Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

FB účet rozesílá viry

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
miloshek
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 26 bře 2007 23:38
Bydliště: OLOMOUCITY
Kontaktovat uživatele:

FB účet rozesílá viry

#1 Příspěvek od miloshek »

Zdravím. Mám tu účet na Facebook a lidem z přátel se rozesílá do zpráv z tohoto účtu spam a viry (odkazy na videa). Dá se s tím něco udělat? Díky.....

Logfile of random's system information tool 1.10 (written by random/random)
Run by LENOVO at 2017-08-03 09:40:35
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 60 GB (40%) free of 153 GB
Total RAM: 3033 MB (71% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:41:25, on 3.8.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18739)
Boot mode: Normal

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Users\LENOVO\Desktop\RSIT.exe
C:\Program Files\trend micro\LENOVO.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_141\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office16\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_141\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\PROGRA~1\MICROS~3\Office16\EXCEL.EXE/3000
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: TeamViewer 11 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer\TeamViewer_Service.exe

--
End of file - 4514 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_141\bin\ssv.dll [2017-07-24 473664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office16\URLREDIR.DLL [2015-07-31 403672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_141\bin\jp2ssv.dll [2017-07-24 187968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-02-11 137752]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-02-11 171032]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-02-11 172568]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2016-11-14 1002984]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2017-07-12 587288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-02-11 228864]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\03556973.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\03556973.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-08-03 09:40:35 ----D---- C:\rsit
2017-08-03 09:40:35 ----D---- C:\Program Files\trend micro
2017-08-02 21:24:43 ----A---- C:\Windows\system32\FNTCACHE.DAT
2017-08-02 21:06:34 ----SHD---- C:\Config.Msi
2017-07-24 20:16:43 ----D---- C:\AdwCleaner
2017-07-24 19:43:35 ----D---- C:\Program Files\Common Files\Java
2017-07-12 07:22:11 ----A---- C:\Windows\system32\mshtml.dll
2017-07-12 07:22:02 ----A---- C:\Windows\system32\ieframe.dll
2017-07-12 07:22:00 ----A---- C:\Windows\system32\win32k.sys
2017-07-12 07:22:00 ----A---- C:\Windows\system32\urlmon.dll
2017-07-12 07:22:00 ----A---- C:\Windows\system32\jscript9.dll
2017-07-12 07:21:59 ----A---- C:\Windows\system32\vbscript.dll
2017-07-12 07:21:59 ----A---- C:\Windows\system32\tquery.dll
2017-07-12 07:21:59 ----A---- C:\Windows\system32\Query.dll
2017-07-12 07:21:59 ----A---- C:\Windows\system32\kerberos.dll
2017-07-12 07:21:59 ----A---- C:\Windows\system32\ExplorerFrame.dll
2017-07-12 07:21:59 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2017-07-12 07:21:58 ----A---- C:\Windows\system32\Wldap32.dll
2017-07-12 07:21:58 ----A---- C:\Windows\system32\wininet.dll
2017-07-12 07:21:58 ----A---- C:\Windows\system32\drivers\ntfs.sys
2017-07-12 07:21:58 ----A---- C:\Windows\system32\drivers\netio.sys
2017-07-12 07:21:57 ----A---- C:\Windows\system32\wdc.dll
2017-07-12 07:21:57 ----A---- C:\Windows\system32\pdhui.dll
2017-07-12 07:21:57 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2017-07-12 07:21:57 ----A---- C:\Windows\system32\msinfo32.exe
2017-07-12 07:21:57 ----A---- C:\Windows\system32\iedkcs32.dll
2017-07-12 07:21:57 ----A---- C:\Windows\system32\drivers\tcpip.sys
2017-07-12 07:21:57 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2017-07-12 07:21:57 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2017-07-12 07:21:57 ----A---- C:\Windows\system32\drivers\http.sys
2017-07-12 07:21:57 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2017-07-12 07:21:57 ----A---- C:\Windows\system32\clfs.sys
2017-07-12 07:21:56 ----A---- C:\Windows\system32\wvc.dll
2017-07-12 07:21:56 ----A---- C:\Windows\system32\perfmon.exe
2017-07-12 07:21:56 ----A---- C:\Windows\system32\msrating.dll
2017-07-12 07:21:56 ----A---- C:\Windows\system32\dxtmsft.dll
2017-07-12 07:21:56 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2017-07-12 07:21:55 ----A---- C:\Windows\system32\webcheck.dll
2017-07-12 07:21:55 ----A---- C:\Windows\system32\resmon.exe
2017-07-12 07:21:55 ----A---- C:\Windows\system32\dxtrans.dll
2017-07-12 07:21:53 ----A---- C:\Windows\system32\mshtmlmedia.dll
2017-07-12 07:21:53 ----A---- C:\Windows\system32\msfeeds.dll
2017-07-12 07:21:52 ----A---- C:\Windows\system32\ieui.dll
2017-07-12 07:21:52 ----A---- C:\Windows\system32\iertutil.dll
2017-07-12 07:21:52 ----A---- C:\Windows\system32\ie4uinit.exe
2017-07-12 07:21:51 ----A---- C:\Windows\system32\occache.dll
2017-07-12 07:21:51 ----A---- C:\Windows\system32\mshtmled.dll
2017-07-12 07:21:51 ----A---- C:\Windows\system32\jscript9diag.dll
2017-07-12 07:21:51 ----A---- C:\Windows\system32\ieUnatt.exe
2017-07-12 07:21:51 ----A---- C:\Windows\system32\iesetup.dll
2017-07-12 07:21:50 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-07-12 07:21:50 ----A---- C:\Windows\system32\inseng.dll
2017-07-12 07:21:50 ----A---- C:\Windows\system32\iernonce.dll
2017-07-12 07:21:49 ----A---- C:\Windows\system32\MshtmlDac.dll
2017-07-12 07:21:49 ----A---- C:\Windows\system32\jsproxy.dll
2017-07-12 07:21:49 ----A---- C:\Windows\system32\ieetwproxystub.dll
2017-07-12 07:21:49 ----A---- C:\Windows\system32\ieetwcollector.exe
2017-07-12 07:21:48 ----A---- C:\Windows\system32\rpcrt4.dll
2017-07-12 07:21:48 ----A---- C:\Windows\system32\mssvp.dll
2017-07-12 07:21:48 ----A---- C:\Windows\system32\mssrch.dll
2017-07-12 07:21:48 ----A---- C:\Windows\system32\jscript.dll
2017-07-12 07:21:48 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2017-07-12 07:21:48 ----A---- C:\Windows\system32\ieapfltr.dll
2017-07-12 07:21:48 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2017-07-12 07:21:48 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2017-07-12 07:21:47 ----A---- C:\Windows\system32\wdigest.dll
2017-07-12 07:21:47 ----A---- C:\Windows\system32\TSpkg.dll
2017-07-12 07:21:47 ----A---- C:\Windows\system32\sspicli.dll
2017-07-12 07:21:47 ----A---- C:\Windows\system32\schannel.dll
2017-07-12 07:21:47 ----A---- C:\Windows\system32\SearchIndexer.exe
2017-07-12 07:21:47 ----A---- C:\Windows\system32\rpchttp.dll
2017-07-12 07:21:47 ----A---- C:\Windows\system32\ncrypt.dll
2017-07-12 07:21:47 ----A---- C:\Windows\system32\msv1_0.dll
2017-07-12 07:21:47 ----A---- C:\Windows\system32\mssphtb.dll
2017-07-12 07:21:47 ----A---- C:\Windows\system32\mssph.dll
2017-07-12 07:21:47 ----A---- C:\Windows\system32\mssitlb.dll
2017-07-12 07:21:47 ----A---- C:\Windows\system32\lsasrv.dll
2017-07-12 07:21:47 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2017-07-12 07:21:47 ----A---- C:\Windows\system32\bcrypt.dll
2017-07-12 07:21:46 ----A---- C:\Windows\system32\sspisrv.dll
2017-07-12 07:21:46 ----A---- C:\Windows\system32\secur32.dll
2017-07-12 07:21:46 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2017-07-12 07:21:46 ----A---- C:\Windows\system32\SearchFilterHost.exe
2017-07-12 07:21:46 ----A---- C:\Windows\system32\mssprxy.dll
2017-07-12 07:21:46 ----A---- C:\Windows\system32\msshooks.dll
2017-07-12 07:21:46 ----A---- C:\Windows\system32\msscntrs.dll
2017-07-12 07:21:46 ----A---- C:\Windows\system32\lsass.exe
2017-07-12 07:21:46 ----A---- C:\Windows\system32\cryptbase.dll
2017-07-12 07:21:46 ----A---- C:\Windows\system32\credssp.dll
2017-07-12 07:21:46 ----A---- C:\Windows\system32\cdd.dll
2017-07-12 07:21:46 ----A---- C:\Windows\system32\auditpol.exe
2017-07-12 07:21:45 ----A---- C:\Windows\system32\tzres.dll
2017-07-12 07:21:44 ----A---- C:\Windows\system32\msobjs.dll
2017-07-12 07:21:44 ----A---- C:\Windows\system32\msaudite.dll
2017-07-12 07:21:44 ----A---- C:\Windows\system32\adtschema.dll
2017-07-12 07:18:12 ----A---- C:\Windows\system32\aitstatic.exe
2017-07-12 07:18:12 ----A---- C:\Windows\system32\aeinv.dll
2017-07-12 07:18:11 ----A---- C:\Windows\system32\appraiser.dll
2017-07-12 07:18:11 ----A---- C:\Windows\system32\aepic.dll
2017-07-12 07:18:10 ----A---- C:\Windows\system32\invagent.dll
2017-07-12 07:18:10 ----A---- C:\Windows\system32\devinv.dll
2017-07-12 07:18:10 ----A---- C:\Windows\system32\centel.dll
2017-07-12 07:18:09 ----A---- C:\Windows\system32\generaltel.dll
2017-07-12 07:18:09 ----A---- C:\Windows\system32\CompatTelRunner.exe
2017-07-12 07:18:08 ----A---- C:\Windows\system32\acmigration.dll
2017-07-07 20:30:52 ----D---- C:\KVRT_Data
2017-07-07 20:29:06 ----D---- C:\ProgramData\AppData

======List of files/folders modified in the last 1 month======

2017-08-03 09:41:08 ----D---- C:\Windows\Prefetch
2017-08-03 09:41:04 ----D---- C:\Windows\Temp
2017-08-03 09:40:35 ----RD---- C:\Program Files
2017-08-02 21:39:10 ----D---- C:\Windows\system32\config
2017-08-02 21:34:35 ----D---- C:\Windows\Microsoft.NET
2017-08-02 21:25:11 ----D---- C:\Windows
2017-08-02 21:24:43 ----D---- C:\Windows\System32
2017-08-02 21:23:24 ----RSD---- C:\Windows\assembly
2017-08-02 21:19:35 ----SHD---- C:\Windows\Installer
2017-08-02 21:19:04 ----D---- C:\ProgramData\Microsoft Help
2017-08-02 21:16:07 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-08-02 21:15:51 ----D---- C:\Windows\inf
2017-08-02 21:05:32 ----D---- C:\Windows\winsxs
2017-08-02 21:05:22 ----D---- C:\Windows\system32\catroot2
2017-08-02 21:04:25 ----SHD---- C:\System Volume Information
2017-08-02 20:04:10 ----D---- C:\Windows\system32\drivers
2017-08-02 19:55:43 ----D---- C:\Windows\AutoKMS
2017-08-02 19:55:28 ----D---- C:\Windows\system32\Tasks
2017-07-28 17:40:37 ----D---- C:\Users\LENOVO\AppData\Roaming\vlc
2017-07-26 18:28:36 ----D---- C:\Program Files\TeamViewer
2017-07-24 20:11:41 ----D---- C:\Windows\debug
2017-07-24 19:45:19 ----D---- C:\ProgramData\Oracle
2017-07-24 19:44:02 ----D---- C:\Program Files\Java
2017-07-24 19:43:35 ----D---- C:\Program Files\Common Files
2017-07-24 19:42:52 ----A---- C:\Windows\system32\WindowsAccessBridge.dll
2017-07-12 12:52:51 ----D---- C:\Windows\rescache
2017-07-12 12:26:56 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2017-07-12 12:26:49 ----D---- C:\Windows\system32\Macromed
2017-07-12 12:13:29 ----D---- C:\Program Files\Internet Explorer
2017-07-12 12:13:28 ----D---- C:\Windows\system32\migration
2017-07-12 12:13:28 ----D---- C:\Windows\system32\cs-CZ
2017-07-12 12:13:27 ----D---- C:\Windows\system32\en-US
2017-07-12 12:13:24 ----D---- C:\Windows\AppPatch
2017-07-12 12:13:22 ----D---- C:\Windows\system32\appraiser
2017-07-12 12:13:20 ----D---- C:\Windows\system32\DriverStore
2017-07-12 08:34:51 ----D---- C:\Windows\system32\MRT
2017-07-12 08:31:58 ----AC---- C:\Windows\system32\MRT.exe
2017-07-12 08:28:42 ----RSD---- C:\Windows\Fonts
2017-07-07 20:29:06 ----HD---- C:\ProgramData

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2016-08-25 252808]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
R3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl6.sys [2009-07-08 2506232]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2011-02-11 9036800]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\Windows\system32\drivers\IntcHdmi.sys [2010-03-15 127488]
R3 JMCR;JMCR; C:\Windows\system32\DRIVERS\jmcr.sys [2008-08-07 97536]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2016-08-25 105696]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-14 207360]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-14 980992]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-14 661504]
S2 Parvdm;Parvdm; C:\Windows\system32\drivers\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-20 84992]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 49152]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2017-04-25 83056]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2016-11-14 103696]
R2 TeamViewer;TeamViewer 11; C:\Program Files\TeamViewer\TeamViewer_Service.exe [2016-09-20 7500048]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 1713904]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2016-11-14 280864]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-04-21 107656]
S2 gupdate;Služba Aktualizace Google (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2016-10-29 153752]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2017-07-12 272384]
S3 gupdatem;Služba Aktualizace Google (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2016-10-29 153752]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2017-06-29 104960]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2015-07-31 202928]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2015-07-30 4846168]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2017-04-21 47224]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118244
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: FB účet rozesílá viry

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

miloshek
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 26 bře 2007 23:38
Bydliště: OLOMOUCITY
Kontaktovat uživatele:

Re: FB účet rozesílá viry

#3 Příspěvek od miloshek »

# AdwCleaner 7.0.1.0 - Logfile created on Thu Aug 03 18:21:05 2017
# Updated on 2017/05/08 by Malwarebytes
# Database: 08-02-2017.1
# Running on Windows 7 Home Premium (X86)
# Mode: scan
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

No malicious registry entries found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries.

*************************

C:/AdwCleaner/AdwCleaner[S0].txt - [952 B] - [2017/7/24 18:18:18]


########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118244
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: FB účet rozesílá viry

#4 Příspěvek od Rudy »

Toto je OK. Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

miloshek
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 26 bře 2007 23:38
Bydliště: OLOMOUCITY
Kontaktovat uživatele:

Re: FB účet rozesílá viry

#5 Příspěvek od miloshek »

Log z OTM:

All processes killed
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users
->Temp folder emptied: 114784 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LENOVO
->Temp folder emptied: 10036 bytes
->Temporary Internet Files folder emptied: 388757 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 25313254 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 11154644 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33030 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 1146 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 35,00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: LENOVO

User: Public

Total Flash Files Cleaned = 0,00 mb


OTM by OldTimer - Version 3.1.21.0 log created on 08042017_154727

Files moved on Reboot...
File move failed. C:\Windows\temp\125442DE-1441-45CC-99C4-99761A39796Aab0.1d30b52b6ae9e0c\nisfull.vdm scheduled to be moved on reboot.
File C:\Windows\temp\TMPA09DDD7B6610CED3 not found!
File C:\Windows\temp\TMPFA985B5AE3B6137A not found!

Registry entries deleted on Reboot...

miloshek
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 26 bře 2007 23:38
Bydliště: OLOMOUCITY
Kontaktovat uživatele:

Re: FB účet rozesílá viry

#6 Příspěvek od miloshek »

Logfile of random's system information tool 1.10 (written by random/random)
Run by LENOVO at 2017-08-04 15:56:57
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 60 GB (39%) free of 153 GB
Total RAM: 3033 MB (74% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:57:44, on 4.8.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18739)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Users\LENOVO\Desktop\RSIT.exe
C:\Program Files\trend micro\LENOVO.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_141\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office16\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_141\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\PROGRA~1\MICROS~3\Office16\EXCEL.EXE/3000
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: TeamViewer 11 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer\TeamViewer_Service.exe

--
End of file - 4354 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_141\bin\ssv.dll [2017-07-24 473664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office16\URLREDIR.DLL [2015-07-31 403672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_141\bin\jp2ssv.dll [2017-07-24 187968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-02-11 137752]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-02-11 171032]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-02-11 172568]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2016-11-14 1002984]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-02-11 228864]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\03556973.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\03556973.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 3 months======

2017-08-04 15:47:27 ----D---- C:\_OTM
2017-08-03 09:40:35 ----D---- C:\rsit
2017-08-03 09:40:35 ----D---- C:\Program Files\trend micro
2017-08-02 21:24:43 ----A---- C:\Windows\system32\FNTCACHE.DAT
2017-08-02 21:06:34 ----SHD---- C:\Config.Msi
2017-07-24 20:16:43 ----D---- C:\AdwCleaner
2017-07-24 19:43:35 ----D---- C:\Program Files\Common Files\Java
2017-07-12 07:22:11 ----A---- C:\Windows\system32\mshtml.dll
2017-07-12 07:22:02 ----A---- C:\Windows\system32\ieframe.dll
2017-07-12 07:22:00 ----A---- C:\Windows\system32\win32k.sys
2017-07-12 07:22:00 ----A---- C:\Windows\system32\urlmon.dll
2017-07-12 07:22:00 ----A---- C:\Windows\system32\jscript9.dll
2017-07-12 07:21:59 ----A---- C:\Windows\system32\vbscript.dll
2017-07-12 07:21:59 ----A---- C:\Windows\system32\tquery.dll
2017-07-12 07:21:59 ----A---- C:\Windows\system32\Query.dll
2017-07-12 07:21:59 ----A---- C:\Windows\system32\kerberos.dll
2017-07-12 07:21:59 ----A---- C:\Windows\system32\ExplorerFrame.dll
2017-07-12 07:21:59 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2017-07-12 07:21:58 ----A---- C:\Windows\system32\Wldap32.dll
2017-07-12 07:21:58 ----A---- C:\Windows\system32\wininet.dll
2017-07-12 07:21:58 ----A---- C:\Windows\system32\drivers\ntfs.sys
2017-07-12 07:21:58 ----A---- C:\Windows\system32\drivers\netio.sys
2017-07-12 07:21:57 ----A---- C:\Windows\system32\wdc.dll
2017-07-12 07:21:57 ----A---- C:\Windows\system32\pdhui.dll
2017-07-12 07:21:57 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2017-07-12 07:21:57 ----A---- C:\Windows\system32\msinfo32.exe
2017-07-12 07:21:57 ----A---- C:\Windows\system32\iedkcs32.dll
2017-07-12 07:21:57 ----A---- C:\Windows\system32\drivers\tcpip.sys
2017-07-12 07:21:57 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2017-07-12 07:21:57 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2017-07-12 07:21:57 ----A---- C:\Windows\system32\drivers\http.sys
2017-07-12 07:21:57 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2017-07-12 07:21:57 ----A---- C:\Windows\system32\clfs.sys
2017-07-12 07:21:56 ----A---- C:\Windows\system32\wvc.dll
2017-07-12 07:21:56 ----A---- C:\Windows\system32\perfmon.exe
2017-07-12 07:21:56 ----A---- C:\Windows\system32\msrating.dll
2017-07-12 07:21:56 ----A---- C:\Windows\system32\dxtmsft.dll
2017-07-12 07:21:56 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2017-07-12 07:21:55 ----A---- C:\Windows\system32\webcheck.dll
2017-07-12 07:21:55 ----A---- C:\Windows\system32\resmon.exe
2017-07-12 07:21:55 ----A---- C:\Windows\system32\dxtrans.dll
2017-07-12 07:21:53 ----A---- C:\Windows\system32\mshtmlmedia.dll
2017-07-12 07:21:53 ----A---- C:\Windows\system32\msfeeds.dll
2017-07-12 07:21:52 ----A---- C:\Windows\system32\ieui.dll
2017-07-12 07:21:52 ----A---- C:\Windows\system32\iertutil.dll
2017-07-12 07:21:52 ----A---- C:\Windows\system32\ie4uinit.exe
2017-07-12 07:21:51 ----A---- C:\Windows\system32\occache.dll
2017-07-12 07:21:51 ----A---- C:\Windows\system32\mshtmled.dll
2017-07-12 07:21:51 ----A---- C:\Windows\system32\jscript9diag.dll
2017-07-12 07:21:51 ----A---- C:\Windows\system32\ieUnatt.exe
2017-07-12 07:21:51 ----A---- C:\Windows\system32\iesetup.dll
2017-07-12 07:21:50 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-07-12 07:21:50 ----A---- C:\Windows\system32\inseng.dll
2017-07-12 07:21:50 ----A---- C:\Windows\system32\iernonce.dll
2017-07-12 07:21:49 ----A---- C:\Windows\system32\MshtmlDac.dll
2017-07-12 07:21:49 ----A---- C:\Windows\system32\jsproxy.dll
2017-07-12 07:21:49 ----A---- C:\Windows\system32\ieetwproxystub.dll
2017-07-12 07:21:49 ----A---- C:\Windows\system32\ieetwcollector.exe
2017-07-12 07:21:48 ----A---- C:\Windows\system32\rpcrt4.dll
2017-07-12 07:21:48 ----A---- C:\Windows\system32\mssvp.dll
2017-07-12 07:21:48 ----A---- C:\Windows\system32\mssrch.dll
2017-07-12 07:21:48 ----A---- C:\Windows\system32\jscript.dll
2017-07-12 07:21:48 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2017-07-12 07:21:48 ----A---- C:\Windows\system32\ieapfltr.dll
2017-07-12 07:21:48 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2017-07-12 07:21:48 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2017-07-12 07:21:47 ----A---- C:\Windows\system32\wdigest.dll
2017-07-12 07:21:47 ----A---- C:\Windows\system32\TSpkg.dll
2017-07-12 07:21:47 ----A---- C:\Windows\system32\sspicli.dll
2017-07-12 07:21:47 ----A---- C:\Windows\system32\schannel.dll
2017-07-12 07:21:47 ----A---- C:\Windows\system32\SearchIndexer.exe
2017-07-12 07:21:47 ----A---- C:\Windows\system32\rpchttp.dll
2017-07-12 07:21:47 ----A---- C:\Windows\system32\ncrypt.dll
2017-07-12 07:21:47 ----A---- C:\Windows\system32\msv1_0.dll
2017-07-12 07:21:47 ----A---- C:\Windows\system32\mssphtb.dll
2017-07-12 07:21:47 ----A---- C:\Windows\system32\mssph.dll
2017-07-12 07:21:47 ----A---- C:\Windows\system32\mssitlb.dll
2017-07-12 07:21:47 ----A---- C:\Windows\system32\lsasrv.dll
2017-07-12 07:21:47 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2017-07-12 07:21:47 ----A---- C:\Windows\system32\bcrypt.dll
2017-07-12 07:21:46 ----A---- C:\Windows\system32\sspisrv.dll
2017-07-12 07:21:46 ----A---- C:\Windows\system32\secur32.dll
2017-07-12 07:21:46 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2017-07-12 07:21:46 ----A---- C:\Windows\system32\SearchFilterHost.exe
2017-07-12 07:21:46 ----A---- C:\Windows\system32\mssprxy.dll
2017-07-12 07:21:46 ----A---- C:\Windows\system32\msshooks.dll
2017-07-12 07:21:46 ----A---- C:\Windows\system32\msscntrs.dll
2017-07-12 07:21:46 ----A---- C:\Windows\system32\lsass.exe
2017-07-12 07:21:46 ----A---- C:\Windows\system32\cryptbase.dll
2017-07-12 07:21:46 ----A---- C:\Windows\system32\credssp.dll
2017-07-12 07:21:46 ----A---- C:\Windows\system32\cdd.dll
2017-07-12 07:21:46 ----A---- C:\Windows\system32\auditpol.exe
2017-07-12 07:21:45 ----A---- C:\Windows\system32\tzres.dll
2017-07-12 07:21:44 ----A---- C:\Windows\system32\msobjs.dll
2017-07-12 07:21:44 ----A---- C:\Windows\system32\msaudite.dll
2017-07-12 07:21:44 ----A---- C:\Windows\system32\adtschema.dll
2017-07-12 07:18:12 ----A---- C:\Windows\system32\aitstatic.exe
2017-07-12 07:18:12 ----A---- C:\Windows\system32\aeinv.dll
2017-07-12 07:18:11 ----A---- C:\Windows\system32\appraiser.dll
2017-07-12 07:18:11 ----A---- C:\Windows\system32\aepic.dll
2017-07-12 07:18:10 ----A---- C:\Windows\system32\invagent.dll
2017-07-12 07:18:10 ----A---- C:\Windows\system32\devinv.dll
2017-07-12 07:18:10 ----A---- C:\Windows\system32\centel.dll
2017-07-12 07:18:09 ----A---- C:\Windows\system32\generaltel.dll
2017-07-12 07:18:09 ----A---- C:\Windows\system32\CompatTelRunner.exe
2017-07-12 07:18:08 ----A---- C:\Windows\system32\acmigration.dll
2017-07-07 20:30:52 ----D---- C:\KVRT_Data
2017-07-07 20:29:06 ----D---- C:\ProgramData\AppData
2017-06-14 07:36:28 ----A---- C:\Windows\system32\D3DCompiler_47.dll
2017-06-14 07:36:24 ----A---- C:\Windows\system32\wuaueng.dll
2017-06-14 07:36:24 ----A---- C:\Windows\system32\ntoskrnl.exe
2017-06-14 07:36:24 ----A---- C:\Windows\system32\ntkrnlpa.exe
2017-06-14 07:36:23 ----A---- C:\Windows\system32\shell32.dll
2017-06-14 07:36:22 ----A---- C:\Windows\system32\win32spl.dll
2017-06-14 07:36:22 ----A---- C:\Windows\system32\usp10.dll
2017-06-14 07:36:22 ----A---- C:\Windows\system32\gdi32.dll
2017-06-14 07:36:22 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2017-06-14 07:36:22 ----A---- C:\Windows\HelpPane.exe
2017-06-14 07:36:21 ----A---- C:\Windows\system32\rundll32.exe
2017-06-14 07:36:21 ----A---- C:\Windows\system32\ntdll.dll
2017-06-14 07:36:21 ----A---- C:\Windows\system32\MigAutoPlay.exe
2017-06-14 07:36:21 ----A---- C:\Windows\system32\drivers\tdx.sys
2017-06-14 07:36:21 ----A---- C:\Windows\system32\atmfd.dll
2017-06-14 07:36:20 ----A---- C:\Windows\system32\wuwebv.dll
2017-06-14 07:36:20 ----A---- C:\Windows\system32\localspl.dll
2017-06-14 07:36:19 ----A---- C:\Windows\system32\wucltux.dll
2017-06-14 07:36:19 ----A---- C:\Windows\system32\DWrite.dll
2017-06-14 07:36:18 ----A---- C:\Windows\system32\smss.exe
2017-06-14 07:36:18 ----A---- C:\Windows\system32\FntCache.dll
2017-06-14 07:36:17 ----A---- C:\Windows\system32\wudriver.dll
2017-06-14 07:36:17 ----A---- C:\Windows\system32\wuauclt.exe
2017-06-14 07:36:17 ----A---- C:\Windows\system32\wuapi.dll
2017-06-14 07:36:17 ----A---- C:\Windows\system32\WinSetupUI.dll
2017-06-14 07:36:17 ----A---- C:\Windows\system32\srcore.dll
2017-06-14 07:36:17 ----A---- C:\Windows\system32\drivers\appid.sys
2017-06-14 07:36:17 ----A---- C:\Windows\system32\csrsrv.dll
2017-06-14 07:36:17 ----A---- C:\Windows\system32\apisetschema.dll
2017-06-14 07:36:17 ----A---- C:\Windows\system32\advapi32.dll
2017-06-14 07:36:16 ----A---- C:\Windows\system32\wups2.dll
2017-06-14 07:36:16 ----A---- C:\Windows\system32\wups.dll
2017-06-14 07:36:16 ----A---- C:\Windows\system32\wuapp.exe
2017-06-14 07:36:16 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2017-06-14 07:36:16 ----A---- C:\Windows\system32\srclient.dll
2017-06-14 07:36:16 ----A---- C:\Windows\system32\setbcdlocale.dll
2017-06-14 07:36:16 ----A---- C:\Windows\system32\rstrui.exe
2017-06-14 07:36:16 ----A---- C:\Windows\system32\msmmsp.dll
2017-06-14 07:36:16 ----A---- C:\Windows\system32\lpk.dll
2017-06-14 07:36:16 ----A---- C:\Windows\system32\fontsub.dll
2017-06-14 07:36:16 ----A---- C:\Windows\system32\dciman32.dll
2017-06-14 07:36:16 ----A---- C:\Windows\system32\atmlib.dll
2017-06-14 07:36:16 ----A---- C:\Windows\system32\appidsvc.dll
2017-06-14 07:36:16 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2017-06-14 07:36:16 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2017-06-14 07:36:16 ----A---- C:\Windows\system32\appidapi.dll
2017-05-10 08:34:02 ----A---- C:\Windows\system32\crypt32.dll
2017-05-10 08:34:01 ----A---- C:\Windows\system32\rpcss.dll
2017-05-10 08:34:01 ----A---- C:\Windows\system32\pla.dll
2017-05-10 08:34:01 ----A---- C:\Windows\system32\pdh.dll
2017-05-10 08:34:01 ----A---- C:\Windows\system32\oleaut32.dll
2017-05-10 08:34:01 ----A---- C:\Windows\system32\ole32.dll
2017-05-10 08:34:01 ----A---- C:\Windows\system32\drivers\srv2.sys
2017-05-10 08:34:01 ----A---- C:\Windows\system32\drivers\srv.sys
2017-05-10 08:34:01 ----A---- C:\Windows\system32\drivers\fastfat.sys
2017-05-10 08:34:01 ----A---- C:\Windows\system32\drivers\exfat.sys
2017-05-10 08:34:01 ----A---- C:\Windows\system32\drivers\afd.sys
2017-05-10 08:34:00 ----A---- C:\Windows\system32\oleres.dll
2017-05-10 08:33:59 ----A---- C:\Windows\system32\plasrv.exe
2017-05-10 08:33:59 ----A---- C:\Windows\system32\drivers\srvnet.sys
2017-05-10 08:33:59 ----A---- C:\Windows\system32\comcat.dll
2017-05-10 08:33:58 ----A---- C:\Windows\system32\wintrust.dll
2017-05-10 08:33:58 ----A---- C:\Windows\system32\winsrv.dll
2017-05-10 08:33:58 ----A---- C:\Windows\system32\KernelBase.dll
2017-05-10 08:33:58 ----A---- C:\Windows\system32\cryptsvc.dll
2017-05-10 08:33:58 ----A---- C:\Windows\system32\cryptnet.dll
2017-05-10 08:33:58 ----A---- C:\Windows\system32\conhost.exe
2017-05-10 08:33:58 ----A---- C:\Windows\system32\cdosys.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-05-10 08:33:57 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-05-10 08:33:57 ----A---- C:\Windows\system32\kernel32.dll

======List of files/folders modified in the last 3 months======

2017-08-04 15:57:19 ----D---- C:\Windows\Temp
2017-08-04 15:47:49 ----D---- C:\Windows\system32\config
2017-08-04 15:46:59 ----D---- C:\Windows\Prefetch
2017-08-03 09:40:35 ----RD---- C:\Program Files
2017-08-02 21:34:35 ----D---- C:\Windows\Microsoft.NET
2017-08-02 21:25:11 ----D---- C:\Windows
2017-08-02 21:24:43 ----D---- C:\Windows\System32
2017-08-02 21:23:24 ----RSD---- C:\Windows\assembly
2017-08-02 21:19:35 ----SHD---- C:\Windows\Installer
2017-08-02 21:19:04 ----D---- C:\ProgramData\Microsoft Help
2017-08-02 21:16:07 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-08-02 21:15:51 ----D---- C:\Windows\inf
2017-08-02 21:05:32 ----D---- C:\Windows\winsxs
2017-08-02 21:05:22 ----D---- C:\Windows\system32\catroot2
2017-08-02 21:04:25 ----SHD---- C:\System Volume Information
2017-08-02 20:04:10 ----D---- C:\Windows\system32\drivers
2017-08-02 19:55:43 ----D---- C:\Windows\AutoKMS
2017-08-02 19:55:28 ----D---- C:\Windows\system32\Tasks
2017-07-28 17:40:37 ----D---- C:\Users\LENOVO\AppData\Roaming\vlc
2017-07-26 18:28:36 ----D---- C:\Program Files\TeamViewer
2017-07-24 20:11:41 ----D---- C:\Windows\debug
2017-07-24 19:45:19 ----D---- C:\ProgramData\Oracle
2017-07-24 19:44:02 ----D---- C:\Program Files\Java
2017-07-24 19:43:35 ----D---- C:\Program Files\Common Files
2017-07-24 19:42:52 ----A---- C:\Windows\system32\WindowsAccessBridge.dll
2017-07-12 12:52:51 ----D---- C:\Windows\rescache
2017-07-12 12:26:56 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2017-07-12 12:26:49 ----D---- C:\Windows\system32\Macromed
2017-07-12 12:13:29 ----D---- C:\Program Files\Internet Explorer
2017-07-12 12:13:28 ----D---- C:\Windows\system32\migration
2017-07-12 12:13:28 ----D---- C:\Windows\system32\cs-CZ
2017-07-12 12:13:27 ----D---- C:\Windows\system32\en-US
2017-07-12 12:13:24 ----D---- C:\Windows\AppPatch
2017-07-12 12:13:22 ----D---- C:\Windows\system32\appraiser
2017-07-12 12:13:20 ----D---- C:\Windows\system32\DriverStore
2017-07-12 08:34:51 ----D---- C:\Windows\system32\MRT
2017-07-12 08:31:58 ----AC---- C:\Windows\system32\MRT.exe
2017-07-12 08:28:42 ----RSD---- C:\Windows\Fonts
2017-07-07 20:29:06 ----HD---- C:\ProgramData
2017-06-14 17:52:12 ----D---- C:\Program Files\Microsoft Silverlight
2017-06-14 17:50:11 ----D---- C:\Windows\system32\migwiz
2017-05-30 22:45:48 ----N---- C:\Windows\system32\MpSigStub.exe
2017-05-11 07:13:07 ----D---- C:\Windows\PolicyDefinitions

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2016-08-25 252808]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
R3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl6.sys [2009-07-08 2506232]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2011-02-11 9036800]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\Windows\system32\drivers\IntcHdmi.sys [2010-03-15 127488]
R3 JMCR;JMCR; C:\Windows\system32\DRIVERS\jmcr.sys [2008-08-07 97536]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2016-08-25 105696]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-14 207360]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-14 980992]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-14 661504]
S2 Parvdm;Parvdm; C:\Windows\system32\drivers\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-20 84992]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 49152]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2017-04-25 83056]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2016-11-14 103696]
R2 TeamViewer;TeamViewer 11; C:\Program Files\TeamViewer\TeamViewer_Service.exe [2016-09-20 7500048]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 1713904]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2016-11-14 280864]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-04-21 107656]
S2 gupdate;Služba Aktualizace Google (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2016-10-29 153752]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2017-07-12 272384]
S3 gupdatem;Služba Aktualizace Google (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2016-10-29 153752]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2017-06-29 104960]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2015-07-31 202928]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2015-07-30 4846168]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2017-04-21 47224]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118244
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: FB účet rozesílá viry

#7 Příspěvek od Rudy »

OK. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

miloshek
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 26 bře 2007 23:38
Bydliště: OLOMOUCITY
Kontaktovat uživatele:

Re: FB účet rozesílá viry

#8 Příspěvek od miloshek »

To zjistím postupem času, jestli se někdo zase ozve s tím, že mu z toho účtu chodí viry. Pro jistotu jsem ještě změnil heslo k FB.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118244
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: FB účet rozesílá viry

#9 Příspěvek od Rudy »

OK. Nechám to tu zatím otevřené.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět