Facebook Vir

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Odpovědět
Zpráva
Autor
Rachtan
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 21 Srp 2011 19:20

Facebook Vir

#1 Příspěvek od Rachtan »

Zdravim, mam momentalne klasicky problem z facebook virusom, prikladam log. Dakujem za odpoved.

Logfile of random's system information tool 1.09 (written by random/random)
Run by Rachtan at 2011-08-21 20:32:37
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 57 GB (57%) free of 100 GB
Total RAM: 3327 MB (48% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:32:45, on 21. 8. 2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\SoundMAX.exe
C:\Program Files\Saitek\SD6\Software\ProfilerU.exe
C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Windows\update.tray-7-0\svchost.exe
C:\Windows\update.tray-2-0\svchost.exe
C:\Windows\update.tray-12-0\svchost.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Pando Networks\Media Booster\PMB.exe
C:\Miranda IM\miranda32.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\ESET\ESET Online Scanner\OnlineScannerApp.exe
C:\Program Files\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe
C:\Windows\system32\conhost.exe
C:\Users\Rachtan\Desktop\RSIT.exe
C:\Program Files\trend micro\Rachtan.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/cheatengine/{ ... 9A44CCAD36}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/cheatengine/{ ... 9A44CCAD36}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.babylon.com/?babsrc=SP_ss ... ffID=16553
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\prxtbBS_0.dll
R3 - URLSearchHook: ToolbarURLSearchHook Class - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files\Cheat Engine DB Toolbar\tbhelper.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\bh\BabylonToolbar.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SMTTB2009 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Cheat Engine DB Toolbar\tbcore3.dll
O2 - BHO: BS Player - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\prxtbBS_0.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\prxtbBS_0.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
O3 - Toolbar: Cheat Engine DB Toolbar - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\Cheat Engine DB Toolbar\tbcore3.dll
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarTlbr.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\soundmax.exe /tray
O4 - HKLM\..\Run: [ProfilerU] C:\Program Files\Saitek\SD6\Software\ProfilerU.exe
O4 - HKLM\..\Run: [SaiMfd] C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [BabylonToolbar] "C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe" /md I
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [wxpdrv] C:\Windows\services32.exe
O4 - HKLM\..\Run: [tray_ico0] C:\Windows\update.tray-7-0\svchost.exe
O4 - HKLM\..\Run: [tray_ico1] C:\Windows\update.tray-2-0\svchost.exe
O4 - HKLM\..\Run: [tray_ico2] C:\Windows\update.tray-12-0\svchost.exe
O4 - HKLM\..\Run: [8434771.exe] "C:\Windows\Temp\8434771.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Rachtan\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [EADM] "C:\Program Files\Electronic Arts\EADM\EADMUI.exe"
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: AutorunsDisabled
O4 - Global Startup: Miranda IM.lnk = C:\Miranda IM\miranda32.exe
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: ddservice - Unknown owner - C:\Windows\update.7.1\svchostdriver.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe (file missing)
O23 - Service: ESET Service (ekrn) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (file missing)
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: srvbtcclient - Unknown owner - C:\Windows\update.5.0\svchost.exe
O23 - Service: srviecheck - Unknown owner - C:\Windows\update.2\svchost.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files\Tunngle\TnglCtrl.exe
O23 - Service: wxpdrivers - Unknown owner - C:\Windows\update.1\svchost.exe

--
End of file - 10627 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2612415274-3809259120-191427226-1001Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2612415274-3809259120-191427226-1001UA.job
C:\Windows\tasks\IIHQRVBB.job
C:\Windows\tasks\Xvxfmvp.job
C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Rachtan\AppData\Roaming\Mozilla\Firefox\Profiles\0e9w6zkr.default

prefs.js - "browser.search.suggest.enabled" - false
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.google.sk/"
prefs.js - "extensions.enabledItems" - "piclens@cooliris.com:1.12.2.44172, toolbar@ask.com:3.11.3.15590, gb@toolbar:1.0.0, {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}:3.3.3.2, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, plugin2@gameplaylabs.com:2.0, engine@conduit.com:3.3.3.2, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
prefs.js - "keyword.URL" - "http://websearch.ask.com/redirect?clien ... YYYYYSK&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll

C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
babylon.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml

C:\Users\Rachtan\AppData\Roaming\Mozilla\Firefox\Profiles\0e9w6zkr.default\extensions\
engine@conduit.com
gb@toolbar
piclens@cooliris.com
plugin2@gameplaylabs.com
toolbar@ask.com
{75656794-AB59-4712-BFBC-5D816D56F3BC}
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}

C:\Users\Rachtan\AppData\Roaming\Mozilla\Firefox\Profiles\0e9w6zkr.default\searchplugins\
askcom.xml
conduit.xml
daemon-search.xml
search.xml
web-search.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}]
CescrtHlpr Object - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\bh\BabylonToolbar.dll [2010-11-07 225720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files\ConduitEngine\prxConduitEngine.dll [2011-01-17 175912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2010-11-10 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files\Microsoft\BingBar\BingExt.dll [2011-02-28 1089288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2011-05-17 1490312]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-05-29 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}]
SMTTB2009 Class - C:\Program Files\Cheat Engine DB Toolbar\tbcore3.dll [2011-05-27 2399744]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
BS Player Toolbar - C:\Program Files\BS_Player\prxtbBS_0.dll [2011-01-17 175912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - BS Player Toolbar - C:\Program Files\BS_Player\prxtbBS_0.dll [2011-01-17 175912]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2011-05-17 1490312]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files\Microsoft\BingBar\BingExt.dll [2011-02-28 1089288]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files\ConduitEngine\prxConduitEngine.dll [2011-01-17 175912]
{338B4DFE-2E2C-4338-9E41-E176D497299E} - Cheat Engine DB Toolbar - C:\Program Files\Cheat Engine DB Toolbar\tbcore3.dll [2011-05-27 2399744]
{98889811-442D-49dd-99D7-DC866BE87DBC} - Babylon Toolbar - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarTlbr.dll [2010-11-07 184760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-09 153136]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2009-06-05 1310720]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\soundmax.exe [2009-05-18 3866624]
"ProfilerU"=C:\Program Files\Saitek\SD6\Software\ProfilerU.exe [2010-07-29 227840]
"SaiMfd"=C:\Program Files\Saitek\SD6\Software\SaiMfd.exe [2010-07-29 123392]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-01-07 253672]
""= []
"ApnUpdater"=C:\Program Files\Ask.com\Updater\Updater.exe [2011-05-17 395144]
"amd_dc_opt"=C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [2008-07-22 77824]
"BabylonToolbar"=C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe [2010-11-07 286720]
"UnlockerAssistant"=C:\Program Files\Unlocker\UnlockerAssistant.exe [2010-07-04 17408]
"LogMeIn Hamachi Ui"=C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2011-08-04 1955208]
"wxpdrv"=C:\Windows\services32.exe []
"tray_ico"= []
"tray_ico0"=C:\Windows\update.tray-7-0\svchost.exe [2011-08-20 1182208]
"tray_ico1"=C:\Windows\update.tray-2-0\svchost.exe [2011-08-20 1182208]
"tray_ico2"=C:\Windows\update.tray-12-0\svchost.exe [2011-08-20 1182208]
"tray_ico3"= []
"tray_ico4"= []
"8434771.exe"=C:\Windows\Temp\8434771.exe [2011-08-21 634880]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe /hide /waitservice []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1174016]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"uTorrent"=C:\Program Files\uTorrent\uTorrent.exe [2011-03-28 399736]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-03-12 153136]
"PlayNC Launcher"= []
"Google Update"=C:\Users\Rachtan\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-06 136176]
"EADM"=C:\Program Files\Electronic Arts\EADM\EADMUI.exe [2011-02-03 11509760]
"Pando Media Booster"=C:\Program Files\Pando Networks\Media Booster\PMB.exe [2011-07-09 3077528]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
AutorunsDisabled
Miranda IM.lnk - C:\Miranda IM\miranda32.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll [2011-06-08 233888]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"msacm.l3fhg"=mp3fhg.acm
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"VIDC.FFDS"=ff_vfw.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.siren"=sirenacm.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"vidc.DIVX"=DivX.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2011-08-21 20:24:37 ----D---- C:\Program Files\trend micro
2011-08-21 20:24:35 ----DC---- C:\rsit
2011-08-21 20:01:27 ----D---- C:\Program Files\ESET
2011-08-21 17:24:31 ----D---- C:\Program Files\Desktop Icon Toy
2011-08-21 17:22:28 ----HD---- C:\ProgramData\Common Files
2011-08-21 17:19:25 ----HD---- C:\Windows\update.tray-12-0-lnk
2011-08-21 17:19:25 ----HD---- C:\Windows\update.tray-12-0
2011-08-21 17:08:55 ----D---- C:\ProgramData\MFAData
2011-08-21 16:51:11 ----HD---- C:\Windows\update.tray-2-0-lnk
2011-08-21 16:51:11 ----HD---- C:\Windows\update.tray-2-0
2011-08-21 16:49:11 ----SHDC---- C:\Config.Msi
2011-08-21 14:32:20 ----D---- C:\Users\Rachtan\AppData\Roaming\Might & Magic Heroes VI - Game Official Demo
2011-08-20 14:12:50 ----D---- C:\Windows\ufa
2011-08-20 14:12:50 ----D---- C:\Windows\rpcminer
2011-08-20 14:12:50 ----D---- C:\Windows\phoenix
2011-08-20 14:10:18 ----A---- C:\Windows\btc_client_iplist.txt
2011-08-20 14:09:15 ----HD---- C:\Windows\update.5.0
2011-08-20 14:08:48 ----A---- C:\Windows\unrar.exe
2011-08-20 14:08:42 ----A---- C:\Windows\iecheck_iplist.txt
2011-08-20 14:08:15 ----HD---- C:\Windows\update.2
2011-08-20 14:07:23 ----HD---- C:\Windows\update.7.1
2011-08-20 14:07:10 ----A---- C:\Windows\iplist.txt
2011-08-20 14:06:36 ----A---- C:\Windows\front_ip_list.txt
2011-08-20 14:06:19 ----D---- C:\Windows\av_ico
2011-08-20 14:04:56 ----HD---- C:\Windows\update.1
2011-08-20 14:04:54 ----HD---- C:\Windows\update.tray-7-0-lnk
2011-08-20 14:04:54 ----HD---- C:\Windows\update.tray-7-0
2011-08-20 13:54:50 ----A---- C:\Windows\winlog-ids.txt
2011-08-20 13:54:50 ----A---- C:\Windows\winlog-dirs.txt
2011-08-19 17:46:01 ----D---- C:\Program Files\7-Zip
2011-08-18 22:22:58 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-08-18 22:22:58 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-08-18 22:22:57 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-08-18 22:22:57 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-08-18 22:22:57 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-08-18 22:22:57 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-08-18 22:22:53 ----A---- C:\Windows\system32\aswBoot.exe
2011-08-18 22:22:53 ----A---- C:\Windows\avastSS.scr
2011-08-12 00:35:04 ----A---- C:\Windows\system32\mshtmled.dll
2011-08-12 00:35:03 ----A---- C:\Windows\system32\jscript.dll
2011-08-12 00:35:03 ----A---- C:\Windows\system32\ieui.dll
2011-08-12 00:35:03 ----A---- C:\Windows\system32\iertutil.dll
2011-08-12 00:35:02 ----A---- C:\Windows\system32\wininet.dll
2011-08-12 00:35:02 ----A---- C:\Windows\system32\urlmon.dll
2011-08-12 00:35:02 ----A---- C:\Windows\system32\url.dll
2011-08-12 00:35:02 ----A---- C:\Windows\system32\jsproxy.dll
2011-08-12 00:35:02 ----A---- C:\Windows\system32\jscript9.dll
2011-08-12 00:35:01 ----A---- C:\Windows\system32\ieframe.dll
2011-08-12 00:35:00 ----A---- C:\Windows\system32\mshtml.dll
2011-08-11 20:07:05 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-08-11 20:07:04 ----A---- C:\Windows\system32\ntkrnlpa.exe
2011-08-11 20:07:04 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-08-11 20:07:02 ----A---- C:\Windows\system32\kernel32.dll
2011-08-11 20:07:02 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-08-11 20:07:01 ----A---- C:\Windows\system32\winsrv.dll
2011-08-11 20:07:01 ----A---- C:\Windows\system32\KernelBase.dll
2011-08-11 20:07:01 ----A---- C:\Windows\system32\conhost.exe
2011-08-11 20:07:00 ----A---- C:\Windows\system32\odbctrac.dll
2011-08-11 20:07:00 ----A---- C:\Windows\system32\odbcjt32.dll
2011-08-11 20:07:00 ----A---- C:\Windows\system32\odbccu32.dll
2011-08-11 20:07:00 ----A---- C:\Windows\system32\odbccr32.dll
2011-08-11 20:07:00 ----A---- C:\Windows\system32\odbccp32.dll
2011-08-09 14:42:35 ----D---- C:\Program Files\LogMeIn Hamachi
2011-08-04 22:44:15 ----D---- C:\Users\Rachtan\AppData\Roaming\Mumble
2011-08-04 22:44:06 ----D---- C:\Program Files\Mumble
2011-08-03 01:08:32 ----D---- C:\Program Files\The KMPlayer
2011-07-28 17:52:56 ----AH---- C:\Windows\system32\mlfcache.dat
2011-07-27 21:35:57 ----D---- C:\Users\Rachtan\AppData\Roaming\LolClient
2011-07-24 16:09:02 ----D---- C:\Users\Rachtan\AppData\Roaming\BugTrap Console Test108
2011-07-24 16:05:05 ----D---- C:\Program Files\Outspark
2011-07-24 16:05:05 ----A---- C:\Windows\patchw32.dll
2011-07-24 16:05:05 ----A---- C:\Windows\patchw.dll
2011-07-23 13:36:10 ----D---- C:\Users\Rachtan\AppData\Roaming\SEGA Corporation
2011-07-23 13:35:14 ----D---- C:\ProgramData\SEGA Corporation
2011-07-22 21:45:15 ----D---- C:\Program Files\VentSrv

======List of files/folders modified in the last 1 month======

2011-08-21 20:32:41 ----D---- C:\Users\Rachtan\AppData\Roaming\uTorrent
2011-08-21 20:29:56 ----D---- C:\Windows\Tasks
2011-08-21 20:29:56 ----D---- C:\Windows
2011-08-21 20:27:33 ----SHD---- C:\System Volume Information
2011-08-21 20:24:37 ----RD---- C:\Program Files
2011-08-21 20:00:58 ----D---- C:\Windows\system32\config
2011-08-21 19:50:15 ----D---- C:\Windows\Temp
2011-08-21 19:47:40 ----D---- C:\Program Files\Common Files\Akamai
2011-08-21 19:47:29 ----D---- C:\ProgramData\NVIDIA
2011-08-21 19:47:17 ----D---- C:\Windows\system32\wfp
2011-08-21 19:47:16 ----D---- C:\Windows\system32\wbem
2011-08-21 19:45:50 ----D---- C:\Windows\system32\Tasks
2011-08-21 19:45:50 ----D---- C:\Windows\system32\DriverStore
2011-08-21 19:45:50 ----D---- C:\Windows\system32\catroot2
2011-08-21 19:45:50 ----D---- C:\Windows\System32
2011-08-21 19:45:49 ----SHD---- C:\Windows\Installer
2011-08-21 19:45:49 ----D---- C:\Windows\system32\drivers
2011-08-21 19:45:49 ----D---- C:\Windows\system32\CodeIntegrity
2011-08-21 19:45:49 ----D---- C:\Windows\inf
2011-08-21 19:45:49 ----D---- C:\Users\Rachtan\AppData\Roaming\TS3Client
2011-08-21 19:45:47 ----D---- C:\Windows\registration
2011-08-21 19:45:47 ----D---- C:\ProgramData\PMB Files
2011-08-21 19:45:37 ----D---- C:\ProgramData\Electronic Arts
2011-08-21 19:45:37 ----AHD---- C:\ProgramData
2011-08-21 19:02:08 ----D---- C:\Windows\Prefetch
2011-08-21 17:17:03 ----D---- C:\Windows\system32\catroot
2011-08-21 16:41:57 ----D---- C:\Users\Rachtan\AppData\Roaming\Media Player Classic
2011-08-21 16:41:53 ----D---- C:\Windows\debug
2011-08-21 16:35:50 ----D---- C:\Windows\system32\drivers\etc
2011-08-21 14:29:40 ----RSD---- C:\Windows\assembly
2011-08-21 14:29:15 ----HD---- C:\Program Files\InstallShield Installation Information
2011-08-20 21:43:42 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-08-20 17:20:52 ----D---- C:\Windows\Logs
2011-08-19 22:22:01 ----D---- C:\Windows\system32\NDF
2011-08-18 22:18:25 ----D---- C:\ProgramData\AVAST Software
2011-08-18 21:06:04 ----D---- C:\Windows\Downloaded Program Files
2011-08-18 00:18:54 ----D---- C:\Program Files\Ubisoft
2011-08-17 00:05:49 ----D---- C:\Program Files\Mozilla Firefox
2011-08-12 15:05:37 ----D---- C:\Windows\Microsoft.NET
2011-08-12 14:33:47 ----D---- C:\Windows\winsxs
2011-08-12 14:32:21 ----D---- C:\Windows\system32\migration
2011-08-12 14:32:20 ----D---- C:\Program Files\Internet Explorer
2011-08-12 00:34:55 ----A---- C:\Windows\system32\MRT.exe
2011-07-23 13:56:50 ----D---- C:\Program Files\Common Files\Wise Installation Wizard

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSEH;AVGIDSEH; C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [2011-02-22 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx86.sys [2011-03-16 32592]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-08-08 691696]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6x.sys [2010-07-12 54112]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx86.sys [2011-03-01 34896]
R1 Avgtdix;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdix.sys [2011-04-05 297168]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-04-28 114984]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2010-04-28 96896]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2010-10-05 25416]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys [2009-06-05 380416]
R3 AmdLLD;AMD Low Level Device Driver; C:\Windows\system32\DRIVERS\AmdLLD.sys [2007-06-29 34304]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 SaiK0CFA;SaiK0CFA; C:\Windows\system32\DRIVERS\SaiK0CFA.sys [2010-08-10 141832]
R3 SaiMini;SaiMini; C:\Windows\system32\DRIVERS\SaiMini.sys [2010-07-08 20744]
R3 SaiNtBus;SaiNtBus; C:\Windows\system32\drivers\SaiBus.sys [2010-07-08 43656]
R3 SaiU0CFA;SaiU0CFA; C:\Windows\system32\DRIVERS\SaiU0CFA.sys [2010-08-10 35208]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\Windows\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
R3 teamviewervpn;TeamViewer VPN Adapter; C:\Windows\system32\DRIVERS\teamviewervpn.sys [2010-03-11 25088]
S1 Avgldx86;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx86.sys [2011-01-07 248656]
S2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2010-10-05 278984]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 AVGIDSShim;AVGIDSShim; C:\Windows\system32\DRIVERS\AVGIDSShim.Sys [2011-02-10 21968]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-06-24 136120]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 39272]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 15872]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
S3 XDva385;XDva385; \??\C:\Windows\system32\XDva385.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AEADIFilters;Andrea ADI Filters Service; C:\Windows\system32\AEADISRV.EXE [2009-06-05 90112]
R2 Akamai;Akamai NetSession Interface; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ddservice;ddservice; C:\Windows\update.7.1\svchostdriver.exe [2011-08-20 382464]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2011-08-04 1361288]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2011-01-07 608872]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2011-03-23 75136]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\BingBar\SeaPort.EXE [2011-02-25 249648]
R2 srvbtcclient;srvbtcclient; C:\Windows\update.5.0\svchost.exe [2011-08-20 348672]
R2 srviecheck;srviecheck; C:\Windows\update.2\svchost.exe [2011-08-21 634880]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-07 378984]
R2 TeamViewer5;TeamViewer 5; C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe [2010-07-06 173352]
R2 TunngleService;TunngleService; C:\Program Files\Tunngle\TnglCtrl.exe [2011-06-15 737016]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
R2 wxpdrivers;wxpdrivers; C:\Windows\update.1\svchost.exe [2011-08-20 1182208]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-03-12 271920]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe []
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 BBSvc;Bing Bar Update Service; C:\Program Files\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe []
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-01-15 774144]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2009-06-30 316664]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-08-09 1343400]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]

-----------------EOF-----------------

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Facebook Vir

#2 Příspěvek od vyosek »

Zdravim a pekny den preji :)

:arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
  • Ukoncete vsechny programy
  • Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
  • Zvolte moznost 2 a potvrte enterem
  • Utilita provede svou cinnost a da log - ten sem vlozte
  • Nyni znovu, ale zvolte moznost 3 a pote jeste 4 - logy opet vlozte
PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Rachtan
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 21 Srp 2011 19:20

Re: Facebook Vir

#3 Příspěvek od Rachtan »

RogueKiller:


RogueKiller V5.3.3 [08/18/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Normal mode
User: Rachtan [Admin rights]
Mode: Remove -- Date : 08/21/2011 22:09:14

Bad processes: 0

Registry Entries: 0

Particular Files / Folders:

HOSTS File:
127.0.0.1 localhost


Finished : << RKreport[1].txt >>
RKreport[1].txt

------------------------------------

RogueKiller V5.3.3 [08/18/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Normal mode
User: Rachtan [Admin rights]
Mode: HOSTSFix -- Date : 08/21/2011 22:09:52

Bad processes: 0

HOSTS File:
127.0.0.1 localhost


Resetted HOSTS:
127.0.0.1 localhost

Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt

-------------------------------------

RogueKiller V5.3.3 [08/18/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Normal mode
User: Rachtan [Admin rights]
Mode: ProxyFix -- Date : 08/21/2011 22:10:10

Bad processes: 0

Registry Entries: 0

Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt

Combo fix:

ComboFix 11-08-21.01 - Rachtan . 08. 2011 22:32:50.1.4 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.421.1051.18.3327.1537 [GMT 2:00]
Running from: c:\users\Rachtan\Desktop\ComboFix.exe
AV: avast! Internet Security *Enabled/Outdated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
FW: avast! Internet Security *Enabled* {FB460EB6-4C6D-E564-6BF5-EEEF2B44B473}
SP: avast! Internet Security *Enabled/Outdated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Cheat Engine DB Toolbar\tbHElper.dll
c:\users\Rachtan\AppData\Local\Temp\NODF28D.tmp
c:\windows\btc_client_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\geoiplist
c:\windows\geoiplist.rar
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\loader2.exe_ok
c:\windows\phoenix
c:\windows\phoenix.rar
c:\windows\phoenix\kernels\phatk\__init__.py
c:\windows\phoenix\kernels\phatk\__init__.pyc
c:\windows\phoenix\kernels\phatk\BFIPatcher.py
c:\windows\phoenix\kernels\phatk\BFIPatcher.pyc
c:\windows\phoenix\kernels\phatk\kernel.cl
c:\windows\phoenix\kernels\poclbm\__init__.py
c:\windows\phoenix\kernels\poclbm\__init__.pyc
c:\windows\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows\phoenix\kernels\poclbm\BFIPatcher.pyc
c:\windows\phoenix\kernels\poclbm\kernel.cl
c:\windows\phoenix\phoenix.exe
c:\windows\proc_list1.log
c:\windows\rpcminer
c:\windows\rpcminer.rar
c:\windows\rpcminer\bitcoinminercuda_10.cubin
c:\windows\rpcminer\bitcoinminercuda_11.cubin
c:\windows\rpcminer\bitcoinminercuda_20.cubin
c:\windows\rpcminer\bitcoinmineropencl.cl
c:\windows\rpcminer\cudart32_32_16.dll
c:\windows\rpcminer\curllib.dll
c:\windows\rpcminer\libeay32.dll
c:\windows\rpcminer\libsasl.dll
c:\windows\rpcminer\openldap.dll
c:\windows\rpcminer\rpcminer-4way.exe
c:\windows\rpcminer\rpcminer-cpu.exe
c:\windows\rpcminer\rpcminer-cuda.exe
c:\windows\rpcminer\rpcminer-opencl.exe
c:\windows\rpcminer\ssleay32.dll
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\ufa.rar
c:\windows\update.1
c:\windows\update.2
c:\windows\update.5.0
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
c:\windows\winsetupapi.log
.
.
((((((((((((((((((((((((( Files Created from 2011-07-21 to 2011-08-21 )))))))))))))))))))))))))))))))
.
.
2011-08-21 18:24 . 2011-08-21 18:32 -------- d-----w- c:\program files\trend micro
2011-08-21 18:24 . 2011-08-21 18:25 -------- dc----w- C:\rsit
2011-08-21 18:01 . 2011-08-21 18:01 -------- d-----w- c:\program files\ESET
2011-08-21 15:24 . 2011-08-21 17:45 -------- d-----w- c:\program files\Desktop Icon Toy
2011-08-21 15:22 . 2011-08-21 15:22 -------- d--h--w- c:\programdata\Common Files
2011-08-21 15:19 . 2011-08-21 18:43 -------- d--h--w- c:\windows\update.tray-12-0-lnk
2011-08-21 15:19 . 2011-08-21 18:43 -------- d--h--w- c:\windows\update.tray-12-0
2011-08-21 15:08 . 2011-08-21 15:22 -------- d-----w- c:\programdata\MFAData
2011-08-21 14:51 . 2011-08-21 18:43 -------- d--h--w- c:\windows\update.tray-2-0-lnk
2011-08-21 14:51 . 2011-08-21 18:43 -------- d--h--w- c:\windows\update.tray-2-0
2011-08-21 12:32 . 2011-08-21 12:32 -------- d-----w- c:\users\Rachtan\AppData\Roaming\Might & Magic Heroes VI - Game Official Demo
2011-08-20 12:12 . 2011-08-20 12:12 -------- d-----w- c:\windows\ufa
2011-08-20 12:08 . 2011-08-20 12:12 246272 ----a-w- c:\windows\unrar.exe
2011-08-20 12:07 . 2011-08-21 18:43 -------- d--h--w- c:\windows\update.7.1
2011-08-20 12:06 . 2011-08-21 17:45 -------- d-----w- c:\windows\av_ico
2011-08-20 12:04 . 2011-08-21 18:43 -------- d--h--w- c:\windows\update.tray-7-0-lnk
2011-08-20 12:04 . 2011-08-21 18:43 -------- d--h--w- c:\windows\update.tray-7-0
2011-08-19 15:46 . 2011-08-19 15:46 -------- d-----w- c:\program files\7-Zip
2011-08-18 20:22 . 2011-01-05 16:12 294352 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-08-18 20:22 . 2011-01-05 16:08 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-08-18 20:22 . 2011-01-05 16:12 357968 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-08-18 20:22 . 2011-01-05 16:11 47440 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-08-18 20:22 . 2011-01-05 16:08 23632 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-08-18 20:22 . 2011-01-05 16:08 51280 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-08-18 20:22 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
2011-08-18 20:22 . 2011-07-04 11:43 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-08-17 22:05 . 2011-08-17 22:25 -------- d-----w- c:\users\Rachtan\AppData\Local\Ubisoft Game Launcher
2011-08-11 18:07 . 2011-06-23 04:33 3912576 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-08-09 12:48 . 2011-08-16 22:04 134104 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-08-09 12:42 . 2011-08-09 12:42 -------- d-----w- c:\program files\LogMeIn Hamachi
2011-08-04 20:44 . 2011-08-17 21:48 -------- d-----w- c:\users\Rachtan\AppData\Roaming\Mumble
2011-08-04 20:44 . 2011-08-04 20:44 -------- d-----w- c:\program files\Mumble
2011-08-02 23:08 . 2011-08-20 14:37 -------- d-----w- c:\program files\The KMPlayer
2011-07-27 20:37 . 2011-08-04 22:28 -------- d-----w- c:\users\Rachtan\riotsGamesLogs
2011-07-27 19:35 . 2011-07-27 19:35 -------- d-----w- c:\users\Rachtan\AppData\Roaming\LolClient
2011-07-24 14:09 . 2011-07-24 14:26 -------- d-----w- c:\users\Rachtan\AppData\Roaming\BugTrap Console Test108
2011-07-24 14:05 . 2011-07-24 14:05 -------- d-----w- c:\program files\Outspark
2011-07-24 14:05 . 2010-01-13 15:48 230752 ----a-w- c:\windows\patchw32.dll
2011-07-24 14:05 . 2010-01-13 15:48 118176 ----a-w- c:\windows\patchw.dll
2011-07-23 11:36 . 2011-07-23 11:36 -------- d-----w- c:\users\Rachtan\AppData\Roaming\SEGA Corporation
2011-07-23 11:35 . 2011-07-23 11:35 -------- d-----w- c:\programdata\SEGA Corporation
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-20 11:59 . 2011-06-01 15:56 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-01 19:27 . 2011-07-01 19:27 113543 ----a-w- c:\windows\system32\slmgr.vbs
2011-07-01 18:05 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-06-11 02:29 . 2011-07-13 16:20 2334208 ----a-w- c:\windows\system32\win32k.sys
2011-06-08 13:29 . 2011-06-08 13:15 8107 ----a-w- c:\windows\w7dsd.reg
2011-06-08 13:29 . 2011-06-08 13:15 8089 ----a-w- c:\windows\w7dse.reg
2011-06-08 13:15 . 2011-06-08 13:15 233888 ----a-w- c:\windows\system32\DreamScene.dll
2011-05-29 13:08 . 2010-10-12 18:53 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-05-24 10:44 . 2011-06-29 17:07 293376 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-08-16 22:04 . 2011-08-09 12:48 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2010-11-20 . 8626F0C30D4E3564FFDD25C90F4426F1 . 811520 . . [6.1.7601.17514] . . c:\windows\System32\user32.dll
[7] 2010-11-20 . F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 . 811520 . . [6.1.7601.17514] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
[7] 2009-07-14 . 34B7E222E81FAFA885F0C5F2CFA56861 . 811520 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\prxtbBS_0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 ----a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-05-17 11:29 1490312 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2011-01-17 14:54 175912 ----a-w- c:\program files\BS_Player\prxtbBS_0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\prxtbBS_0.dll" [2011-01-17 175912]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312]
"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "c:\program files\BS_Player\prxtbBS_0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-03-28 399736]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"EADM"="c:\program files\Electronic Arts\EADM\EADMUI.exe" [2011-02-03 11509760]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2011-07-09 3077528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-06-05 1310720]
"ProfilerU"="c:\program files\Saitek\SD6\Software\ProfilerU.exe" [2010-07-29 227840]
"SaiMfd"="c:\program files\Saitek\SD6\Software\SaiMfd.exe" [2010-07-29 123392]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2011-05-17 395144]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"BabylonToolbar"="c:\program files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe" [2010-11-07 286720]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2010-07-04 17408]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2011-08-04 1955208]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Miranda IM.lnk - c:\miranda im\miranda32.exe [2010-8-9 694368]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled
BumpTop.lnk - c:\program files\BumpTop\BumpTop.exe [2011-6-8 7162696]
Ventrilo.lnk - c:\program files\Ventrilo\Ventrilo.exe [2010-8-8 561152]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [2011-01-07 248656]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [x]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\AVGIDSShim.Sys [2011-02-10 21968]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-06-24 136120]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-08-09 1343400]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2011-02-22 22992]
S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [2011-03-16 32592]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-08-08 691696]
S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6x.sys [2010-07-12 54112]
S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2011-04-04 297168]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-04-28 114984]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2010-04-28 96896]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2011-08-04 1361288]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-07 378984]
S2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe [2010-07-06 173352]
S2 TunngleService;TunngleService;c:\program files\Tunngle\TnglCtrl.exe [2011-06-15 737016]
S3 SaiK0CFA;SaiK0CFA;c:\windows\system32\DRIVERS\SaiK0CFA.sys [2010-08-10 141832]
S3 SaiU0CFA;SaiU0CFA;c:\windows\system32\DRIVERS\SaiU0CFA.sys [2010-08-10 35208]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2010-03-11 25088]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2612415274-3809259120-191427226-1001Core.job
- c:\users\Rachtan\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-06 21:06]
.
2011-08-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2612415274-3809259120-191427226-1001UA.job
- c:\users\Rachtan\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-06 21:06]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bigseekpro.com/cheatengine/{7CE0E9D ... 9A44CCAD36}
mStart Page = hxxp://www.bigseekpro.com/cheatengine/{7CE0E9D ... 9A44CCAD36}
FF - ProfilePath - c:\users\Rachtan\AppData\Roaming\Mozilla\Firefox\Profiles\0e9w6zkr.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.google.sk/
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=PCW&o=14734&locale=en_EU&apn_uid=AFB86C80-3D39-4D1C-B9E8-B8835AA0CD5D&apn_ptnrs=WZ&apn_sauid=13170DEC-D1E0-4AA0-95F5-19B19099F5C1&apn_dtid=YYYYYYYYSK&q=
.
- - - - ORPHANS REMOVED - - - -
.
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
HKCU-Run-PlayNC Launcher - (no file)
HKLM-Run-tray_ico - (no file)
HKLM-Run-tray_ico3 - (no file)
HKLM-Run-tray_ico4 - (no file)
HKLM-Run-egui - c:\program files\ESET\ESET NOD32 Antivirus\egui.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{32099AAC-C132-4136-9E9A-4E364A424E17}"=hex:51,66,7a,6c,4c,1d,38,12,c2,99,1a,
36,00,8f,58,04,e1,8c,0d,76,4f,1c,0a,03
"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"=hex:51,66,7a,6c,4c,1d,38,12,ab,6e,c5,
fa,46,55,6a,0f,f0,4a,56,85,a9,bc,fd,b1
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=hex:51,66,7a,6c,4c,1d,38,12,11,7f,11,
d0,78,5b,08,05,de,bb,01,03,dd,4c,30,54
"{8DCB7100-DF86-4384-8842-8FA844297B3F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,72,d8,
89,b4,91,ea,06,f7,54,cc,e8,41,77,3f,2b
"{30F9B915-B755-4826-820B-08FBA6BD249D}"=hex:51,66,7a,6c,4c,1d,38,12,7b,ba,ea,
34,67,f9,48,0d,fd,1d,4b,bb,a3,e3,60,89
"{338B4DFE-2E2C-4338-9E41-E176D497299E}"=hex:51,66,7a,6c,4c,1d,38,12,90,4e,98,
37,1e,60,56,06,e1,57,a2,36,d1,c9,6d,8a
"{98889811-442D-49DD-99D7-DC866BE87DBC}"=hex:51,66,7a,6c,4c,1d,38,12,7f,9b,9b,
9c,1f,0a,b3,0c,e6,c1,9f,c6,6e,b6,39,a8
"{2EECD738-5844-4A99-B4B6-146BF802613B}"=hex:51,66,7a,6c,4c,1d,38,12,56,d4,ff,
2a,76,16,f7,0f,cb,a0,57,2b,fd,5c,25,2f
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{9FDDE16B-836F-4806-AB1F-1455CBEFF289}"=hex:51,66,7a,6c,4c,1d,38,12,05,e2,ce,
9b,5d,cd,68,0d,d4,09,57,15,ce,b1,b6,9d
"{D2CE3E00-F94A-4740-988E-03DC2F38C34F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,3d,dd,
d6,78,b7,2e,02,e7,98,40,9c,2a,66,87,5b
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{FCBCCB87-9224-4B8D-B117-F56D924BEB18}"=hex:51,66,7a,6c,4c,1d,38,12,e9,c8,af,
f8,16,dc,e3,0e,ce,01,b6,2d,97,15,af,0c
"{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}"=hex:51,66,7a,6c,4c,1d,38,12,35,fc,e1,
93,3e,68,a1,09,fc,5c,6e,9a,4b,77,a7,8a
"{8C8A010F-BBC2-446F-84F4-BD1B721BF052}"=hex:51,66,7a,6c,4c,1d,38,12,61,02,99,
88,f0,f5,01,01,fb,e2,fe,5b,77,45,b4,46
"{AA8ADDFD-767F-439F-90BD-9E0D7F28E8F9}"=hex:51,66,7a,6c,4c,1d,38,12,93,de,99,
ae,4d,38,f1,06,ef,ab,dd,4d,7a,76,ac,ed
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:2e,f7,c8,23,79,5f,cc,01
.
[HKEY_USERS\S-1-5-21-2612415274-3809259120-191427226-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-2612415274-3809259120-191427226-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_USERS\S-1-5-21-2612415274-3809259120-191427226-1001\Software\SecuROM\License information*]
"datasecu"=hex:ff,df,35,ba,17,51,8c,94,58,c7,f7,e6,df,e3,b0,13,e0,49,74,5c,bb,
da,c5,d2,b7,41,3c,8d,09,a9,14,96,7b,de,c2,5f,c0,5e,b1,ff,fa,3f,63,a4,8f,51,\
"rkeysecu"=hex:79,a0,04,7a,a1,46,ff,07,c7,b5,50,7d,66,0e,e2,2d
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-08-21 22:53:19
ComboFix-quarantined-files.txt 2011-08-21 20:53
.
Pre-Run: 60 439 793 664 bytes free
Post-Run: 60 535 463 936 bytes free
.
- - End Of File - - 3F6E4441F4B139BDD11FAF0FF0DA4073

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Facebook Vir

#4 Příspěvek od vyosek »

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Folder::
    c:\windows\update.tray-12-0-lnk
    c:\windows\update.tray-12-0
    c:\windows\update.tray-2-0-lnk
    c:\windows\update.tray-2-0
    c:\windows\ufa
    c:\windows\update.7.1
    c:\windows\av_ico
    c:\windows\update.tray-7-0-lnk
    c:\windows\update.tray-7-0
    C:\Program Files\Common Files\Akamai
    c:\program files\Ask.com
    c:\program files\BabylonToolbar
    C:\Program Files\Cheat Engine DB Toolbar
    
    Restore::
    c:\windows\System32\user32.dll
    
    Collect::
    C:\Windows\tasks\IIHQRVBB.job
    C:\Windows\tasks\Xvxfmvp.job
    C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
    
    File::
    c:\windows\unrar.exe
    c:\program files\BS_Player\prxtbBS_0.dll
    C:\Program Files\ConduitEngine\prxConduitEngine.dl
    c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2612415274-3809259120-191427226-1001Core.job
    c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2612415274-3809259120-191427226-1001UA.job
    
    DDS::
    uStart Page = hxxp://www.bigseekpro.com/cheatengine/{7CE0E9D7-AB84-49F4-93DF-AB9A44CCAD36}
    mStart Page = hxxp://www.bigseekpro.com/cheatengine/{7CE0E9D7-AB84-49F4-93DF-AB9A44CCAD36}
    
    Firefox::
    FF - ProfilePath - c:\users\Rachtan\AppData\Roaming\Mozilla\Firefox\Profiles\0e9w6zkr.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
    FF - prefs.js: browser.search.selectedEngine - Ask.com
    FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?clien ... YYYYYSK&q=
    
    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{00000000-6E41-4FD3-8538-502F5495E5FC}"=-
    "{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"=-
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"=-
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    "{30F9B915-B755-4826-820B-08FBA6BD249D}"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    "{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"=-
    [-HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
    [-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
    [-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Lite"=-
    "uTorrent"=-
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-
    "EADM"=-
    "Pando Media Booster"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NeroFilterCheck"=-
    "SunJavaUpdateSched"=-
    "ApnUpdater"=-
    "BabylonToolbar"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "FirewallOverride"=dword:00000000
    "DisableThumbnailCache"=dword:00000000
    
    Driver::
    Akamai
    
    NetSvc::
    Akamai
    
    RegLockDel::
    [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
    
    RegLock::
    [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
    [HKEY_USERS\S-1-5-21-2612415274-3809259120-191427226-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
    [HKEY_USERS\S-1-5-21-2612415274-3809259120-191427226-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
    [HKEY_USERS\S-1-5-21-2612415274-3809259120-191427226-1001\Software\SecuROM\License information*]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    
    Reboot::
    
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Rachtan
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 21 Srp 2011 19:20

Re: Facebook Vir

#5 Příspěvek od Rachtan »

Log z ComboFixu


ComboFix 11-08-22.03 - Rachtan . 08. 2011 17:55:07.2.4 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.421.1051.18.3327.2251 [GMT 2:00]
Running from: c:\users\Rachtan\Desktop\ComboFix.exe
Command switches used :: c:\users\Rachtan\Desktop\CFScript.txt
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\program files\BS_Player\prxtbBS_0.dll"
"c:\program files\ConduitEngine\prxConduitEngine.dl"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2612415274-3809259120-191427226-1001Core.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2612415274-3809259120-191427226-1001UA.job"
"c:\windows\unrar.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Ask.com
c:\program files\Ask.com\assets\oobe\b.png
c:\program files\Ask.com\assets\oobe\bl.png
c:\program files\Ask.com\assets\oobe\br.png
c:\program files\Ask.com\assets\oobe\l.png
c:\program files\Ask.com\assets\oobe\pointer.png
c:\program files\Ask.com\assets\oobe\r.png
c:\program files\Ask.com\assets\oobe\t.png
c:\program files\Ask.com\assets\oobe\tl.png
c:\program files\Ask.com\assets\oobe\tr.png
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\fv_ae2c.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\precache.exe
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\Updater\config.xml
c:\program files\Ask.com\Updater\Updater.exe
c:\program files\Ask.com\UpdateTask.exe
c:\program files\BabylonToolbar
c:\program files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbar.crx
c:\program files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarApp.dll
c:\program files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarEng.dll
c:\program files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe
c:\program files\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarTlbr.dll
c:\program files\BabylonToolbar\BabylonToolbar\1.4.19.19\bh\BabylonToolbar.dll
c:\program files\BabylonToolbar\BabylonToolbar\1.4.19.19\uninstall.exe
c:\program files\BabylonToolbar\sqlite3.dll
c:\program files\BS_Player\prxtbBS_0.dll
c:\program files\Common Files\Akamai
c:\program files\Common Files\Akamai\AdminTool.exe
c:\program files\Common Files\Akamai\appregistry.dat
c:\program files\Common Files\Akamai\client.ini
c:\program files\Common Files\Akamai\client.ini.json
c:\program files\Common Files\Akamai\ControlPanel.exe
c:\program files\Common Files\Akamai\CplTasks.xml
c:\program files\Common Files\Akamai\data.dat
c:\program files\Common Files\Akamai\euc_state.json
c:\program files\Common Files\Akamai\guid.ini
c:\program files\Common Files\Akamai\Languages\csy.dll
c:\program files\Common Files\Akamai\Languages\dan.dll
c:\program files\Common Files\Akamai\Languages\deu.dll
c:\program files\Common Files\Akamai\Languages\esp.dll
c:\program files\Common Files\Akamai\Languages\fin.dll
c:\program files\Common Files\Akamai\Languages\fra.dll
c:\program files\Common Files\Akamai\Languages\chs.dll
c:\program files\Common Files\Akamai\Languages\cht.dll
c:\program files\Common Files\Akamai\Languages\ita.dll
c:\program files\Common Files\Akamai\Languages\jpn.dll
c:\program files\Common Files\Akamai\Languages\kor.dll
c:\program files\Common Files\Akamai\Languages\nld.dll
c:\program files\Common Files\Akamai\Languages\nor.dll
c:\program files\Common Files\Akamai\Languages\plk.dll
c:\program files\Common Files\Akamai\Languages\ptb.dll
c:\program files\Common Files\Akamai\Languages\ptg.dll
c:\program files\Common Files\Akamai\Languages\rus.dll
c:\program files\Common Files\Akamai\Languages\sve.dll
c:\program files\Common Files\Akamai\Languages\trk.dll
c:\program files\Common Files\Akamai\Logs\debug.log
c:\program files\Common Files\Akamai\Logs\debug.log.110815_170710.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110815_180711.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110815_190712.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110815_200713.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110815_210713.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110815_220713.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110816_032123.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110816_032133.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110816_033008.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110816_120724.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110816_130724.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110816_140724.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110816_150724.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110816_160725.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110816_170726.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110816_180726.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110816_190726.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110816_200727.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110816_210727.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110816_220728.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110816_224851.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110817_121926.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110817_131927.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110817_141927.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110817_151928.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110817_161929.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110817_171929.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110817_181930.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110817_191930.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110817_201931.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110817_211932.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110817_221933.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110817_231933.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110817_231945.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110818_125234.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110818_135234.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110818_145235.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110818_155236.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110818_165236.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110818_175237.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110818_185238.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110818_195238.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110818_205239.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110818_214646.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110818_214653.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110819_120319.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110819_130320.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110819_140320.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110819_150320.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110819_160321.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110819_170322.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110819_174425.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110819_175901.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110819_185902.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110819_195902.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110819_205903.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110819_215346.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110820_112240.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110820_120328.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110820_120643.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110820_130643.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110820_140644.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110820_143004.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110820_143151.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110820_145729.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110820_150107.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110820_151206.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110820_151540.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110820_161541.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110820_171541.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110820_181542.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110820_191543.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110820_201543.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_042038.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_044131.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_114735.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_124736.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_134736.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_142809.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_143152.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_143357.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_143733.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_144942.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_145307.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_152136.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_152609.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_152929.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_162019.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_162509.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_170118.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_174146.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_174744.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_184746.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_194746.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_204747.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_214747.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110821_223742.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110822_112654.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110822_122655.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110822_132655.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110822_142656.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110822_152656.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110822_153440.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110822_154314.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110822_154944.sent
c:\program files\Common Files\Akamai\Logs\debug.log.110822_155126.sent
c:\program files\Common Files\Akamai\netsession_win_2da1ebd.dll
c:\program files\Common Files\Akamai\readme.txt
c:\program files\Common Files\Akamai\root.pem
c:\program files\Common Files\Akamai\rswinui.exe
c:\program files\Common Files\Akamai\uninstall.exe
c:\program files\Common Files\Akamai\vcredist_x86.exe
c:\program files\Cheat Engine DB Toolbar
c:\program files\Cheat Engine DB Toolbar\affid.dat
c:\program files\Cheat Engine DB Toolbar\alert_plugin.dll
c:\program files\Cheat Engine DB Toolbar\basis.xml
c:\program files\Cheat Engine DB Toolbar\CustomTabPage.dll
c:\program files\Cheat Engine DB Toolbar\icons.bmp
c:\program files\Cheat Engine DB Toolbar\info.txt
c:\program files\Cheat Engine DB Toolbar\install.ico
c:\program files\Cheat Engine DB Toolbar\MacroParserPlugin.dll
c:\program files\Cheat Engine DB Toolbar\mbback.bmp
c:\program files\Cheat Engine DB Toolbar\mbbigopen.bmp
c:\program files\Cheat Engine DB Toolbar\mbclose.bmp
c:\program files\Cheat Engine DB Toolbar\mbfwd.bmp
c:\program files\Cheat Engine DB Toolbar\mbsep.bmp
c:\program files\Cheat Engine DB Toolbar\nav1c.bmp
c:\program files\Cheat Engine DB Toolbar\somoto.dll
c:\program files\Cheat Engine DB Toolbar\TbCommonUtils.dll
c:\program files\Cheat Engine DB Toolbar\tbcore3.dll
c:\program files\Cheat Engine DB Toolbar\tbcore3.inf
c:\program files\Cheat Engine DB Toolbar\TbHelper2.exe
c:\program files\Cheat Engine DB Toolbar\uninstall.exe
c:\program files\Cheat Engine DB Toolbar\UninstallToolbar.exe
c:\program files\Cheat Engine DB Toolbar\update.exe
c:\program files\Cheat Engine DB Toolbar\version.txt
c:\windows\av_ico
c:\windows\av_ico\ico_avast_desktop.ico
c:\windows\av_ico\ico_avast_start.ico
c:\windows\av_ico\ico_NOD_AV_START.ico
c:\windows\av_ico\ico_NOD_SYSINSP.ico
c:\windows\av_ico\ico_NOD_SYSRESC.ico
c:\windows\av_ico\ico_NOD_TXT.ico
c:\windows\av_ico\ico_NOD_UNINSTALL.ico
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2612415274-3809259120-191427226-1001Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2612415274-3809259120-191427226-1001UA.job
c:\windows\ufa
c:\windows\ufa\ufa.exe
c:\windows\unrar.exe
c:\windows\update.7.1
c:\windows\update.tray-12-0-lnk
c:\windows\update.tray-12-0
c:\windows\update.tray-2-0-lnk
c:\windows\update.tray-2-0
c:\windows\update.tray-7-0-lnk
c:\windows\update.tray-7-0
.
Infected copy of c:\windows\System32\user32.dll was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_Akamai
.
.
((((((((((((((((((((((((( Files Created from 2011-07-22 to 2011-08-22 )))))))))))))))))))))))))))))))
.
.
2011-08-22 15:59 . 2011-08-22 16:02 -------- d-----w- c:\users\Rachtan\AppData\Local\temp
2011-08-22 15:59 . 2011-08-22 15:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-22 15:16 . 2011-08-22 15:40 -------- d-----w- c:\users\Rachtan\AppData\Roaming\AVG10
2011-08-22 15:14 . 2011-08-22 15:50 -------- d-----w- c:\programdata\AVG10
2011-08-22 15:14 . 2011-08-22 15:46 -------- d-----w- c:\windows\system32\drivers\AVG
2011-08-22 15:13 . 2011-08-22 15:13 -------- d-----w- c:\program files\AVG
2011-08-22 15:09 . 2011-08-22 15:09 -------- d-----w- c:\programdata\Alwil Software
2011-08-22 15:09 . 2011-08-22 15:09 -------- d-----w- c:\program files\AVAST Software
2011-08-21 18:24 . 2011-08-21 18:32 -------- d-----w- c:\program files\trend micro
2011-08-21 18:24 . 2011-08-21 18:25 -------- dc----w- C:\rsit
2011-08-21 18:01 . 2011-08-21 18:01 -------- d-----w- c:\program files\ESET
2011-08-21 15:24 . 2011-08-21 17:45 -------- d-----w- c:\program files\Desktop Icon Toy
2011-08-21 15:22 . 2011-08-21 15:22 -------- d--h--w- c:\programdata\Common Files
2011-08-21 15:08 . 2011-08-22 15:49 -------- d-----w- c:\programdata\MFAData
2011-08-21 12:32 . 2011-08-21 22:08 -------- d-----w- c:\users\Rachtan\AppData\Roaming\Might & Magic Heroes VI - Game Official Demo
2011-08-19 15:46 . 2011-08-22 15:40 -------- d-----w- c:\program files\7-Zip
2011-08-17 22:05 . 2011-08-17 22:25 -------- d-----w- c:\users\Rachtan\AppData\Local\Ubisoft Game Launcher
2011-08-11 18:07 . 2011-06-23 04:33 3912576 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-08-09 12:48 . 2011-08-16 22:04 134104 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-08-09 12:42 . 2011-08-09 12:42 -------- d-----w- c:\program files\LogMeIn Hamachi
2011-08-04 20:44 . 2011-08-17 21:48 -------- d-----w- c:\users\Rachtan\AppData\Roaming\Mumble
2011-08-04 20:44 . 2011-08-04 20:44 -------- d-----w- c:\program files\Mumble
2011-08-02 23:08 . 2011-08-20 14:37 -------- d-----w- c:\program files\The KMPlayer
2011-07-27 20:37 . 2011-08-04 22:28 -------- d-----w- c:\users\Rachtan\riotsGamesLogs
2011-07-27 19:35 . 2011-07-27 19:35 -------- d-----w- c:\users\Rachtan\AppData\Roaming\LolClient
2011-07-24 14:09 . 2011-07-24 14:26 -------- d-----w- c:\users\Rachtan\AppData\Roaming\BugTrap Console Test108
2011-07-24 14:05 . 2011-07-24 14:05 -------- d-----w- c:\program files\Outspark
2011-07-24 14:05 . 2010-01-13 15:48 230752 ----a-w- c:\windows\patchw32.dll
2011-07-24 14:05 . 2010-01-13 15:48 118176 ----a-w- c:\windows\patchw.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-20 11:59 . 2011-06-01 15:56 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-01 19:27 . 2011-07-01 19:27 113543 ----a-w- c:\windows\system32\slmgr.vbs
2011-07-01 18:05 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-06-11 02:29 . 2011-07-13 16:20 2334208 ----a-w- c:\windows\system32\win32k.sys
2011-06-08 13:29 . 2011-06-08 13:15 8107 ----a-w- c:\windows\w7dsd.reg
2011-06-08 13:29 . 2011-06-08 13:15 8089 ----a-w- c:\windows\w7dse.reg
2011-06-08 13:15 . 2011-06-08 13:15 233888 ----a-w- c:\windows\system32\DreamScene.dll
2011-05-29 13:08 . 2010-10-12 18:53 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-08-16 22:04 . 2011-08-09 12:48 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-06-05 1310720]
"ProfilerU"="c:\program files\Saitek\SD6\Software\ProfilerU.exe" [2010-07-29 227840]
"SaiMfd"="c:\program files\Saitek\SD6\Software\SaiMfd.exe" [2010-07-29 123392]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2010-07-04 17408]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2011-08-04 1955208]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Miranda IM.lnk - c:\miranda im\miranda32.exe [2010-8-9 694368]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled
BumpTop.lnk - c:\program files\BumpTop\BumpTop.exe [2011-6-8 7162696]
Ventrilo.lnk - c:\program files\Ventrilo\Ventrilo.exe [2010-8-8 561152]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [x]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-06-24 136120]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-08-09 1343400]
R3 XDva385;XDva385;c:\windows\system32\XDva385.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-08-08 691696]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-04-28 114984]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2010-04-28 96896]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2011-08-04 1361288]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-07 378984]
S2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe [2010-07-06 173352]
S2 TunngleService;TunngleService;c:\program files\Tunngle\TnglCtrl.exe [2011-06-15 737016]
S3 SaiK0CFA;SaiK0CFA;c:\windows\system32\DRIVERS\SaiK0CFA.sys [2010-08-10 141832]
S3 SaiU0CFA;SaiU0CFA;c:\windows\system32\DRIVERS\SaiU0CFA.sys [2010-08-10 35208]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2010-03-11 25088]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-07-13 311296]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\users\Rachtan\AppData\Roaming\Mozilla\Firefox\Profiles\0e9w6zkr.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.sk/
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
BHO-{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
AddRemove-Akamai - c:\program files\Common Files\Akamai\uninstall.exe
AddRemove-BabylonToolbar - c:\program files\BabylonToolbar\BabylonToolbar\1.4.19.19\uninstall.exe
AddRemove-Cheat Engine DB Toolbar - c:\program files\Cheat Engine DB Toolbar\UninstallToolbar.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2612415274-3809259120-191427226-1001\Software\SecuROM\License information*]
"datasecu"=hex:ff,df,35,ba,17,51,8c,94,58,c7,f7,e6,df,e3,b0,13,e0,49,74,5c,bb,
da,c5,d2,b7,41,3c,8d,09,a9,14,96,7b,de,c2,5f,c0,5e,b1,ff,fa,3f,63,a4,8f,51,\
"rkeysecu"=hex:79,a0,04,7a,a1,46,ff,07,c7,b5,50,7d,66,0e,e2,2d
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\Display\NvXDSync.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\AEADISRV.EXE
c:\windows\system32\PnkBstrA.exe
c:\program files\Microsoft\BingBar\SeaPort.EXE
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\windows\system32\conhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\DllHost.exe
.
**************************************************************************
.
Completion time: 2011-08-22 18:04:29 - machine was rebooted
ComboFix-quarantined-files.txt 2011-08-22 16:04
ComboFix2.txt 2011-08-21 20:53
.
Pre-Run: 64 880 418 816 bytes free
Post-Run: 64 580 046 848 bytes free
.
- - End Of File - - 9B74376F9B0044B110739489FA06346D

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Facebook Vir

#6 Příspěvek od vyosek »

Ten ESET NOD32 mate legalni = zakoupena licence :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Rachtan
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 21 Srp 2011 19:20

Re: Facebook Vir

#7 Příspěvek od Rachtan »

Mal by to byt len eset online scanner.

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Facebook Vir

#8 Příspěvek od vyosek »

c:\program files\ESET\ESET NOD32 Antivirus sice poskozeny ale je tam
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Rachtan
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 21 Srp 2011 19:20

Re: Facebook Vir

#9 Příspěvek od Rachtan »

Nasiel som tam len ten online scanner, teda asi iba jeho zbytky. A cely ten priecinok ESET ma 0 bitov.

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Facebook Vir

#10 Příspěvek od vyosek »

:arrow: Odinstalujte Combofix
  • Prejmenujte ComboFix na Uninstall
  • Spustte jej
  • Tohle smaze Combofix a jeho slozky
:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: v nouzovem rezimu (restart PC, mackat F8, zvolit Stav nouze s praci v siti) projedte PC temito utilitami, at se zbavime zbytku antiviru co tam mate :arrow: Stahnete Ccleaner (viz muj podpis)
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: Nainstalujte Avast Free http://www.avast.com/cs-cz/free-antivirus-download

:arrow: Dejte novy log z RSIT a napiste, jak se chova PC
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Rachtan
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 21 Srp 2011 19:20

Re: Facebook Vir

#11 Příspěvek od Rachtan »

PC sa zatial chova normalne. Facebook ide, avast tiez.

Logfile of random's system information tool 1.09 (written by random/random)
Run by Rachtan at 2011-08-22 22:25:05
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 62 GB (62%) free of 100 GB
Total RAM: 3327 MB (55% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:25:16, on 22. 8. 2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Saitek\SD6\Software\ProfilerU.exe
C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Miranda IM\miranda32.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Rachtan\Desktop\RSIT.exe
C:\Program Files\trend micro\Rachtan.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - (no file)
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SMTTB2009 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - (no file)
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - (no file)
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ProfilerU] C:\Program Files\Saitek\SD6\Software\ProfilerU.exe
O4 - HKLM\..\Run: [SaiMfd] C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - Global Startup: AutorunsDisabled
O4 - Global Startup: Miranda IM.lnk = C:\Miranda IM\miranda32.exe
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe (file missing)
O23 - Service: ESET Service (ekrn) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (file missing)
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files\Tunngle\TnglCtrl.exe

--
End of file - 6430 bytes

=========Mozilla firefox=========

ProfilePath - C:\Users\Rachtan\AppData\Roaming\Mozilla\Firefox\Profiles\0e9w6zkr.default

prefs.js - "browser.search.suggest.enabled" - false
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.google.sk/"
prefs.js - "extensions.enabledItems" - "piclens@cooliris.com:1.12.2.44172, toolbar@ask.com:3.11.3.15590, gb@toolbar:1.0.0, {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}:3.3.3.2, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, plugin2@gameplaylabs.com:2.0, engine@conduit.com:3.3.3.2, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
prefs.js - "keyword.URL" - "http://search.babylon.com/?babsrc=toolbar2&q="

"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll

C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
avg_igeared.xml
azet-sk.xml
babylon.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml

C:\Users\Rachtan\AppData\Roaming\Mozilla\Firefox\Profiles\0e9w6zkr.default\extensions\
engine@conduit.com
gb@toolbar
piclens@cooliris.com
plugin2@gameplaylabs.com
toolbar@ask.com
{75656794-AB59-4712-BFBC-5D816D56F3BC}
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}

C:\Users\Rachtan\AppData\Roaming\Mozilla\Firefox\Profiles\0e9w6zkr.default\searchplugins\
askcom.xml
conduit.xml
daemon-search.xml
search.xml
web-search.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-07-04 820864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2010-11-10 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files\Microsoft\BingBar\BingExt.dll [2011-02-28 1089288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-05-29 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files\Microsoft\BingBar\BingExt.dll [2011-02-28 1089288]
{98889811-442D-49dd-99D7-DC866BE87DBC}
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-07-04 820864]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2009-06-05 1310720]
"ProfilerU"=C:\Program Files\Saitek\SD6\Software\ProfilerU.exe [2010-07-29 227840]
"SaiMfd"=C:\Program Files\Saitek\SD6\Software\SaiMfd.exe [2010-07-29 123392]
"amd_dc_opt"=C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [2008-07-22 77824]
"UnlockerAssistant"=C:\Program Files\Unlocker\UnlockerAssistant.exe [2010-07-04 17408]
"LogMeIn Hamachi Ui"=C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2011-08-04 1955208]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-07-04 3493720]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1174016]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
AutorunsDisabled
Miranda IM.lnk - C:\Miranda IM\miranda32.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2011-04-18 203776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll [2011-06-08 233888]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=3
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"msacm.l3fhg"=mp3fhg.acm
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"VIDC.FFDS"=ff_vfw.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.siren"=sirenacm.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"vidc.DIVX"=DivX.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2011-08-22 22:25:05 ----DC---- C:\rsit
2011-08-22 20:30:11 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-08-22 20:30:10 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-08-22 20:30:07 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-08-22 20:30:07 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-08-22 20:30:07 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-08-22 20:30:06 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-08-22 20:29:57 ----A---- C:\Windows\system32\aswBoot.exe
2011-08-22 20:29:57 ----A---- C:\Windows\avastSS.scr
2011-08-22 19:42:15 ----SDC---- C:\Uninstall
2011-08-22 18:04:31 ----D---- C:\Windows\temp
2011-08-22 18:02:07 ----DC---- C:\$RECYCLE.BIN
2011-08-22 17:14:07 ----D---- C:\ProgramData\AVG10
2011-08-22 17:09:52 ----D---- C:\ProgramData\Alwil Software
2011-08-22 17:09:52 ----D---- C:\Program Files\AVAST Software
2011-08-21 22:13:04 ----D---- C:\Windows\ERDNT
2011-08-21 20:24:37 ----D---- C:\Program Files\trend micro
2011-08-21 20:01:27 ----D---- C:\Program Files\ESET
2011-08-21 17:24:31 ----D---- C:\Program Files\Desktop Icon Toy
2011-08-21 17:22:28 ----HD---- C:\ProgramData\Common Files
2011-08-21 17:08:55 ----D---- C:\ProgramData\MFAData
2011-08-21 16:49:11 ----DC---- C:\Config.Msi
2011-08-21 14:32:20 ----D---- C:\Users\Rachtan\AppData\Roaming\Might & Magic Heroes VI - Game Official Demo
2011-08-19 17:46:01 ----D---- C:\Program Files\7-Zip
2011-08-12 00:35:04 ----A---- C:\Windows\system32\mshtmled.dll
2011-08-12 00:35:03 ----A---- C:\Windows\system32\jscript.dll
2011-08-12 00:35:03 ----A---- C:\Windows\system32\ieui.dll
2011-08-12 00:35:03 ----A---- C:\Windows\system32\iertutil.dll
2011-08-12 00:35:02 ----A---- C:\Windows\system32\wininet.dll
2011-08-12 00:35:02 ----A---- C:\Windows\system32\urlmon.dll
2011-08-12 00:35:02 ----A---- C:\Windows\system32\url.dll
2011-08-12 00:35:02 ----A---- C:\Windows\system32\jsproxy.dll
2011-08-12 00:35:02 ----A---- C:\Windows\system32\jscript9.dll
2011-08-12 00:35:01 ----A---- C:\Windows\system32\ieframe.dll
2011-08-12 00:35:00 ----A---- C:\Windows\system32\mshtml.dll
2011-08-11 20:07:05 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-08-11 20:07:04 ----A---- C:\Windows\system32\ntkrnlpa.exe
2011-08-11 20:07:04 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-08-11 20:07:02 ----A---- C:\Windows\system32\kernel32.dll
2011-08-11 20:07:02 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-08-11 20:07:01 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-08-11 20:07:01 ----A---- C:\Windows\system32\winsrv.dll
2011-08-11 20:07:01 ----A---- C:\Windows\system32\KernelBase.dll
2011-08-11 20:07:01 ----A---- C:\Windows\system32\conhost.exe
2011-08-11 20:07:00 ----A---- C:\Windows\system32\odbctrac.dll
2011-08-11 20:07:00 ----A---- C:\Windows\system32\odbcjt32.dll
2011-08-11 20:07:00 ----A---- C:\Windows\system32\odbccu32.dll
2011-08-11 20:07:00 ----A---- C:\Windows\system32\odbccr32.dll
2011-08-11 20:07:00 ----A---- C:\Windows\system32\odbccp32.dll
2011-08-09 14:42:35 ----D---- C:\Program Files\LogMeIn Hamachi
2011-08-04 22:44:15 ----D---- C:\Users\Rachtan\AppData\Roaming\Mumble
2011-08-04 22:44:06 ----D---- C:\Program Files\Mumble
2011-08-03 01:08:32 ----D---- C:\Program Files\The KMPlayer
2011-07-28 17:52:56 ----AH---- C:\Windows\system32\mlfcache.dat
2011-07-27 21:35:57 ----D---- C:\Users\Rachtan\AppData\Roaming\LolClient
2011-07-24 16:09:02 ----D---- C:\Users\Rachtan\AppData\Roaming\BugTrap Console Test108
2011-07-24 16:05:05 ----D---- C:\Program Files\Outspark
2011-07-24 16:05:05 ----A---- C:\Windows\patchw32.dll
2011-07-24 16:05:05 ----A---- C:\Windows\patchw.dll
2011-07-23 13:36:10 ----D---- C:\Users\Rachtan\AppData\Roaming\SEGA Corporation
2011-07-23 13:35:14 ----D---- C:\ProgramData\SEGA Corporation

======List of files/folders modified in the last 1 month======

2011-08-22 22:22:32 ----D---- C:\Windows\system32\config
2011-08-22 22:19:26 ----D---- C:\ProgramData\NVIDIA
2011-08-22 22:19:01 ----D---- C:\Windows
2011-08-22 20:43:49 ----D---- C:\Windows\System32
2011-08-22 20:43:49 ----D---- C:\Program Files\Windows Journal
2011-08-22 20:30:11 ----D---- C:\Windows\system32\drivers
2011-08-22 20:30:05 ----SHD---- C:\Windows\Installer
2011-08-22 20:29:53 ----D---- C:\ProgramData\AVAST Software
2011-08-22 20:29:49 ----SHD---- C:\System Volume Information
2011-08-22 20:23:49 ----D---- C:\Program Files\CCleaner
2011-08-22 20:20:12 ----RD---- C:\Program Files
2011-08-22 18:02:09 ----AC---- C:\Windows\system.ini
2011-08-22 18:02:04 ----D---- C:\Windows\system32\drivers\etc
2011-08-22 18:02:04 ----D---- C:\Program Files\Common Files
2011-08-22 17:59:34 ----D---- C:\Windows\Tasks
2011-08-22 17:59:20 ----D---- C:\Program Files\BS_Player
2011-08-22 17:57:41 ----D---- C:\Windows\AppPatch
2011-08-22 17:52:30 ----D---- C:\Users\Rachtan\AppData\Roaming\uTorrent
2011-08-22 17:46:53 ----D---- C:\Windows\inf
2011-08-22 17:44:53 ----AD---- C:\ProgramData
2011-08-22 17:42:30 ----D---- C:\Windows\system32\wbem
2011-08-22 17:40:30 ----D---- C:\Program Files\DAEMON Tools Lite
2011-08-22 17:40:27 ----D---- C:\Program Files\WinRAR
2011-08-22 17:40:27 ----D---- C:\Program Files\Windows Sidebar
2011-08-22 17:40:27 ----D---- C:\Program Files\Unlocker
2011-08-22 17:40:27 ----D---- C:\Program Files\TeamSpeak 3 Client
2011-08-22 17:40:23 ----D---- C:\Users\Rachtan\AppData\Roaming\TS3Client
2011-08-22 17:40:20 ----D---- C:\Windows\ehome
2011-08-22 17:40:18 ----D---- C:\Windows\system32\DriverStore
2011-08-22 17:40:18 ----D---- C:\Windows\system32\catroot2
2011-08-22 17:40:15 ----D---- C:\Windows\system32\Speech
2011-08-22 17:40:14 ----D---- C:\Windows\winsxs
2011-08-22 17:40:14 ----D---- C:\Windows\system32\Tasks
2011-08-22 17:39:55 ----D---- C:\Windows\registration
2011-08-21 19:47:17 ----D---- C:\Windows\system32\wfp
2011-08-21 19:45:49 ----D---- C:\Windows\system32\CodeIntegrity
2011-08-21 19:45:47 ----D---- C:\ProgramData\PMB Files
2011-08-21 19:45:37 ----D---- C:\ProgramData\Electronic Arts
2011-08-21 19:02:08 ----D---- C:\Windows\Prefetch
2011-08-21 17:17:03 ----D---- C:\Windows\system32\catroot
2011-08-21 16:41:57 ----D---- C:\Users\Rachtan\AppData\Roaming\Media Player Classic
2011-08-21 16:41:53 ----D---- C:\Windows\debug
2011-08-21 14:29:40 ----RSD---- C:\Windows\assembly
2011-08-21 14:29:15 ----HD---- C:\Program Files\InstallShield Installation Information
2011-08-20 21:43:42 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-08-20 17:20:52 ----D---- C:\Windows\Logs
2011-08-19 22:22:01 ----D---- C:\Windows\system32\NDF
2011-08-18 21:06:04 ----D---- C:\Windows\Downloaded Program Files
2011-08-18 00:18:54 ----D---- C:\Program Files\Ubisoft
2011-08-17 00:05:49 ----D---- C:\Program Files\Mozilla Firefox
2011-08-12 15:05:37 ----D---- C:\Windows\Microsoft.NET
2011-08-12 14:32:21 ----D---- C:\Windows\system32\migration
2011-08-12 14:32:20 ----D---- C:\Program Files\Internet Explorer
2011-08-12 00:34:55 ----A---- C:\Windows\system32\MRT.exe
2011-07-23 13:56:50 ----D---- C:\Program Files\Common Files\Wise Installation Wizard

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-08-08 691696]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-07-04 25432]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-07-04 441176]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-07-04 309848]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-07-04 43608]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-04-28 114984]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-07-04 19544]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-07-04 54104]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2010-04-28 96896]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2010-10-05 25416]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys [2009-06-05 380416]
R3 AmdLLD;AMD Low Level Device Driver; C:\Windows\system32\DRIVERS\AmdLLD.sys [2007-06-29 34304]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 SaiK0CFA;SaiK0CFA; C:\Windows\system32\DRIVERS\SaiK0CFA.sys [2010-08-10 141832]
R3 SaiMini;SaiMini; C:\Windows\system32\DRIVERS\SaiMini.sys [2010-07-08 20744]
R3 SaiNtBus;SaiNtBus; C:\Windows\system32\drivers\SaiBus.sys [2010-07-08 43656]
R3 SaiU0CFA;SaiU0CFA; C:\Windows\system32\DRIVERS\SaiU0CFA.sys [2010-08-10 35208]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\Windows\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
R3 teamviewervpn;TeamViewer VPN Adapter; C:\Windows\system32\DRIVERS\teamviewervpn.sys [2010-03-11 25088]
S2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2010-10-05 278984]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 a9j65jsa;a9j65jsa; C:\Windows\system32\drivers\a9j65jsa.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-06-24 136120]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 39272]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 15872]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
S3 XDva385;XDva385; \??\C:\Windows\system32\XDva385.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AEADIFilters;Andrea ADI Filters Service; C:\Windows\system32\AEADISRV.EXE [2009-06-05 90112]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-07-04 42184]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2011-08-04 1361288]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2011-01-07 608872]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2011-03-23 75136]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\BingBar\SeaPort.EXE [2011-02-25 249648]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-07 378984]
R2 TeamViewer5;TeamViewer 5; C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe [2010-07-06 173352]
R2 TunngleService;TunngleService; C:\Program Files\Tunngle\TnglCtrl.exe [2011-06-15 737016]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe []
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 BBSvc;Bing Bar Update Service; C:\Program Files\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe []
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-01-15 774144]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-03-12 271920]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2009-06-30 316664]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-08-09 1343400]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]

-----------------EOF-----------------

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Facebook Vir

#12 Příspěvek od vyosek »

Tohle jste delal :???:
vyosek napsal: :arrow: v nouzovem rezimu (restart PC, mackat F8, zvolit Stav nouze s praci v siti) projedte PC temito utilitami, at se zbavime zbytku antiviru co tam mate
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět