Prosím o pomoc a zjištění malweru na niže uvdeném logu.
Děkuji
Windows XP SP 3 (build 2600)
Boot Mode: Normal
Ověření souborů Microsoftu: Ano
Whitelist: Ano
Internet Explorer v8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Log vygenerován: 5.9.2011 22:22:37
================================================================
SmallARK
================================================================
[?]NtCreateFile -> AntiLog32.sys
[?]NtCreateSymbolicLinkObject -> AntiLog32.sys
[?]NtCreateThread -> AntiLog32.sys
[?]NtDeleteKey -> AntiLog32.sys
[?]NtDeleteValueKey -> AntiLog32.sys
[?]NtDeviceIoControlFile -> AntiLog32.sys
[?]NtLoadDriver -> AntiLog32.sys
[?]NtMapViewOfSection -> AntiLog32.sys
[?]NtOpenFile -> AntiLog32.sys
[?]NtOpenKey -> AntiLog32.sys
[?]NtOpenProcess -> AntiLog32.sys
[?]NtOpenSection -> AntiLog32.sys
[?]NtOpenThread -> AntiLog32.sys
[?]NtProtectVirtualMemory -> AntiLog32.sys
[?]NtQueueApcThread -> AntiLog32.sys
[?]NtSecureConnectPort -> AntiLog32.sys
[?]NtSetContextThread -> AntiLog32.sys
[?]NtSetSystemInformation -> AntiLog32.sys
[?]NtSetValueKey -> AntiLog32.sys
[?]NtTerminateProcess -> AntiLog32.sys
[R]NtTerminateThread -> C:\WINDOWS\system32\drivers\AVGIDSShim.Sys
[?]NtWriteVirtualMemory -> AntiLog32.sys
Běžící procesy
================================================================
C:\PROGRAM FILES\EASEUS\TODO BACKUP 2.0\BIN\AGENT.EXE
C:\WINDOWS\SYSTEM32\NVSVC32.EXE
C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\UPDATESERVICE\ISSCH.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRAM FILES\EPSON\CREATIVITY SUITE\EVENT MANAGER\EEVENTMANAGER.EXE
C:\PROGRAM FILES\BROTHER\BRMFCMON\BRMFCWND.EXE
C:\PROGRAM FILES\EASEUS\TODO BACKUP 2.0\BIN\EUWATCH.EXE
C:\PROGRAM FILES\BROTHER\CONTROLCENTER3\BRCCMCTL.EXE
C:\PROGRAM FILES\BROTHER\BRMFCMON\BRMFCMON.EXE
Scanner
================================================================
[R] IMFsrv.exe
EntryPoint v sekci: .ITEXT
|_ Celkový počet sekcí: 10
[R] ASCService.exe
EntryPoint v sekci: .ITEXT
|_ Celkový počet sekcí: 7
[?] Agent.exe
Nemá okno
Soubor 7%
[R] MDM.EXE
Ověřený Microsoft: Ne
[?] nvsvc32.exe
Non Microsoft v System32:
[R] avgnsx.exe
Podobná jména: AVGNSX.EXE X AVGRSX.EXE
[R] avgrsx.exe
Podobná jména: AVGRSX.EXE X AVGNSX.EXE
[S] explorer.exe
Spouští se po startu HKLM Winlogon [Shell]
[S] rundll32.exe
Spouští se po startu HKLM Run [NvCplDaemon]
[?] issch.exe
Spouští se po startu HKLM Run [ISUSScheduler]
Nemá okno
Soubor 7%
[R] SearchSettings.exe
Spouští se po startu HKLM Run [SearchSettings]
[?] RTHDCPL.EXE
Spouští se po startu HKLM Run [RTHDCPL]
[?] EEventManager.exe
Spouští se po startu HKLM Run [EEventManager]
Soubor 7%
[?] BrMfcWnd.exe
Spouští se po startu HKLM Run [BrMfcWnd]
Soubor 14%
[R] jusched.exe
Spouští se po startu HKLM Run [SunJavaUpdateSched]
[?] EuWatch.exe
Spouští se po startu HKLM Run [EaseUs Watch]
Soubor 14%
[?] BrccMCtl.exe
Soubor 7%
[R] avgtray.exe
Spouští se po startu HKLM Run [AVG_TRAY]
[?] BrMfcMon.exe
Soubor 7%
[R] AntiLogger.exe
Spouští se po startu HKLM Run [AntiLogger]
EntryPoint v sekci:
|_ Celkový počet sekcí: 10
[S] ctfmon.exe
Spouští se po startu HKCU Run [CTFMON.EXE]
[R] ASCTray.exe
Spouští se po startu HKCU Run [Advanced SystemCare 4]
EntryPoint v sekci: .ITEXT
|_ Celkový počet sekcí: 7
[R] IMF.exe
Spouští se po startu HKLM Run [IObit Malware Fighter]
EntryPoint v sekci: .ITEXT
|_ Celkový počet sekcí: 10
Po spuštění
================================================================
HKCU Run
|_ [R][ccleaner] C:\Program Files\CCleaner\CCleaner.exe /AUTO
HKLM Run
|_ [?][NvCplDaemon] C:\WINDOWS\system32\NvCpl.dll ,NvStartup
|_ [?][nwiz] nwiz.exe /install
|_ [?][NvMediaCenter] C:\WINDOWS\system32\NvMcTray.dll ,NvTaskbarInit
|_ [?][PCLEPCI] C:\Program Files\Pinnacle\PPE\PPE.EXE
|_ [X][ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe -startup (Soubor nenalezen)
|_ [?][ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe -start
|_ [?][RTHDCPL] C:\WINDOWS\RTHDCPL.EXE
|_ [?][Alcmtr] C:\WINDOWS\ALCMTR.EXE
|_ [?][EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
|_ [R][SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot
|_ [?][BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
|_ [?][ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
|_ [?][EaseUs Watch] C:\Program Files\EASEUS\Todo Backup 2.0\bin\EuWatch.exe
|_ [R][IObit Malware Fighter] C:\Program Files\IObit\IObit Malware Fighter\IMF.exe /autostart
|_ [R][AntiLogger] C:\Program Files\AntiLogger\AntiLogger.exe /minimized
|_ (Soubor nenalezen)
HKLM IC
|_ [X][>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP (Soubor nenalezen)
|_ [?][{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] C:\WINDOWS\INF\msnetmtg.inf ,NetMtg.Install.PerUser.NT
|_ [?][{5945c046-1e7d-11d1-bc44-00c04fd912be}] C:\WINDOWS\INF\msmsgs.inf ,BLC.QuietInstall.PerUser
|_ [?][{6BF52A52-394A-11d3-B153-00C04F79FAA6}] C:\WINDOWS\INF\wmp.inf ,PerUserStub
|_ [?][{89820200-ECBD-11cf-8B85-00AA005B4340}] regsvr32.exe /s /n /i:U shell32.dll
Po spuštění
|_ C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Služby (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] EASEUS Agent
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\Agent.exe
| |_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
| |_ Popis: EASEUS Todo Backup Agent Application
| |_ MD5: 2EA8CCC4AF7D9223DD397D8CCB636F5D
|
|_ Jméno: EASEUS Agent
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
[X] Java Quick Starter
|_ Cesta: C:\Program Files\Java\jre6\bin\jqs.exe -service -config C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf
| |_ Výrobce:
| |_ Popis:
| |_ MD5:
|
|_ Jméno: JavaQuickStarterService
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
[?] NVIDIA Display Driver Service
|_ Cesta: C:\WINDOWS\system32\nvsvc32.exe
| |_ Výrobce: NVIDIA Corporation
| |_ Popis: NVIDIA Driver Helper Service, Version 181.20
| |_ MD5: 77ECDF9E3D43D4E86E85B73886992625
|
|_ Jméno: NVSvc
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
Ovladače (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] Brother USB Still Image driver
|_ Cesta: C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys
| |_ Výrobce: Brother Industries Ltd.
| |_ Popis: Brother USB Scanner Driver
| |_ MD5: 92A964547B96D697E5E9ED43B4297F5A
|
|_ Jméno: BrScnUsb
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Brother Serial Interface Driver(WDM)
|_ Cesta: C:\WINDOWS\system32\DRIVERS\BrSerIb.sys
| |_ Výrobce: Brother Industries Ltd.
| |_ Popis: Brother MFC Serial Interface Driver(WDM)
| |_ MD5: 9F80879913DC2712FD0C4D734E3F519B
|
|_ Jméno: BrSerIb
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Brother Serial USB Driver(WDM)
|_ Cesta: C:\WINDOWS\system32\DRIVERS\BrUsbSIb.sys
| |_ Výrobce: Brother Industries Ltd.
| |_ Popis: Brother MFC Serial USB Driver(WDM)
| |_ MD5: B67512DA42C0C90BF236D5485226C1C7
|
|_ Jméno: BrUsbSIb
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] CdaC15BA
|_ Cesta: C:\WINDOWS\system32\drivers\CdaC15BA.SYS
| |_ Výrobce: Macrovision Europe Ltd
| |_ Popis: Macrovision SECURITY Driver
| |_ MD5: 08F60F40D1A2A95A1F12EDDBD9F25C1C
|
|_ Jméno: CdaC15BA
|_ StartName:
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] EUBAKUP
|_ Cesta: C:\WINDOWS\system32\drivers\eubakup.sys
| |_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
| |_ Popis: Disk Backup Driver
| |_ MD5: 3E5DDBD7405AD6F59F0646A15C754079
|
|_ Jméno: EUBAKUP
|_ StartName:
|_ Typ spouštění: Boot Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] EASEUS Disk Enumerator
|_ Cesta: C:\WINDOWS\system32\DRIVERS\EuDisk.sys
| |_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
| |_ Popis: EuDisk Bus Enumerator
| |_ MD5: 155666649521732BD4CC1A10823515F0
|
|_ Jméno: EuDisk
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] EUDSKACS
|_ Cesta: C:\WINDOWS\system32\drivers\eudskacs.sys
| |_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
| |_ Popis: Disk Access Driver
| |_ MD5: 1ACC054DFCC3A53CDBC8CFD6B111346F
|
|_ Jméno: EUDSKACS
|_ StartName:
|_ Typ spouštění: System Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] EUFS
|_ Cesta: C:\WINDOWS\system32\drivers\eufs.sys
| |_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
| |_ Popis: File System Filter Driver
| |_ MD5: A0DEA491AC141207B348013725651044
|
|_ Jméno: EUFS
|_ StartName:
|_ Typ spouštění: Boot Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Service for Realtek HD Audio (WDM)
|_ Cesta: C:\WINDOWS\system32\drivers\RtkHDAud.sys
| |_ Výrobce: Realtek Semiconductor Corp.
| |_ Popis: Realtek(r) High Definition Audio Function Driver
| |_ MD5: 3FD00A073361937B705822775255D4E0
|
|_ Jméno: IntcAzAudAddService
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] nv
|_ Cesta: C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
| |_ Výrobce: NVIDIA Corporation
| |_ Popis: NVIDIA Compatible Windows 2000 Miniport Driver, Version 181.20
| |_ MD5: CE34061A298BFB4EBD1A0BB8592DC977
|
|_ Jméno: nv
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] PCLEPCI
|_ Cesta: C:\WINDOWS\system32\Drivers\PCLEPCI.SYS
| |_ Výrobce: Pinnacle Systems GmbH
| |_ Popis: PCLEPCI
| |_ MD5: 14D4FE0A208CDD66E5A97AF26B1F54E5
|
|_ Jméno: PCLEPCI
|_ StartName:
|_ Typ spouštění: System Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
lNetStat
================================================================
Typ: PID Proces Local <-> Remote Status
-----------------------------------------------------------------------------------------
TCP (2004) tcpsvcs.exe 0.0.0.0:7 LISTENING
TCP (2004) tcpsvcs.exe 0.0.0.0:9 LISTENING
TCP (2004) tcpsvcs.exe 0.0.0.0:13 LISTENING
TCP (2004) tcpsvcs.exe 0.0.0.0:17 LISTENING
TCP (2004) tcpsvcs.exe 0.0.0.0:19 LISTENING
TCP (1680) inetinfo.exe 0.0.0.0:21 LISTENING
TCP (1680) inetinfo.exe 0.0.0.0:25 LISTENING
TCP (1680) inetinfo.exe 0.0.0.0:80 LISTENING
TCP (1012) svchost.exe 0.0.0.0:135 LISTENING
TCP (1680) inetinfo.exe 0.0.0.0:443 LISTENING
TCP (4) Systém 0.0.0.0:445 LISTENING
TCP (1680) inetinfo.exe 0.0.0.0:1025 LISTENING
TCP (4) Systém 10.0.0.139:139 LISTENING
TCP (4308) iexplore.exe 10.0.0.139:1342 CLOSE_WAIT
TCP (4308) iexplore.exe 10.0.0.139:1343 CLOSE_WAIT
TCP (4308) iexplore.exe 10.0.0.139:1360 CLOSE_WAIT
TCP (4308) iexplore.exe 10.0.0.139:1370 CLOSE_WAIT
TCP (4308) iexplore.exe 10.0.0.139:1383 CLOSE_WAIT
TCP (5112) chrome.exe 10.0.0.139:1387 CLOSE_WAIT
TCP (5112) chrome.exe 10.0.0.139:1389 CLOSE_WAIT
TCP (5112) chrome.exe 10.0.0.139:1394 CLOSE_WAIT
TCP (5112) chrome.exe 10.0.0.139:1403 CLOSE_WAIT
TCP (5112) chrome.exe 10.0.0.139:1406 CLOSE_WAIT
TCP (5112) chrome.exe 10.0.0.139:1407 CLOSE_WAIT
TCP (5112) chrome.exe 10.0.0.139:1408 CLOSE_WAIT
TCP (5112) chrome.exe 10.0.0.139:1409 CLOSE_WAIT
TCP (5112) chrome.exe 10.0.0.139:1410 CLOSE_WAIT
TCP (5112) chrome.exe 10.0.0.139:1411 CLOSE_WAIT
TCP (5112) chrome.exe 10.0.0.139:1412 CLOSE_WAIT
TCP (5112) chrome.exe 10.0.0.139:1418 CLOSE_WAIT
TCP (5112) chrome.exe 10.0.0.139:1419 CLOSE_WAIT
TCP (5236) iexplore.exe 10.0.0.139:1448 CLOSE_WAIT
TCP (5236) iexplore.exe 10.0.0.139:1449 CLOSE_WAIT
TCP (640) jusched.exe 10.0.0.139:1456 CLOSE_WAIT
TCP (4136) UPM.exe 10.0.0.139:1515 CLOSE_WAIT
TCP (4136) UPM.exe 10.0.0.139:1518 <-> 199.7.48.190:80 ESTABLISHED
TCP (4136) UPM.exe 10.0.0.139:1519 <-> 199.7.51.190:80 ESTABLISHED
TCP (4136) UPM.exe 10.0.0.139:1520 <-> 199.7.48.190:80 ESTABLISHED
TCP (4136) UPM.exe 10.0.0.139:1521 <-> 95.100.248.24:80 ESTABLISHED
TCP (4136) UPM.exe 10.0.0.139:1522 <-> 64.18.21.1:80 ESTABLISHED
TCP (2440) alg.exe 127.0.0.1:1031 LISTENING
TCP (1744) jqs.exe 127.0.0.1:5152 LISTENING
UDP (2004) tcpsvcs.exe 0.0.0.0:7 CLOSE_WAIT
UDP (2004) tcpsvcs.exe 0.0.0.0:9
UDP (2004) tcpsvcs.exe 0.0.0.0:13
UDP (2004) tcpsvcs.exe 0.0.0.0:17
UDP (2004) tcpsvcs.exe 0.0.0.0:19
UDP (152) snmp.exe 0.0.0.0:161
UDP (4) Systém 0.0.0.0:445
UDP (796) lsass.exe 0.0.0.0:500
UDP (1060) svchost.exe 0.0.0.0:1118
UDP (1680) inetinfo.exe 0.0.0.0:3456
UDP (1060) svchost.exe 0.0.0.0:3544
UDP (796) lsass.exe 0.0.0.0:4500
UDP (1060) svchost.exe 10.0.0.139:123
UDP (4) Systém 10.0.0.139:137
UDP (4) Systém 10.0.0.139:138
UDP (1060) svchost.exe 10.0.0.139:1116
UDP (1160) svchost.exe 10.0.0.139:1900
UDP (1060) svchost.exe 10.0.0.139:21205
UDP (1060) svchost.exe 127.0.0.1:123
UDP (4308) iexplore.exe 127.0.0.1:1177
UDP (4224) iexplore.exe 127.0.0.1:1189
UDP (5236) iexplore.exe 127.0.0.1:1420
UDP (5012) iexplore.exe 127.0.0.1:1431
UDP (5608) iexplore.exe 127.0.0.1:1457
UDP (2548) iexplore.exe 127.0.0.1:1471
UDP (1160) svchost.exe 127.0.0.1:1900
Moduly (Zobraz i bezpečné DLL: False, Jen bez výrobce: True, Zobraz registrované: False)
================================================================
[?] bzpdf101.dll
|_ Cesta: C:\WINDOWS\system32\bzpdf101.dll
|_ MD5: 1D490E115CAB352083D2C3930431F537
|_ Výrobce: STORMWARE
|_ Procesy
|_ spoolsv.exe (1268)
[!] rtl120.bpl
|_ Cesta: C:\Program Files\IObit\IObit Malware Fighter\rtl120.bpl
|_ MD5: DD82EB68D97944B192C7803EB585B03C
|_ Výrobce: Embarcadero Technologies, Inc.
|_ Procesy
|_ IMFsrv.exe (1352)
|_ ASCService.exe (1440)
|_ ASCTray.exe (3072)
|_ IMF.exe (3696)
[!] vcl120.bpl
|_ Cesta: C:\Program Files\IObit\IObit Malware Fighter\vcl120.bpl
|_ MD5: 773EBD87010A6F644869A59D98792C9C
|_ Výrobce: Embarcadero Technologies, Inc.
|_ Procesy
|_ IMFsrv.exe (1352)
|_ ASCService.exe (1440)
|_ ASCTray.exe (3072)
|_ IMF.exe (3696)
[?] cmdmanager.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\CmdManager.dll
|_ MD5: 8112A43FA710B56B3CC22A14DEDFCC8C
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] xmlwrapper.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\XmlWrapper.dll
|_ MD5: F3ACAD757B8579ABC18E540B4FA61024
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] iconv.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\iconv.dll
|_ MD5: D7CBBEDFAD7AD68E12BF6FFCC01C3080
|_ Výrobce: Free Software Foundation
|_ Procesy
|_ Agent.exe (1584)
[?] zlib1.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\zlib1.dll
|_ MD5: BA845EB55909E3D3899055E81BAB58EB
|_ Výrobce: ?
|_ Procesy
|_ Agent.exe (1584)
[?] options.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\Options.dll
|_ MD5: 6EE06AB5AE7B896DC242692558EB3C33
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] eupipe.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\EuPipe.dll
|_ MD5: 8676F12F6A551BFA8B873711144E17CF
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] matchstr.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\MatchStr.dll
|_ MD5: 0A0CB8C5FAFAC33FD87547854682CAFB
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] flsearchimg.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\FlSearchImg.dll
|_ MD5: 99ABA502B87DA7A1F37A619200FFCAD2
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] flbackupsize.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\FlBackupSize.dll
|_ MD5: 5AC33ED09E4FB9491F29A1ADFAF7C10A
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] logsys.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\LogSys.dll
|_ MD5: D91BBFE8CC4C9A7A630D1FFB6E59D6CB
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] mountimg.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\MountImg.dll
|_ MD5: B90BAE69643EE4D7C16AD8B4D1BCA7F2
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] imgfile.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\ImgFile.dll
|_ MD5: 481CD6F2A595E7C8496A1FC344C7E578
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] imgfilehlp.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\ImgFileHlp.dll
|_ MD5: 5D0F3484722049337FC81D60C33D9E32
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] dsimgfile.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\DsImgFile.dll
|_ MD5: C713BBAA107914F34A20C91FFD8FA959
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] checkimg.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\CheckImg.dll
|_ MD5: E931E939D265F92EED1F0780AF7658F4
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] vhdvmdk.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\VhdVmdk.dll
|_ MD5: 790D260585D687CC18F8C721E740EF47
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] bootdriver.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\BootDriver.dll
|_ MD5: 0B5DC815C3D12CD5ACFAC4BC7280C354
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] enumdisk.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\EnumDisk.dll
|_ MD5: 81ADFBAF69B27305D83118F82510C797
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] fatlib.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\FatLib.dll
|_ MD5: C45A0B8F6A73E883F905D137424F4E4B
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] imagefileinfo.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\ImageFileInfo.dll
|_ MD5: 1FBEE7FA56975ADC4B75DC4721372747
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] flimgfile.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\FlImgFile.dll
|_ MD5: 37164299840049AF129D267B9D5F81FA
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] getdriverinfo.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\GetDriverInfo.dll
|_ MD5: 8636224E7573DAE7B35C22F9CA28A1AE
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] xsnapshot.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\XSnapshot.dll
|_ MD5: 1F257669B686694C8E1941FB8146227B
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] xsssdk.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\xsssdk.dll
|_ MD5: 110548739F295C00ECB820C9450E56FC
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] email.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\EMail.dll
|_ MD5: 50951EB9069E8302ADEA7616571A939D
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] ftptest.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\FTPTest.dll
|_ MD5: 30C0774AD07D8372C01CBF03033A24D2
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] ftp.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\FTP.dll
|_ MD5: E61EAD225BB6E26B5D35695B005487FC
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] correctmbr.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\CorrectMbr.dll
|_ MD5: 8738EEB685991CD4FA92C30109AC1172
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] tbdataswap.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\TbDataSwap.dll
|_ MD5: 531EB2F2C8E202B44BE304B9D41EBE04
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] transmit.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\Transmit.dll
|_ MD5: 8E2A3ADA356A5D110D751A747BDC55F5
|_ Výrobce: CHENGDU YIWO Tech Development Co., Ltd
|_ Procesy
|_ Agent.exe (1584)
[?] codelog.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\CodeLog.dll
|_ MD5: 74705EC98490AEE3A65E21B2A775CF86
|_ Výrobce:
|_ Procesy
|_ Agent.exe (1584)
|_ EuWatch.exe (1292)
[?] libxml2.dll
|_ Cesta: C:\Program Files\EASEUS\Todo Backup 2.0\bin\libxml2.dll
|_ MD5: E75D9887E0A9A6FBB812B629F8EA0916
|_ Výrobce:
|_ Procesy
|_ Agent.exe (1584)
[?] brlogapi.dll
|_ Cesta: C:\Program Files\Brother\BrUtilities\BrLogAPI.dll
|_ MD5: 7A3119D2211E3532E8FC0EE7138C619D
|_ Výrobce: ?
|_ Procesy
|_ svchost.exe (204)
|_ BrMfcWnd.exe (3980)
|_ BrccMCtl.exe (3412)
|_ BrMfcMon.exe (2860)
[?] acsignicon.dll
|_ Cesta: C:\WINDOWS\system32\AcSignIcon.dll
|_ MD5: 8D566D1D239B3AFE06DCA53264A1ED44
|_ Výrobce: Autodesk, Inc.
|_ Procesy
|_ explorer.exe (3272)
|_ IMF.exe (3696)
|_ iexplore.exe (4224)
|_ iexplore.exe (5012)
|_ iexplore.exe (2548)
|_ iexplore.exe (5608)
[?] acsigncore16.dll
|_ Cesta: C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll
|_ MD5: AC9A93C782B6A2D29DAAE75C19FD9816
|_ Výrobce: Autodesk, Inc.
|_ Procesy
|_ explorer.exe (3272)
[?] mfc42.dll
|_ Cesta: C:\Program Files\epson\Creativity Suite\Event Manager\Mfc42.dll
|_ MD5: 4D197238FDFAA5793D1B0961AAEF649A
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ EEventManager.exe (3492)
[?] brmfcwndcze.dll
|_ Cesta: C:\Program Files\Brother\Brmfcmon\BrmfcwndCze.dll
|_ MD5: 02187196DA7537020C8E1848C546A64F
|_ Výrobce: Brother Industries, Ltd.
|_ Procesy
|_ BrMfcWnd.exe (3980)
[?] brfirmupdatecheck.dll
|_ Cesta: C:\Program Files\Brother\Brmfcmon\BrFirmUpdateCheck.dll
|_ MD5: 878CD9FA1E2A60BF1AA758FF8A84F1DA
|_ Výrobce: Brother Industries, Ltd.
|_ Procesy
|_ BrMfcWnd.exe (3980)
[?] brccdctl.dll
|_ Cesta: C:\Program Files\Brother\ControlCenter3\brccDCtl.dll
|_ MD5: 3C74921805057089E96C693154C2BED6
|_ Výrobce: Brother Industries, Ltd.
|_ Procesy
|_ BrccMCtl.exe (3412)
[?] brcccze.dll
|_ Cesta: C:\Program Files\Brother\ControlCenter3\brcccze.dll
|_ MD5: 2BD9418404CAC9203F259C7C88C9A5CB
|_ Výrobce: Brother Industries, Ltd.
|_ Procesy
|_ BrccMCtl.exe (3412)
[?] brccimg.dll
|_ Cesta: C:\Program Files\Brother\ControlCenter3\brccimg.dll
|_ MD5: 9CBC05B2044AF8F85D7CA39F3588DB06
|_ Výrobce: Brother Industries, Ltd.
|_ Procesy
|_ BrccMCtl.exe (3412)
[?] brccfctl.dll
|_ Cesta: C:\Program Files\Brother\ControlCenter3\brccFCtl.dll
|_ MD5: 6018782189696B9F1AE1CDCD00575549
|_ Výrobce: Brother Industries, Ltd.
|_ Procesy
|_ BrccMCtl.exe (3412)
[?] ltdis12n.dll
|_ Cesta: C:\Program Files\Brother\ControlCenter3\LTDIS12n.dll
|_ MD5: 77FB208063DA1322C2E3355466BB3FD4
|_ Výrobce: LEAD Technologies, Inc.
|_ Procesy
|_ BrccMCtl.exe (3412)
[?] ltfil12n.dll
|_ Cesta: C:\Program Files\Brother\ControlCenter3\ltfil12n.DLL
|_ MD5: 3E673974AB50A2B8276DE3FDED15D56A
|_ Výrobce: LEAD Technologies, Inc.
|_ Procesy
|_ BrccMCtl.exe (3412)
[?] ltkrn12n.dll
|_ Cesta: C:\Program Files\Brother\ControlCenter3\ltkrn12n.dll
|_ MD5: F122133B677E43C0A027F5F742822BEC
|_ Výrobce: LEAD Technologies, Inc.
|_ Procesy
|_ BrccMCtl.exe (3412)
[?] brlmw03a.dll
|_ Cesta: C:\Program Files\Brother\Brmfcmon\BRLMW03A.DLL
|_ MD5: F71EC3FEC2EBEB67D067E9DA1469A9E0
|_ Výrobce: Brother Industries, Ltd.
|_ Procesy
|_ BrMfcMon.exe (2860)
[?] brlm03a.dll
|_ Cesta: C:\Program Files\Brother\Brmfcmon\brlm03a.dll
|_ MD5: 3524B19B9DF27873F0AEB2C0EC82EBC9
|_ Výrobce: Brother Industries, Ltd
|_ Procesy
|_ BrMfcMon.exe (2860)
[X] scan.dll
|_ Cesta: C:\Program Files\IObit\IObit Malware Fighter\Scan.dll
|_ MD5: EE9ED29509606336C7395BDE48F81C90
|_ Výrobce:
|_ Procesy
|_ IMF.exe (3696)
[?] unrar.dll
|_ Cesta: C:\Program Files\IObit\IObit Malware Fighter\unrar.dll
|_ MD5: 8269C503475678F513B8837B9450DF00
|_ Výrobce: ?
|_ Procesy
|_ IMF.exe (3696)
[!] integratefilter.dll
|_ Cesta: C:\Program Files\IObit\IObit Malware Fighter\IntegrateFilter.dll
|_ MD5: 2913B8FF130F4E94C9F5DE9841851DC2
|_ Výrobce: IObit.com
|_ Procesy
|_ IMF.exe (3696)
[?] zlibwapi.dll
|_ Cesta: C:\Program Files\IObit\IObit Malware Fighter\zlibwapi.dll
|_ MD5: D49E943F9741074C0C23916720CD143F
|_ Výrobce: ?
|_ Procesy
|_ IMF.exe (3696)
[?] filemonitor.dll
|_ Cesta: C:\Program Files\IObit\IObit Malware Fighter\FileMonitor.dll
|_ MD5: 25B1A0C6273E67787FE7521C0BE702E3
|_ Výrobce: IObit
|_ Procesy
|_ IMF.exe (3696)
[!] urlfilter.dll
|_ Cesta: C:\Program Files\IObit\IObit Malware Fighter\URLFilter.dll
|_ MD5: C834B75A9BD6941D62EB439E2DE66375
|_ Výrobce: IObit.com
|_ Procesy
|_ IMF.exe (3696)
[!] regfilter.dll
|_ Cesta: C:\Program Files\IObit\IObit Malware Fighter\RegFilter.dll
|_ MD5: 596F806EEAD1ED0F41028769454F690C
|_ Výrobce: IObit.com
|_ Procesy
|_ IMF.exe (3696)
[?] acshellextension.dll
|_ Cesta: C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll
|_ MD5: AEB0705C73B3EC97D986D935EFF7093E
|_ Výrobce: Autodesk
|_ Procesy
|_ iexplore.exe (2548)
[?] msvbvm60.dll
|_ Cesta: C:\WINDOWS\system32\msvbvm60.dll
|_ MD5: 5343A19C618BC515CEB1695586C6C137
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ UPM.exe (4136)
Výpis souborů
================================================================
\System32:
[?] aac_parser.ax AAC_PA~1.AX 14 hdn + ncmpny, {CCC9F9B3}
[?] AcSignExt.dll ACSIGN~2.DLL 7 no vrfy, {D5999304}
[?] AcSignIcon.dll ACSIGN~3.DLL 14 no vrfy, {F7A05DD8}
[?] AcSignOpt.exe ACSIGN~1.EXE 14 no vrfy, {F916BAD0}
[?] atl70.dll 12 ncmpny, {BD6CF416}
[X] AVCDX.ax 100 no vrfy, hdn cmpny, cx (UPX1)?, {B94FFCF2}
[!] avisynth.dll 63 no vrfy, cx (UPX1)?, {3D7A5DF6}
[X] AVSredirect.dll AVSRED~1.DLL 100 ncmpny, cx ()?, {04366C92}
[?] BRCrypt.dll 7 no vrfy, {C9CDF58D}
[?] BrDctF2.dll 7 no vrfy, {8DF3F11A}
[?] BrfxD05b.dll 7 no vrfy, {E99CEF12}
[?] BrMfNt.dll 7 no vrfy, {03ECA2ED}
[?] BrMuSNMP.dll 12 ncmpny, {DA030C5D}
[?] BroSNMP.dll 7 no vrfy, {D4A43949}
[?] bzpdf101.dll 14 no vrfy, {2C608895}
[?] bzpdf101c.dll BZPDF1~1.DLL 7 no vrfy, {F2C02397}
[X] CoreAAC.ax 100 no vrfy, hdn cmpny, cx (UPX1)?, {4B1EA38E}
[X] DiracSplitter.ax DIRACS~1.AX 100 no vrfy, hdn cmpny, cx (UPX1)?, {2C6E01A7}
[?] DLLDEV32i.dll DLLDEV~1.DLL 12 ncmpny, {F0CDC65A}
[?] fbnative.exe 7 no vrfy, {481AA10E}
[?] FLACDX.ax 14 hdn + ncmpny, {B61F8D1A}
[X] flvDX.dll 100 no vrfy, hdn cmpny, cx (UPX1)?, {C752ADD1}
[?] fmcodec.DLL 7 no vrfy, {F8DE4E41}
[?] javacpl.cpl 14 no vrfy, {A32F0498}
[?] JETCOMP.exe 12 ncmpny, {77CB41C3}
[X] kenale32.dll 100 ncmpny, cx (CODE)?, {A36848C7}
[?] ma32.dll 12 ncmpny, {3C5809A1}
[?] mase32.dll 12 ncmpny, {306A70A4}
[X] MatroskaDX.ax MATROS~1.AX 100 no vrfy, hdn cmpny, cx (UPX1)?, {4DA465FB}
[?] mfc71u.dll 12 ncmpny, {CDC72817}
[?] MJ14.exe 14 no vrfy, {CA159BC4}
[?] mousewheel.ocx MOUSEW~1.OCX 12 ncmpny, {C996A3DE}
[?] MPCDx.ax 14 hdn + ncmpny, {273277C5}
[?] mqad.dll 12 ncmpny, {716E8435}
[?] mqbkup.exe 12 ncmpny, {D97B5726}
[?] mqdscli.dll 12 ncmpny, {E55E28BD}
[?] mqise.dll 12 ncmpny, {A6F63285}
[?] mqoa.dll 12 ncmpny, {794736BE}
[?] mqqm.dll 12 ncmpny, {E10CC06F}
[?] mqrt.dll 12 ncmpny, {CF2206A7}
[?] mqrtdep.dll 12 ncmpny, {794CB3C3}
[?] mqsec.dll 12 ncmpny, {13E15EBA}
[?] mqsnap.dll 12 ncmpny, {E2ED763A}
[?] mqsvc.exe 12 ncmpny, {363EDBC0}
[?] mqtgsvc.exe 12 ncmpny, {36A337D6}
[?] mqtrig.dll 12 ncmpny, {05FA894C}
[?] mqupgrd.dll 12 ncmpny, {9B2EADE8}
[?] mqutil.dll 25 ncmpny, {7A280018}
[?] msexch35.dll 12 ncmpny, {A3DE78F7}
[?] msexcl35.dll 12 ncmpny, {9A854518}
[?] msfDX.dll 12 no vrfy, hdn cmpny, {12F941CC}
[?] msjet35.dll 12 ncmpny, {567835AC}
[?] msjint35.dll 25 ncmpny, {5C3DA57F}
[?] msjt4jlt.dll 12 ncmpny, {F9C834EA}
[?] msltus35.dll 12 ncmpny, {78DE4B1F}
[?] mspdox35.dll 12 ncmpny, {AE37A713}
[?] msrd2x35.dll 12 ncmpny, {E55E51A5}
[?] msrepl35.dll 12 ncmpny, {B7843B57}
[?] msrpfs35.dll 12 ncmpny, {86DD4FE4}
[?] mstext35.dll 12 ncmpny, {F70A78A1}
[?] msvbvm60.dll 12 ncmpny, {5DAD5DE2}
[?] msxbse35.dll 12 ncmpny, {A4C920B5}
[?] nbDX.dll 12 no vrfy, hdn cmpny, {CC78C0E7}
[?] NSSearch.dll 7 no vrfy, {C498040E}
[?] nvcolor.exe 7 no vrfy, {854E0083}
[?] nview.dll 12 ncmpny, {03AEAC51}
[?] nvshell.dll 25 ncmpny, {B80AFEC8}
[?] nvtuicpl.cpl 25 ncmpny, {4BD11CF7}
[?] nvwdmcpl.dll 25 ncmpny, {9A1B86F3}
[?] pvmjpg30.dll 14 no vrfy, {63F75035}
[X] RealMediaDX.ax REALME~1.AX 100 no vrfy, hdn cmpny, cx (UPX1)?, {43C40812}
[X] RLAPEDec.ax 100 hdn + ncmpny, infected? {223BB113}
[?] RLMPCDec.ax 14 hdn + ncmpny, {3E35A855}
[X] RLOgg.ax 100 no vrfy, hdn cmpny, cx (UPX1)?, {31D28760}
[X] RLSpeexDec.ax RLSPEE~1.AX 100 hdn + ncmpny, cx (UPX1)?, {A47C4438}
[X] RLTheoraDec.ax RLTHEO~1.AX 100 no vrfy, hdn cmpny, cx (UPX1)?, {61774A87}
[X] RLVorbisDec.ax RLVORB~1.AX 100 no vrfy, hdn cmpny, cx (UPX1)?, {BFE808A4}
[?] trayicon_handler.ocx TRAYIC~1.OCX 7 no vrfy, {960AC655}
[?] TTADSDecoder.ax TTADSD~1.AX 14 hdn + ncmpny, {4D059055}
[?] TTADSSplitter.ax TTADSS~1.AX 14 hdn + ncmpny, {1AFDB826}
[?] Vb40032.dll 12 ncmpny, {28FDA37E}
[?] xvid.ax 12 ncmpny, {541DD030}
[?] xvidcore.dll 12 ncmpny, {E41F1C77}
[?] xvidvfw.dll 12 ncmpny, {D104454C}
[!] yv12vfw.dll 63 no vrfy, cx (UPX1)?, {6B0DDA7D}
\Drivers:
[?] CdaC15BA.SYS 21 no vrfy, {B7081B67}
[?] eubakup.sys 14 no vrfy, {120DE6A2}
[?] EuDisk.sys 14 no vrfy, {EB7E256B}
[?] eudskacs.sys 21 no vrfy, {DFA63FD0}
[?] eufs.sys 14 no vrfy, {3F005FA0}
[?] mqac.sys 25 ncmpny, {BC49FFDB}
[?] PCLEPCI.sys 14 no vrfy, {2BF1EEC6}
[?] thdudf.sys 14 no vrfy, {F7238D4E}
================================================================
Ultimate Process Manager v4.1.3 - [ Lodus Software ]

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Postupne zpomalování internetového prohlížeče
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
- chodnik74
- Přítel fóra
- Příspěvky: 4975
- Registrován: 13 zář 2010 21:30
- Bydliště: Napajedla
- Kontaktovat uživatele:
Re: Postupne zpomalování internetového prohlížeče
Dobré ránko 
Odinstalujte vše od IObit(Advanced system care a malware fighter)
Dále bych zvážil přechod z AVG na jiné bezpečnostní řešení,doporučím vám Avast či MSE,protože AVG má slabší detekci a velmi zatěžuje počítač 
Až budete mít všechny kroky,tak pokračujte..
Vložte mi sem log z RSIT,návod vás povede: http://www.viry.cz/forum/viewtopic.php?f=13&t=105895




Až budete mít všechny kroky,tak pokračujte..

Napiš mi: chodnik74@gmail.com nebo 
>RSIT<>MBAM<>VirusTotal
Doporučuji:
| 
Postup si raději vícekrát přečtěte a v případě jakýchkoliv nejasností či pochybností se ptejte.
Pokud máte infikovaný počítač nebo se nechová jako obvykle, tak si zálohujte všechny data a pozorně postupujte dle pokynů rádce! 
Nepoužívejte utilitu Combofix bez dohledu a doporučení rádce!
Jste s naší pomocí spokojeni
Neváhejte a podpořte forum ZDE.
Pravidla fora: č.1 a č.2

>RSIT<>MBAM<>VirusTotal
Doporučuji:








Pravidla fora: č.1 a č.2