Ahojte. Neviem si dat rady s notebookom. Dufam, ze mi tu niekto pomoze
Kompletne preinstalovanie, by som chcel nechat ako poslednu moznost aby som sa podobnemu problemu druhy krat vyhol.
Za pomoc vopred dakujem.
V kratkom case po nainstalovani poslednych updatoch Visty sa mi neskutocne spomalil comp. Bud zamrzol alebo mu otvorenie aj textoveho suboru trvalo cez 3 minuty. Zaujmave, ze vyuzitie procesora aj fyzickej pamäte bolo na minime.
Ziadny antivir mi nenasiel infekciu ani podobnu haved.
Skusil som vypnut EsetSmartSecurity, ci nesposobuje problemy, kedze je to BETA verzia. Problemy pretrvavali. Po niekolkych vypnutiach a zapnutiach compu, kde som skusal aj vypnut niektore softy spustane pri starte som docielil akurat to,
ze uz sice nie je spomaleny, ale pri spustany niektorych suborov mi namiesto spustenia/otvorenia vypise len hlasku:
"Systém Windows nemôže získať prístup k zadanému zariadeniu, ceste alebo súboru. Možno nemáte príslušné povolenie na prístup k danej položke."
Neviem presne co znamena HIPS, no ked som pozrel protokoly v Esete, nasiel som vela zaznamov typu:
23. 6. 2011 21:16:12 C:\Windows\System32\consent.exe Modify startup settings HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run\internat.exe povolené Automatický režim
alebo
26. 6. 2011 13:42:08 C:\Windows\System32\WerFault.exe Get access to another application C:\Program Files\Mozilla Firefox\firefox.exe prístup čiastočne zablokovaný Interaktívny režim Terminate/suspend another application,Modify state of another application
Prikladam log z ComboFixu
ComboFix 11-06-27.01 - CiBO . 06. 2011 20:07:19.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1051.18.3066.2170 [GMT 2:00]
Running from: c:\users\CiBO\Desktop\ComboFix.exe
AV: ESET Smart Security 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Acer\Acer Bio Protection\PwdFilter.dll
c:\windows\system32\lsprst7.dll
c:\windows\system32\msvcsv60.dll
c:\windows\system32\ssprs.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-05-27 to 2011-06-27 )))))))))))))))))))))))))))))))
.
.
2011-06-27 18:12 . 2011-06-27 18:12 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-06-27 17:46 . 2011-06-27 18:06 -------- d-----w- C:\32788R22FWJFW
2011-06-26 16:18 . 2011-06-26 16:18 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-06-23 19:16 . 2011-06-23 19:16 -------- d-----w- c:\program files\Lavasoft
2011-06-23 19:16 . 2011-06-23 19:16 -------- d-----w- c:\programdata\Lavasoft
2011-06-20 18:17 . 2010-09-06 16:20 125952 ----a-w- c:\windows\system32\srvsvc.dll
2011-06-20 18:17 . 2010-09-06 16:19 17920 ----a-w- c:\windows\system32\netevent.dll
2011-06-20 18:16 . 2009-08-24 11:36 377344 ----a-w- c:\windows\system32\winhttp.dll
2011-06-20 18:16 . 2011-04-14 14:59 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys
2011-06-20 18:16 . 2011-04-21 13:58 273408 ----a-w- c:\windows\system32\drivers\afd.sys
2011-06-20 18:14 . 2011-04-29 13:24 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-20 18:14 . 2011-04-29 13:24 79872 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-20 18:14 . 2011-04-29 13:24 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-06-20 17:21 . 2010-12-20 16:35 563712 ----a-w- c:\windows\system32\oleaut32.dll
2011-06-20 17:21 . 2011-05-02 17:16 739328 ----a-w- c:\windows\system32\inetcomm.dll
2011-06-20 17:21 . 2011-04-29 13:25 146432 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-06-20 17:21 . 2011-04-29 13:25 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-16 19:33 . 2011-06-26 11:57 -------- d-----w- c:\program files\Common Files\Adobe
2011-06-15 18:19 . 2002-12-05 12:12 692224 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iKernel.dll
2011-06-15 18:19 . 2002-12-05 12:10 155648 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iuser.dll
2011-06-15 18:19 . 2002-12-02 13:22 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe
2011-06-15 18:19 . 2002-12-02 11:33 57344 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\ctor.dll
2011-06-15 18:19 . 2002-12-02 11:33 237568 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iscript.dll
2011-06-15 18:19 . 2011-06-15 18:19 282756 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\setup.dll
2011-06-15 18:19 . 2011-06-15 18:19 163972 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iGdi.dll
2011-06-15 16:09 . 2011-04-22 23:25 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-06-15 16:09 . 2011-04-25 15:29 141104 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2011-06-15 16:09 . 2011-04-22 23:35 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-06-14 21:08 . 2011-06-15 01:24 -------- d-----w- C:\divx
2011-06-14 16:39 . 2011-06-14 16:39 -------- d-----w- c:\program files\Common Files\reFX
2011-06-14 16:39 . 2011-06-14 16:39 -------- d-----w- c:\program files\Common Files\Digidesign
2011-06-14 13:35 . 2006-09-22 10:41 25088 ----a-w- c:\windows\system32\drivers\ni_avs.sys
2011-06-14 13:35 . 2006-09-22 10:41 84992 ----a-w- c:\windows\system32\drivers\ni_usb.sys
2011-06-14 11:55 . 2011-06-14 11:55 -------- d-----w- c:\program files\Common Files\Native Instruments
2011-06-13 19:01 . 2011-06-13 19:01 2048 ----a-w- c:\windows\system32\sysprs7.dll
2011-06-13 19:01 . 2011-06-13 19:01 1025 ----a-w- c:\windows\system32\clauth2.dll
2011-06-13 19:01 . 2011-06-13 19:01 1025 ----a-w- c:\windows\system32\clauth1.dll
2011-06-13 18:51 . 2011-06-13 18:51 -------- d-----w- c:\program files\Common Files\KORG
2011-06-13 17:23 . 2002-07-07 22:14 1294336 ----a-w- c:\windows\system32\vorbis.acm
2011-06-13 17:22 . 2011-06-13 17:23 -------- d-----w- c:\program files\Image-Line
2011-06-13 17:22 . 2011-06-13 17:22 -------- d-----w- c:\program files\Outsim
2011-06-12 14:50 . 2011-06-12 14:49 720896 ----a-w- c:\windows\iun6002.exe
2011-06-12 14:40 . 2011-06-12 14:40 -------- d-----w- c:\programdata\Propellerhead Software
2011-06-08 19:05 . 2011-06-08 19:05 -------- d-----w- c:\programdata\Ableton
2011-06-08 19:04 . 2009-11-19 00:57 368640 ----a-w- c:\windows\system32\ReWire.dll
2011-06-08 19:04 . 2009-11-19 00:57 233472 ----a-w- c:\windows\system32\REX Shared Library.dll
2011-06-07 19:28 . 2011-06-07 19:28 -------- d-----w- c:\windows\system32\drivers\UMDF\sk-SK
2011-06-07 19:28 . 2011-06-07 19:28 -------- d-----w- c:\program files\Windows Portable Devices
2011-06-07 19:26 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2011-06-07 19:26 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2011-06-07 19:26 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2011-06-07 19:25 . 2009-10-01 01:02 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2011-06-07 19:25 . 2009-10-01 01:02 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll
2011-06-07 19:25 . 2009-10-01 01:01 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
2011-06-07 19:25 . 2009-10-01 01:01 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2011-06-07 19:25 . 2009-10-01 01:02 2537472 ----a-w- c:\windows\system32\wpdshext.dll
2011-06-07 19:25 . 2009-10-01 01:02 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2011-06-07 19:25 . 2009-10-01 01:02 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll
2011-06-07 19:25 . 2009-10-01 01:01 546816 ----a-w- c:\windows\system32\wpd_ci.dll
2011-06-07 19:25 . 2009-10-01 01:01 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2011-06-07 19:25 . 2009-10-01 01:01 350208 ----a-w- c:\windows\system32\WPDSp.dll
2011-06-07 19:25 . 2009-10-01 01:01 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2011-06-07 19:25 . 2009-10-01 01:01 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2011-06-07 19:23 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2011-06-07 19:23 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2011-06-07 19:23 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
2011-06-07 19:07 . 2011-06-07 19:07 -------- d-----w- c:\program files\Microsoft.NET
2011-06-07 19:05 . 2009-11-08 08:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-06-07 19:05 . 2009-11-08 08:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2011-06-07 19:05 . 2009-11-08 08:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2011-06-07 19:05 . 2009-11-08 08:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2011-06-07 19:05 . 2009-11-08 08:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2011-06-07 18:20 . 2005-05-09 18:08 33792 ----a-w- c:\windows\system32\drivers\cledx.sys
2011-06-07 18:20 . 2002-11-25 12:46 16896 ----a-w- c:\windows\system32\drivers\synasUSB.sys
2011-06-07 18:20 . 2002-11-25 15:36 45056 ----a-w- c:\windows\system32\Synsopos.exe
2011-06-07 18:20 . 1999-12-01 08:40 401462 ----a-w- c:\windows\system32\temp.000
2011-06-07 18:20 . 2005-02-01 02:34 700416 ----a-w- c:\windows\system32\SYNSOACC.dll
2011-06-07 18:20 . 2004-05-10 22:58 147456 ----a-w- c:\windows\system32\SynsoLChk.dll
2011-06-07 18:20 . 2011-06-07 18:20 -------- d-----w- c:\program files\Syncrosoft
2011-06-07 18:20 . 2001-04-09 12:03 17784 ----a-w- c:\windows\system32\drivers\NSynas32.sys
2011-06-04 13:01 . 2011-06-04 13:01 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2011-06-04 12:59 . 2011-06-04 12:59 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2011-06-04 12:59 . 2011-06-04 12:59 519680 ----a-w- c:\windows\system32\d3d11.dll
2011-06-04 12:59 . 2011-06-04 12:59 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2011-06-04 12:59 . 2011-06-04 12:59 252928 ----a-w- c:\windows\system32\dxdiag.exe
2011-06-04 12:59 . 2011-06-04 12:59 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2011-06-04 12:59 . 2011-06-04 12:59 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2011-06-04 12:59 . 2011-06-04 12:59 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2011-06-04 09:12 . 2011-06-04 09:12 -------- d-----w- c:\programdata\Sony Ericsson
2011-06-04 09:04 . 2011-06-14 13:38 -------- d-----w- c:\program files\Mozilla Thunderbird
2011-06-04 08:11 . 2010-05-04 19:13 231424 ----a-w- c:\windows\system32\msshsq.dll
2011-06-02 20:58 . 2011-06-02 20:58 -------- d-----w- c:\program files\Common Files\Java
2011-06-02 20:57 . 2011-06-02 20:57 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-06-02 20:57 . 2011-06-02 20:57 -------- d-----w- c:\program files\Java
2011-06-02 20:27 . 2011-06-02 20:27 -------- d-----w- c:\program files\uTorrent
2011-06-02 20:20 . 2011-06-02 20:20 -------- d-----w- c:\program files\The KMPlayer
2011-06-02 20:05 . 2011-06-02 20:05 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2011-06-02 20:04 . 2011-06-02 20:04 -------- d-----w- c:\program files\Common Files\DivX Shared
2011-06-02 19:56 . 2011-06-02 20:06 -------- d-----w- c:\program files\DivX
2011-06-02 19:54 . 2011-06-02 20:06 -------- d-----w- c:\programdata\DivX
2011-06-02 19:52 . 2011-06-02 19:52 -------- d-----w- c:\program files\Speccy
2011-06-02 19:27 . 2011-06-02 19:27 -------- d-----w- c:\windows\system32\ca-ES
2011-06-02 19:27 . 2011-06-02 19:27 -------- d-----w- c:\windows\system32\eu-ES
2011-06-02 19:27 . 2011-06-02 19:27 -------- d-----w- c:\windows\system32\vi-VN
2011-06-02 18:48 . 2011-06-02 18:48 -------- d-----w- c:\windows\system32\EventProviders
2011-06-02 17:30 . 2011-06-02 17:35 -------- d-----w- c:\program files\Common Files\COWON
2011-06-02 17:30 . 2011-06-02 17:37 -------- d-----w- c:\program files\JetAudio
2011-06-02 17:24 . 2009-04-11 05:03 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2011-06-02 17:24 . 2009-04-11 06:28 1081344 ----a-w- c:\windows\system32\SLCExt.dll
2011-06-02 17:24 . 2009-04-11 06:27 3408896 ----a-w- c:\windows\system32\SLsvc.exe
2011-06-02 17:24 . 2009-04-11 06:28 2134528 ----a-w- c:\windows\system32\FunctionDiscoveryFolder.dll
2011-06-02 17:24 . 2009-04-11 06:27 65536 ----a-w- c:\windows\system32\DevicePairingWizard.exe
2011-06-02 17:24 . 2009-04-11 05:03 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2011-06-02 17:22 . 2009-04-11 06:28 160768 ----a-w- c:\windows\system32\spoolss.dll
2011-06-02 17:20 . 2009-04-11 06:28 58880 ----a-w- c:\windows\system32\iasacct.dll
2011-06-02 17:19 . 2009-04-11 06:28 61952 ----a-w- c:\windows\system32\wbem\xml\wmi2xml.dll
2011-06-02 17:18 . 2009-04-11 06:28 705536 ----a-w- c:\windows\system32\SmiEngine.dll
2011-06-02 17:18 . 2009-04-11 06:28 218624 ----a-w- c:\windows\system32\wdscore.dll
2011-06-02 17:18 . 2009-04-11 06:27 130560 ----a-w- c:\windows\system32\PkgMgr.exe
2011-06-02 17:17 . 2009-04-11 06:28 247808 ----a-w- c:\windows\system32\drvstore.dll
2011-06-02 16:59 . 2011-06-26 13:04 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-06-02 16:59 . 2011-06-02 17:03 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-06-02 16:50 . 2011-06-02 16:50 -------- d-----w- c:\program files\PowerISO
2011-06-02 16:45 . 2010-09-13 13:56 168960 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2011-06-02 16:45 . 2009-07-15 12:39 107520 ----a-w- c:\program files\Windows Media Player\wmpconfig.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-04 13:02 . 2011-06-04 13:02 203776 ----a-w- c:\windows\system32\webcheck.dll
2011-06-04 12:59 . 2011-06-04 12:59 4096 ----a-w- c:\windows\system32\drivers\sk-SK\dxgkrnl.sys.mui
2011-04-27 11:09 . 2011-04-27 11:09 161864 ----a-w- c:\windows\system32\drivers\eamonm.sys
2011-04-20 07:47 . 2011-04-20 07:47 45456 ----a-w- c:\windows\system32\drivers\epfwwfp.sys
2011-04-20 07:47 . 2011-04-20 07:47 31072 ----a-w- c:\windows\system32\drivers\EpfwLWF.sys
2011-04-20 07:47 . 2011-04-20 07:47 143872 ----a-w- c:\windows\system32\drivers\epfw.sys
2011-04-20 07:47 . 2011-04-20 07:47 118104 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2011-04-09 16:36 . 2011-04-09 16:36 10752 ----a-w- c:\windows\system32\drivers\loopbe1.sys
2011-06-21 15:46 . 2011-06-02 16:06 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-05-10 2474624]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-08-01 405504]
"H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-05-11 200069]
"PLFSetI"="c:\windows\PLFSetI.exe" [2008-07-29 200704]
"ProductReg"="c:\program files\Acer\WR_PopUp\ProductReg.exe" [2008-09-23 6144]
"Skytel"="Skytel.exe" [2007-11-21 1826816]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-2-12 723496]
LoopBe1 Monitor.lnk - d:\program files\LoopBe1\loopBeMon.exe [2011-4-9 273024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000]
2011-06-01 16:16 3167744 ----a-w- c:\program files\Acer\Acer Bio Protection\WinNotify.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\spba]
2008-03-25 13:24 567560 ----a-w- c:\program files\Common Files\SPBA\homefus2.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 10:55 937920 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-06-06 10:55 35736 ----a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BkupTray]
2008-04-06 20:42 34040 ----a-w- c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-03-21 18:56 1230704 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
2008-07-25 03:48 875016 ----a-w- c:\progra~1\LAUNCH~1\LManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2008-05-21 02:06 6144000 ----a-w- c:\windows\RtHDVCpl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 09:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2008-02-22 19:50 1037608 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZPdtWzdVitaKey MC3000]
2011-06-01 16:16 3724800 ----a-w- c:\program files\Acer\Acer Bio Protection\PdtWzd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiSpywareOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 ESHASRV;ESET SHA Service;c:\program files\ESET\ESET Smart Security\EShaSrv.exe [2011-04-20 183904]
R3 TpChoice;Touch Pad Detection Filter driver;c:\windows\system32\DRIVERS\TpChoice.sys [2007-12-26 17968]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 AlfaFF;AlfaFF File System mini-filter;c:\windows\system32\Drivers\AlfaFF.sys [2011-06-01 42608]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2011-04-20 45456]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2011-04-20 118104]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys [2011-04-20 31072]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2011-04-27 161864]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2011-04-20 958464]
S2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-03-21 24576]
S2 IGBASVC;iGroupTec Service;c:\program files\Acer\Acer Bio Protection\BASVC.exe [2011-06-01 3566080]
S2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-06 50424]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-04 131072]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-17 11032]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2008-03-28 210432]
S3 CLEDX;Team H2O CLEDX service;c:\windows\system32\DRIVERS\cledx.sys [2005-05-09 33792]
S3 NETw5v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-04-28 3658752]
S3 O2MDRDR;O2MDRDR;c:\windows\system32\DRIVERS\o2media.sys [2008-04-15 51160]
S3 O2SDRDR;O2SDRDR;c:\windows\system32\DRIVERS\o2sd.sys [2008-04-08 43736]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.sk/
mStart Page =
hxxp://homepage.acer.com/rdr.aspx?b=ACA ... lmate_5730
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.15.1 213.151.236.66 213.151.236.74
FF - ProfilePath - c:\users\CiBO\AppData\Roaming\Mozilla\Firefox\Profiles\k2rcznv5.default\
FF - prefs.js: browser.startup.homepage -
www.google.sk
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-eRecoveryService - (no file)
MSConfigStartUp-SUPERAntiSpyware - c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
AddRemove-Native Instruments - Rig Kontrol 2 Driver - d:\program files\Native Instruments\Guitar Rig 2\DXi\Rig Kontrol 2 Driver\uninst.exe Software\Native Instruments\Rig Kontrol 2 Driver\Setup
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-06-27 20:14
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(3528)
c:\windows\system32\btncopy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\SPBA\upeksvr.exe
c:\program files\Acer\Acer Bio Protection\CompPtcVUI.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\acer\Mobility Center\MobilityService.exe
c:\program files\O2Micro Flash Memory Card Driver\o2flash.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\system32\conime.exe
.
**************************************************************************
.
Completion time: 2011-06-27 20:18:01 - machine was rebooted
ComboFix-quarantined-files.txt 2011-06-27 18:17
.
Pre-Run: 28 123 435 008 bytes free
Post-Run: 27 817 582 592 bytes free
.
- - End Of File - - F9B4059FFEC3C9101176600F7F0C3A74