Explorer.exe - Win Vista 32

Operační systémy Windows 98, 2000, XP, 2003, Vista a další.

Moderátor: Loki5567

Pravidla fóra
Vše okolo nového systému Windows 8 se řeší jen a pouze v PODSEKCI (klik), ostatní se přesouvá nebo zamyká.
Odpovědět
Drastic
Nováček
Nováček
Registrován: 28. dub 2010

Explorer.exe - Win Vista 32

Příspěvek od Drastic »

Ahoj, mám problém, program explorer který spuští plochu se mi nechce automaticky po spuštění PC zapnout, jen se mi objeví černá plocha a složka dokumenty a já si přes ni musím zajed do windows a manuálně ho spustít, nevíte co stím je?? Mám OS Vistu 32
Bez_n1ck
Pokročilý
Pokročilý
Uživatelský avatar
Registrován: 15. pro 2006
Bydliště: Praha - Vinohrady

Re: Explorer.exe

Příspěvek od Bez_n1ck »

zaplať za to co používáš ;)
PC: MB: ASUS TUF Z370-PRO GAMING ; CPU: INTEL Core i7-8700K @ 3,7GHz ; CPUcooler: Noctua NH-D14 ; GPU: GIGABYTE GTX2070 WINDFORCE 3X 8GB ; DDR4: 2x16 GB 2666MHz CL16 ; HDD: Samsung 960 EVO M.2 500GB + WD Green 2,5TB + WD Red 4TB + 2xWD Red 8TB ; CASE: Be Quiet! Dark Base 900 ; PSU: Corsair RM650x ; MOUSE: Logitech G700s ; KEYBOARD: Razer Huntsman Elite ; SOUND: Logitech X530 ; MONITOR: 2x Dell U2515H (25" QHD IPS) | Games, that you can play with me | Diablo III - Divina
NOTEBOOK: Dell Precision 7730 ; CPU: Intel Core i7-8750H ; GPU: nVidia Quadro P4200 8GB ; DDR4: 2x16GB 2667MHz ; HDD: Samsung NVMe 256GB + Samsung 980 EVO M.2 1TB ; FullHD
Drastic
Nováček
Nováček
Registrován: 28. dub 2010

Re: Explorer.exe

Příspěvek od Drastic »

V klidu, mám origo OS, sice to je tak asi jediné co mám zaplacené ale mám!!!
zombux
Odborník PCT
Odborník PCT
Uživatelský avatar
Registrován: 05. čer 2003
Bydliště: sluníčkář a havloid z pražské lumpenkavárny

Re: Explorer.exe

Příspěvek od zombux »

dej sem výpis HijackThis, eventuelně bych to projel ComboFixem
ignorelist: kremrole a dezoláti
Drastic
Nováček
Nováček
Registrován: 28. dub 2010

Re: Explorer.exe

Příspěvek od Drastic »

jestli se v tom vyznáš...

Kód: Vybrat vše

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:34:35, on 28.4.2010
Platform: Windows Vista  (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.17037)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\mobsync.exe
C:\Windows\explorer.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\OSCAR Editor\OscarEditor.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Safari\Safari.exe
C:\Windows\system32\conime.exe
C:\Users\MaRaS\Downloads\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\MaRaS\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: (no name) -  - (no file)
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\csrss.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\MaRaS\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [recinfo613] c:\RecInfo\RecInfo.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [recinfo] RecInfo.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKCU\..\Run: [fsc-reg] C:\ProgramData\fsc-reg\fscreg.exe 20100409
O4 - HKCU\..\Run: [EPSON SX100 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIEDE.EXE /FU "C:\Windows\TEMP\E_S956C.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [OscarEditor] "C:\Program Files\OSCAR Editor\OscarEditor.exe" Minimum
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: Download Using &BitSpirit - C:\Program Files\BitSpirit\bsurl.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O13 - Gopher Prefix: 
O15 - Trusted Zone: http://software.kuaiche.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe

--
End of file - 8022 bytes
zombux
Odborník PCT
Odborník PCT
Uživatelský avatar
Registrován: 05. čer 2003
Bydliště: sluníčkář a havloid z pražské lumpenkavárny

Re: Explorer.exe

Příspěvek od zombux »

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\csrss.exe

tohle rozhodně v pořádku není, takže to fixni a restartuj, pak stáhni ComboFix, nech ho projet systém, a až vyhodí log, zas ho sem dej.
ignorelist: kremrole a dezoláti
Drastic
Nováček
Nováček
Registrován: 28. dub 2010

Re: Explorer.exe

Příspěvek od Drastic »

Tady...tak plocha po restartu naběhla, tak uvidíme...jinak díky moc za rady ;)

Kód: Vybrat vše

ComboFix 10-04-28.03 - MaRaS 28.04.2010  22:58:17.3.4 - x86
Spuštěný z: c:\users\MaRaS\Downloads\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
SP: ESET Smart Security 3.0 *disabled* (Updated) {E5E70D32-0101-4B98-A4D6-D1D15C3BB448}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
 * Rezidentní štít AV je zapnutý

.

(((((((((((((((((((((((((((((((((((((((   Ostatní výmazy   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\$recycle.bin\S-1-5-21-2177344061-1213171447-1916667378-500
c:\users\MaRaS\AppData\Roaming\BITS
c:\users\MaRaS\AppData\Roaming\BITS\BITS.ini
c:\users\MaRaS\AppData\Roaming\FlashGetBHO
c:\users\MaRaS\AppData\Roaming\FlashGetBHO\FlashGetBHO3.dll
c:\users\MaRaS\AppData\Roaming\FlashGetBHO\FlashGetHook.dll
c:\users\MaRaS\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
c:\users\MaRaS\AppData\Roaming\FlashGetBHO\GetUrl.htm

.
(((((((((((((((((((((((((   Soubory vytvořené od 2010-03-28 do 2010-04-28  )))))))))))))))))))))))))))))))
.

2010-04-28 21:04 . 2010-04-28 21:04	--------	d-----w-	c:\users\MaRaS\AppData\Local\temp
2010-04-28 21:04 . 2010-04-28 21:04	--------	d-----w-	c:\users\Default\AppData\Local\temp
2010-04-28 20:49 . 2010-04-28 20:49	320000	----a-w-	c:\windows\system32\CF1298.exe
2010-04-28 20:48 . 2010-04-28 20:46	320000	----a-w-	c:\windows\system32\CF602.exe
2010-04-28 20:36 . 2010-04-28 20:36	320000	----a-w-	c:\windows\system32\CF31417.exe
2010-04-28 18:46 . 2010-04-28 18:46	320000	----a-w-	c:\windows\system32\CF9878.exe
2010-04-28 18:43 . 2010-04-28 18:43	320000	----a-w-	c:\windows\system32\CF9385.exe
2010-04-28 17:43 . 2010-04-28 17:43	320000	----a-w-	c:\windows\system32\CF30370.exe
2010-04-28 17:42 . 2010-04-28 17:40	320000	----a-w-	c:\windows\system32\CF29776.exe
2010-04-28 15:44 . 2010-04-28 15:44	--------	d-----w-	c:\programdata\Uniblue
2010-04-28 15:42 . 2010-04-28 15:42	--------	d-----w-	c:\users\MaRaS\AppData\Roaming\Uniblue
2010-04-24 18:29 . 2010-04-24 18:29	--------	d-----w-	c:\users\MaRaS\AppData\Local\PokerStars
2010-04-24 18:28 . 2010-04-24 19:25	--------	d-----w-	c:\program files\PokerStars
2010-04-23 20:47 . 2010-04-23 20:47	--------	d-----w-	c:\program files\Driver-Soft
2010-04-20 21:14 . 2010-04-12 15:29	411368	----a-w-	c:\windows\system32\deployJava1.dll
2010-04-19 16:10 . 2010-04-19 16:10	--------	d-----w-	c:\programdata\AltrixSoft
2010-04-15 14:58 . 2010-04-15 14:58	1184	----a-w-	c:\windows\system32\ealregsnapshot1.reg
2010-04-15 14:57 . 2010-04-15 14:57	--------	d-----w-	c:\users\MaRaS\AppData\Local\Downloaded Installations
2010-04-15 14:48 . 2010-04-15 14:48	--------	d-----w-	c:\program files\EA Games
2010-04-15 05:00 . 2010-02-23 11:30	58368	----a-w-	c:\windows\system32\drivers\mrxsmb20.sys
2010-04-15 05:00 . 2010-02-23 11:30	102912	----a-w-	c:\windows\system32\drivers\mrxsmb.sys
2010-04-15 05:00 . 2010-02-23 11:30	211968	----a-w-	c:\windows\system32\drivers\mrxsmb10.sys
2010-04-15 05:00 . 2010-02-18 14:54	3502480	----a-w-	c:\windows\system32\ntkrnlpa.exe
2010-04-15 05:00 . 2010-02-18 14:54	3468168	----a-w-	c:\windows\system32\ntoskrnl.exe
2010-04-15 05:00 . 2010-03-04 19:24	434176	----a-w-	c:\windows\system32\vbscript.dll
2010-04-15 04:59 . 2010-02-18 11:51	818688	----a-w-	c:\windows\system32\drivers\tcpip.sys
2010-04-15 04:59 . 2010-02-18 14:34	213896	----a-w-	c:\windows\system32\drivers\netio.sys
2010-04-15 04:59 . 2010-02-18 12:04	25088	----a-w-	c:\windows\system32\drivers\tunnel.sys
2010-04-15 04:59 . 2010-02-18 14:19	179712	----a-w-	c:\windows\system32\iphlpsvc.dll
2010-04-15 04:59 . 2010-02-18 13:56	416768	----a-w-	c:\windows\system32\IKEEXT.DLL
2010-04-15 04:59 . 2010-02-18 13:55	317440	----a-w-	c:\windows\system32\BFE.DLL
2010-04-15 04:59 . 2010-02-18 11:50	85504	----a-w-	c:\windows\system32\drivers\FWPKCLNT.SYS
2010-04-15 04:59 . 2010-02-18 13:56	543232	----a-w-	c:\windows\system32\FWPUCLNT.DLL
2010-04-15 04:59 . 2010-02-18 11:51	22016	----a-w-	c:\windows\system32\netiougc.exe
2010-04-15 04:59 . 2010-02-18 14:01	167424	----a-w-	c:\windows\system32\tcpipcfg.dll
2010-04-15 04:59 . 2010-02-18 12:04	15360	----a-w-	c:\windows\system32\drivers\TUNMP.SYS
2010-04-14 05:48 . 2009-12-23 12:45	171520	----a-w-	c:\windows\system32\wintrust.dll
2010-04-14 05:48 . 2010-01-13 18:23	97792	----a-w-	c:\windows\system32\cabview.dll
2010-04-13 13:52 . 2010-02-16 07:31	1647984	----a-w-	c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20100412.003\NAVEX32A.DLL
2010-04-13 13:52 . 2010-02-16 07:31	84912	----a-w-	c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20100412.003\NAVENG.SYS
2010-04-13 13:52 . 2010-02-16 07:31	177520	----a-w-	c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20100412.003\NAVENG32.DLL
2010-04-13 13:52 . 2010-02-16 07:31	1324720	----a-w-	c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20100412.003\NAVEX15.SYS
2010-04-13 13:52 . 2010-02-16 07:31	102448	----a-w-	c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20100412.003\ERASER.SYS
2010-04-13 13:52 . 2010-02-16 07:31	371248	----a-w-	c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20100412.003\EECTRL.SYS
2010-04-10 15:17 . 2010-04-10 15:19	--------	d-----w-	c:\program files\Pixarra
2010-04-03 10:13 . 2010-04-03 10:13	107888	----a-w-	c:\windows\system32\CmdLineExt.dll
2010-04-03 10:10 . 2010-04-03 10:10	--------	d-----w-	c:\users\MaRaS\AppData\Local\ESET
2010-04-02 17:37 . 2010-04-02 17:31	754984	----a-w-	c:\programdata\DivX\Setup\Resource.dll
2010-04-02 17:37 . 2010-04-02 17:31	986904	----a-w-	c:\programdata\DivX\Setup\DivXSetup.exe
2010-04-02 17:37 . 2010-04-02 17:37	56766	----a-w-	c:\programdata\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-04-02 17:37 . 2010-04-02 17:37	56978	----a-w-	c:\programdata\DivX\WebPlayer\Uninstaller.exe
2010-04-02 17:37 . 2010-04-02 17:37	53600	----a-w-	c:\programdata\DivX\Update\Uninstaller.exe
2010-04-02 17:37 . 2010-04-02 17:37	57677	----a-w-	c:\programdata\DivX\Player\Uninstaller.exe
2010-04-02 17:37 . 2010-04-19 14:45	--------	d-----w-	c:\users\MaRaS\AppData\Roaming\DivX
2010-04-02 17:31 . 2010-04-02 17:37	--------	d-----w-	c:\program files\DivX
2010-04-02 17:31 . 2010-04-02 17:37	--------	d-----w-	c:\programdata\DivX
2010-04-02 13:36 . 2010-04-02 13:36	--------	d-----w-	c:\windows\1C4551A64743409391E41477CD655043.TMP

.
((((((((((((((((((((((((((((((((((((((((   Find3M výpis   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-28 19:24 . 2010-03-16 16:10	138592	----a-w-	c:\windows\system32\drivers\PnkBstrK.sys
2010-04-28 19:23 . 2010-03-16 16:10	219128	----a-w-	c:\windows\system32\PnkBstrB.exe
2010-04-28 16:34 . 2010-03-05 14:27	--------	d-----w-	c:\users\MaRaS\AppData\Roaming\ICQ
2010-04-28 16:13 . 2010-03-06 12:57	--------	d-----w-	c:\program files\Ubisoft
2010-04-28 16:13 . 2010-03-05 14:20	--------	d--h--w-	c:\program files\InstallShield Installation Information
2010-04-28 16:13 . 2010-03-06 13:17	--------	d-----w-	c:\programdata\Ubisoft
2010-04-25 18:11 . 2010-03-16 15:48	--------	d-----w-	c:\program files\Activision
2010-04-24 18:05 . 2010-03-07 20:43	--------	d-----w-	c:\users\MaRaS\AppData\Roaming\Skype
2010-04-24 18:05 . 2010-03-07 20:45	--------	d-----w-	c:\users\MaRaS\AppData\Roaming\skypePM
2010-04-24 07:30 . 2008-02-08 12:05	81198	----a-w-	c:\windows\system32\perfc005.dat
2010-04-24 07:30 . 2008-02-08 12:05	473360	----a-w-	c:\windows\system32\perfh005.dat
2010-04-20 21:14 . 2010-03-05 14:03	--------	d-----w-	c:\program files\Java
2010-04-16 05:46 . 2006-11-02 11:18	--------	d-----w-	c:\program files\Windows Mail
2010-04-16 05:03 . 2010-03-05 10:01	--------	d-----w-	c:\programdata\Microsoft Help
2010-04-13 13:52 . 2010-04-10 15:57	--------	d-----w-	c:\program files\Common Files\Symantec Shared
2010-04-12 15:39 . 2010-03-28 16:50	--------	d-----w-	c:\users\MaRaS\AppData\Roaming\TS3Client
2010-04-12 15:25 . 2010-04-12 14:03	--------	d-----w-	c:\program files\OSCAR Editor
2010-04-12 14:13 . 2010-04-12 14:13	8854	----a-r-	c:\users\MaRaS\AppData\Roaming\Microsoft\Installer\{361693F2-A153-4359-A4CB-A1B9FF2AA5E6}\UNINST_Uninstall_A_361693F2A1534359A4CBA1B9FF2AA5E6.exe
2010-04-12 14:13 . 2010-04-12 14:13	45056	----a-r-	c:\users\MaRaS\AppData\Roaming\Microsoft\Installer\{361693F2-A153-4359-A4CB-A1B9FF2AA5E6}\Witness.exe1_361693F2A1534359A4CBA1B9FF2AA5E6.exe
2010-04-12 14:13 . 2010-04-12 14:13	45056	----a-r-	c:\users\MaRaS\AppData\Roaming\Microsoft\Installer\{361693F2-A153-4359-A4CB-A1B9FF2AA5E6}\Witness.exe_361693F2A1534359A4CBA1B9FF2AA5E6.exe
2010-04-12 14:13 . 2010-04-12 14:13	10134	----a-r-	c:\users\MaRaS\AppData\Roaming\Microsoft\Installer\{361693F2-A153-4359-A4CB-A1B9FF2AA5E6}\ARPPRODUCTICON.exe
2010-04-12 14:13 . 2010-04-12 14:13	--------	d-----w-	c:\program files\A4TECH
2010-04-12 14:02 . 2010-04-12 14:02	--------	d-----w-	c:\program files\OscarX7
2010-04-02 13:36 . 2010-03-17 18:23	--------	d-----w-	c:\program files\Common Files\Wise Installation Wizard
2010-04-02 09:19 . 2010-03-05 14:03	--------	d-----w-	c:\program files\Common Files\Java
2010-03-29 06:15 . 2010-03-29 06:15	86016	----a-w-	c:\windows\system32\frapsvid.dll
2010-03-28 17:39 . 2010-03-06 15:10	--------	d-----w-	c:\programdata\Symantec
2010-03-28 16:48 . 2010-03-28 16:48	--------	d-----w-	c:\program files\TeamSpeak 3 Client
2010-03-27 23:34 . 2010-03-27 23:34	--------	d-----w-	c:\program files\THQ
2010-03-25 22:12 . 2008-02-09 01:55	--------	d-----w-	c:\program files\ATI
2010-03-25 22:04 . 2010-03-25 22:04	--------	d-----w-	c:\programdata\ATI
2010-03-25 22:04 . 2008-02-09 01:55	--------	d-----w-	c:\program files\ATI Technologies
2010-03-25 07:32 . 2010-03-25 07:32	--------	d-----w-	c:\program files\Recuva
2010-03-25 07:15 . 2010-03-25 07:15	--------	d-----w-	c:\program files\SQUARE ENIX - Eidos Interactive
2010-03-23 21:02 . 2010-03-23 21:02	--------	d-----w-	c:\programdata\salvation
2010-03-23 20:57 . 2010-03-23 20:57	418480	----a-w-	c:\windows\system32\wrap_oal.dll
2010-03-23 20:57 . 2010-03-23 20:57	115432	----a-w-	c:\windows\system32\OpenAL32.dll
2010-03-23 20:57 . 2010-03-23 20:57	--------	d-----w-	c:\program files\OpenAL
2010-03-23 20:50 . 2010-03-23 20:50	--------	d-----w-	c:\program files\Evolved Games
2010-03-22 15:54 . 2010-03-16 16:10	75064	----a-w-	c:\windows\system32\PnkBstrA.exe
2010-03-21 20:07 . 2010-03-21 19:54	--------	d-----w-	c:\program files\GamePark
2010-03-21 20:04 . 2010-03-21 20:04	--------	d-----w-	c:\program files\Zaparit
2010-03-21 09:39 . 2010-03-17 18:12	--------	d-----w-	c:\program files\METRO 2033
2010-03-20 17:14 . 2010-03-05 09:52	102816	----a-w-	c:\users\MaRaS\AppData\Local\GDIPFONTCACHEV1.DAT
2010-03-20 17:03 . 2010-03-20 17:03	--------	d-----w-	c:\program files\Electronic Arts
2010-03-20 16:28 . 2010-03-20 16:28	--------	d-----w-	c:\program files\Kodek CZ
2010-03-20 16:16 . 2010-03-20 16:12	--------	d-----w-	c:\program files\AVS4YOU
2010-03-20 16:16 . 2010-03-20 16:13	--------	d-----w-	c:\program files\Common Files\AVSMedia
2010-03-20 16:14 . 2010-03-20 16:14	--------	d-----w-	c:\programdata\AVS4YOU
2010-03-20 16:08 . 2010-03-20 16:08	--------	d-----w-	c:\users\MaRaS\AppData\Roaming\Media Player Classic
2010-03-19 14:38 . 2010-03-19 14:32	--------	d-----w-	c:\users\MaRaS\AppData\Roaming\Prison Break
2010-03-19 14:35 . 2010-03-19 14:35	281760	----a-w-	c:\windows\system32\drivers\atksgt.sys
2010-03-19 14:35 . 2010-03-19 14:35	25888	----a-w-	c:\windows\system32\drivers\lirsgt.sys
2010-03-19 14:27 . 2010-03-19 14:27	--------	d-----w-	c:\program files\Deep Silver
2010-03-19 14:08 . 2006-11-02 12:37	--------	d-----w-	c:\program files\MSBuild
2010-03-19 14:01 . 2010-03-19 14:01	--------	d-----w-	c:\program files\Microsoft Visual Studio 8
2010-03-17 18:24 . 2010-03-17 18:24	--------	d-----w-	c:\program files\NVIDIA Corporation
2010-03-16 20:59 . 2010-03-16 20:56	--------	d-----w-	c:\program files\Common Files\Macromedia
2010-03-16 20:57 . 2010-03-16 20:56	--------	d-----w-	c:\program files\Macromedia
2010-03-16 20:56 . 2010-03-16 20:56	45056	----a-r-	c:\users\MaRaS\AppData\Roaming\Microsoft\Installer\{885A63EA-382B-4DD4-A755-14809B8557D6}\ARPPRODUCTICON.exe
2010-03-16 20:55 . 2010-03-05 14:43	--------	d-----w-	c:\program files\Common Files\InstallShield
2010-03-16 20:17 . 2010-03-16 20:15	--------	d-----w-	c:\program files\The KMPlayer
2010-03-16 16:10 . 2010-03-16 16:10	22328	----a-w-	c:\users\MaRaS\AppData\Roaming\PnkBstrK.sys
2010-03-16 16:10 . 2010-03-16 16:10	22328	----a-w-	c:\users\MaRaS\AppData\Roaming\PnkBstrK.sys
2010-03-15 22:05 . 2010-03-15 22:05	--------	d-----w-	c:\program files\Bethesda Softworks
2010-03-15 20:07 . 2010-03-15 20:07	305	----a-w-	c:\windows\system32\secushr.dat
2010-03-15 20:06 . 2010-03-15 20:06	--------	d-----w-	c:\users\MaRaS\AppData\Roaming\FlashGet
2010-03-14 17:38 . 2010-03-14 17:38	--------	d-----w-	c:\program files\FlashFXP
2010-03-14 17:38 . 2010-03-14 17:38	--------	d-----w-	c:\programdata\FlashFXP
2010-03-13 16:46 . 2010-03-05 14:00	--------	d-----w-	c:\program files\Safari
2010-03-13 16:44 . 2010-03-13 16:44	79144	----a-w-	c:\programdata\Apple Computer\Installer Cache\Safari 5.31.22.7\SetupAdmin.exe
2010-03-13 13:12 . 2010-03-13 13:11	--------	d-----w-	c:\program files\Microsoft Games for Windows - LIVE
2010-03-13 12:56 . 2010-03-13 12:56	--------	d-----w-	c:\program files\7-Zip
2010-03-09 20:39 . 2010-03-09 20:39	--------	d-----w-	c:\users\MaRaS\AppData\Roaming\EPSON
2010-03-09 16:54 . 2010-03-31 05:59	832512	----a-w-	c:\windows\system32\wininet.dll
2010-03-09 16:50 . 2010-03-31 05:59	56320	----a-w-	c:\windows\system32\iesetup.dll
2010-03-09 16:50 . 2010-03-31 05:59	78336	----a-w-	c:\windows\system32\ieencode.dll
2010-03-09 16:50 . 2010-03-31 05:59	52736	----a-w-	c:\windows\AppPatch\iebrshim.dll
2010-03-09 16:48 . 2010-03-31 05:59	72704	----a-w-	c:\windows\system32\admparse.dll
2010-03-09 14:17 . 2010-03-31 05:59	26624	----a-w-	c:\windows\system32\ieUnatt.exe
2010-03-09 12:43 . 2010-03-31 05:59	48128	----a-w-	c:\windows\system32\mshtmler.dll
2010-03-09 06:06 . 2010-03-09 06:06	268800	----a-w-	c:\windows\system32\es.dll
2010-03-08 17:59 . 2010-03-08 17:59	94208	----a-w-	c:\windows\system32\dpl100.dll
2010-03-07 20:45 . 2010-03-07 20:45	56	---ha-w-	c:\programdata\ezsidmv.dat
2010-03-07 20:43 . 2010-03-07 20:43	--------	d-----w-	c:\program files\Common Files\Skype
2010-03-07 20:43 . 2010-03-07 20:43	--------	d-----r-	c:\program files\Skype
2010-03-07 20:43 . 2010-03-07 20:42	--------	d-----w-	c:\programdata\Skype
2010-03-07 14:59 . 2006-11-02 10:25	665600	----a-w-	c:\windows\inf\drvindex.dat
2010-03-07 11:45 . 2010-03-07 11:45	34304	----a-w-	c:\windows\system32\atmlib.dll
2010-03-07 11:45 . 2010-03-07 11:45	289792	----a-w-	c:\windows\system32\atmfd.dll
2010-03-07 11:45 . 2010-03-07 11:45	24064	----a-w-	c:\windows\system32\lpk.dll
2010-03-07 11:45 . 2010-03-07 11:45	156672	----a-w-	c:\windows\system32\t2embed.dll
2010-03-07 11:45 . 2010-03-07 11:45	10240	----a-w-	c:\windows\system32\dciman32.dll
2010-03-07 11:45 . 2010-03-07 11:45	72704	----a-w-	c:\windows\system32\fontsub.dll
2010-03-07 11:40 . 2010-03-07 11:40	61440	----a-w-	c:\windows\system32\winipsec.dll
2010-03-07 11:40 . 2010-03-07 11:40	361984	----a-w-	c:\windows\system32\IPSECSVC.DLL
2010-03-07 11:40 . 2010-03-07 11:40	28672	----a-w-	c:\windows\system32\FwRemoteSvr.dll
2010-03-07 11:40 . 2010-03-07 11:40	272896	----a-w-	c:\windows\system32\polstore.dll
2010-03-07 11:38 . 2010-03-07 11:38	84992	----a-w-	c:\windows\system32\drivers\srvnet.sys
2010-03-07 11:38 . 2010-03-07 11:38	307200	----a-w-	c:\windows\system32\drivers\srv.sys
.

((((((((((((((((((((((((((((((((((   Spouštěcí body v registru   )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny. 
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]

[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-02-04 15:50	1197448	----a-w-	c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"fsc-reg"="c:\programdata\fsc-reg\fscreg.exe" [2007-11-08 519440]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
"OscarEditor"="c:\program files\OSCAR Editor\OscarEditor.exe" [2009-11-24 2642432]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-12-17 4718592]
"recinfo613"="c:\recinfo\RecInfo.exe" [2007-10-23 2764800]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-02-26 153136]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-03-01 1443072]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-03-02 98304]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-03-05 1135912]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-03-06 691696]
R3 GarenaPEngine;GarenaPEngine;c:\users\MaRaS\AppData\Local\Temp\LKM5DFE.tmp [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-03-03 172032]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2008-10-19 222456]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [2010-03-03 5340160]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-03-03 152064]
S3 MouseCap;MouseCapture Driver;c:\windows\system32\Drivers\MouseCap.sys [2005-08-08 6640]

.
Obsah adresáře 'Naplánované úlohy'

2010-04-24 c:\windows\Tasks\Norton Security Scan for MaRaS.job
- c:\program files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-03-06 10:50]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
uDefault_Search_URL = hxxp://search.qip.ru
uInternet Settings,ProxyOverride = *.local
IE: Download Using &BitSpirit - c:\program files\BitSpirit\bsurl.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: ÓñČĚŘľ«ÁéĎÂÔŘ(&B)
Trusted Zone: kuaiche.com\software
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKLM-Run-recinfo - RecInfo.exe
AddRemove-Tow Truck Simulator 2010_is1 - c:\program files\astragon Software GmbH\Tow Truck Simulator 2010\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-28 23:04
Windows 6.0.6000  NTFS

skenování skrytých procesů ...  

skenování skrytých položek 'Po spuštění' ... 

skenování skrytých souborů ...  

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\users\MaRaS\AppData\Local\Temp\LKM5DFE.tmp"
.
Celkový čas: 2010-04-28  23:06:31
ComboFix-quarantined-files.txt  2010-04-28 21:06

Před spuštěním: Volných bajtů: 77 882 060 800
Po spuštění: Volných bajtů: 79 015 997 440

- - End Of File - - 0CBCAD43298EFABEFC16301A47354791
Bez_n1ck
Pokročilý
Pokročilý
Uživatelský avatar
Registrován: 15. pro 2006
Bydliště: Praha - Vinohrady

Re: Explorer.exe - Win Vista 32

Příspěvek od Bez_n1ck »

tak promiň za radu k ničemu :oops: ... tohle je jeden z příznaků, jak se projevuje zablokovaný nelegální OS a s takovýmito problémy tu obvykle bývají právě lidi s neorigo OS.
PC: MB: ASUS TUF Z370-PRO GAMING ; CPU: INTEL Core i7-8700K @ 3,7GHz ; CPUcooler: Noctua NH-D14 ; GPU: GIGABYTE GTX2070 WINDFORCE 3X 8GB ; DDR4: 2x16 GB 2666MHz CL16 ; HDD: Samsung 960 EVO M.2 500GB + WD Green 2,5TB + WD Red 4TB + 2xWD Red 8TB ; CASE: Be Quiet! Dark Base 900 ; PSU: Corsair RM650x ; MOUSE: Logitech G700s ; KEYBOARD: Razer Huntsman Elite ; SOUND: Logitech X530 ; MONITOR: 2x Dell U2515H (25" QHD IPS) | Games, that you can play with me | Diablo III - Divina
NOTEBOOK: Dell Precision 7730 ; CPU: Intel Core i7-8750H ; GPU: nVidia Quadro P4200 8GB ; DDR4: 2x16GB 2667MHz ; HDD: Samsung NVMe 256GB + Samsung 980 EVO M.2 1TB ; FullHD
zombux
Odborník PCT
Odborník PCT
Uživatelský avatar
Registrován: 05. čer 2003
Bydliště: sluníčkář a havloid z pražské lumpenkavárny

Re: Explorer.exe - Win Vista 32

Příspěvek od zombux »

Bez_n1ck píše:tak promiň za radu k ničemu :oops: ... tohle je jeden z příznaků, jak se projevuje zablokovaný nelegální OS a s takovýmito problémy tu obvykle bývají právě lidi s neorigo OS.
já to spíš pochopil tak, že dobře mu tak že má Vistu :mrgreen: nicméně, vypadá to že už je čisto. je tam pár blbin jako Ask toolbar které bych ze systému vykopal, ale přímo škodlivé to není.
ignorelist: kremrole a dezoláti
Odpovědět

Zpět na „Operační systémy Microsoft“