Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

facebook vir

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
jaryman
Návštěvník
Návštěvník
Příspěvky: 33
Registrován: 22 srp 2011 12:51

facebook vir

#1 Příspěvek od jaryman »

Logfile of random's system information tool 1.09 (written by random/random)
Run by Martin at 2011-08-22 13:47:58
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 17 GB (22%) free of 76 GB
Total RAM: 3071 MB (37% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:48:07, on 22.8.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Windows\SysWOW64\DllHost.exe
D:\World of Warcraft\Wow.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\Martin.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [1707595.exe] "C:\Windows\Temp\1707595.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: FancyStart daemon.lnk = ?
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O4 - Global Startup: SRS Premium Sound.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - Unknown owner - C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ShowAnalyzerMaster - Dragon Global - C:\Program Files (x86)\Dragon Global\ShowAnalyzerSuite\ShowAnalyzerMaster.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Windows\SysWOW64\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11720 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Windows\system32\FBAgent.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe"
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\Dragon Global\ShowAnalyzerSuite\ShowAnalyzerMaster.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
"taskhost.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
ATKOSD.exe
KBFiltr.exe
WDC.exe
taskeng.exe {875145E1-496C-4CC9-933F-96919B41F5D7}
C:\Windows\SysWOW64\nvSCPAPISvr.exe
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files\ASUS\Net4Switch\Net4Switch.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe"
"C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe"
"C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe"
"C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"
"C:\Program Files\P4G\BatteryLife.exe"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe"
"C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel_64.exe" /f=srs_premium_sound_nopreset.zip
"C:\Windows\SysWOW64\ACEngSvr.exe" -Embedding
"C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe"
"C:\Windows\AsScrPro.exe"
"C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE"
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe"
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\SysWOW64\DllHost.exe /Processid:{FCC74B77-EC3E-4DD8-A80B-008A702075A9}
"C:\Program Files\Windows Sidebar\sidebar.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide
"D:\World of Warcraft\Wow.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=408.658a990.1340092272 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" Mozilla.Firefox.6.0 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 408 "\\.\pipe\gecko-crash-server-pipe.408" plugin
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe10_ Global\UsGthrCtrlFltPipeMssGthrPipe10 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 508 512 520 65536 516
"c:\program files\windows defender\MpCmdRun.exe" SpyNetService -RestrictPrivileges -AccessKey 9CC5D8BB-24B2-EE03-4C66-84EF4EA6A20E -Reinvoke
"C:\Users\Martin\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\742z7rsh.default

prefs.js - "browser.startup.homepage" - "http://search.conduit.com/?ctid=CT17505 ... hSource=13"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18]
"Description"=Veetle TV Core
"Path"=C:\Program Files (x86)\Veetle\plugins\npVeetle.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18]
"Description"=Veetle TV Player
"Path"=C:\Program Files (x86)\Veetle\Player\npvlc.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll

C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\742z7rsh.default\extensions\
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}

C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\742z7rsh.default\searchplugins\
conduit.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
Windows Live Family Safety Browser Helper Class - C:\Program Files\Windows Live\Family Safety\fssbho.dll [2008-12-08 68960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2010-09-16 346736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg64.dll [2010-09-16 318960]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2008-12-04 92504]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2010-09-16 256112]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-07-11 3821568]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll [2010-09-16 761840]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2010-09-16 458736]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [2008-12-08 1067352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2010-09-16 346736]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2010-09-16 256112]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [2008-12-08 1067352]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ASUS WebStorage"=C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [2010-03-16 1754448]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-12-11 16414824]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2009-09-30 621440]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2009-09-02 323584]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2011-01-12 2918656]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-28 35696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADSMTray]
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe [2009-06-24 272952]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\AsScrPro.exe [2010-09-16 3054136]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boingo Wi-Fi]
C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk [2010-09-16 2429]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2009-11-02 103720]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-08-02 4910912]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-12-21 9639424]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"UpdateLBPShortCut"=C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [2009-05-20 222504]
"UpdateP2GoShortCut"=C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2009-05-20 222504]
"ATKOSD2"=C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2009-10-27 6998656]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2009-08-20 170624]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2011-07-19 421736]
"tray_ico"= []
"tray_ico2"= []
"tray_ico3"= []
"tray_ico4"= []
"1707595.exe"=C:\Windows\Temp\1707595.exe []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
FancyStart daemon.lnk - C:\Windows\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe
McAfee Security Scan Plus.lnk - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
SRS Premium Sound.lnk - C:\Windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2011-08-22 13:47:58 ----D---- C:\rsit
2011-08-22 13:47:58 ----D---- C:\Program Files\trend micro
2011-08-22 11:43:20 ----D---- C:\ProgramData\ESET
2011-08-22 11:43:20 ----D---- C:\Program Files\ESET
2011-08-21 17:47:32 ----D---- C:\ProgramData\AVAST Software
2011-08-21 17:47:32 ----D---- C:\Program Files\AVAST Software
2011-08-21 17:18:05 ----A---- C:\ProgramData\NTUSER.DAT
2011-08-20 08:38:20 ----D---- C:\Users\Martin\AppData\Roaming\BSplayer Pro
2011-08-20 08:38:20 ----D---- C:\Users\Martin\AppData\Roaming\BSplayer
2011-08-20 08:38:19 ----D---- C:\Program Files (x86)\Webteh
2011-08-19 13:16:38 ----HD---- C:\Windows\update.7.1
2011-08-19 10:40:09 ----D---- C:\Windows\ufa
2011-08-19 10:40:09 ----D---- C:\Windows\rpcminer
2011-08-19 10:40:09 ----D---- C:\Windows\phoenix
2011-08-19 10:38:43 ----A---- C:\Windows\btc_client_iplist.txt
2011-08-19 10:38:33 ----A---- C:\Windows\unrar.exe
2011-08-19 10:38:19 ----HD---- C:\Windows\update.5.0
2011-08-19 10:38:11 ----A---- C:\Windows\iecheck_iplist.txt
2011-08-19 10:37:44 ----HD---- C:\Windows\update.2
2011-08-19 10:34:26 ----A---- C:\Windows\iplist.txt
2011-08-19 10:33:20 ----D---- C:\Windows\av_ico
2011-08-19 10:33:15 ----A---- C:\Windows\front_ip_list.txt
2011-08-19 10:23:18 ----HD---- C:\Windows\update.1
2011-08-19 10:23:15 ----HD---- C:\Windows\update.tray-9-0-lnk
2011-08-19 10:23:15 ----HD---- C:\Windows\update.tray-9-0
2011-08-19 10:23:14 ----HD---- C:\Windows\update.tray-7-0-lnk
2011-08-19 10:23:14 ----HD---- C:\Windows\update.tray-7-0
2011-08-19 10:09:21 ----A---- C:\Windows\winlog-ids.txt
2011-08-19 10:09:21 ----A---- C:\Windows\winlog-dirs.txt
2011-08-14 22:13:23 ----D---- C:\Program Files (x86)\Veetle
2011-08-12 05:42:40 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2011-08-12 05:42:40 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2011-08-12 05:42:40 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2011-08-12 05:42:40 ----A---- C:\Windows\system32\XAudio2_7.dll
2011-08-12 05:42:40 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2011-08-12 05:42:40 ----A---- C:\Windows\system32\xactengine3_7.dll
2011-08-12 05:42:39 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2011-08-12 05:42:39 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2011-08-12 05:42:38 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2011-08-12 05:42:38 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2011-08-12 05:42:38 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2011-08-12 05:42:38 ----A---- C:\Windows\system32\d3dx11_43.dll
2011-08-12 05:42:38 ----A---- C:\Windows\system32\d3dx10_43.dll
2011-08-12 05:42:38 ----A---- C:\Windows\system32\d3dcsx_43.dll
2011-08-12 05:42:37 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2011-08-12 05:42:37 ----A---- C:\Windows\system32\D3DX9_43.dll
2011-08-12 05:42:36 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2011-08-12 05:42:36 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2011-08-12 05:42:36 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2011-08-12 05:42:36 ----A---- C:\Windows\system32\XAudio2_6.dll
2011-08-12 05:42:36 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2011-08-12 05:42:36 ----A---- C:\Windows\system32\xactengine3_6.dll
2011-08-12 05:42:35 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2011-08-12 05:42:35 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2011-08-12 05:42:34 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2011-08-12 05:42:34 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2011-08-12 05:42:34 ----A---- C:\Windows\system32\XAudio2_5.dll
2011-08-12 05:42:34 ----A---- C:\Windows\system32\xactengine3_5.dll
2011-08-12 05:42:33 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2011-08-12 05:42:33 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2011-08-12 05:42:28 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2011-08-12 05:42:28 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2011-08-12 05:42:28 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2011-08-12 05:42:28 ----A---- C:\Windows\system32\d3dx11_42.dll
2011-08-12 05:42:28 ----A---- C:\Windows\system32\d3dx10_42.dll
2011-08-12 05:42:28 ----A---- C:\Windows\system32\d3dcsx_42.dll
2011-08-12 05:42:27 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2011-08-12 05:42:27 ----A---- C:\Windows\system32\D3DX9_42.dll
2011-08-12 05:42:26 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2011-08-12 05:42:26 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2011-08-12 05:42:26 ----A---- C:\Windows\system32\d3dx10_41.dll
2011-08-12 05:42:26 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2011-08-12 05:42:25 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2011-08-12 05:42:25 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2011-08-12 05:42:25 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-08-12 05:42:25 ----A---- C:\Windows\system32\D3DX9_41.dll
2011-08-12 05:42:24 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2011-08-12 05:42:24 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2011-08-12 05:42:24 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2011-08-12 05:42:24 ----A---- C:\Windows\system32\XAudio2_4.dll
2011-08-12 05:42:24 ----A---- C:\Windows\system32\xactengine3_4.dll
2011-08-12 05:42:24 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2011-08-12 05:42:23 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2011-08-12 05:42:23 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2011-08-12 05:42:22 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2011-08-12 05:42:22 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2011-08-12 05:42:22 ----A---- C:\Windows\system32\D3DX9_40.dll
2011-08-12 05:42:22 ----A---- C:\Windows\system32\d3dx10_40.dll
2011-08-12 05:42:21 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2011-08-12 05:42:21 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2011-08-12 05:42:21 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2011-08-12 05:42:21 ----A---- C:\Windows\system32\XAudio2_3.dll
2011-08-12 05:42:21 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2011-08-12 05:42:21 ----A---- C:\Windows\system32\xactengine3_3.dll
2011-08-12 05:42:20 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2011-08-12 05:42:20 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2011-08-12 05:42:20 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2011-08-12 05:42:20 ----A---- C:\Windows\system32\XAudio2_2.dll
2011-08-12 05:42:20 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2011-08-12 05:42:20 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2011-08-12 05:42:19 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2011-08-12 05:42:19 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2011-08-12 05:42:19 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2011-08-12 05:42:19 ----A---- C:\Windows\system32\xactengine3_2.dll
2011-08-12 05:42:19 ----A---- C:\Windows\system32\d3dx10_39.dll
2011-08-12 05:42:19 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2011-08-12 05:42:18 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2011-08-12 05:42:18 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-08-12 05:42:17 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2011-08-12 05:42:17 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2011-08-12 05:42:17 ----A---- C:\Windows\system32\XAudio2_1.dll
2011-08-12 05:42:17 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2011-08-12 05:42:16 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2011-08-12 05:42:16 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2011-08-12 05:42:16 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2011-08-12 05:42:16 ----A---- C:\Windows\system32\xactengine3_1.dll
2011-08-12 05:42:16 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2011-08-12 05:42:16 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2011-08-12 05:42:15 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2011-08-12 05:42:15 ----A---- C:\Windows\system32\d3dx10_38.dll
2011-08-12 05:42:14 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2011-08-12 05:42:14 ----A---- C:\Windows\system32\D3DX9_38.dll
2011-08-12 05:42:13 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2011-08-12 05:42:13 ----A---- C:\Windows\system32\XAudio2_0.dll
2011-08-12 05:42:12 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2011-08-12 05:42:12 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2011-08-12 05:42:12 ----A---- C:\Windows\system32\xactengine3_0.dll
2011-08-12 05:42:12 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2011-08-12 05:42:11 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2011-08-12 05:42:11 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2011-08-12 05:42:10 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2011-08-12 05:42:10 ----A---- C:\Windows\system32\d3dx10_37.dll
2011-08-12 05:42:09 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2011-08-12 05:42:09 ----A---- C:\Windows\system32\D3DX9_37.dll
2011-08-12 05:42:08 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2011-08-12 05:42:08 ----A---- C:\Windows\system32\xactengine2_10.dll
2011-08-12 05:42:05 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2011-08-12 05:42:05 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2011-08-12 05:42:05 ----A---- C:\Windows\system32\d3dx10_36.dll
2011-08-12 05:42:05 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2011-08-12 05:42:04 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2011-08-12 05:42:04 ----A---- C:\Windows\system32\d3dx9_36.dll
2011-08-12 05:42:02 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2011-08-12 05:42:02 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2011-08-12 05:42:02 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2011-08-12 05:42:02 ----A---- C:\Windows\system32\xactengine2_9.dll
2011-08-12 05:42:02 ----A---- C:\Windows\system32\d3dx10_35.dll
2011-08-12 05:42:02 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2011-08-12 05:42:00 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2011-08-12 05:42:00 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2011-08-12 05:42:00 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2011-08-12 05:42:00 ----A---- C:\Windows\system32\xactengine2_8.dll
2011-08-12 05:42:00 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2011-08-12 05:42:00 ----A---- C:\Windows\system32\d3dx9_35.dll
2011-08-12 05:41:59 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2011-08-12 05:41:59 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2011-08-12 05:41:59 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-08-12 05:41:59 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-08-12 05:41:57 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2011-08-12 05:41:57 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-08-12 05:41:56 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2011-08-12 05:41:56 ----A---- C:\Windows\system32\xinput1_3.dll
2011-08-12 05:41:55 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2011-08-12 05:41:55 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2011-08-12 05:41:55 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2011-08-12 05:41:55 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-08-12 05:41:55 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-08-12 05:41:55 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-08-12 05:41:54 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2011-08-12 05:41:54 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-08-12 05:41:51 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2011-08-12 05:41:51 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-08-12 05:41:50 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2011-08-12 05:41:50 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-08-12 05:41:50 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-08-12 05:41:50 ----A---- C:\Windows\system32\d3dx10.dll
2011-08-12 05:41:48 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2011-08-12 05:41:48 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-08-12 05:41:47 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2011-08-12 05:41:47 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-08-12 05:41:46 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2011-08-12 05:41:46 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-08-12 05:41:45 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2011-08-12 05:41:45 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-08-12 05:41:44 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2011-08-12 05:41:44 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2011-08-12 05:41:44 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2011-08-12 05:41:44 ----A---- C:\Windows\system32\xinput1_2.dll
2011-08-12 05:41:44 ----A---- C:\Windows\system32\xinput1_1.dll
2011-08-12 05:41:44 ----A---- C:\Windows\system32\xactengine2_2.dll
2011-08-12 05:41:43 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2011-08-12 05:41:43 ----A---- C:\Windows\system32\xactengine2_1.dll
2011-08-12 05:41:38 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-08-12 05:41:38 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-08-12 05:41:37 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2011-08-12 05:41:37 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2011-08-12 05:41:37 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2011-08-12 05:41:37 ----A---- C:\Windows\system32\xactengine2_0.dll
2011-08-12 05:41:37 ----A---- C:\Windows\system32\x3daudio1_0.dll
2011-08-12 05:41:37 ----A---- C:\Windows\system32\d3dx9_29.dll
2011-08-12 05:41:36 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2011-08-12 05:41:36 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2011-08-12 05:41:36 ----A---- C:\Windows\system32\d3dx9_28.dll
2011-08-12 05:41:36 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-08-12 05:41:34 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2011-08-12 05:41:34 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2011-08-12 05:41:34 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-08-12 05:41:34 ----A---- C:\Windows\system32\d3dx9_25.dll
2011-08-12 05:41:33 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2011-08-12 05:41:33 ----A---- C:\Windows\system32\d3dx9_24.dll
2011-08-12 05:41:09 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2011-08-11 15:50:51 ----D---- C:\Program Files\CCleaner
2011-08-11 14:00:10 ----A---- C:\Windows\SYSWOW64\xmllite.dll
2011-08-11 14:00:10 ----A---- C:\Windows\system32\xmllite.dll
2011-08-11 14:00:07 ----A---- C:\Windows\system32\odbccu32.dll
2011-08-11 14:00:07 ----A---- C:\Windows\system32\odbccr32.dll
2011-08-11 14:00:07 ----A---- C:\Windows\system32\odbccp32.dll
2011-08-11 14:00:06 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2011-08-11 14:00:06 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2011-08-11 14:00:06 ----A---- C:\Windows\SYSWOW64\odbccu32.dll
2011-08-11 14:00:06 ----A---- C:\Windows\SYSWOW64\odbccr32.dll
2011-08-11 14:00:06 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2011-08-11 14:00:06 ----A---- C:\Windows\system32\odbctrac.dll
2011-08-11 14:00:04 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-08-11 13:59:53 ----A---- C:\Windows\system32\kernel32.dll
2011-08-11 13:59:53 ----A---- C:\Windows\system32\conhost.exe
2011-08-11 13:59:52 ----A---- C:\Windows\system32\wow64.dll
2011-08-11 13:59:52 ----A---- C:\Windows\system32\winsrv.dll
2011-08-11 13:59:52 ----A---- C:\Windows\system32\KernelBase.dll
2011-08-11 13:59:51 ----A---- C:\Windows\SYSWOW64\setup16.exe
2011-08-11 13:59:51 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2011-08-11 13:59:51 ----A---- C:\Windows\system32\wow64win.dll
2011-08-11 13:59:51 ----A---- C:\Windows\system32\ntvdm64.dll
2011-08-11 13:59:50 ----A---- C:\Windows\system32\wow64cpu.dll
2011-08-11 13:59:49 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-08-11 13:59:48 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-08-11 13:59:48 ----A---- C:\Windows\SYSWOW64\wow32.dll
2011-08-11 13:59:48 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-08-11 13:59:47 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-08-11 13:59:46 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-08-11 13:59:46 ----A---- C:\Windows\SYSWOW64\user.exe
2011-08-11 13:59:46 ----A---- C:\Windows\SYSWOW64\instnm.exe
2011-08-11 13:59:44 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-08-11 13:59:39 ----A---- C:\Windows\system32\mshtml.dll
2011-08-11 13:59:35 ----A---- C:\Windows\system32\iertutil.dll
2011-08-11 13:59:34 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-08-11 13:59:33 ----A---- C:\Windows\system32\ieframe.dll
2011-08-11 13:59:31 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-08-11 13:59:29 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-08-11 13:59:29 ----A---- C:\Windows\system32\urlmon.dll
2011-08-11 13:59:28 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-08-11 13:59:28 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-08-11 13:59:28 ----A---- C:\Windows\system32\wininet.dll
2011-08-11 13:59:28 ----A---- C:\Windows\system32\msfeeds.dll
2011-08-11 13:59:27 ----A---- C:\Windows\SYSWOW64\url.dll
2011-08-11 13:59:27 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-08-11 13:59:27 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-08-11 13:59:27 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-08-11 13:59:27 ----A---- C:\Windows\system32\url.dll
2011-08-11 13:59:27 ----A---- C:\Windows\system32\mshtmled.dll
2011-08-11 13:59:27 ----A---- C:\Windows\system32\ieui.dll
2011-08-11 13:59:26 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-08-11 13:59:26 ----A---- C:\Windows\system32\jsproxy.dll
2011-08-11 13:59:22 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-08-11 13:59:22 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-08-11 13:59:21 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-08-10 17:39:50 ----D---- C:\Users\Martin\AppData\Roaming\Skype
2011-08-10 17:39:30 ----RD---- C:\Program Files (x86)\Skype
2011-08-10 17:39:21 ----D---- C:\ProgramData\Skype
2011-08-10 16:48:53 ----D---- C:\ProgramData\Blizzard
2011-08-09 13:02:33 ----D---- C:\Program Files\Zrychleni Pocitace
2011-08-09 13:02:20 ----D---- C:\Users\Martin\AppData\Roaming\OpenCandy
2011-08-09 13:01:22 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2011-08-09 13:01:09 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2011-08-09 13:00:44 ----D---- C:\Users\Martin\AppData\Roaming\DAEMON Tools Lite
2011-08-09 13:00:40 ----D---- C:\ProgramData\DAEMON Tools Lite
2011-08-09 12:50:00 ----D---- C:\Users\Martin\AppData\Roaming\CyberLink
2011-08-08 18:45:35 ----D---- C:\ProgramData\VirtualizedApplications
2011-08-05 19:27:49 ----D---- C:\Users\Martin\AppData\Roaming\Leawo
2011-08-05 19:27:23 ----A---- C:\Windows\SYSWOW64\xvidcore.dll
2011-08-05 19:24:05 ----D---- C:\ProgramData\Dragon Global
2011-08-05 19:24:05 ----D---- C:\Program Files (x86)\Dragon Global
2011-08-05 19:22:46 ----D---- C:\Program Files (x86)\DVRMSToolbox
2011-07-30 12:27:31 ----D---- C:\Program Files\iPod
2011-07-30 12:27:29 ----D---- C:\Program Files\iTunes
2011-07-30 12:27:29 ----D---- C:\Program Files (x86)\iTunes
2011-07-30 12:25:54 ----D---- C:\Program Files\Bonjour
2011-07-30 12:25:54 ----D---- C:\Program Files (x86)\Bonjour

======List of files/folders modified in the last 1 month======

2011-08-22 13:48:07 ----D---- C:\Windows\Temp
2011-08-22 13:47:58 ----RD---- C:\Program Files
2011-08-22 13:46:36 ----D---- C:\Windows
2011-08-22 12:42:34 ----SHD---- C:\System Volume Information
2011-08-22 11:55:25 ----D---- C:\Windows\system32\config
2011-08-22 11:45:05 ----D---- C:\Windows\inf
2011-08-22 11:43:51 ----SHD---- C:\Windows\Installer
2011-08-22 11:43:44 ----D---- C:\Windows\system32\DriverStore
2011-08-22 11:43:44 ----D---- C:\Windows\system32\drivers
2011-08-22 11:43:44 ----D---- C:\Windows\system32\catroot
2011-08-22 11:43:41 ----D---- C:\Windows\system32\catroot2
2011-08-22 11:43:20 ----HD---- C:\ProgramData
2011-08-22 11:42:26 ----D---- C:\Windows\SysWOW64
2011-08-22 11:39:57 ----D---- C:\Windows\system32\Tasks
2011-08-22 11:35:12 ----D---- C:\Users\Martin\AppData\Roaming\TS3Client
2011-08-22 11:35:08 ----D---- C:\Windows\Logs
2011-08-22 11:35:08 ----D---- C:\Windows\debug
2011-08-22 09:37:06 ----D---- C:\Windows\system32\drivers\etc
2011-08-22 09:29:42 ----D---- C:\ProgramData\NVIDIA
2011-08-22 09:29:15 ----RD---- C:\Program Files (x86)
2011-08-21 17:17:19 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-08-21 15:00:55 ----A---- C:\Windows\system32\AutoRunFilter.ini
2011-08-20 05:11:37 ----A---- C:\Windows\system32\ServiceFilter.ini
2011-08-13 16:31:19 ----D---- C:\Windows\System32
2011-08-13 16:31:19 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-08-13 15:25:38 ----D---- C:\Users\Martin\AppData\Roaming\Adobe
2011-08-12 15:39:32 ----D---- C:\Windows\Microsoft.NET
2011-08-12 15:39:31 ----RSD---- C:\Windows\assembly
2011-08-12 09:00:07 ----D---- C:\Windows\system32\NDF
2011-08-12 04:59:58 ----D---- C:\Windows\winsxs
2011-08-12 04:57:24 ----D---- C:\Windows\AppPatch
2011-08-12 04:57:23 ----D---- C:\Windows\SYSWOW64\migration
2011-08-12 04:57:23 ----D---- C:\Program Files\Internet Explorer
2011-08-12 04:57:23 ----D---- C:\Program Files (x86)\Internet Explorer
2011-08-12 04:57:19 ----D---- C:\Windows\system32\migration
2011-08-11 22:14:24 ----D---- C:\ProgramData\Microsoft Help
2011-08-11 22:11:03 ----A---- C:\Windows\system32\MRT.exe
2011-08-10 17:40:42 ----D---- C:\Program Files (x86)\Google
2011-08-10 17:40:04 ----D---- C:\Windows\Tasks
2011-08-09 13:07:09 ----SD---- C:\Users\Martin\AppData\Roaming\Microsoft
2011-08-09 12:49:53 ----D---- C:\ProgramData\CyberLink
2011-08-08 22:18:36 ----D---- C:\Users\Martin\AppData\Roaming\SoftGrid Client
2011-08-06 19:05:01 ----D---- C:\ProgramData\ASUS
2011-07-26 14:02:20 ----D---- C:\Windows\rescache

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AsDsm;AsDsm; C:\Windows\system32\drivers\AsDsm.sys [2011-06-15 35384]
R0 nvstor64;nvstor64; C:\Windows\system32\DRIVERS\nvstor64.sys [2010-04-27 244328]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-08-09 270912]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-12-21 141264]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-12-21 170640]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2010-12-21 125296]
R2 ghaio;ghaio; \??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2007-08-03 17464]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2009-10-05 1542656]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2009-10-15 117760]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 34152]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-12-22 2229280]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATK64AMD.sys [2009-05-13 15928]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2009-08-21 84512]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2009-06-28 28704]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-08-18 236544]
R3 Sftfs;Sftfs; C:\Windows\system32\DRIVERS\Sftfslh.sys [2009-12-02 721768]
R3 Sftplay;Sftplay; C:\Windows\system32\DRIVERS\Sftplaylh.sys [2009-12-02 269672]
R3 Sftredir;Sftredir; C:\Windows\system32\DRIVERS\Sftredirlh.sys [2009-12-02 25960]
R3 Sftvol;Sftvol; C:\Windows\system32\DRIVERS\Sftvollh.sys [2009-12-02 22376]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2009-06-05 1806400]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2008-12-08 61792]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys [2009-12-15 29696]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2009-12-15 117248]
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys [2009-12-15 114304]
S3 ipswuio;ipswuio; C:\Windows\System32\DRIVERS\ipswuio.sys []
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-24 154168]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2009-09-17 359552]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-05-25 37664]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2009-06-16 84536]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2009-11-10 96896]
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2011-07-12 387944]
R2 cvhsvc;Client Virtualization Handler; C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-01-12 810144]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-12-11 392296]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2008-12-04 226640]
R2 sftlist;Application Virtualization Client; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
R2 ShowAnalyzerMaster;ShowAnalyzerMaster; C:\Program Files (x86)\Dragon Global\ShowAnalyzerSuite\ShowAnalyzerMaster.exe [2010-02-08 2074112]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Windows\SysWOW64\nvSCPAPISvr.exe [2009-12-11 239208]
R3 ADSMService;ADSM Service; C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2008-03-31 225280]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-07-19 934760]
R3 sftvsa;Application Virtualization Service Agent; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
R3 spmgr;spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [2007-08-03 125496]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 136176]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2011-01-12 42360]
S3 fsssvc;Windows Live Zabezpečení rodiny; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2008-12-08 533344]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 136176]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-09-16 182768]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe []
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-06-17 1255736]

-----------------EOF-----------------

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: facebook vir

#2 Příspěvek od Roli »

Zdravím, tohle fixni v HJT :

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R3 - URLSearchHook: (no name) - - (no file)
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [1707595.exe] "C:\Windows\Temp\1707595.exe"
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?


HJT najdeš zde :

C:\Program Files\trend micro\Martin.exe

Fix znamená že spustíš HJT Obrázek jako admin

v okně které se ti otevře klikneš na Do a system scan only

v dalším okně najdeš řádky které jsem ti vypsal,

vedle nich je čtvereček do kterého uděláš zatržítko,

pak klikneš na Fix checked které je vlevo dole,

program se ti zeptá zda opravdu ANO s tím samozřejmě souhlasíš a je hotovo.


Přes Start >> Všechny programy >> Příslušenství >> Spustit >> napiš - services.msc >> Enter. Najdi službu :

Služba Google Update (gupdate)

Služba Google Update (gupdatem)

Google Software Updater (gusvc)

McAfee Security Scan Component Host Service


klikni na ni pravým myšítkem, zvol vlastnosti, na další kartě nejprve službu zastav tlačítkem Zastavit a u položky Typ spouštění zvol Zakázáno.


Přes Odebrat programy odinstaluj vše od McAfee


Smaž nepotřebné soubory

pomocí CCleaneru

návod :

Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš

Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)

čištění registru je třeba několikrát zopakovat !

Nástroje - tady lze odinstalovat programy, upravit co se spustí po Startu systému a obnovit systém


Pak použij Mbam z mého podpisu a dej mi sem z něj log, předem nic nemazat !!!
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

jaryman
Návštěvník
Návštěvník
Příspěvky: 33
Registrován: 22 srp 2011 12:51

Re: facebook vir

#3 Příspěvek od jaryman »

Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org

Verze databáze: 7535

Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514

22.8.2011 17:08:49
mbam-log-2011-08-22 (17-08-41).txt

Typ kontroly: Rychlý test
Testované objekty: 172227
Uplynulý čas: 3 minut, 44 sekund

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 5
Infikované hodnoty v registru: 1
Infikované datové položky v registru: 3
Infikované složky: 1
Infikované soubory: 14

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\sysdriver32.exe (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\systeminfog (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\SERVICES32.EXE (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\wxpdrivers (Trojan.Agent) -> No action taken.

Infikované hodnoty v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Services32.exe\close (Trojan.Agent) -> Value: close -> No action taken.

Infikované datové položky v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

Infikované složky:
c:\Windows\rpcminer (Trojan.BCMiner) -> No action taken.

Infikované soubory:
c:\Windows\rpcminer\bitcoinmineropencl.cl (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\bitcoinminercuda_10.cubin (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\bitcoinminercuda_11.cubin (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\bitcoinminercuda_20.cubin (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\cudart32_32_16.dll (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\curllib.dll (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\libeay32.dll (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\libsasl.dll (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\openldap.dll (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\rpcminer-4way.exe (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\rpcminer-cpu.exe (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\rpcminer-cuda.exe (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\rpcminer-opencl.exe (Trojan.BCMiner) -> No action taken.
c:\Windows\rpcminer\ssleay32.dll (Trojan.BCMiner) -> No action taken.

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: facebook vir

#4 Příspěvek od Roli »

To co Mbam našel nech smazat.


Nyní použijeme větší kalibr tak že pozorně čti, protože tenhle softík netoleruje chyby.

Stáhni a ulož na plochu ComboFix,

spusť aplikaci jako Administrátor a povol instalaci Konzole pro zotavení - Recovery Console.

Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,

pak ještě jednou klik na ANO a už to jede.

Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.

Při skenovaní může být PC i restartováno nelekat se.

Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,

protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.

Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt

(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.


V případě nejasností je ZDE obrázkový návod.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

jaryman
Návštěvník
Návštěvník
Příspěvky: 33
Registrován: 22 srp 2011 12:51

Re: facebook vir

#5 Příspěvek od jaryman »

ComboFix 11-08-23.01 - Martin 23.08.2011 11:59:29.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3071.1709 [GMT 2:00]
Spuštěný z: c:\users\Martin\Downloads\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\FullRemove.exe
c:\programdata\ntuser.dat
c:\windows\btc_client_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\geoiplist
c:\windows\geoiplist.rar
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\loader2.exe_ok
c:\windows\phoenix
c:\windows\phoenix.rar
c:\windows\phoenix\kernels\phatk\__init__.py
c:\windows\phoenix\kernels\phatk\__init__.pyc
c:\windows\phoenix\kernels\phatk\BFIPatcher.py
c:\windows\phoenix\kernels\phatk\kernel.cl
c:\windows\phoenix\kernels\poclbm\__init__.py
c:\windows\phoenix\kernels\poclbm\__init__.pyc
c:\windows\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows\phoenix\kernels\poclbm\kernel.cl
c:\windows\phoenix\phoenix.exe
c:\windows\rpcminer.rar
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\ufa.rar
c:\windows\update.1
c:\windows\update.2
c:\windows\update.5.0
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-23 do 2011-08-23 )))))))))))))))))))))))))))))))
.
.
2011-08-23 10:05 . 2011-08-23 10:05 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-23 09:57 . 2011-08-12 04:10 8862544 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7FC62B65-97E7-4FB2-9C05-78319483F57A}\mpengine.dll
2011-08-22 14:15 . 2011-08-22 14:15 -------- d-----w- c:\users\Martin\AppData\Roaming\Malwarebytes
2011-08-22 14:15 . 2010-11-29 15:42 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-08-22 14:15 . 2011-08-22 14:15 -------- d-----w- c:\programdata\Malwarebytes
2011-08-22 14:15 . 2011-08-22 15:08 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-08-22 14:15 . 2010-11-29 15:42 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-22 11:47 . 2011-08-22 13:20 -------- d-----w- c:\program files\trend micro
2011-08-22 11:47 . 2011-08-22 11:48 -------- d-----w- C:\rsit
2011-08-22 09:44 . 2011-08-22 09:44 -------- d-----w- c:\users\Martin\AppData\Local\ESET
2011-08-22 09:43 . 2011-08-22 09:43 -------- d-----w- c:\program files\ESET
2011-08-21 15:47 . 2011-08-22 09:42 -------- d-----w- c:\programdata\AVAST Software
2011-08-21 15:47 . 2011-08-21 15:47 -------- d-----w- c:\program files\AVAST Software
2011-08-20 06:38 . 2011-08-20 06:42 -------- d-----w- c:\users\Martin\AppData\Roaming\BSplayer
2011-08-20 06:38 . 2011-08-20 06:38 -------- d-----w- c:\users\Martin\AppData\Roaming\BSplayer Pro
2011-08-20 06:38 . 2011-08-20 06:38 -------- d-----w- c:\program files (x86)\Webteh
2011-08-19 11:16 . 2011-08-21 15:19 -------- d--h--w- c:\windows\update.7.1
2011-08-19 08:40 . 2011-08-21 13:06 -------- d-----w- c:\windows\ufa
2011-08-19 08:38 . 2011-08-21 13:06 246272 ----a-w- c:\windows\unrar.exe
2011-08-19 08:33 . 2011-08-19 08:33 -------- d-----w- c:\windows\av_ico
2011-08-19 08:23 . 2011-08-22 10:25 -------- d--h--w- c:\windows\update.tray-9-0-lnk
2011-08-19 08:23 . 2011-08-21 15:19 -------- d--h--w- c:\windows\update.tray-9-0
2011-08-19 08:23 . 2011-08-21 15:19 -------- d--h--w- c:\windows\update.tray-7-0
2011-08-19 08:23 . 2011-08-21 15:19 -------- d--h--w- c:\windows\update.tray-7-0-lnk
2011-08-14 20:13 . 2011-08-14 20:13 -------- d-----w- c:\program files (x86)\Veetle
2011-08-14 20:05 . 2011-08-14 20:05 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-08-13 13:25 . 2011-08-13 13:26 -------- d-----w- c:\users\Martin\AppData\Local\Adobe
2011-08-12 03:41 . 2007-05-16 14:45 506728 ----a-w- c:\windows\system32\d3dx10_34.dll
2011-08-11 13:50 . 2011-08-11 13:50 -------- d-----w- c:\program files\CCleaner
2011-08-10 16:30 . 2011-08-10 16:30 -------- d-----w- c:\users\Martin\AppData\Local\2K Games
2011-08-10 15:39 . 2011-08-11 14:04 -------- d-----w- c:\users\Martin\AppData\Roaming\Skype
2011-08-10 15:39 . 2011-08-10 15:39 -------- d-----r- c:\program files (x86)\Skype
2011-08-10 15:39 . 2011-08-10 15:39 -------- d-----w- c:\programdata\Skype
2011-08-10 14:48 . 2011-08-10 14:48 -------- d-----w- c:\programdata\Blizzard
2011-08-09 11:02 . 2011-08-09 16:13 -------- d-----w- c:\program files\Zrychleni Pocitace
2011-08-09 11:02 . 2011-08-09 15:13 -------- d-----w- c:\users\Martin\AppData\Local\OpenCandy
2011-08-09 11:02 . 2011-08-09 11:02 -------- d-----w- c:\users\Martin\AppData\Roaming\OpenCandy
2011-08-09 11:01 . 2011-08-09 11:01 270912 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-08-09 11:01 . 2011-08-09 11:01 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2011-08-09 11:00 . 2011-08-22 09:35 -------- d-----w- c:\users\Martin\AppData\Roaming\DAEMON Tools Lite
2011-08-09 11:00 . 2011-08-12 03:38 -------- d-----w- c:\programdata\DAEMON Tools Lite
2011-08-09 10:50 . 2011-08-09 10:50 -------- d-----w- c:\users\Public\CyberLink
2011-08-09 10:50 . 2011-08-09 10:50 -------- d-----w- c:\users\Martin\AppData\Roaming\CyberLink
2011-08-08 16:45 . 2011-08-09 03:32 -------- d-----w- c:\programdata\VirtualizedApplications
2011-08-06 17:04 . 2011-08-06 17:04 -------- d-----w- c:\users\Martin\AppData\Local\ASUS
2011-08-05 17:27 . 2011-08-05 17:27 -------- d-----w- c:\users\Martin\AppData\Roaming\Leawo
2011-08-05 17:27 . 2008-10-28 08:10 139264 ----a-w- c:\windows\SysWow64\xvid.ax
2011-08-05 17:27 . 2008-10-08 07:45 606208 ----a-w- c:\windows\SysWow64\xvidcore.dll
2011-08-05 17:24 . 2011-08-05 17:24 -------- d-----w- c:\programdata\Dragon Global
2011-08-05 17:24 . 2011-08-05 17:24 -------- d-----w- c:\program files (x86)\Dragon Global
2011-08-05 17:23 . 2011-08-05 17:39 -------- d-----w- c:\users\Public\DvrmsToolbox
2011-08-05 17:22 . 2011-08-05 17:41 -------- d-----w- c:\program files (x86)\DVRMSToolbox
2011-07-30 10:27 . 2011-07-30 10:27 -------- d-----w- c:\program files\iPod
2011-07-30 10:27 . 2011-07-30 10:28 -------- d-----w- c:\program files\iTunes
2011-07-30 10:27 . 2011-07-30 10:28 -------- d-----w- c:\program files (x86)\iTunes
2011-07-30 10:25 . 2011-07-30 10:25 -------- d-----w- c:\program files\Bonjour
2011-07-30 10:25 . 2011-07-30 10:25 -------- d-----w- c:\program files (x86)\Bonjour
2011-07-29 18:32 . 2011-07-29 19:07 -------- d-----w- c:\users\Martin\AppData\Local\Microsoft Games
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-16 04:26 . 2011-08-11 11:59 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-07-12 09:34 . 2011-07-12 09:34 96104 ----a-w- c:\windows\system32\dns-sd.exe
2011-07-12 09:34 . 2011-07-12 09:34 85864 ----a-w- c:\windows\system32\dnssd.dll
2011-07-12 09:34 . 2011-07-12 09:34 61288 ----a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 09:34 . 2011-07-12 09:34 212840 ----a-w- c:\windows\system32\dnssdX.dll
2011-07-12 09:20 . 2011-07-12 09:20 83816 ----a-w- c:\windows\SysWow64\dns-sd.exe
2011-07-12 09:20 . 2011-07-12 09:20 73064 ----a-w- c:\windows\SysWow64\dnssd.dll
2011-07-12 09:20 . 2011-07-12 09:20 50536 ----a-w- c:\windows\SysWow64\jdns_sd.dll
2011-07-12 09:20 . 2011-07-12 09:20 178536 ----a-w- c:\windows\SysWow64\dnssdX.dll
2011-07-04 11:43 . 2011-06-15 14:58 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-06-22 16:33 . 2011-06-22 16:33 34064 ----a-w- c:\windows\SysWow64\lhacm.acm
2011-06-20 06:54 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-06-20 06:54 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-06-15 15:31 . 2011-06-15 15:31 35384 ----a-w- c:\windows\system32\drivers\AsDsm.sys
2011-06-11 03:07 . 2011-07-13 11:55 3137536 ----a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 15:08 143360 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2009-10-27 6998656]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2009-08-20 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-07-19 421736]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
FancyStart daemon.lnk - c:\windows\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe [2010-9-16 12862]
SRS Premium Sound.lnk - c:\windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe [2010-9-16 156952]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\DRIVERS\ewdcsc.sys [x]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [x]
R3 ipswuio;ipswuio;c:\windows\system32\DRIVERS\ipswuio.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 136176]
R4 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 136176]
R4 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-01-12 810144]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
S2 ShowAnalyzerMaster;ShowAnalyzerMaster;c:\program files (x86)\Dragon Global\ShowAnalyzerSuite\ShowAnalyzerMaster.exe [2010-02-08 2074112]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\windows\SysWOW64\nvSCPAPISvr.exe [2009-12-11 239208]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-08-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 15:39]
.
2011-08-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 15:39]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 14:52 159744 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS WebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe" [2010-03-16 1754448]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-12-11 16414824]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-09-30 621440]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-09-01 323584]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-01-12 2918656]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>;*.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\742z7rsh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - BS Player Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1750559&SearchSource=13
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKLM-Run-tray_ico - (no file)
Wow6432Node-HKLM-Run-tray_ico2 - (no file)
Wow6432Node-HKLM-Run-tray_ico3 - (no file)
Wow6432Node-HKLM-Run-tray_ico4 - (no file)
Toolbar-Locked - (no file)
AddRemove-ASUS_Screensaver - c:\windows\system32\ASUS_Screensaver.scr
AddRemove-Counter-Strike 1.6 v42b instalace - c:\program files (x86)\Counter-Strike 1.6\Uninstal.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
c:\program files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
c:\program files\ASUS\Net4Switch\Net4Switch.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
c:\program files\ASUS\NB Probe\SPM\spmgr.exe
c:\windows\AsScrPro.exe
c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe
.
**************************************************************************
.
Celkový čas: 2011-08-23 12:11:37 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-23 10:11
.
Před spuštěním: Volných bajtů: 17 837 584 384
Po spuštění: Volných bajtů: 17 426 857 984
.
- - End Of File - - 7F3FE910DE45000CE5C87171D9E9B7EB

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: facebook vir

#6 Příspěvek od Roli »

Pokud jsi tak ještě neučinil, přesuň Combofix na Plochu

otevři si Poznámkový blok

do něj zkopíruj skript z následujícího okna:

Kód: Vybrat vše

File:: 
c:\windows\unrar.exe 

Folder::
c:\windows\update.7.1
c:\windows\ufa
c:\windows\av_ico
c:\windows\update.tray-9-0-lnk
c:\windows\update.tray-9-0
c:\windows\update.tray-7-0
c:\windows\update.tray-7-0-lnk

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000000
"DisableThumbnailCache"=dword:00000000

FireFox::
FF - ProfilePath - c:\users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\742z7rsh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - BS Player Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT17505 ... hSource=13

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
ulož Tebou vytvořený TXT soubor jako CFScript.txt na plochu,

po uložení uchop vytvořený skript levým myšítkem a přesuň ho nad ikonu Combofixu, kde ho upustíš:

Obrázek

Po aplikaci na Tebe vypadne další log, zkopíruj ho sem

Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou,

v tom případě znovu restartuj a přitom mačkej F8 poté zvol Poslední známou funkční konfiguraci
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

jaryman
Návštěvník
Návštěvník
Příspěvky: 33
Registrován: 22 srp 2011 12:51

Re: facebook vir

#7 Příspěvek od jaryman »

ComboFix 11-08-23.01 - Martin 23.08.2011 13:34:46.2.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3071.1121 [GMT 2:00]
Spuštěný z: c:\users\Martin\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Martin\Desktop\CFScript.txt.txt
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\unrar.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\av_ico
c:\windows\av_ico\ico_avast_desktop.ico
c:\windows\av_ico\ico_avast_start.ico
c:\windows\av_ico\ico_mcafee_start.ico
c:\windows\ufa
c:\windows\ufa\ufa.exe
c:\windows\unrar.exe
c:\windows\update.7.1
c:\windows\update.tray-7-0-lnk
c:\windows\update.tray-7-0
c:\windows\update.tray-9-0-lnk
c:\windows\update.tray-9-0
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-23 do 2011-08-23 )))))))))))))))))))))))))))))))
.
.
2011-08-23 11:40 . 2011-08-23 11:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-23 09:57 . 2011-08-12 04:10 8862544 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7FC62B65-97E7-4FB2-9C05-78319483F57A}\mpengine.dll
2011-08-22 14:15 . 2011-08-22 14:15 -------- d-----w- c:\users\Martin\AppData\Roaming\Malwarebytes
2011-08-22 14:15 . 2010-11-29 15:42 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-08-22 14:15 . 2011-08-22 14:15 -------- d-----w- c:\programdata\Malwarebytes
2011-08-22 14:15 . 2011-08-22 15:08 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-08-22 14:15 . 2010-11-29 15:42 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-22 11:47 . 2011-08-22 13:20 -------- d-----w- c:\program files\trend micro
2011-08-22 11:47 . 2011-08-22 11:48 -------- d-----w- C:\rsit
2011-08-22 09:44 . 2011-08-22 09:44 -------- d-----w- c:\users\Martin\AppData\Local\ESET
2011-08-22 09:43 . 2011-08-22 09:43 -------- d-----w- c:\program files\ESET
2011-08-21 15:47 . 2011-08-22 09:42 -------- d-----w- c:\programdata\AVAST Software
2011-08-21 15:47 . 2011-08-21 15:47 -------- d-----w- c:\program files\AVAST Software
2011-08-20 06:38 . 2011-08-20 06:42 -------- d-----w- c:\users\Martin\AppData\Roaming\BSplayer
2011-08-20 06:38 . 2011-08-20 06:38 -------- d-----w- c:\users\Martin\AppData\Roaming\BSplayer Pro
2011-08-20 06:38 . 2011-08-20 06:38 -------- d-----w- c:\program files (x86)\Webteh
2011-08-14 20:13 . 2011-08-14 20:13 -------- d-----w- c:\program files (x86)\Veetle
2011-08-14 20:05 . 2011-08-14 20:05 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-08-13 13:25 . 2011-08-13 13:26 -------- d-----w- c:\users\Martin\AppData\Local\Adobe
2011-08-12 03:41 . 2007-05-16 14:45 506728 ----a-w- c:\windows\system32\d3dx10_34.dll
2011-08-11 13:50 . 2011-08-11 13:50 -------- d-----w- c:\program files\CCleaner
2011-08-10 16:30 . 2011-08-10 16:30 -------- d-----w- c:\users\Martin\AppData\Local\2K Games
2011-08-10 15:39 . 2011-08-11 14:04 -------- d-----w- c:\users\Martin\AppData\Roaming\Skype
2011-08-10 15:39 . 2011-08-10 15:39 -------- d-----r- c:\program files (x86)\Skype
2011-08-10 15:39 . 2011-08-10 15:39 -------- d-----w- c:\programdata\Skype
2011-08-10 14:48 . 2011-08-10 14:48 -------- d-----w- c:\programdata\Blizzard
2011-08-09 11:02 . 2011-08-09 16:13 -------- d-----w- c:\program files\Zrychleni Pocitace
2011-08-09 11:02 . 2011-08-09 15:13 -------- d-----w- c:\users\Martin\AppData\Local\OpenCandy
2011-08-09 11:02 . 2011-08-09 11:02 -------- d-----w- c:\users\Martin\AppData\Roaming\OpenCandy
2011-08-09 11:01 . 2011-08-09 11:01 270912 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-08-09 11:01 . 2011-08-09 11:01 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2011-08-09 11:00 . 2011-08-22 09:35 -------- d-----w- c:\users\Martin\AppData\Roaming\DAEMON Tools Lite
2011-08-09 11:00 . 2011-08-12 03:38 -------- d-----w- c:\programdata\DAEMON Tools Lite
2011-08-09 10:50 . 2011-08-09 10:50 -------- d-----w- c:\users\Public\CyberLink
2011-08-09 10:50 . 2011-08-09 10:50 -------- d-----w- c:\users\Martin\AppData\Roaming\CyberLink
2011-08-08 16:45 . 2011-08-09 03:32 -------- d-----w- c:\programdata\VirtualizedApplications
2011-08-06 17:04 . 2011-08-06 17:04 -------- d-----w- c:\users\Martin\AppData\Local\ASUS
2011-08-05 17:27 . 2011-08-05 17:27 -------- d-----w- c:\users\Martin\AppData\Roaming\Leawo
2011-08-05 17:27 . 2008-10-28 08:10 139264 ----a-w- c:\windows\SysWow64\xvid.ax
2011-08-05 17:27 . 2008-10-08 07:45 606208 ----a-w- c:\windows\SysWow64\xvidcore.dll
2011-08-05 17:24 . 2011-08-05 17:24 -------- d-----w- c:\programdata\Dragon Global
2011-08-05 17:24 . 2011-08-05 17:24 -------- d-----w- c:\program files (x86)\Dragon Global
2011-08-05 17:23 . 2011-08-05 17:39 -------- d-----w- c:\users\Public\DvrmsToolbox
2011-08-05 17:22 . 2011-08-05 17:41 -------- d-----w- c:\program files (x86)\DVRMSToolbox
2011-07-30 10:27 . 2011-07-30 10:27 -------- d-----w- c:\program files\iPod
2011-07-30 10:27 . 2011-07-30 10:28 -------- d-----w- c:\program files\iTunes
2011-07-30 10:27 . 2011-07-30 10:28 -------- d-----w- c:\program files (x86)\iTunes
2011-07-30 10:25 . 2011-07-30 10:25 -------- d-----w- c:\program files\Bonjour
2011-07-30 10:25 . 2011-07-30 10:25 -------- d-----w- c:\program files (x86)\Bonjour
2011-07-29 18:32 . 2011-07-29 19:07 -------- d-----w- c:\users\Martin\AppData\Local\Microsoft Games
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-16 04:26 . 2011-08-11 11:59 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-07-12 09:34 . 2011-07-12 09:34 96104 ----a-w- c:\windows\system32\dns-sd.exe
2011-07-12 09:34 . 2011-07-12 09:34 85864 ----a-w- c:\windows\system32\dnssd.dll
2011-07-12 09:34 . 2011-07-12 09:34 61288 ----a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 09:34 . 2011-07-12 09:34 212840 ----a-w- c:\windows\system32\dnssdX.dll
2011-07-12 09:20 . 2011-07-12 09:20 83816 ----a-w- c:\windows\SysWow64\dns-sd.exe
2011-07-12 09:20 . 2011-07-12 09:20 73064 ----a-w- c:\windows\SysWow64\dnssd.dll
2011-07-12 09:20 . 2011-07-12 09:20 50536 ----a-w- c:\windows\SysWow64\jdns_sd.dll
2011-07-12 09:20 . 2011-07-12 09:20 178536 ----a-w- c:\windows\SysWow64\dnssdX.dll
2011-07-04 11:43 . 2011-06-15 14:58 253888 ----a-w- c:\windows\system32\aswBoot.exe
2011-06-22 16:33 . 2011-06-22 16:33 34064 ----a-w- c:\windows\SysWow64\lhacm.acm
2011-06-20 06:54 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-06-20 06:54 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-06-15 15:31 . 2011-06-15 15:31 35384 ----a-w- c:\windows\system32\drivers\AsDsm.sys
2011-06-11 03:07 . 2011-07-13 11:55 3137536 ----a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2011-08-23_10.07.21 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-08-23 11:41 . 2011-08-23 11:41 13330 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
- 2011-08-23 10:05 . 2011-08-23 10:05 13330 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
- 2009-07-14 04:54 . 2011-08-23 10:06 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-08-23 11:42 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-08-23 10:06 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-08-23 11:42 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-09-16 19:48 . 2011-08-23 10:08 41650 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-08-23 10:08 41500 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2011-06-15 13:59 . 2011-08-23 10:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-06-15 13:59 . 2011-08-23 11:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-06-15 13:59 . 2011-08-23 11:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-06-15 13:59 . 2011-08-23 10:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-06-15 13:54 . 2011-08-23 10:08 9994 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1504789416-810619661-2310688379-1000_UserData.bin
+ 2011-08-23 11:41 . 2011-08-23 11:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-08-23 10:06 . 2011-08-23 10:06 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-08-23 11:41 . 2011-08-23 11:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-08-23 10:06 . 2011-08-23 10:06 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 05:01 . 2011-08-23 10:05 389832 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-08-23 11:41 389832 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-08-19 08:34 . 2011-08-23 11:41 390600 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1504789416-810619661-2310688379-1000-12288.dat
- 2011-08-19 08:34 . 2011-08-23 10:05 390600 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1504789416-810619661-2310688379-1000-12288.dat
- 2009-07-14 04:54 . 2011-08-23 10:06 2146304 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-08-23 11:42 2146304 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 15:08 143360 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2009-10-27 6998656]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2009-08-20 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-07-19 421736]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
FancyStart daemon.lnk - c:\windows\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe [2010-9-16 12862]
SRS Premium Sound.lnk - c:\windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe [2010-9-16 156952]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\DRIVERS\ewdcsc.sys [x]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [x]
R3 ipswuio;ipswuio;c:\windows\system32\DRIVERS\ipswuio.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 136176]
R4 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 136176]
R4 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-01-12 810144]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
S2 ShowAnalyzerMaster;ShowAnalyzerMaster;c:\program files (x86)\Dragon Global\ShowAnalyzerSuite\ShowAnalyzerMaster.exe [2010-02-08 2074112]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\windows\SysWOW64\nvSCPAPISvr.exe [2009-12-11 239208]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2011-08-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 15:39]
.
2011-08-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-10 15:39]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 14:52 159744 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS WebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe" [2010-03-16 1754448]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-12-11 16414824]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-09-30 621440]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-09-01 323584]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-01-12 2918656]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>;*.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\742z7rsh.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
c:\program files\ASUS\Net4Switch\Net4Switch.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
c:\windows\AsScrPro.exe
c:\program files\ASUS\NB Probe\SPM\spmgr.exe
c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe
.
**************************************************************************
.
Celkový čas: 2011-08-23 13:47:00 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-23 11:46
ComboFix2.txt 2011-08-23 10:11
.
Před spuštěním: Volných bajtů: 17 179 639 808
Po spuštění: Volných bajtů: 17 108 942 848
.
- - End Of File - - 3B23DB4DF25F6B9BBF862811DDE7B1F4

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: facebook vir

#8 Příspěvek od Roli »

Přes Start >> Spustit zkopíruj do okna:

ComboFix /Uninstall

a stiskni Enter

To odinstaluje ComboFix a smaže s ním související soubory a složky.


Použij T-Cleaner, který smaže případné zbytky po aplikacích které jsme použili.

Jen před jeho stažením a při použití stopni antivir, protože ho muže detekovat jako vir ale není tomu tak.


Pak znovu použij Mbam, ale tentokrát dej kompletní kontrolu a opět mi sem dej log dříve než něco smažeš.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

jaryman
Návštěvník
Návštěvník
Příspěvky: 33
Registrován: 22 srp 2011 12:51

Re: facebook vir

#9 Příspěvek od jaryman »

Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org

Verze databáze: 7535

Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514

23.8.2011 18:38:06
mbam-log-2011-08-23 (18-38-06).txt

Typ kontroly: Úplný test (C:\|D:\|Q:\|)
Testované objekty: 296024
Uplynulý čas: 48 minut, 57 sekund

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 0

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: facebook vir

#10 Příspěvek od Roli »

Řekl bych že šmejdi jsou pryč, tak že pokud se PC chová korektně je to z mé strany vše.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

jaryman
Návštěvník
Návštěvník
Příspěvky: 33
Registrován: 22 srp 2011 12:51

Re: facebook vir

#11 Příspěvek od jaryman »

super, ty jo díky moc :) tohle je nejužitečnější stránka na kterou sem kdy narazil ! du vám udělat reklamu na facebooku :D

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: facebook vir

#12 Příspěvek od Roli »

jaryman píše:du vám udělat reklamu na facebooku :D
A proč ne, jen abychom pak tady stíhali :D
jaryman píše:tohle je nejužitečnější stránka na kterou sem kdy narazil !
No vidíš :)
jaryman píše:super, ty jo díky moc :)
Není zač a příště neklikej kam nemáš :wink:
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Odpovědět