Explorer.exe - Win Vista 32
Moderátor: Loki5567
Pravidla fóra
Vše okolo nového systému Windows 8 se řeší jen a pouze v PODSEKCI (klik), ostatní se přesouvá nebo zamyká.
Vše okolo nového systému Windows 8 se řeší jen a pouze v PODSEKCI (klik), ostatní se přesouvá nebo zamyká.
- Drastic
- Nováček

-
- Registrován: 28. dub 2010
Explorer.exe - Win Vista 32
Ahoj, mám problém, program explorer který spuští plochu se mi nechce automaticky po spuštění PC zapnout, jen se mi objeví černá plocha a složka dokumenty a já si přes ni musím zajed do windows a manuálně ho spustít, nevíte co stím je?? Mám OS Vistu 32
- Bez_n1ck
- Pokročilý

- Registrován: 15. pro 2006
- Bydliště: Praha - Vinohrady
Re: Explorer.exe
zaplať za to co používáš 
PC: MB: ASUS TUF Z370-PRO GAMING ; CPU: INTEL Core i7-8700K @ 3,7GHz ; CPUcooler: Noctua NH-D14 ; GPU: GIGABYTE GTX2070 WINDFORCE 3X 8GB ; DDR4: 2x16 GB 2666MHz CL16 ; HDD: Samsung 960 EVO M.2 500GB + WD Green 2,5TB + WD Red 4TB + 2xWD Red 8TB ; CASE: Be Quiet! Dark Base 900 ; PSU: Corsair RM650x ; MOUSE: Logitech G700s ; KEYBOARD: Razer Huntsman Elite ; SOUND: Logitech X530 ; MONITOR: 2x Dell U2515H (25" QHD IPS) | Games, that you can play with me | Diablo III - Divina
NOTEBOOK: Dell Precision 7730 ; CPU: Intel Core i7-8750H ; GPU: nVidia Quadro P4200 8GB ; DDR4: 2x16GB 2667MHz ; HDD: Samsung NVMe 256GB + Samsung 980 EVO M.2 1TB ; FullHD
NOTEBOOK: Dell Precision 7730 ; CPU: Intel Core i7-8750H ; GPU: nVidia Quadro P4200 8GB ; DDR4: 2x16GB 2667MHz ; HDD: Samsung NVMe 256GB + Samsung 980 EVO M.2 1TB ; FullHD
- Drastic
- Nováček

-
- Registrován: 28. dub 2010
Re: Explorer.exe
V klidu, mám origo OS, sice to je tak asi jediné co mám zaplacené ale mám!!!
- zombux
- Odborník PCT

- Registrován: 05. čer 2003
- Bydliště: sluníčkář a havloid z pražské lumpenkavárny
Re: Explorer.exe
dej sem výpis HijackThis, eventuelně bych to projel ComboFixem
ignorelist: kremrole a dezoláti
- Drastic
- Nováček

-
- Registrován: 28. dub 2010
Re: Explorer.exe
jestli se v tom vyznáš...
Kód: Vybrat vše
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:34:35, on 28.4.2010
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.17037)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\mobsync.exe
C:\Windows\explorer.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\OSCAR Editor\OscarEditor.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Safari\Safari.exe
C:\Windows\system32\conime.exe
C:\Users\MaRaS\Downloads\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\MaRaS\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\csrss.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\MaRaS\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [recinfo613] c:\RecInfo\RecInfo.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [recinfo] RecInfo.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKCU\..\Run: [fsc-reg] C:\ProgramData\fsc-reg\fscreg.exe 20100409
O4 - HKCU\..\Run: [EPSON SX100 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIEDE.EXE /FU "C:\Windows\TEMP\E_S956C.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [OscarEditor] "C:\Program Files\OSCAR Editor\OscarEditor.exe" Minimum
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: Download Using &BitSpirit - C:\Program Files\BitSpirit\bsurl.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O13 - Gopher Prefix:
O15 - Trusted Zone: http://software.kuaiche.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
--
End of file - 8022 bytes- zombux
- Odborník PCT

- Registrován: 05. čer 2003
- Bydliště: sluníčkář a havloid z pražské lumpenkavárny
Re: Explorer.exe
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\csrss.exe
tohle rozhodně v pořádku není, takže to fixni a restartuj, pak stáhni ComboFix, nech ho projet systém, a až vyhodí log, zas ho sem dej.
tohle rozhodně v pořádku není, takže to fixni a restartuj, pak stáhni ComboFix, nech ho projet systém, a až vyhodí log, zas ho sem dej.
ignorelist: kremrole a dezoláti
- Drastic
- Nováček

-
- Registrován: 28. dub 2010
Re: Explorer.exe
Tady...tak plocha po restartu naběhla, tak uvidíme...jinak díky moc za rady
Kód: Vybrat vše
ComboFix 10-04-28.03 - MaRaS 28.04.2010 22:58:17.3.4 - x86
Spuštěný z: c:\users\MaRaS\Downloads\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
SP: ESET Smart Security 3.0 *disabled* (Updated) {E5E70D32-0101-4B98-A4D6-D1D15C3BB448}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\$recycle.bin\S-1-5-21-2177344061-1213171447-1916667378-500
c:\users\MaRaS\AppData\Roaming\BITS
c:\users\MaRaS\AppData\Roaming\BITS\BITS.ini
c:\users\MaRaS\AppData\Roaming\FlashGetBHO
c:\users\MaRaS\AppData\Roaming\FlashGetBHO\FlashGetBHO3.dll
c:\users\MaRaS\AppData\Roaming\FlashGetBHO\FlashGetHook.dll
c:\users\MaRaS\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
c:\users\MaRaS\AppData\Roaming\FlashGetBHO\GetUrl.htm
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-03-28 do 2010-04-28 )))))))))))))))))))))))))))))))
.
2010-04-28 21:04 . 2010-04-28 21:04 -------- d-----w- c:\users\MaRaS\AppData\Local\temp
2010-04-28 21:04 . 2010-04-28 21:04 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-04-28 20:49 . 2010-04-28 20:49 320000 ----a-w- c:\windows\system32\CF1298.exe
2010-04-28 20:48 . 2010-04-28 20:46 320000 ----a-w- c:\windows\system32\CF602.exe
2010-04-28 20:36 . 2010-04-28 20:36 320000 ----a-w- c:\windows\system32\CF31417.exe
2010-04-28 18:46 . 2010-04-28 18:46 320000 ----a-w- c:\windows\system32\CF9878.exe
2010-04-28 18:43 . 2010-04-28 18:43 320000 ----a-w- c:\windows\system32\CF9385.exe
2010-04-28 17:43 . 2010-04-28 17:43 320000 ----a-w- c:\windows\system32\CF30370.exe
2010-04-28 17:42 . 2010-04-28 17:40 320000 ----a-w- c:\windows\system32\CF29776.exe
2010-04-28 15:44 . 2010-04-28 15:44 -------- d-----w- c:\programdata\Uniblue
2010-04-28 15:42 . 2010-04-28 15:42 -------- d-----w- c:\users\MaRaS\AppData\Roaming\Uniblue
2010-04-24 18:29 . 2010-04-24 18:29 -------- d-----w- c:\users\MaRaS\AppData\Local\PokerStars
2010-04-24 18:28 . 2010-04-24 19:25 -------- d-----w- c:\program files\PokerStars
2010-04-23 20:47 . 2010-04-23 20:47 -------- d-----w- c:\program files\Driver-Soft
2010-04-20 21:14 . 2010-04-12 15:29 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-19 16:10 . 2010-04-19 16:10 -------- d-----w- c:\programdata\AltrixSoft
2010-04-15 14:58 . 2010-04-15 14:58 1184 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2010-04-15 14:57 . 2010-04-15 14:57 -------- d-----w- c:\users\MaRaS\AppData\Local\Downloaded Installations
2010-04-15 14:48 . 2010-04-15 14:48 -------- d-----w- c:\program files\EA Games
2010-04-15 05:00 . 2010-02-23 11:30 58368 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-15 05:00 . 2010-02-23 11:30 102912 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-15 05:00 . 2010-02-23 11:30 211968 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-15 05:00 . 2010-02-18 14:54 3502480 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-15 05:00 . 2010-02-18 14:54 3468168 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-04-15 05:00 . 2010-03-04 19:24 434176 ----a-w- c:\windows\system32\vbscript.dll
2010-04-15 04:59 . 2010-02-18 11:51 818688 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-04-15 04:59 . 2010-02-18 14:34 213896 ----a-w- c:\windows\system32\drivers\netio.sys
2010-04-15 04:59 . 2010-02-18 12:04 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2010-04-15 04:59 . 2010-02-18 14:19 179712 ----a-w- c:\windows\system32\iphlpsvc.dll
2010-04-15 04:59 . 2010-02-18 13:56 416768 ----a-w- c:\windows\system32\IKEEXT.DLL
2010-04-15 04:59 . 2010-02-18 13:55 317440 ----a-w- c:\windows\system32\BFE.DLL
2010-04-15 04:59 . 2010-02-18 11:50 85504 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2010-04-15 04:59 . 2010-02-18 13:56 543232 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2010-04-15 04:59 . 2010-02-18 11:51 22016 ----a-w- c:\windows\system32\netiougc.exe
2010-04-15 04:59 . 2010-02-18 14:01 167424 ----a-w- c:\windows\system32\tcpipcfg.dll
2010-04-15 04:59 . 2010-02-18 12:04 15360 ----a-w- c:\windows\system32\drivers\TUNMP.SYS
2010-04-14 05:48 . 2009-12-23 12:45 171520 ----a-w- c:\windows\system32\wintrust.dll
2010-04-14 05:48 . 2010-01-13 18:23 97792 ----a-w- c:\windows\system32\cabview.dll
2010-04-13 13:52 . 2010-02-16 07:31 1647984 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20100412.003\NAVEX32A.DLL
2010-04-13 13:52 . 2010-02-16 07:31 84912 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20100412.003\NAVENG.SYS
2010-04-13 13:52 . 2010-02-16 07:31 177520 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20100412.003\NAVENG32.DLL
2010-04-13 13:52 . 2010-02-16 07:31 1324720 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20100412.003\NAVEX15.SYS
2010-04-13 13:52 . 2010-02-16 07:31 102448 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20100412.003\ERASER.SYS
2010-04-13 13:52 . 2010-02-16 07:31 371248 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20100412.003\EECTRL.SYS
2010-04-10 15:17 . 2010-04-10 15:19 -------- d-----w- c:\program files\Pixarra
2010-04-03 10:13 . 2010-04-03 10:13 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-04-03 10:10 . 2010-04-03 10:10 -------- d-----w- c:\users\MaRaS\AppData\Local\ESET
2010-04-02 17:37 . 2010-04-02 17:31 754984 ----a-w- c:\programdata\DivX\Setup\Resource.dll
2010-04-02 17:37 . 2010-04-02 17:31 986904 ----a-w- c:\programdata\DivX\Setup\DivXSetup.exe
2010-04-02 17:37 . 2010-04-02 17:37 56766 ----a-w- c:\programdata\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-04-02 17:37 . 2010-04-02 17:37 56978 ----a-w- c:\programdata\DivX\WebPlayer\Uninstaller.exe
2010-04-02 17:37 . 2010-04-02 17:37 53600 ----a-w- c:\programdata\DivX\Update\Uninstaller.exe
2010-04-02 17:37 . 2010-04-02 17:37 57677 ----a-w- c:\programdata\DivX\Player\Uninstaller.exe
2010-04-02 17:37 . 2010-04-19 14:45 -------- d-----w- c:\users\MaRaS\AppData\Roaming\DivX
2010-04-02 17:31 . 2010-04-02 17:37 -------- d-----w- c:\program files\DivX
2010-04-02 17:31 . 2010-04-02 17:37 -------- d-----w- c:\programdata\DivX
2010-04-02 13:36 . 2010-04-02 13:36 -------- d-----w- c:\windows\1C4551A64743409391E41477CD655043.TMP
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-28 19:24 . 2010-03-16 16:10 138592 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-04-28 19:23 . 2010-03-16 16:10 219128 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-04-28 16:34 . 2010-03-05 14:27 -------- d-----w- c:\users\MaRaS\AppData\Roaming\ICQ
2010-04-28 16:13 . 2010-03-06 12:57 -------- d-----w- c:\program files\Ubisoft
2010-04-28 16:13 . 2010-03-05 14:20 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-04-28 16:13 . 2010-03-06 13:17 -------- d-----w- c:\programdata\Ubisoft
2010-04-25 18:11 . 2010-03-16 15:48 -------- d-----w- c:\program files\Activision
2010-04-24 18:05 . 2010-03-07 20:43 -------- d-----w- c:\users\MaRaS\AppData\Roaming\Skype
2010-04-24 18:05 . 2010-03-07 20:45 -------- d-----w- c:\users\MaRaS\AppData\Roaming\skypePM
2010-04-24 07:30 . 2008-02-08 12:05 81198 ----a-w- c:\windows\system32\perfc005.dat
2010-04-24 07:30 . 2008-02-08 12:05 473360 ----a-w- c:\windows\system32\perfh005.dat
2010-04-20 21:14 . 2010-03-05 14:03 -------- d-----w- c:\program files\Java
2010-04-16 05:46 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-04-16 05:03 . 2010-03-05 10:01 -------- d-----w- c:\programdata\Microsoft Help
2010-04-13 13:52 . 2010-04-10 15:57 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-04-12 15:39 . 2010-03-28 16:50 -------- d-----w- c:\users\MaRaS\AppData\Roaming\TS3Client
2010-04-12 15:25 . 2010-04-12 14:03 -------- d-----w- c:\program files\OSCAR Editor
2010-04-12 14:13 . 2010-04-12 14:13 8854 ----a-r- c:\users\MaRaS\AppData\Roaming\Microsoft\Installer\{361693F2-A153-4359-A4CB-A1B9FF2AA5E6}\UNINST_Uninstall_A_361693F2A1534359A4CBA1B9FF2AA5E6.exe
2010-04-12 14:13 . 2010-04-12 14:13 45056 ----a-r- c:\users\MaRaS\AppData\Roaming\Microsoft\Installer\{361693F2-A153-4359-A4CB-A1B9FF2AA5E6}\Witness.exe1_361693F2A1534359A4CBA1B9FF2AA5E6.exe
2010-04-12 14:13 . 2010-04-12 14:13 45056 ----a-r- c:\users\MaRaS\AppData\Roaming\Microsoft\Installer\{361693F2-A153-4359-A4CB-A1B9FF2AA5E6}\Witness.exe_361693F2A1534359A4CBA1B9FF2AA5E6.exe
2010-04-12 14:13 . 2010-04-12 14:13 10134 ----a-r- c:\users\MaRaS\AppData\Roaming\Microsoft\Installer\{361693F2-A153-4359-A4CB-A1B9FF2AA5E6}\ARPPRODUCTICON.exe
2010-04-12 14:13 . 2010-04-12 14:13 -------- d-----w- c:\program files\A4TECH
2010-04-12 14:02 . 2010-04-12 14:02 -------- d-----w- c:\program files\OscarX7
2010-04-02 13:36 . 2010-03-17 18:23 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-04-02 09:19 . 2010-03-05 14:03 -------- d-----w- c:\program files\Common Files\Java
2010-03-29 06:15 . 2010-03-29 06:15 86016 ----a-w- c:\windows\system32\frapsvid.dll
2010-03-28 17:39 . 2010-03-06 15:10 -------- d-----w- c:\programdata\Symantec
2010-03-28 16:48 . 2010-03-28 16:48 -------- d-----w- c:\program files\TeamSpeak 3 Client
2010-03-27 23:34 . 2010-03-27 23:34 -------- d-----w- c:\program files\THQ
2010-03-25 22:12 . 2008-02-09 01:55 -------- d-----w- c:\program files\ATI
2010-03-25 22:04 . 2010-03-25 22:04 -------- d-----w- c:\programdata\ATI
2010-03-25 22:04 . 2008-02-09 01:55 -------- d-----w- c:\program files\ATI Technologies
2010-03-25 07:32 . 2010-03-25 07:32 -------- d-----w- c:\program files\Recuva
2010-03-25 07:15 . 2010-03-25 07:15 -------- d-----w- c:\program files\SQUARE ENIX - Eidos Interactive
2010-03-23 21:02 . 2010-03-23 21:02 -------- d-----w- c:\programdata\salvation
2010-03-23 20:57 . 2010-03-23 20:57 418480 ----a-w- c:\windows\system32\wrap_oal.dll
2010-03-23 20:57 . 2010-03-23 20:57 115432 ----a-w- c:\windows\system32\OpenAL32.dll
2010-03-23 20:57 . 2010-03-23 20:57 -------- d-----w- c:\program files\OpenAL
2010-03-23 20:50 . 2010-03-23 20:50 -------- d-----w- c:\program files\Evolved Games
2010-03-22 15:54 . 2010-03-16 16:10 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-03-21 20:07 . 2010-03-21 19:54 -------- d-----w- c:\program files\GamePark
2010-03-21 20:04 . 2010-03-21 20:04 -------- d-----w- c:\program files\Zaparit
2010-03-21 09:39 . 2010-03-17 18:12 -------- d-----w- c:\program files\METRO 2033
2010-03-20 17:14 . 2010-03-05 09:52 102816 ----a-w- c:\users\MaRaS\AppData\Local\GDIPFONTCACHEV1.DAT
2010-03-20 17:03 . 2010-03-20 17:03 -------- d-----w- c:\program files\Electronic Arts
2010-03-20 16:28 . 2010-03-20 16:28 -------- d-----w- c:\program files\Kodek CZ
2010-03-20 16:16 . 2010-03-20 16:12 -------- d-----w- c:\program files\AVS4YOU
2010-03-20 16:16 . 2010-03-20 16:13 -------- d-----w- c:\program files\Common Files\AVSMedia
2010-03-20 16:14 . 2010-03-20 16:14 -------- d-----w- c:\programdata\AVS4YOU
2010-03-20 16:08 . 2010-03-20 16:08 -------- d-----w- c:\users\MaRaS\AppData\Roaming\Media Player Classic
2010-03-19 14:38 . 2010-03-19 14:32 -------- d-----w- c:\users\MaRaS\AppData\Roaming\Prison Break
2010-03-19 14:35 . 2010-03-19 14:35 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys
2010-03-19 14:35 . 2010-03-19 14:35 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2010-03-19 14:27 . 2010-03-19 14:27 -------- d-----w- c:\program files\Deep Silver
2010-03-19 14:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\MSBuild
2010-03-19 14:01 . 2010-03-19 14:01 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-03-17 18:24 . 2010-03-17 18:24 -------- d-----w- c:\program files\NVIDIA Corporation
2010-03-16 20:59 . 2010-03-16 20:56 -------- d-----w- c:\program files\Common Files\Macromedia
2010-03-16 20:57 . 2010-03-16 20:56 -------- d-----w- c:\program files\Macromedia
2010-03-16 20:56 . 2010-03-16 20:56 45056 ----a-r- c:\users\MaRaS\AppData\Roaming\Microsoft\Installer\{885A63EA-382B-4DD4-A755-14809B8557D6}\ARPPRODUCTICON.exe
2010-03-16 20:55 . 2010-03-05 14:43 -------- d-----w- c:\program files\Common Files\InstallShield
2010-03-16 20:17 . 2010-03-16 20:15 -------- d-----w- c:\program files\The KMPlayer
2010-03-16 16:10 . 2010-03-16 16:10 22328 ----a-w- c:\users\MaRaS\AppData\Roaming\PnkBstrK.sys
2010-03-16 16:10 . 2010-03-16 16:10 22328 ----a-w- c:\users\MaRaS\AppData\Roaming\PnkBstrK.sys
2010-03-15 22:05 . 2010-03-15 22:05 -------- d-----w- c:\program files\Bethesda Softworks
2010-03-15 20:07 . 2010-03-15 20:07 305 ----a-w- c:\windows\system32\secushr.dat
2010-03-15 20:06 . 2010-03-15 20:06 -------- d-----w- c:\users\MaRaS\AppData\Roaming\FlashGet
2010-03-14 17:38 . 2010-03-14 17:38 -------- d-----w- c:\program files\FlashFXP
2010-03-14 17:38 . 2010-03-14 17:38 -------- d-----w- c:\programdata\FlashFXP
2010-03-13 16:46 . 2010-03-05 14:00 -------- d-----w- c:\program files\Safari
2010-03-13 16:44 . 2010-03-13 16:44 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\Safari 5.31.22.7\SetupAdmin.exe
2010-03-13 13:12 . 2010-03-13 13:11 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2010-03-13 12:56 . 2010-03-13 12:56 -------- d-----w- c:\program files\7-Zip
2010-03-09 20:39 . 2010-03-09 20:39 -------- d-----w- c:\users\MaRaS\AppData\Roaming\EPSON
2010-03-09 16:54 . 2010-03-31 05:59 832512 ----a-w- c:\windows\system32\wininet.dll
2010-03-09 16:50 . 2010-03-31 05:59 56320 ----a-w- c:\windows\system32\iesetup.dll
2010-03-09 16:50 . 2010-03-31 05:59 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-09 16:50 . 2010-03-31 05:59 52736 ----a-w- c:\windows\AppPatch\iebrshim.dll
2010-03-09 16:48 . 2010-03-31 05:59 72704 ----a-w- c:\windows\system32\admparse.dll
2010-03-09 14:17 . 2010-03-31 05:59 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2010-03-09 12:43 . 2010-03-31 05:59 48128 ----a-w- c:\windows\system32\mshtmler.dll
2010-03-09 06:06 . 2010-03-09 06:06 268800 ----a-w- c:\windows\system32\es.dll
2010-03-08 17:59 . 2010-03-08 17:59 94208 ----a-w- c:\windows\system32\dpl100.dll
2010-03-07 20:45 . 2010-03-07 20:45 56 ---ha-w- c:\programdata\ezsidmv.dat
2010-03-07 20:43 . 2010-03-07 20:43 -------- d-----w- c:\program files\Common Files\Skype
2010-03-07 20:43 . 2010-03-07 20:43 -------- d-----r- c:\program files\Skype
2010-03-07 20:43 . 2010-03-07 20:42 -------- d-----w- c:\programdata\Skype
2010-03-07 14:59 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-03-07 11:45 . 2010-03-07 11:45 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-03-07 11:45 . 2010-03-07 11:45 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-03-07 11:45 . 2010-03-07 11:45 24064 ----a-w- c:\windows\system32\lpk.dll
2010-03-07 11:45 . 2010-03-07 11:45 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-03-07 11:45 . 2010-03-07 11:45 10240 ----a-w- c:\windows\system32\dciman32.dll
2010-03-07 11:45 . 2010-03-07 11:45 72704 ----a-w- c:\windows\system32\fontsub.dll
2010-03-07 11:40 . 2010-03-07 11:40 61440 ----a-w- c:\windows\system32\winipsec.dll
2010-03-07 11:40 . 2010-03-07 11:40 361984 ----a-w- c:\windows\system32\IPSECSVC.DLL
2010-03-07 11:40 . 2010-03-07 11:40 28672 ----a-w- c:\windows\system32\FwRemoteSvr.dll
2010-03-07 11:40 . 2010-03-07 11:40 272896 ----a-w- c:\windows\system32\polstore.dll
2010-03-07 11:38 . 2010-03-07 11:38 84992 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-03-07 11:38 . 2010-03-07 11:38 307200 ----a-w- c:\windows\system32\drivers\srv.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-02-04 15:50 1197448 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"fsc-reg"="c:\programdata\fsc-reg\fscreg.exe" [2007-11-08 519440]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
"OscarEditor"="c:\program files\OSCAR Editor\OscarEditor.exe" [2009-11-24 2642432]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-12-17 4718592]
"recinfo613"="c:\recinfo\RecInfo.exe" [2007-10-23 2764800]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-02-26 153136]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-03-01 1443072]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-03-02 98304]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-03-05 1135912]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-03-06 691696]
R3 GarenaPEngine;GarenaPEngine;c:\users\MaRaS\AppData\Local\Temp\LKM5DFE.tmp [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-03-03 172032]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2008-10-19 222456]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [2010-03-03 5340160]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-03-03 152064]
S3 MouseCap;MouseCapture Driver;c:\windows\system32\Drivers\MouseCap.sys [2005-08-08 6640]
.
Obsah adresáře 'Naplánované úlohy'
2010-04-24 c:\windows\Tasks\Norton Security Scan for MaRaS.job
- c:\program files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-03-06 10:50]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
uDefault_Search_URL = hxxp://search.qip.ru
uInternet Settings,ProxyOverride = *.local
IE: Download Using &BitSpirit - c:\program files\BitSpirit\bsurl.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: ÓñČĚŘľ«ÁéĎÂÔŘ(&B)
Trusted Zone: kuaiche.com\software
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKLM-Run-recinfo - RecInfo.exe
AddRemove-Tow Truck Simulator 2010_is1 - c:\program files\astragon Software GmbH\Tow Truck Simulator 2010\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-28 23:04
Windows 6.0.6000 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\users\MaRaS\AppData\Local\Temp\LKM5DFE.tmp"
.
Celkový čas: 2010-04-28 23:06:31
ComboFix-quarantined-files.txt 2010-04-28 21:06
Před spuštěním: Volných bajtů: 77 882 060 800
Po spuštění: Volných bajtů: 79 015 997 440
- - End Of File - - 0CBCAD43298EFABEFC16301A47354791
- Bez_n1ck
- Pokročilý

- Registrován: 15. pro 2006
- Bydliště: Praha - Vinohrady
Re: Explorer.exe - Win Vista 32
tak promiň za radu k ničemu
... tohle je jeden z příznaků, jak se projevuje zablokovaný nelegální OS a s takovýmito problémy tu obvykle bývají právě lidi s neorigo OS.
PC: MB: ASUS TUF Z370-PRO GAMING ; CPU: INTEL Core i7-8700K @ 3,7GHz ; CPUcooler: Noctua NH-D14 ; GPU: GIGABYTE GTX2070 WINDFORCE 3X 8GB ; DDR4: 2x16 GB 2666MHz CL16 ; HDD: Samsung 960 EVO M.2 500GB + WD Green 2,5TB + WD Red 4TB + 2xWD Red 8TB ; CASE: Be Quiet! Dark Base 900 ; PSU: Corsair RM650x ; MOUSE: Logitech G700s ; KEYBOARD: Razer Huntsman Elite ; SOUND: Logitech X530 ; MONITOR: 2x Dell U2515H (25" QHD IPS) | Games, that you can play with me | Diablo III - Divina
NOTEBOOK: Dell Precision 7730 ; CPU: Intel Core i7-8750H ; GPU: nVidia Quadro P4200 8GB ; DDR4: 2x16GB 2667MHz ; HDD: Samsung NVMe 256GB + Samsung 980 EVO M.2 1TB ; FullHD
NOTEBOOK: Dell Precision 7730 ; CPU: Intel Core i7-8750H ; GPU: nVidia Quadro P4200 8GB ; DDR4: 2x16GB 2667MHz ; HDD: Samsung NVMe 256GB + Samsung 980 EVO M.2 1TB ; FullHD
- zombux
- Odborník PCT

- Registrován: 05. čer 2003
- Bydliště: sluníčkář a havloid z pražské lumpenkavárny
Re: Explorer.exe - Win Vista 32
já to spíš pochopil tak, že dobře mu tak že má VistuBez_n1ck píše:tak promiň za radu k ničemu... tohle je jeden z příznaků, jak se projevuje zablokovaný nelegální OS a s takovýmito problémy tu obvykle bývají právě lidi s neorigo OS.
ignorelist: kremrole a dezoláti