Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Zavirovaný NTBk virem Win32:Malware-gen.

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Denisa
Návštěvník
Návštěvník
Příspěvky: 93
Registrován: 01 črc 2013 15:32

Zavirovaný NTBk virem Win32:Malware-gen.

#1 Příspěvek od Denisa »

Dobrý den, moc se omlouvám, že otravuju ,ale před chvílí mi antivir zařval, že mám 2 viry :boxed: a z toho jeden má závažnost nízká, ale ten druhý vysoká.: Win32:Malware-gen. Pomůžete mi ho prosím odstranit? Děkuji.

Logfile of random's system information tool 1.10 (written by random/random)
Run by PLANEO at 2016-05-08 01:14:14
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 11 GB (7%) free of 153 GB
Total RAM: 3070 MB (37% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:14:22, on 8.5.2016
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16749)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Windows\WindowsMobile\wmdSync.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT.EXE
C:\Program Files\Western Digital\WD Security\WDDriveAutoUnlock.exe
C:\Program Files\Western Digital\WD Quick View\WDDMStatus.exe
C:\Program Files\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe
C:\Program Files\Real\RealPlayer\Update\realsched.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Windows\system32\wuauclt.exe
C:\Users\PLANEO\Desktop\RSIT(1).exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_21_0_0_213.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_21_0_0_213.exe
C:\Users\PLANEO\Desktop\RSIT(1).exe
C:\Program Files\trend micro\PLANEO.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quick ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quick ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: PXCIEaddin5 - {42DFA04F-0F16-418e-B80C-AB97A5AFAD3A} - C:\Program Files\Tracker Software\PDF-XChange 5\PXCIEaddin5.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_66\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: STATISTICA Browser Helper - {990A8747-93BF-4EF7-B72E-94A6884B98C2} - C:\Program Files\StatSoft\STATISTICA 12\StaBHO.dll
O2 - BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_66\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll
O3 - Toolbar: PDFXChange 2012 - {42DFA04F-0F16-418e-B80C-AB97A5AFAD3A} - C:\Program Files\Tracker Software\PDF-XChange 5\PXCIEaddin5.dll
O3 - Toolbar: Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [MFNetworkScanUtility] C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT.EXE
O4 - HKLM\..\Run: [DivXMediaServer] C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [WD Drive Unlocker] C:\Program Files\Western Digital\WD Security\WDDriveAutoUnlock.exe
O4 - HKLM\..\Run: [WD Quick View] C:\Program Files\Western Digital\WD Quick View\WDDMStatus.exe
O4 - HKLM\..\Run: [DriveUtilitiesHelper] C:\Program Files\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://oas.support.microsoft.com/ActiveX/MSDcode.cab
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: WD Backup (WDBackup) - Western Digital Technologies, Inc. - C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe
O23 - Service: WD Drive Manager (WDDriveService) - Western Digital Technologies, Inc. - C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe

--
End of file - 8784 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\cpuof8o9.default-1443448626419

prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
"web2pdfextension@web2pdf.adobedotcom"=C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 21.0.0.213 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_21_0_0_213.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]
"Description"=DivX VOD Helper Plug-in
"Path"=C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Web Player Plug-In,version=1.0.0]
"Description"=DivX Web Player
"Path"=C:\Program Files\DivX\DivX Web Player\npdivx32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.66.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.66.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_66\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5]
"Description"=Office Live Update v1.5
"Path"=C:\Program Files\Microsoft\Office Live\npOLW.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0]
"Description"=RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0]
"Description"=RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0]
"Description"=RealNetworks(tm) RealDownloader Peppe rFlash Video Shim Plug-In
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282]
"Description"=RealPlayer Download Plugin
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@realnetworks.com/npdlplugin;version=1]
"Description"=RealDownloader Plugin
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.0]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.2.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Acrobat]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll


C:\Program Files\Mozilla Firefox\components\
nsIQTScriptablePlugin.xpt

C:\Program Files\Mozilla Firefox\plugins\
NPOFF12.DLL
nppdf32.CZE
nppdf32.dll
nppl3260.dll
nppl3260.xpt
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
nprpplugin.dll
QuickTimePlugin.class

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2012-09-23 72336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{42DFA04F-0F16-418e-B80C-AB97A5AFAD3A}]
PDFXChange 2012 - C:\Program Files\Tracker Software\PDF-XChange 5\PXCIEaddin5.dll [2012-08-14 423040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_66\bin\ssv.dll [2015-12-20 460384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-04-19 679680]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{990A8747-93BF-4EF7-B72E-94A6884B98C2}]
STATISTICA Browser Helper - C:\Program Files\StatSoft\STATISTICA 12\StaBHO.dll [2013-04-02 232448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe Acrobat Create PDF Helper - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2013-12-21 141192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-12-20 172640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
Adobe Acrobat Create PDF from Selection - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2013-12-21 141192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{42DFA04F-0F16-418e-B80C-AB97A5AFAD3A} - PDFXChange 2012 - C:\Program Files\Tracker Software\PDF-XChange 5\PXCIEaddin5.dll [2012-08-14 423040]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe Acrobat Create PDF Toolbar - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2013-12-21 141192]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-08-12 6265376]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdSync.exe [2008-01-21 215552]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2016-04-19 7390608]
"MFNetworkScanUtility"=C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT.EXE [2009-12-15 484760]
"DivXMediaServer"=C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [2016-03-10 839648]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2014-10-02 421888]
"WD Drive Unlocker"=C:\Program Files\Western Digital\WD Security\WDDriveAutoUnlock.exe [2013-07-10 1694080]
"WD Quick View"=C:\Program Files\Western Digital\WD Quick View\WDDMStatus.exe [2015-10-28 5565296]
"DriveUtilitiesHelper"=C:\Program Files\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe [2015-07-31 1890664]
"TkBellExe"=C:\Program Files\Real\RealPlayer\update\realsched.exe [2013-03-29 295072]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2015-11-09 596528]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2014-12-12 5489944]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2013-05-08 115440]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=iyvu9_32.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"msacm.siren"=sirenacm.dll
"wave2"=serwvdrv.dll
"vidc.VP60"=C:\Windows\system32\vp6vfw.dll
"vidc.VP61"=C:\Windows\system32\vp6vfw.dll
"VIDC.IV41"=IR41_32.AX
"VIDC.IV32"=ir32_32.dll
"VIDC.IV31"=ir32_32.dll
"VIDC.FMVC"=fmcodec.dll
"vidc.DIVX"=DivX.dll
"vidc.yv12"=DivX.dll
"VIDC.NSVI"=nsvideo.dll
"vidc.mjpg"=pvmjpg30.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2016-05-08 00:58:32 ----D---- C:\rsit
2016-05-07 19:42:00 ----D---- C:\Program Files\Mozilla Firefox
2016-04-26 17:22:25 ----ASH---- C:\pagefile.sys
2016-04-19 18:39:44 ----A---- C:\Windows\system32\drivers\aswKbd.sys
2016-04-19 18:38:44 ----A---- C:\Windows\system32\aswBoot.exe
2016-04-19 18:37:57 ----A---- C:\Windows\avastSS.scr
2016-04-10 23:03:18 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2016-04-10 23:01:54 ----D---- C:\Program Files\Malwarebytes Anti-Malware
2016-04-10 23:01:54 ----A---- C:\Windows\system32\drivers\mwac.sys
2016-04-10 23:01:54 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2016-04-10 23:01:54 ----A---- C:\Windows\system32\drivers\mbam.sys
2016-04-09 13:53:56 ----D---- C:\AdwCleaner

======List of files/folders modified in the last 1 month======

2016-05-08 01:14:17 ----D---- C:\Program Files\trend micro
2016-05-08 01:14:07 ----D---- C:\Windows\temp
2016-05-08 00:58:48 ----D---- C:\Windows\Prefetch
2016-05-07 20:18:47 ----D---- C:\Windows\System32
2016-05-07 20:18:14 ----D---- C:\Program Files\Mozilla Maintenance Service
2016-05-07 20:18:10 ----D---- C:\Program Files
2016-05-07 20:17:56 ----D---- C:\Windows\system32\Tasks
2016-05-07 19:59:04 ----D---- C:\ProgramData
2016-05-07 18:21:52 ----A---- C:\Windows\system32\acovcnt.exe
2016-05-05 16:27:23 ----D---- C:\Program Files\Opera
2016-05-04 20:40:45 ----D---- C:\Windows\system32\catroot2
2016-04-29 00:14:13 ----D---- C:\Windows\Minidump
2016-04-29 00:14:06 ----D---- C:\Windows
2016-04-26 17:22:43 ----SHD---- C:\System Volume Information
2016-04-25 22:44:37 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-04-25 22:44:36 ----D---- C:\Windows\inf
2016-04-22 03:10:00 ----D---- C:\Windows\system32\config
2016-04-22 03:09:50 ----D---- C:\Windows\Tasks
2016-04-22 03:09:50 ----D---- C:\Windows\system32\spool
2016-04-22 03:09:50 ----D---- C:\Windows\system32\Msdtc
2016-04-22 03:09:50 ----D---- C:\ProgramData\P4G
2016-04-22 03:09:48 ----D---- C:\Windows\system32\wbem
2016-04-22 03:09:48 ----D---- C:\Windows\registration
2016-04-21 22:27:26 ----D---- C:\Windows\system32\catroot
2016-04-20 19:06:49 ----D---- C:\Users\PLANEO\AppData\Roaming\DivX
2016-04-19 20:04:44 ----D---- C:\ProgramData\Package Cache
2016-04-19 20:03:24 ----SHD---- C:\Windows\Installer
2016-04-19 19:59:19 ----D---- C:\Program Files\Common Files\Western Digital
2016-04-19 19:59:18 ----D---- C:\ProgramData\Western Digital
2016-04-19 19:59:18 ----D---- C:\Program Files\Western Digital
2016-04-19 19:22:15 ----D---- C:\ProgramData\DivX
2016-04-19 19:22:14 ----D---- C:\Program Files\DivX
2016-04-19 19:16:38 ----D---- C:\Program Files\Common Files\DivX Shared
2016-04-19 18:51:17 ----D---- C:\Windows\system32\drivers
2016-04-19 18:39:18 ----D---- C:\Windows\winsxs
2016-04-19 18:38:36 ----D---- C:\ProgramData\AVAST Software
2016-04-19 18:37:13 ----D---- C:\Program Files\AVAST Software
2016-04-14 17:33:37 ----D---- C:\ProgramData\Microsoft Help
2016-04-11 21:13:22 ----D---- C:\Windows\schemas

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 Achernar;Achernar - SCSI Command Filter Drivers; C:\Windows\System32\Drivers\Achernar.sys [2007-02-05 18432]
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2016-04-19 58776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2016-04-19 221368]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\Windows\System32\drivers\sfhlp02.sys [2005-02-23 6656]
R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:\Windows\System32\drivers\sfsync02.sys [2004-12-03 20544]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-03-09 691696]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2016-04-19 35096]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2016-04-19 64272]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2016-04-19 815792]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2016-04-19 449640]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [2011-07-22 12880]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [2011-07-12 67664]
R2 ASMMAP;ASMMAP; \??\C:\Program Files\ATKGFNEX\ASMMAP.sys [2007-07-24 13880]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2016-04-19 32792]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2016-04-19 91168]
R2 cpuz135;cpuz135; \??\C:\Windows\system32\drivers\cpuz135_x32.sys [2010-11-09 21992]
R2 ghaio;ghaio; \??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2007-08-03 20936]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-03-21 1203776]
R3 aswStmXP;Avast StreamFilter Driver; C:\Windows\system32\drivers\aswStmXP.sys [2016-04-19 187208]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-04-06 908800]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-08-12 2159384]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2008-06-03 15928]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\Windows\system32\drivers\MODEMCSA.sys [2008-01-21 18432]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2006-12-14 7680]
R3 NVENETFD;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2008-07-08 1050656]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2008-06-25 44064]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-07-25 7547552]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2008-07-22 15872]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2008-07-23 1772544]
R3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\Windows\system32\DRIVERS\serscan.sys [2008-01-21 9216]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-08-17 190512]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560]
S0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\Windows\System32\drivers\sfdrv01.sys [2005-03-03 48640]
S3 arpba9ad;arpba9ad; C:\Windows\system32\drivers\arpba9ad.sys []
S3 aswTap;avast! SecureLine TAP Adapter v3; C:\Windows\system32\DRIVERS\aswTap.sys [2013-10-24 35272]
S3 aswTdi;aswTdi; C:\Windows\system32\drivers\aswTdi.sys [2016-04-19 67216]
S3 CRFILTER;USB Mass Storage Filter; C:\Windows\system32\DRIVERS\CRFILTER.sys [2008-04-07 6656]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2013-06-04 84248]
S3 Dot4;Ovladač MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
S3 Dot4Print;Ovladač třídy tiskárny standardu IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
S3 dot4usb;Filtr Dot4USB Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2008-12-08 55264]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2006-11-02 1010560]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2013-06-04 181912]
S3 TrueSight;TrueSight; \??\C:\Windows\system32\TrueSight.sys [2013-10-28 26624]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 35328]
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\Windows\system32\DRIVERS\wdcsam.sys [2013-07-10 11520]
S3 winusb;WinUSB Service; C:\Windows\system32\DRIVERS\winusb.sys [2009-07-14 34944]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WSDPrintDevice;Podpora tisku WSD prostřednictvím funkce UMB; C:\Windows\system32\DRIVERS\WSDPrint.sys [2008-01-21 16896]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136]
S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 194048]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
S4 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
S4 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2008-03-18 13312]
R2 ASLDRService;ASLDR Service; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [2007-10-03 94208]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2016-04-19 243296]
R2 BcmSqlStartupSvc;Služba spouštění serveru SQL Server aplikace Business Contact Manager; C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-16 30312]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-28 144200]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-06-09 73728]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-07-25 196608]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [2012-11-29 38608]
R2 spmgr;spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [2007-08-03 125496]
R2 SQLBrowser;SQL Server Browser; C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-12-10 238944]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-12-10 86880]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 WDBackup;WD Backup; C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe [2015-10-28 1042808]
R2 WDDriveService;WD Drive Manager; C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe [2015-10-28 307576]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-12 103608]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2014-12-11 315496]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-07 269504]
S3 fsssvc;Windows Live Zabezpečení rodiny; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2008-12-08 533344]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-28 144200]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2016-05-07 146888]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2008-10-24 145248]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2014-04-12 772296]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2014-04-12 45744]
S4 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe []
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2010-12-10 44384]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]

-----------------EOF-----------------

altrok
Moderátor
Moderátor
Příspěvky: 7264
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Zavirovaný NTBk virem Win32:Malware-gen.

#2 Příspěvek od altrok »

Dobry den,


:arrow: Zadny aktivni vir v logu nevidim, takze Vas antivir ocividne ochranil. V jakem umisteni ty dva nalezene viry jsou?


:arrow: V ramci cisteni Vam budou vyprazdneny docasne adresare (vcetne Kose).


:arrow: Ulozte na plochu AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/ (nebo http://www.bleepingcomputer.com/download/adwcleaner/ )
  • ukoncete vsechny programy
  • kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
  • kliknete na Scan, pote na Cleaning
  • po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\AdwCleaner[Cx].txt), jehoz obsah zkopirujte do pristi odpovedi
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Denisa
Návštěvník
Návštěvník
Příspěvky: 93
Registrován: 01 črc 2013 15:32

Re: Zavirovaný NTBk virem Win32:Malware-gen.

#3 Příspěvek od Denisa »

Dobrý den, nález antiviru příkládám v příloze, snad to bude vidět.
Přílohy
nález antiviru.pdf
(80.31 KiB) Staženo 70 x

altrok
Moderátor
Moderátor
Příspěvky: 7264
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Zavirovaný NTBk virem Win32:Malware-gen.

#4 Příspěvek od altrok »

:arrow: Prvni nalez je nase utilitka pro zjisteni verze operacniho systemu (zda se jedna o 32 nebo 64 bitovy operacni system), ktera je avastem mylne detekovana - https://virustotal.com/en/file/d66c6d8f ... 462900148/


:arrow: Druhy nalez vypada na instalacni soubor, ktery je podezrely - pokud jste jej nespustila, neni se ceho bat. Podivame se pro jistotu jeste hloubeji do systemu.


:arrow: Dejte logy FRST.txt a Addition.txt - http://forum.viry.cz/viewtopic.php?f=30&t=133101
Pozn. pri druhem a dalsim spusteni FRST je pro vytvoreni logu Addition.txt nutne tuto volbu explicitne zatrhnout pred zacatkem skenu.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Denisa
Návštěvník
Návštěvník
Příspěvky: 93
Registrován: 01 črc 2013 15:32

Re: Zavirovaný NTBk virem Win32:Malware-gen.

#5 Příspěvek od Denisa »

Joj tady je log z AdwDleaneru:

# AdwCleaner v5.116 - Log soubor vytvořen 10/05/2016 o 19:28:25
# Aktualizováno 09/05/2016 by Xplode
# Databáze : 2016-05-09.1 [Server]
# Operační systém : Windows Vista (TM) Home Premium Service Pack 2 (X86)
# Jméno uživatele : PLANEO - PLANEO-PC
# Spuštěno z : C:\Users\PLANEO\Desktop\adwcleaner_5.116.exe
# Volba : Čištění
# Podpora : http://toolslib.net/forum

***** [ Služby ] *****


***** [ Složky ] *****


***** [ Soubory ] *****

[#] Soubor smazáno : C:\Users\PLANEO\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pkmpcdbgnfjfeelcpebpkflcmbkclfho

***** [ DLLs ] *****


***** [ WMI ] *****


***** [ Zástupci ] *****


***** [ Naplánované úkoly ] *****


***** [ Registr ] *****


***** [ Webové prohlížeče ] *****


*************************

:: "Tracing" odstraněných kláves
:: Nastavení Winsock odstraněno

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [2441 bytes] - [09/04/2016 14:04:28]
C:\AdwCleaner\AdwCleaner[C2].txt - [1019 bytes] - [10/05/2016 19:28:25]
C:\AdwCleaner\AdwCleaner[S1].txt - [2372 bytes] - [09/04/2016 13:54:18]
C:\AdwCleaner\AdwCleaner[S2].txt - [1132 bytes] - [10/05/2016 19:15:01]

########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [1238 bytes] ##########

Denisa
Návštěvník
Návštěvník
Příspěvky: 93
Registrován: 01 črc 2013 15:32

Re: Zavirovaný NTBk virem Win32:Malware-gen.

#6 Příspěvek od Denisa »

U toho FRST to ječí, že je to riskantní stránka, tak snad to bude v pořádku :roll:

altrok
Moderátor
Moderátor
Příspěvky: 7264
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Zavirovaný NTBk virem Win32:Malware-gen.

#7 Příspěvek od altrok »

Je to nase stranka a je bezpecna, nemusite se niceho bat.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Denisa
Návštěvník
Návštěvník
Příspěvky: 93
Registrován: 01 črc 2013 15:32

Re: Zavirovaný NTBk virem Win32:Malware-gen.

#8 Příspěvek od Denisa »

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:09-05-2016
Ran by PLANEO (administrator) on PLANEO-PC (10-05-2016 20:03:43)
Running from C:\Users\PLANEO\Desktop
Loaded Profiles: PLANEO (Available Profiles: PLANEO & Asined)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 9 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\Program Files\ATK Hotkey\AsLdrSrv.exe
() C:\Program Files\ATKGFNEX\GFNEXSrv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Agere Systems) C:\Windows\System32\agrsmsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
() C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Western Digital Technologies, Inc.) C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Western Digital Technologies, Inc.) C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe
(ASUS) C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
(ASUS) C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
(ATK0100) C:\Program Files\ATK Hotkey\HControl.exe
() C:\Program Files\ATK Hotkey\MsgTranAgt.exe
() C:\Program Files\Wireless Console 2\wcourier.exe
(ASUSTeK Computer INC.) C:\Program Files\ASUS\ATK Media\DMedia.exe
( ) C:\Program Files\ASUS\ATK Media\GPSWatch.exe
(ATK) C:\Program Files\P4G\BatteryLife.exe
(ATK) C:\Program Files\ASUS\Splendid\ACMON.exe
() C:\Program Files\ASUS\ASUS Live Update\ALU.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
() C:\Program Files\ATK Hotkey\ATKOSD.exe
(ASUSTeK) C:\Windows\System32\ACEngSvr.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(CANON INC.) C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT.EXE
(Western Digital Technologies, Inc.) C:\Program Files\Western Digital\WD Security\WDDriveAutoUnlock.exe
(Western Digital Technologies, Inc.) C:\Program Files\Western Digital\WD Quick View\WDDMStatus.exe
(Western Digital Technologies, Inc.) C:\Program Files\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
() C:\Program Files\ATK Hotkey\KBFiltr.exe
() C:\Program Files\ATK Hotkey\WDC.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(forum.viry.cz) C:\Users\PLANEO\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [6265376 2008-08-12] (Realtek Semiconductor)
HKLM\...\Run: [Windows Mobile-based device management] => C:\Windows\WindowsMobile\wmdSync.exe [215552 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7390608 2016-04-19] (AVAST Software)
HKLM\...\Run: [MFNetworkScanUtility] => C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT.EXE [484760 2009-12-15] (CANON INC.)
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [839648 2016-03-10] (DivX, LLC)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM\...\Run: [WD Drive Unlocker] => C:\Program Files\Western Digital\WD Security\WDDriveAutoUnlock.exe [1694080 2013-07-10] (Western Digital Technologies, Inc.)
HKLM\...\Run: [WD Quick View] => C:\Program Files\Western Digital\WD Quick View\WDDMStatus.exe [5565296 2015-10-28] (Western Digital Technologies, Inc.)
HKLM\...\Run: [DriveUtilitiesHelper] => C:\Program Files\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe [1890664 2015-07-31] (Western Digital Technologies, Inc.)
HKLM\...\Run: [TkBellExe] => C:\Program Files\Real\RealPlayer\update\realsched.exe [295072 2013-03-29] (RealNetworks, Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation)
HKU\S-1-5-21-4067374528-2909061595-2700989555-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-4067374528-2909061595-2700989555-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5489944 2014-12-12] (Piriform Ltd)
HKU\S-1-5-21-4067374528-2909061595-2700989555-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-4067374528-2909061595-2700989555-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssBranded.scr [8139264 2008-01-21] (Microsoft Corporation)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [115440 2013-05-08] (SuperAdBlocker.com)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2016-04-19] (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\PLANEO\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\PLANEO\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\PLANEO\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\PLANEO\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2009-11-03]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog5 02 C:\Windows\system32\napinsp.dll [50176 2008-01-21] (Společnost Microsoft)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{D003C604-8EF5-412A-8446-85EB4FA30311}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.seznam.cz/?clid=22668
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-4067374528-2909061595-2700989555-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
HKU\S-1-5-21-4067374528-2909061595-2700989555-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.seznam.cz/?clid=22668
SearchScopes: HKLM -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
SearchScopes: HKLM -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={s ... lz=1I7ASUS
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-4067374528-2909061595-2700989555-1000 -> DefaultScope {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
SearchScopes: HKU\S-1-5-21-4067374528-2909061595-2700989555-1000 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
SearchScopes: HKU\S-1-5-21-4067374528-2909061595-2700989555-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={s ... 1I7ASUS_cs
BHO: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2012-09-23] (Adobe Systems Incorporated)
BHO: PDFXChange 2012 -> {42DFA04F-0F16-418e-B80C-AB97A5AFAD3A} -> C:\Program Files\Tracker Software\PDF-XChange 5\PXCIEaddin5.dll [2012-08-14] (Tracker Software Products (Canada) Ltd.)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_66\bin\ssv.dll [2015-12-20] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-04-19] (AVAST Software)
BHO: STATISTICA Browser Helper -> {990A8747-93BF-4EF7-B72E-94A6884B98C2} -> C:\Program Files\StatSoft\STATISTICA 12\StaBHO.dll [2013-04-02] (StatSoft, Inc.)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2013-12-21] (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-12-20] (Oracle Corporation)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2013-12-21] (Adobe Systems Incorporated)
Toolbar: HKLM - PDFXChange 2012 - {42DFA04F-0F16-418e-B80C-AB97A5AFAD3A} - C:\Program Files\Tracker Software\PDF-XChange 5\PXCIEaddin5.dll [2012-08-14] (Tracker Software Products (Canada) Ltd.)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2013-12-21] (Adobe Systems Incorporated)
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} hxxps://oas.support.microsoft.com/ActiveX/MSDcode.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll [2008-12-02] (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll [2008-12-02] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\cpuof8o9.default-1443448626419
FF Homepage: hxxp://www.seznam.cz/
FF Session Restore: -> is enabled.
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-07] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll [2016-03-04] (DivX, LLC)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2012-03-22] (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-12-20] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-12-20] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8051.1204 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2008-12-04] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.0.282 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll [2013-03-29] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.0 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2012-11-29] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.0 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2012-11-29] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.0 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2012-11-29] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.0.282 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll [2013-03-29] (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2012-11-29] (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2014-04-28] (Adobe Systems)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2008-10-25] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll [2013-03-29] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2015-02-07] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2015-02-07] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2015-02-07] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2015-02-07] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2015-02-07] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpplugin.dll [2013-03-29] (RealPlayer)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-01-19] [not signed]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-04-19]
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-03-29] [not signed]
FF HKLM\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2014-06-23] [not signed]

Chrome:
=======
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\PLANEO\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Adobe Acrobat) - C:\Users\PLANEO\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2016-01-03]
CHR Extension: (Avast Online Security) - C:\Users\PLANEO\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-04-19]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\PLANEO\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2014-05-08]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-04-19]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASLDRService; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [94208 2007-10-03] () [File not signed]
R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] () [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [243296 2016-04-19] (AVAST Software)
R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [225280 2007-01-20] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [131072 2007-01-20] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2008-06-09] (Hewlett-Packard Company) [File not signed]
S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [38608 2012-11-29] ()
R2 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] ()
R2 WDBackup; C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2015-10-28] (Western Digital Technologies, Inc.)
R2 WDDriveService; C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe [307576 2015-10-28] (Western Digital Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)
U4 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 Achernar; C:\Windows\System32\Drivers\Achernar.sys [18432 2007-02-05] (NewSoft Technology Corporation) [File not signed]
R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] ()
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [32792 2016-04-19] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [35096 2016-04-19] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [91168 2016-04-19] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [64272 2016-04-19] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [58776 2016-04-19] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [815792 2016-04-19] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [449640 2016-04-19] (AVAST Software)
R3 aswStmXP; C:\Windows\system32\drivers\aswStmXP.sys [187208 2016-04-19] (AVAST Software)
S3 aswTap; C:\Windows\System32\DRIVERS\aswTap.sys [35272 2013-10-24] (The OpenVPN Project)
S3 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [67216 2016-04-19] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [221368 2016-04-19] (AVAST Software)
S3 CRFILTER; C:\Windows\System32\DRIVERS\CRFILTER.sys [6656 2008-04-07] (Generic)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-11] (Společnost Microsoft)
R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [20936 2007-08-03] ()
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15928 2008-06-03] ( )
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100)
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1082232 2013-03-03] (Společnost Microsoft)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S0 sfdrv01; C:\Windows\System32\drivers\sfdrv01.sys [48640 2005-03-03] (Protection Technology) [File not signed]
R0 sfhlp02; C:\Windows\System32\drivers\sfhlp02.sys [6656 2005-02-23] (Protection Technology) [File not signed]
R0 sfsync02; C:\Windows\System32\drivers\sfsync02.sys [20544 2004-12-03] (Protection Technology) [File not signed]
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1772544 2008-07-23] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-03-09] () [File not signed]
U3 TrueSight; C:\Windows\system32\TrueSight.sys [26624 2013-10-28] () [File not signed]
U3 ao550boq; C:\Windows\system32\Drivers\ao550boq.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
U4 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-05-10 20:03 - 2016-05-10 20:05 - 00025489 _____ C:\Users\PLANEO\Desktop\FRST.txt
2016-05-10 20:03 - 2016-05-10 20:03 - 00000000 ____D C:\FRST
2016-05-10 19:58 - 2016-05-10 19:59 - 00112640 _____ (forum.viry.cz) C:\Users\PLANEO\Desktop\FRSTLauncher.exe
2016-05-10 19:44 - 2016-05-10 19:44 - 01732096 _____ (Farbar) C:\Users\PLANEO\Desktop\FRST.exe
2016-05-10 19:10 - 2016-05-10 19:10 - 03640384 _____ C:\Users\PLANEO\Desktop\adwcleaner_5.116.exe
2016-05-10 19:05 - 2016-05-10 19:05 - 00082238 _____ C:\Users\PLANEO\Desktop\nález antiviru.pdf
2016-05-09 20:05 - 2016-05-09 20:38 - 733308928 _____ C:\Users\PLANEO\Downloads\Olga Šípkova Aerobic pro všechny - Nová řada.avi
2016-05-09 10:29 - 2016-05-09 10:29 - 00143888 _____ C:\Windows\Minidump\Mini050916-01.dmp
2016-05-08 19:55 - 2016-05-08 20:03 - 1042073600 _____ C:\Users\PLANEO\Downloads\Dovolená za trest [Blended] (2014) CZ dabing.avi
2016-05-08 19:33 - 2016-05-08 19:39 - 787892224 _____ C:\Users\PLANEO\Downloads\Mysli jako on Think Like a Man (2012) CZdub.avi
2016-05-08 19:20 - 2016-05-08 19:24 - 787892224 _____ C:\Users\PLANEO\Downloads\Mysli jako on Think Like a Man (2012)CZdabing.avi
2016-05-08 00:58 - 2016-05-08 01:01 - 00000000 ____D C:\rsit
2016-05-08 00:56 - 2016-05-08 00:56 - 01107968 _____ C:\Users\PLANEO\Desktop\RSIT(1).exe
2016-05-07 19:42 - 2016-05-08 10:31 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-04-29 00:14 - 2016-04-29 00:14 - 00143888 _____ C:\Windows\Minidump\Mini042916-01.dmp
2016-04-28 21:34 - 2016-04-28 21:35 - 00143888 _____ C:\Windows\Minidump\Mini042816-01.dmp
2016-04-24 21:42 - 2016-04-24 21:42 - 00143888 _____ C:\Windows\Minidump\Mini042416-01.dmp
2016-04-19 19:20 - 2016-04-19 19:20 - 00000834 _____ C:\Users\Public\Desktop\DivX Player.lnk
2016-04-19 18:52 - 2016-04-19 18:52 - 00000863 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk
2016-04-19 18:52 - 2016-04-19 18:52 - 00000863 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-04-19 18:39 - 2016-04-19 18:37 - 00035096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2016-04-19 18:38 - 2016-04-19 18:37 - 00334280 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2016-04-19 18:37 - 2016-04-19 18:37 - 00052184 _____ (AVAST Software) C:\Windows\avastSS.scr
2016-04-10 23:03 - 2016-04-11 20:15 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-04-10 23:02 - 2016-04-10 23:02 - 00000866 _____ C:\Users\PLANEO\Desktop\Malwarebytes Anti-Malware.lnk
2016-04-10 23:02 - 2016-04-10 23:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-04-10 23:01 - 2016-04-10 23:02 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2016-04-10 23:01 - 2016-03-10 14:09 - 00053120 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-04-10 23:01 - 2016-03-10 14:08 - 00126336 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-04-10 23:01 - 2016-03-10 14:08 - 00024448 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-04-10 22:59 - 2016-04-10 23:00 - 22851472 _____ (Malwarebytes ) C:\Users\PLANEO\Desktop\mbam-setup-2.2.1.1043.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-05-10 19:53 - 2009-10-04 21:34 - 00027934 _____ C:\ProgramData\nvModes.001
2016-05-10 19:52 - 2016-03-02 21:14 - 00008192 _____ C:\Windows\system32\WDPABKP.dat
2016-05-10 19:49 - 2009-10-05 20:34 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2016-05-10 19:49 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-05-10 19:49 - 2006-11-02 14:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2016-05-10 19:49 - 2006-11-02 14:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2016-05-10 19:47 - 2006-11-02 15:01 - 00032568 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-05-10 19:30 - 2015-01-31 00:28 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-05-10 19:28 - 2016-04-09 13:53 - 00000000 ____D C:\AdwCleaner
2016-05-10 16:29 - 2014-04-29 12:46 - 00045056 _____ C:\Windows\system32\acovcnt.exe
2016-05-10 07:38 - 2008-04-17 12:34 - 00692028 _____ C:\Windows\system32\perfh005.dat
2016-05-10 07:38 - 2008-04-17 12:34 - 00155480 _____ C:\Windows\system32\perfc005.dat
2016-05-10 07:38 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\inf
2016-05-10 07:38 - 2006-11-02 12:33 - 01663968 _____ C:\Windows\system32\PerfStringBackup.INI
2016-05-09 10:29 - 2015-10-13 16:35 - 371531718 _____ C:\Windows\MEMORY.DMP
2016-05-09 10:29 - 2010-10-03 11:00 - 00000000 ____D C:\Windows\Minidump
2016-05-09 09:17 - 2012-04-06 03:21 - 00000000 ____D C:\Users\PLANEO\AppData\Roaming\vlc
2016-05-09 09:16 - 2009-10-05 20:33 - 00209408 _____ C:\Users\PLANEO\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-05-09 09:14 - 2009-10-01 22:09 - 00112488 _____ C:\Users\PLANEO\AppData\Local\GDIPFONTCACHEV1.DAT
2016-05-08 10:31 - 2012-04-25 18:37 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2016-05-08 01:14 - 2013-10-27 18:31 - 00000000 ____D C:\Program Files\trend micro
2016-05-05 16:27 - 2011-10-29 09:54 - 00000000 ____D C:\Program Files\Opera
2016-05-03 19:10 - 2009-10-04 21:31 - 00027934 _____ C:\ProgramData\nvModes.dat
2016-04-22 03:10 - 2006-11-02 12:22 - 74186752 _____ C:\Windows\system32\config\software_previous
2016-04-22 03:09 - 2013-07-01 14:59 - 00000000 ____D C:\Users\Asined
2016-04-22 03:09 - 2009-10-01 22:09 - 00000000 ____D C:\Users\PLANEO
2016-04-22 03:09 - 2009-05-05 08:07 - 00000000 ____D C:\ProgramData\P4G
2016-04-22 03:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\spool
2016-04-22 03:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\Msdtc
2016-04-22 03:09 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\registration
2016-04-22 03:09 - 2006-11-02 12:22 - 43253760 _____ C:\Windows\system32\config\system_previous
2016-04-22 03:06 - 2006-11-02 12:22 - 49020928 _____ C:\Windows\system32\config\components_previous
2016-04-22 03:06 - 2006-11-02 12:22 - 00262144 _____ C:\Windows\system32\config\sam_previous
2016-04-20 19:15 - 2006-11-02 12:22 - 00524288 _____ C:\Windows\system32\config\default_previous
2016-04-20 19:07 - 2006-11-02 12:22 - 00262144 _____ C:\Windows\system32\config\security_previous
2016-04-20 19:06 - 2012-04-06 14:38 - 00000000 ____D C:\Users\PLANEO\AppData\Roaming\DivX
2016-04-19 20:04 - 2015-03-15 19:13 - 00000000 ____D C:\ProgramData\Package Cache
2016-04-19 19:59 - 2015-03-08 17:34 - 00000000 ____D C:\Program Files\Western Digital
2016-04-19 19:59 - 2015-03-08 17:34 - 00000000 ____D C:\Program Files\Common Files\Western Digital
2016-04-19 19:59 - 2015-03-08 17:33 - 00000000 ____D C:\ProgramData\Western Digital
2016-04-19 19:22 - 2015-01-31 00:32 - 00001402 _____ C:\Users\PLANEO\Desktop\DivX Movies.lnk
2016-04-19 19:22 - 2012-04-06 01:16 - 00000000 ____D C:\Program Files\DivX
2016-04-19 19:22 - 2012-04-06 01:15 - 00000000 ____D C:\ProgramData\DivX
2016-04-19 19:20 - 2013-11-21 16:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX
2016-04-19 19:19 - 2014-07-27 14:38 - 00000859 _____ C:\Users\Public\Desktop\DivX Converter.lnk
2016-04-19 19:16 - 2012-04-06 01:21 - 00000000 ____D C:\Program Files\Common Files\DivX Shared
2016-04-19 18:41 - 2013-04-21 11:50 - 00221368 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys
2016-04-19 18:38 - 2015-09-30 19:30 - 00187208 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStmXP.sys
2016-04-19 18:38 - 2014-04-28 17:35 - 00032792 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2016-04-19 18:38 - 2013-04-21 11:50 - 00058776 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2016-04-19 18:38 - 2011-10-25 08:00 - 00000000 ____D C:\ProgramData\AVAST Software
2016-04-19 18:38 - 2010-01-05 12:30 - 00449640 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2016-04-19 18:38 - 2010-01-05 12:30 - 00091168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2016-04-19 18:38 - 2010-01-05 12:30 - 00067216 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2016-04-19 18:38 - 2010-01-05 12:30 - 00064272 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr.sys
2016-04-19 18:37 - 2011-10-25 08:02 - 00815792 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2016-04-19 18:37 - 2011-10-25 08:01 - 00000000 ____D C:\Program Files\AVAST Software
2016-04-12 17:06 - 2012-02-20 02:04 - 00001950 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-12 17:06 - 2012-02-20 02:04 - 00001938 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-04-11 21:13 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\schemas
2016-04-10 21:08 - 2006-11-02 14:47 - 00419832 _____ C:\Windows\system32\FNTCACHE.DAT

==================== Files in the root of some directories =======

2002-08-29 18:33 - 2002-08-29 18:33 - 0319488 _____ () C:\Users\PLANEO\AppData\Roaming\MafiaSetup.exe
2010-09-28 20:42 - 2015-10-07 19:39 - 0001356 _____ () C:\Users\PLANEO\AppData\Local\d3d9caps.dat
2009-10-05 20:33 - 2016-05-09 09:16 - 0209408 _____ () C:\Users\PLANEO\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-12-22 21:11 - 2015-12-22 21:11 - 0000000 _____ () C:\Users\PLANEO\AppData\Local\{14C41B13-ECA6-4B7E-9594-AEA2746953C1}
2016-02-20 20:21 - 2016-02-20 20:21 - 0000000 _____ () C:\Users\PLANEO\AppData\Local\{2AF634FD-7DDC-4A99-8BD2-CFE8154C3D6D}
2016-03-25 20:19 - 2016-03-25 20:19 - 0000000 _____ () C:\Users\PLANEO\AppData\Local\{3244FF5F-C96F-4A97-90C3-A3E50938D660}
2016-01-03 21:13 - 2016-01-03 21:13 - 0000000 _____ () C:\Users\PLANEO\AppData\Local\{3ACF774F-4283-4D77-9F29-63B99FAC7567}
2016-03-24 20:19 - 2016-03-24 20:19 - 0000000 _____ () C:\Users\PLANEO\AppData\Local\{6D0E40EF-A4F2-4FEA-861B-C1E57523F539}
2009-11-11 23:17 - 2009-11-11 23:17 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2013-06-22 17:00 - 2013-06-23 00:35 - 0000000 _____ () C:\ProgramData\g252qs.txt
2009-11-03 19:31 - 2010-03-30 20:34 - 0001854 _____ () C:\ProgramData\hpzinstall.log
2009-10-04 21:34 - 2016-05-10 19:53 - 0027934 _____ () C:\ProgramData\nvModes.001
2009-10-04 21:31 - 2016-05-03 19:10 - 0027934 _____ () C:\ProgramData\nvModes.dat

Files to move or delete:
====================
C:\Users\PLANEO\winmail.dat
C:\Users\PLANEO\WMDecode.exe


Some files in TEMP:
====================
C:\Users\PLANEO\AppData\Local\temp\libeay32.dll
C:\Users\PLANEO\AppData\Local\temp\msvcr120.dll
C:\Users\PLANEO\AppData\Local\temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\PLANEO\Desktop" je 455 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================
Přílohy
Addition.zip
(6.11 KiB) Staženo 49 x

altrok
Moderátor
Moderátor
Příspěvky: 7264
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Zavirovaný NTBk virem Win32:Malware-gen.

#9 Příspěvek od altrok »

:arrow: Odinstalujte starou a zranitelnou verzi Javy. Pokud Javu potrebujete, pak nainstalujte novou z java.com/verify - pozor na adware pri instalaci. Pote se presvedcte, ze starsi verze jsou odinstalovane. Z hlediska bezpecnosti (zranitelnosti a exploity) je lepsi ji nemit. Aktualni je 8U91. Verze Javy, ktere v PC mate nainstalovane:

  • Java 8 Update 66



:arrow: Velikost plochy by nemela presahovat 200 MB. Zpomaluje se pak start i samotny chod celeho PC. Doporucuji hlavne velke soubory a slozky premistit napr. do Dokumentu a na plochu umistit pouze zastupce.


:arrow: Odinstalujte
:arrow: Po restartu dejte vedet, jak se PC chova.



  • Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
  • ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
  • znovu spustte FRST a kliknete na Fix
  • po restartu bude na plose ulozen fixlog, jehoz obsah vlozte do pristi odpovedi

    Kód: Vybrat vše

    Start
    CreateRestorePoint:
    CloseProcesses:
    HKLM\...\Run: [TkBellExe] => C:\Program Files\Real\RealPlayer\update\realsched.exe [295072 2013-03-29] (RealNetworks, Inc.)
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    2016-05-10 19:10 - 2016-05-10 19:10 - 03640384 _____ C:\Users\PLANEO\Desktop\adwcleaner_5.116.exe
    2016-05-10 19:05 - 2016-05-10 19:05 - 00082238 _____ C:\Users\PLANEO\Desktop\nález antiviru.pdf
    2016-05-08 00:58 - 2016-05-08 01:01 - 00000000 ____D C:\rsit
    2016-05-08 00:56 - 2016-05-08 00:56 - 01107968 _____ C:\Users\PLANEO\Desktop\RSIT(1).exe
    2016-04-10 22:59 - 2016-04-10 23:00 - 22851472 _____ (Malwarebytes ) C:\Users\PLANEO\Desktop\mbam-setup-2.2.1.1043.exe
    File: C:\ProgramData\nvModes.001
    2016-05-10 19:28 - 2016-04-09 13:53 - 00000000 ____D C:\AdwCleaner
    2016-05-08 01:14 - 2013-10-27 18:31 - 00000000 ____D C:\Program Files\trend micro
    2015-12-22 21:11 - 2015-12-22 21:11 - 0000000 _____ () C:\Users\PLANEO\AppData\Local\{14C41B13-ECA6-4B7E-9594-AEA2746953C1}
    2016-02-20 20:21 - 2016-02-20 20:21 - 0000000 _____ () C:\Users\PLANEO\AppData\Local\{2AF634FD-7DDC-4A99-8BD2-CFE8154C3D6D}
    2016-03-25 20:19 - 2016-03-25 20:19 - 0000000 _____ () C:\Users\PLANEO\AppData\Local\{3244FF5F-C96F-4A97-90C3-A3E50938D660}
    2016-01-03 21:13 - 2016-01-03 21:13 - 0000000 _____ () C:\Users\PLANEO\AppData\Local\{3ACF774F-4283-4D77-9F29-63B99FAC7567}
    2016-03-24 20:19 - 2016-03-24 20:19 - 0000000 _____ () C:\Users\PLANEO\AppData\Local\{6D0E40EF-A4F2-4FEA-861B-C1E57523F539}
    2009-11-11 23:17 - 2009-11-11 23:17 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
    File: C:\Users\PLANEO\winmail.dat
    File: C:\Users\PLANEO\WMDecode.exe
    C:\Users\PLANEO\AppData\Local\temp
    Task: {0AFC1AA3-17C5-47FB-BAC5-1A6BAC228A1D} - System32\Tasks\{D5B0385B-7A0C-4CA5-B310-6CA5C17F9033} => pcalua.exe -a G:\Install.exe -d G:\
    Task: {79A384F1-56FB-4383-B169-BB65F2E81196} - System32\Tasks\{2F664B61-AE20-4E30-AF7E-02EBBA9A2EA6} => pcalua.exe -a G:\enzin\Enzin.exe -d G:\enzin
    Task: {9F238C3C-0421-4CCF-A60A-F5FD4D855A73} - System32\Tasks\{25B7A020-9E7B-4885-8EED-27EC89863F90} => pcalua.exe -a G:\enzin\Enzin.exe -d G:\enzin
    Hosts:
    End
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Denisa
Návštěvník
Návštěvník
Příspěvky: 93
Registrován: 01 črc 2013 15:32

Re: Zavirovaný NTBk virem Win32:Malware-gen.

#10 Příspěvek od Denisa »

Dobrý den, děkuji moc za upozornění, staré věci jsou fuč a Plocha má teď (pokud se dívám správně) méně než 20 Mb :D

Tady je fixlog:

Fix result of Farbar Recovery Scan Tool (x86) Version:14-05-2016
Ran by PLANEO (2016-05-14 14:17:44) Run:1
Running from C:\Users\PLANEO\Desktop
Loaded Profiles: PLANEO (Available Profiles: PLANEO & Asined)
Boot Mode: Normal

==============================================

fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
HKLM\...\Run: [TkBellExe] => C:\Program Files\Real\RealPlayer\update\realsched.exe [295072 2013-03-29] (RealNetworks, Inc.)
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
2016-05-10 19:10 - 2016-05-10 19:10 - 03640384 _____ C:\Users\PLANEO\Desktop\adwcleaner_5.116.exe
2016-05-10 19:05 - 2016-05-10 19:05 - 00082238 _____ C:\Users\PLANEO\Desktop\nález antiviru.pdf
2016-05-08 00:58 - 2016-05-08 01:01 - 00000000 ____D C:\rsit
2016-05-08 00:56 - 2016-05-08 00:56 - 01107968 _____ C:\Users\PLANEO\Desktop\RSIT(1).exe
2016-04-10 22:59 - 2016-04-10 23:00 - 22851472 _____ (Malwarebytes ) C:\Users\PLANEO\Desktop\mbam-setup-2.2.1.1043.exe
File: C:\ProgramData\nvModes.001
2016-05-10 19:28 - 2016-04-09 13:53 - 00000000 ____D C:\AdwCleaner
2016-05-08 01:14 - 2013-10-27 18:31 - 00000000 ____D C:\Program Files\trend micro
2015-12-22 21:11 - 2015-12-22 21:11 - 0000000 _____ () C:\Users\PLANEO\AppData\Local\{14C41B13-ECA6-4B7E-9594-AEA2746953C1}
2016-02-20 20:21 - 2016-02-20 20:21 - 0000000 _____ () C:\Users\PLANEO\AppData\Local\{2AF634FD-7DDC-4A99-8BD2-CFE8154C3D6D}
2016-03-25 20:19 - 2016-03-25 20:19 - 0000000 _____ () C:\Users\PLANEO\AppData\Local\{3244FF5F-C96F-4A97-90C3-A3E50938D660}
2016-01-03 21:13 - 2016-01-03 21:13 - 0000000 _____ () C:\Users\PLANEO\AppData\Local\{3ACF774F-4283-4D77-9F29-63B99FAC7567}
2016-03-24 20:19 - 2016-03-24 20:19 - 0000000 _____ () C:\Users\PLANEO\AppData\Local\{6D0E40EF-A4F2-4FEA-861B-C1E57523F539}
2009-11-11 23:17 - 2009-11-11 23:17 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
File: C:\Users\PLANEO\winmail.dat
File: C:\Users\PLANEO\WMDecode.exe
C:\Users\PLANEO\AppData\Local\temp
Task: {0AFC1AA3-17C5-47FB-BAC5-1A6BAC228A1D} - System32\Tasks\{D5B0385B-7A0C-4CA5-B310-6CA5C17F9033} => pcalua.exe -a G:\Install.exe -d G:\
Task: {79A384F1-56FB-4383-B169-BB65F2E81196} - System32\Tasks\{2F664B61-AE20-4E30-AF7E-02EBBA9A2EA6} => pcalua.exe -a G:\enzin\Enzin.exe -d G:\enzin
Task: {9F238C3C-0421-4CCF-A60A-F5FD4D855A73} - System32\Tasks\{25B7A020-9E7B-4885-8EED-27EC89863F90} => pcalua.exe -a G:\enzin\Enzin.exe -d G:\enzin
Hosts:
End
*****************

Restore point was successfully created.
Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\TkBellExe => value removed successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
C:\Users\PLANEO\Desktop\adwcleaner_5.116.exe => moved successfully
"C:\Users\PLANEO\Desktop\nález antiviru.pdf" => not found.
C:\rsit => moved successfully
C:\Users\PLANEO\Desktop\RSIT(1).exe => moved successfully
C:\Users\PLANEO\Desktop\mbam-setup-2.2.1.1043.exe => moved successfully

========================= File: C:\ProgramData\nvModes.001 ========================

====== End of File: ======

C:\AdwCleaner => moved successfully
C:\Program Files\trend micro => moved successfully
C:\Users\PLANEO\AppData\Local\{14C41B13-ECA6-4B7E-9594-AEA2746953C1} => moved successfully
C:\Users\PLANEO\AppData\Local\{2AF634FD-7DDC-4A99-8BD2-CFE8154C3D6D} => moved successfully
C:\Users\PLANEO\AppData\Local\{3244FF5F-C96F-4A97-90C3-A3E50938D660} => moved successfully
C:\Users\PLANEO\AppData\Local\{3ACF774F-4283-4D77-9F29-63B99FAC7567} => moved successfully
C:\Users\PLANEO\AppData\Local\{6D0E40EF-A4F2-4FEA-861B-C1E57523F539} => moved successfully
C:\ProgramData\ezsidmv.dat => moved successfully

========================= File: C:\Users\PLANEO\winmail.dat ========================

====== End of File: ======


========================= File: C:\Users\PLANEO\WMDecode.exe ========================

====== End of File: ======

C:\Users\PLANEO\AppData\Local\temp => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0AFC1AA3-17C5-47FB-BAC5-1A6BAC228A1D}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0AFC1AA3-17C5-47FB-BAC5-1A6BAC228A1D}" => key removed successfully.
C:\Windows\System32\Tasks\{D5B0385B-7A0C-4CA5-B310-6CA5C17F9033} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D5B0385B-7A0C-4CA5-B310-6CA5C17F9033}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{79A384F1-56FB-4383-B169-BB65F2E81196}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79A384F1-56FB-4383-B169-BB65F2E81196}" => key removed successfully.
C:\Windows\System32\Tasks\{2F664B61-AE20-4E30-AF7E-02EBBA9A2EA6} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2F664B61-AE20-4E30-AF7E-02EBBA9A2EA6}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9F238C3C-0421-4CCF-A60A-F5FD4D855A73}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9F238C3C-0421-4CCF-A60A-F5FD4D855A73}" => key removed successfully.
C:\Windows\System32\Tasks\{25B7A020-9E7B-4885-8EED-27EC89863F90} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{25B7A020-9E7B-4885-8EED-27EC89863F90}" => key removed successfully.
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.


The system needed a reboot.

==== End of Fixlog 14:22:20 ====

altrok
Moderátor
Moderátor
Příspěvky: 7264
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Zavirovaný NTBk virem Win32:Malware-gen.

#11 Příspěvek od altrok »

:arrow: Ulozte na plochu ESET Online Scanner kliknutim na esetsmartinstaller_csy.exe
  • ulozeny esetsmartinstaller_csy.exe dvojklikem spustte
  • zaskrtnete Ano, souhlasim s podminkami uziti a kliknete na Spustit
  • vyberte moznost Povolit detekci nechtenych aplikaci
  • rozkliknete moznost Rozsirene nastaveni a
    • zruste zatrzitko u volby Odstranit nalezene infiltrace
    • ponechte zatrhnutou moznost Pouzit technologii Anti-Stealth
  • kliknete na Kontrola, cimz se spusti az nekolikahodinovy sken
  • po dokonceni skenu kliknete na Seznam nalezenych infiltraci (v pripade zadneho nalezu log nevytvorite)
  • kliknete na Ulozit do textoveho souboru, log pojmenujte jako ESETlog a ulozte na plochu
  • obsah logu vlozte do pristi odpovedi
  • kliknete na << Zpet a zatrhnete moznost Odinstalovat
  • klikem na Dokoncit ESET Online Scanner zavrete.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Denisa
Návštěvník
Návštěvník
Příspěvky: 93
Registrován: 01 črc 2013 15:32

Re: Zavirovaný NTBk virem Win32:Malware-gen.

#12 Příspěvek od Denisa »

C:\ProgramData\InstallMate\{8455ABBB-F1EB-4267-A08C-B9C95FB6894D}\Custom.dll Win32/InstalleRex.T potenciálně nechtěná aplikace
C:\ProgramData\InstallMate\{96CEC88C-B018-4ADF-A834-F83A4D2DEA7A}\Custom.dll Win32/InstalleRex.L potenciálně nechtěná aplikace
C:\ProgramData\InstallMate\{FD459AC9-3709-C651-F0A8-3334F9696BB4}\_Setupx.dll varianta infiltrace Win32/InstalleRex.T potenciálně nechtěná aplikace
C:\Users\PLANEO\Downloads\cbsidlm-cbsi188-Winmail_Opener-BP-10469892.exe varianta infiltrace Win32/CNETInstaller.B potenciálně nechtěná aplikace
C:\Users\PLANEO\Downloads\nsinstall(1).exe varianta infiltrace Win32/Trackware.Gemius.AB potenciálně nechtěná aplikace
C:\Users\PLANEO\Downloads\nsinstall.exe varianta infiltrace Win32/Trackware.Gemius.AB potenciálně nechtěná aplikace
C:\Users\PLANEO\Vejška\Bakalářky\The Lair (TV) Season 3 [2009]\The_Lair_Season_3_downloader_424b.exe varianta infiltrace Win32/ExpressFiles potenciálně nechtěná aplikace
C:\Users\PLANEO\Vejška\BP\Koulová\The_Lair_Season_3_downloader_424b.exe varianta infiltrace Win32/ExpressFiles potenciálně nechtěná aplikace
D:\Vejška\Bakalářky\The Lair (TV) Season 3 [2009]\The_Lair_Season_3_downloader_424b.exe varianta infiltrace Win32/ExpressFiles potenciálně nechtěná aplikace
D:\Vejška\BP\Koulová\The_Lair_Season_3_downloader_424b.exe varianta infiltrace Win32/ExpressFiles potenciálně nechtěná aplikace

altrok
Moderátor
Moderátor
Příspěvky: 7264
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Zavirovaný NTBk virem Win32:Malware-gen.

#13 Příspěvek od altrok »

  • Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
  • ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
  • znovu spustte FRST a kliknete na Fix
  • po restartu bude na plose ulozen fixlog, jehoz obsah vlozte do pristi odpovedi

    Kód: Vybrat vše

    Start
    CloseProcesses:
    C:\ProgramData\InstallMate\{8455ABBB-F1EB-4267-A08C-B9C95FB6894D}\Custom.dll
    C:\ProgramData\InstallMate\{96CEC88C-B018-4ADF-A834-F83A4D2DEA7A}\Custom.dll
    C:\ProgramData\InstallMate\{FD459AC9-3709-C651-F0A8-3334F9696BB4}\_Setupx.dll
    C:\Users\PLANEO\Downloads\cbsidlm-cbsi188-Winmail_Opener-BP-10469892.exe
    C:\Users\PLANEO\Downloads\nsinstall(1).exe
    C:\Users\PLANEO\Downloads\nsinstall.exe
    C:\Users\PLANEO\Vejška\Bakalářky\The Lair (TV) Season 3 [2009]\The_Lair_Season_3_downloader_424b.exe
    C:\Users\PLANEO\Vejška\BP\Koulová\The_Lair_Season_3_downloader_424b.exe
    D:\Vejška\Bakalářky\The Lair (TV) Season 3 [2009]\The_Lair_Season_3_downloader_424b.exe
    D:\Vejška\BP\Koulová\The_Lair_Season_3_downloader_424b.exe
    End
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Denisa
Návštěvník
Návštěvník
Příspěvky: 93
Registrován: 01 črc 2013 15:32

Re: Zavirovaný NTBk virem Win32:Malware-gen.

#14 Příspěvek od Denisa »

Dobrý den, omlouvám se, měla jsem teď trochu moc práce. Tady to je:

Fix result of Farbar Recovery Scan Tool (x86) Version:25-05-2016
Ran by PLANEO (2016-05-25 20:22:25) Run:2
Running from C:\Users\PLANEO\Desktop
Loaded Profiles: PLANEO (Available Profiles: PLANEO & Asined)
Boot Mode: Normal

==============================================

fixlist content:
*****************
Start
CloseProcesses:
C:\ProgramData\InstallMate\{8455ABBB-F1EB-4267-A08C-B9C95FB6894D}\Custom.dll
C:\ProgramData\InstallMate\{96CEC88C-B018-4ADF-A834-F83A4D2DEA7A}\Custom.dll
C:\ProgramData\InstallMate\{FD459AC9-3709-C651-F0A8-3334F9696BB4}\_Setupx.dll
C:\Users\PLANEO\Downloads\cbsidlm-cbsi188-Winmail_Opener-BP-10469892.exe
C:\Users\PLANEO\Downloads\nsinstall(1).exe
C:\Users\PLANEO\Downloads\nsinstall.exe
C:\Users\PLANEO\Vejška\Bakalářky\The Lair (TV) Season 3 [2009]\The_Lair_Season_3_downloader_424b.exe
C:\Users\PLANEO\Vejška\BP\Koulová\The_Lair_Season_3_downloader_424b.exe
D:\Vejška\Bakalářky\The Lair (TV) Season 3 [2009]\The_Lair_Season_3_downloader_424b.exe
D:\Vejška\BP\Koulová\The_Lair_Season_3_downloader_424b.exe
End

*****************

Processes closed successfully.
C:\ProgramData\InstallMate\{8455ABBB-F1EB-4267-A08C-B9C95FB6894D}\Custom.dll => moved successfully
C:\ProgramData\InstallMate\{96CEC88C-B018-4ADF-A834-F83A4D2DEA7A}\Custom.dll => moved successfully
C:\ProgramData\InstallMate\{FD459AC9-3709-C651-F0A8-3334F9696BB4}\_Setupx.dll => moved successfully
C:\Users\PLANEO\Downloads\cbsidlm-cbsi188-Winmail_Opener-BP-10469892.exe => moved successfully
C:\Users\PLANEO\Downloads\nsinstall(1).exe => moved successfully
C:\Users\PLANEO\Downloads\nsinstall.exe => moved successfully
C:\Users\PLANEO\Vejška\Bakalářky\The Lair (TV) Season 3 [2009]\The_Lair_Season_3_downloader_424b.exe => moved successfully
C:\Users\PLANEO\Vejška\BP\Koulová\The_Lair_Season_3_downloader_424b.exe => moved successfully
D:\Vejška\Bakalářky\The Lair (TV) Season 3 [2009]\The_Lair_Season_3_downloader_424b.exe => moved successfully
D:\Vejška\BP\Koulová\The_Lair_Season_3_downloader_424b.exe => moved successfully


The system needed a reboot.

==== End of Fixlog 20:22:35 ====

altrok
Moderátor
Moderátor
Příspěvky: 7264
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Zavirovaný NTBk virem Win32:Malware-gen.

#15 Příspěvek od altrok »

:arrow: Nic se nedeje - kazdy ma povinnosti. Za tech 10 dni se v PC jeste mohlo neco prihodit, takze jeste jednou pro jistotu zkontrolujeme. Dejte logy FRST.txt a Addition.txt - http://forum.viry.cz/viewtopic.php?f=30&t=133101
Pozn. pri druhem a dalsim spusteni FRST je pro vytvoreni logu Addition.txt nutne tuto volbu explicitne zatrhnout pred zacatkem skenu.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Odpovědět