08-11 21:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-08-11 21:30 . 2012-07-03 11:46 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-11 19:39 . 2012-08-11 19:39 -------- d-----w- c:\documents and settings\All Users\Data aplikací\GFI Software
2012-07-30 22:08 . 2012-07-30 22:08 -------- d-----w- c:\program files\CCleaner
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-17 17:34 . 2010-04-19 05:12 544656 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-15 05:08 . 2012-04-05 06:26 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-15 05:08 . 2011-05-26 05:32 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-06 13:58 . 2008-04-14 12:00 78336 ----a-w- c:\windows\system32\browser.dll
2012-07-05 20:06 . 2012-05-10 17:04 772544 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-07-04 14:05 . 2009-03-28 11:58 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 18:22 . 2008-04-14 12:00 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-07-03 16:21 . 2009-03-28 12:41 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-07-03 16:21 . 2011-06-29 16:58 721000 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-07-03 16:21 . 2009-03-28 12:41 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-07-03 16:21 . 2009-03-28 12:41 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-07-03 16:21 . 2009-03-28 12:41 89624 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-07-03 16:21 . 2009-03-28 12:41 353688 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-07-03 16:21 . 2009-03-28 12:41 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-07-03 16:21 . 2009-03-28 12:41 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-07-03 16:21 . 2010-06-30 20:00 41224 ----a-w- c:\windows\avastSS.scr
2012-07-03 16:21 . 2009-03-28 12:41 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-07-02 17:38 . 2008-04-14 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-07-02 17:38 . 2008-04-14 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-07-02 17:38 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-07-02 12:05 . 2008-04-14 12:00 385024 ------w- c:\windows\system32\html.iec
2012-06-06 18:59 . 2012-06-06 18:59 1070152 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2012-06-05 15:49 . 2008-04-14 12:00 1372672 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:49 . 2008-04-14 12:00 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2008-04-14 12:00 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 13:19 . 2008-10-16 13:07 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2008-10-16 13:08 22552 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2009-03-28 12:00 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2009-03-28 12:00 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-02 13:19 . 2009-03-28 12:00 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2009-03-28 12:00 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2009-03-28 12:00 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 13:19 . 2008-10-16 13:09 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 13:19 . 2008-10-16 13:07 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 13:19 . 2008-10-16 13:07 18456 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2008-04-14 12:00 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 13:19 . 2009-03-28 12:00 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2009-03-28 12:00 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 13:19 . 2009-12-03 06:24 17648 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-06-02 13:18 . 2009-12-03 06:24 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-05-31 13:22 . 2008-04-14 12:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2012-05-29 07:38 . 2011-07-26 15:26 330240 ----a-w- c:\windows\MASetupCaller.dll
2012-07-28 16:44 . 2011-05-01 07:40 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2012-08-16_21.41.24 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-08-17 17:34 . 2012-08-17 17:34 214408 c:\windows\system32\javaws.exe
+ 2012-08-17 17:34 . 2012-08-17 17:34 173960 c:\windows\system32\javaw.exe
+ 2012-08-17 17:34 . 2012-08-17 17:34 173960 c:\windows\system32\java.exe
+ 2012-08-17 17:37 . 2012-08-17 17:37 176640 c:\windows\Installer\471f5e.msi
+ 2012-08-17 17:34 . 2012-08-17 17:34 937984 c:\windows\Installer\471f58.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-07-03 16:21 121528 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GEST"="=" [X]
"RTHDCPL"="RTHDCPL.EXE" [2008-08-26 16851456]
"Lexmark 1200 Series"="c:\program files\Lexmark 1200 Series\lxczbmgr.exe" [2006-07-13 57344]
"pdfFactory Pro Dispatcher v1"="c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis1.exe" [2002-10-30 364544]
"FinePrint Dispatcher v4"="c:\windows\System32\spool\DRIVERS\W32X86\2\fpdisp4.exe" [1999-12-13 303104]
"LogitechCommunicationsManager"="c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [2006-06-26 497200]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam10\QuickCam10.exe" [2006-06-26 614960]
"LVCOMSX"="c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe" [2006-06-26 243248]
"WD Drive Manager"="c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe" [2008-07-24 450560]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2012-06-08 3521464]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-02-14 98304]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-05-04 252136]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2003-8-29 499779]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-2-7 813584]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 11:28 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Documents and Settings\\Karolína\\temp\\TeamViewer3\\TeamViewer.exe"=
"d:\\Miloš\\World of Warcraft\\Launcher.exe"=
"d:\\Miloš\\World of Warcraft\\BackgroundDownloader.exe"=
"d:\\Miloš\\World of Warcraft\\WoW-3.1.2.9901-to-3.1.3.9947-enGB-downloader.exe"=
"d:\\Miloš\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enGB-downloader.exe"=
"d:\\Miloš\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enGB-downloader.exe"=
"d:\\Miloš\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-enGB-downloader.exe"=
"d:\\Miloš\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-enGB-downloader.exe"=
"c:\\Program Files\\THQ\\Dawn of War\\W40k.exe"=
"d:\\Miloš\\World of Warcraft\\WoW-x.x.x.x-4.0.0.12911-EU-Downloader.exe"=
"d:\\Miloš\\StarCraft II\\StarCraft II.exe"=
"d:\\Miloš\\StarCraft II\\Versions\\Base16939\\SC2.exe"=
"d:\\Miloš\\StarCraft II\\Versions\\Base17326\\SC2.exe"=
"c:\\WINDOWS\\system32\\SUPDSvc.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"d:\\Miloš\\StarCraft II\\Versions\\Base18574\\SC2.exe"=
"c:\\Program Files\\THQ\\Dawn of War - Soulstorm\\Soulstorm.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Documents and Settings\\All Users\\Data aplikací\\Battle.net\\Agent\\Agent.524\\Agent.exe"=
"c:\\Documents and Settings\\All Users\\Data aplikací\\Battle.net\\Agent\\Agent.954\\Agent.exe"=
"c:\\Program Files\\Opera\\pluginwrapper\\opera_plugin_wrapper.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"5985:TCP"= 5985:TCP:*:Disabled:Vzdálená správa systému Windows
.
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [29.6.2011 18:58 721000]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [28.3.2009 14:41 353688]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [28.3.2009 14:41 21256]
S2 dgdersvc;Device Error Recovery Service;c:\windows\system32\dgdersvc.exe [25.5.2010 8:44 95568]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [20.3.2010 23:29 233472]
S2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [7.2.2010 14:07 10384]
S2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [24.7.2008 15:22 102400]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [5.4.2012 8:26 250056]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [12.9.2011 17:05 30312]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [10.3.2012 21:45 100368]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [25.5.2010 8:44 18136]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [20.3.2010 23:29 36608]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [11.8.2012 23:30 22344]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [8.5.2012 12:22 113120]
S3 Samsung UPD Service;Samsung UPD Service;c:\windows\system32\SUPDSvc.exe [23.5.2011 20:48 131888]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\drivers\ss_bbus.sys [12.9.2011 17:05 98432]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\drivers\ss_bmdfl.sys [12.9.2011 17:05 14848]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\drivers\ss_bmdm.sys [12.9.2011 17:05 123648]
S3 ss_bserd;SAMSUNG USB Mobile Logging Driver;c:\windows\system32\drivers\ss_bserd.sys [12.9.2011 17:05 100224]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [12.9.2011 17:05 121064]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [12.9.2011 17:05 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [12.9.2011 17:05 136808]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\ssadserd.sys [12.9.2011 17:05 114280]
S4 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [11.8.2012 23:30 655944]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - LBEEPKE
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 05:08]
.
2012-08-17 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\Alwil Software\Avast5\AvastEmUpdate.exe [2012-07-10 16:21]
.
.
------- Doplňkový sken -------
.
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath -
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-17 20:05
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(216)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
Celkový čas: 2012-08-17 20:08:15
ComboFix-quarantined-files.txt 2012-08-17 18:08
ComboFix2.txt 2012-08-16 21:44
ComboFix3.txt 2012-08-15 17:49
ComboFix4.txt 2012-08-12 19:32
.
Před spuštěním: Volných bajtů: 57 275 617 280
Po spuštění: Volných bajtů: 57 255 342 080
.
- - End Of File - - 048272E30BD7A4FAC77D1B31B01A033D

rychlik
nováček
Příspěvky: 49
Registrován: srpen 12
Pohlaví: Muž
Stav:
Offline

Re: problémy při startu, prosím o kontrolu logu

Příspěvekod rychlik » 17 srp 2012 20:22

nemám znova rozbalit ten soubor z letecke posty a zkusit to znova? třeba ten soubor vzal za své při dřívějším pádu combofixu

Uživatelský avatar
bledulka
Level 5
Level 5
Příspěvky: 2242
Registrován: srpen 09
Pohlaví: Žena
Stav:
Offline

Re: problémy při startu, prosím o kontrolu logu

Příspěvekod bledulka » 17 srp 2012 22:16

Zkus to.
Jinak Miliness se tu brzo objeví, ted byl týden mimo dosah pc.

rychlik
nováček
Příspěvky: 49
Registrován: srpen 12
Pohlaví: Muž
Stav:
Offline

Re: problémy při startu, prosím o kontrolu logu

Příspěvekod rychlik » 17 srp 2012 22:34

aha, von byl ten soubor v podadresáři...

Uživatelský avatar
MiliNess
člen BSOD týmu
Master Level 9.5
Master Level 9.5
Příspěvky: 9112
Registrován: říjen 09
Bydliště: Cheb
Pohlaví: Muž
Stav:
Offline

Re: problémy při startu, prosím o kontrolu logu

Příspěvekod MiliNess » 17 srp 2012 22:35

Ahoj, co se týká toho BSOD, tak to způsobuje přímo chybka v ovladači catchme.sys - součást Combofixu (je tam chybná hodnota velikosti hlavičky bloku paměťového fondu)
Chyba se pravděpodobně projeví díky nějakému jinému ovladači (např. filtru antiviru - zde by to mohl být mbam.sys). Pak je nutno Combofix spustit v nouzovém režimu, jak jsi to už dělal.
-každý má svou pravdu a ta se nemusí vždycky shodovat s tvou vlastní
-naše problémy jsou pouze v naší hlavě
-okolní svět není ani dobrý ani špatný, je mu zcela lhostejné, jestli existuješ
-nejdůležitější v životě je láska. Všechno ostatní jsou zbytečnosti

rychlik
nováček
Příspěvky: 49
Registrován: srpen 12
Pohlaví: Muž
Stav:
Offline

Re: problémy při startu, prosím o kontrolu logu

Příspěvekod rychlik » 17 srp 2012 23:32

MiliNess: ok, dík za vysvětlení, je třeba to nějak řešit?

Nový log z combofixu, poté co jsem ho spustil když byl i8042prt.sys opravdu v c:\


ComboFix 12-08-16.01 - Administrator 17.08.2012 23:02:54.7.2 - x86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1790.1414 [GMT 2:00]
Spuštěný z: c:\documents and settings\KarolÝna\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\KarolÝna\Plocha\CFScript.txt
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\drivers\i8042prt.sys . . . chybí !!
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-17 do 2012-08-17 )))))))))))))))))))))))))))))))
.
.
2012-08-17 18:21 . 2012-08-17 18:21 -------- d-----w- c:\program files\Common Files\Java
2012-08-17 18:20 . 2012-08-17 18:19 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-08-17 18:19 . 2012-08-17 18:19 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-08-17 18:19 . 2012-08-17 18:19 -------- d-----w- c:\program files\Java
2012-08-17 18:19 . 2012-08-17 18:19 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Data aplikací\Sun
2012-08-16 20:38 . 2008-04-14 04:51 52096 ----a-w- C:\i8042prt.sys
2012-08-15 18:57 . 2012-08-15 18:57 -------- d-----w- c:\program files\CrystalDiskInfo
2012-08-15 17:24 . 2012-08-15 17:25 -------- d-----w- c:\documents and settings\Administrator
2012-08-12 19:53 . 2012-08-12 19:55 -------- d-----w- c:\program files\WhoCrashed
2012-08-12 05:14 . 2012-06-02 13:18 214256 ----a-w- c:\windows\system32\muweb.dll
2012-08-11 21:30 . 2012-08-11 21:30 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2012-08-11 21:30 . 2012-08-11 21:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-08-11 21:30 . 2012-07-03 11:46 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-11 19:39 . 2012-08-11 19:39 -------- d-----w- c:\documents and settings\All Users\Data aplikací\GFI Software
2012-07-30 22:08 . 2012-07-30 22:08 -------- d-----w- c:\program files\CCleaner
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-17 18:19 . 2012-05-10 17:04 821736 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-08-17 18:19 . 2010-04-19 05:12 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-15 05:08 . 2012-04-05 06:26 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-15 05:08 . 2011-05-26 05:32 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-06 13:58 . 2008-04-14 12:00 78336 ----a-w- c:\windows\system32\browser.dll
2012-07-04 14:05 . 2009-03-28 11:58 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 18:22 . 2008-04-14 12:00 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-07-03 16:21 . 2009-03-28 12:41 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-07-03 16:21 . 2011-06-29 16:58 721000 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-07-03 16:21 . 2009-03-28 12:41 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-07-03 16:21 . 2009-03-28 12:41 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-07-03 16:21 . 2009-03-28 12:41 89624 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-07-03 16:21 . 2009-03-28 12:41 353688 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-07-03 16:21 . 2009-03-28 12:41 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-07-03 16:21 . 2009-03-28 12:41 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-07-03 16:21 . 2010-06-30 20:00 41224 ----a-w- c:\windows\avastSS.scr
2012-07-03 16:21 . 2009-03-28 12:41 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-07-02 17:38 . 2008-04-14 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-07-02 17:38 . 2008-04-14 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-07-02 17:38 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-07-02 12:05 . 2008-04-14 12:00 385024 ------w- c:\windows\system32\html.iec
2012-06-06 18:59 . 2012-06-06 18:59 1070152 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2012-06-05 15:49 . 2008-04-14 12:00 1372672 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:49 . 2008-04-14 12:00 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2008-04-14 12:00 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 13:19 . 2008-10-16 13:07 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2008-10-16 13:08 22552 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2009-03-28 12:00 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2009-03-28 12:00 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-02 13:19 . 2009-03-28 12:00 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2009-03-28 12:00 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2009-03-28 12:00 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 13:19 . 2008-10-16 13:09 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 13:19 . 2008-10-16 13:07 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 13:19 . 2008-10-16 13:07 18456 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2008-04-14 12:00 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 13:19 . 2009-03-28 12:00 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2009-03-28 12:00 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 13:19 . 2009-12-03 06:24 17648 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-06-02 13:18 . 2009-12-03 06:24 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-05-31 13:22 . 2008-04-14 12:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2012-05-29 07:38 . 2011-07-26 15:26 330240 ----a-w- c:\windows\MASetupCaller.dll
2012-07-28 16:44 . 2011-05-01 07:40 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2012-08-16_21.41.24 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-08-17 18:20 . 2012-08-17 18:19 246760 c:\windows\system32\javaws.exe
+ 2012-08-17 18:19 . 2012-08-17 18:19 174056 c:\windows\system32\javaw.exe
+ 2012-08-17 18:19 . 2012-08-17 18:19 174056 c:\windows\system32\java.exe
+ 2012-08-17 18:21 . 2012-08-17 18:21 176128 c:\windows\Installer\812b9.msi
+ 2012-08-17 18:19 . 2012-08-17 18:19 873984 c:\windows\Installer\812a9.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-07-03 16:21 121528 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GEST"="=" [X]
"RTHDCPL"="RTHDCPL.EXE" [2008-08-26 16851456]
"Lexmark 1200 Series"="c:\program files\Lexmark 1200 Series\lxczbmgr.exe" [2006-07-13 57344]
"pdfFactory Pro Dispatcher v1"="c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis1.exe" [2002-10-30 364544]
"FinePrint Dispatcher v4"="c:\windows\System32\spool\DRIVERS\W32X86\2\fpdisp4.exe" [1999-12-13 303104]
"LogitechCommunicationsManager"="c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [2006-06-26 497200]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam10\QuickCam10.exe" [2006-06-26 614960]
"LVCOMSX"="c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe" [2006-06-26 243248]
"WD Drive Manager"="c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe" [2008-07-24 450560]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2012-06-08 3521464]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-02-14 98304]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2003-8-29 499779]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-2-7 813584]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 11:28 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Documents and Settings\\Karolína\\temp\\TeamViewer3\\TeamViewer.exe"=
"d:\\Miloš\\World of Warcraft\\Launcher.exe"=
"d:\\Miloš\\World of Warcraft\\BackgroundDownloader.exe"=
"d:\\Miloš\\World of Warcraft\\WoW-3.1.2.9901-to-3.1.3.9947-enGB-downloader.exe"=
"d:\\Miloš\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enGB-downloader.exe"=
"d:\\Miloš\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enGB-downloader.exe"=
"d:\\Miloš\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-enGB-downloader.exe"=
"d:\\Miloš\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-enGB-downloader.exe"=
"c:\\Program Files\\THQ\\Dawn of War\\W40k.exe"=
"d:\\Miloš\\World of Warcraft\\WoW-x.x.x.x-4.0.0.12911-EU-Downloader.exe"=
"d:\\Miloš\\StarCraft II\\StarCraft II.exe"=
"d:\\Miloš\\StarCraft II\\Versions\\Base16939\\SC2.exe"=
"d:\\Miloš\\StarCraft II\\Versions\\Base17326\\SC2.exe"=
"c:\\WINDOWS\\system32\\SUPDSvc.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"d:\\Miloš\\StarCraft II\\Versions\\Base18574\\SC2.exe"=
"c:\\Program Files\\THQ\\Dawn of War - Soulstorm\\Soulstorm.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Documents and Settings\\All Users\\Data aplikací\\Battle.net\\Agent\\Agent.524\\Agent.exe"=
"c:\\Documents and Settings\\All Users\\Data aplikací\\Battle.net\\Agent\\Agent.954\\Agent.exe"=
"c:\\Program Files\\Opera\\pluginwrapper\\opera_plugin_wrapper.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"5985:TCP"= 5985:TCP:*:Disabled:Vzdálená správa systému Windows
.
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [29.6.2011 18:58 721000]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [28.3.2009 14:41 353688]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [28.3.2009 14:41 21256]
S2 dgdersvc;Device Error Recovery Service;c:\windows\system32\dgdersvc.exe [25.5.2010 8:44 95568]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [20.3.2010 23:29 233472]
S2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [7.2.2010 14:07 10384]
S2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [24.7.2008 15:22 102400]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [5.4.2012 8:26 250056]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [12.9.2011 17:05 30312]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [10.3.2012 21:45 100368]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [25.5.2010 8:44 18136]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [20.3.2010 23:29 36608]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [11.8.2012 23:30 22344]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [8.5.2012 12:22 113120]
S3 Samsung UPD Service;Samsung UPD Service;c:\windows\system32\SUPDSvc.exe [23.5.2011 20:48 131888]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\drivers\ss_bbus.sys [12.9.2011 17:05 98432]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\drivers\ss_bmdfl.sys [12.9.2011 17:05 14848]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\drivers\ss_bmdm.sys [12.9.2011 17:05 123648]
S3 ss_bserd;SAMSUNG USB Mobile Logging Driver;c:\windows\system32\drivers\ss_bserd.sys [12.9.2011 17:05 100224]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [12.9.2011 17:05 121064]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [12.9.2011 17:05 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [12.9.2011 17:05 136808]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\ssadserd.sys [12.9.2011 17:05 114280]
S4 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [11.8.2012 23:30 655944]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - LBEEPKE
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 05:08]
.
2012-08-17 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\Alwil Software\Avast5\AvastEmUpdate.exe [2012-07-10 16:21]
.
.
------- Doplňkový sken -------
.
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath -
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-17 23:15
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(220)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
c:\windows\system32\COMRes.dll
.
Celkový čas: 2012-08-17 23:18:37
ComboFix-quarantined-files.txt 2012-08-17 21:18
ComboFix2.txt 2012-08-17 18:08
ComboFix3.txt 2012-08-16 21:44
ComboFix4.txt 2012-08-15 17:49
ComboFix5.txt 2012-08-17 20:59
.
Před spuštěním: Volných bajtů: 57 022 640 128
Po spuštění: Volných bajtů: 57 003 372 544
.
- - End Of File - - 8A63BAF8CA1054F9E418F09F04E838A6


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 5 hostů