Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Máte problém s virem? Vložte sem log z FRST nebo RSIT.
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST
[návod zde] nebo RSIT
[návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte
Pravidlo o zamykání témat . Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
vyosek
VIP
Příspěvky: 56373 Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno
#16
Příspěvek
od vyosek » 30 led 2012 22:00
Odinstalujte Advanced SystemCare 5 a nasledne i vse od IOBit - jsou to cinske smejdy a spise jen skodi nez jsou uzitkem. Hledaji nesmyslne a neexistujici problemy, databazi haveti ukradli jine renomovane spolecnosti
Pokud nemate, tak presunte
Combofix na plochu
Spustte poznamkovy blok (Start-spustit-notepad)
Zkopirujte skript nize
Kód: Vybrat vše
KillAll::
Collect::
c:\windows\svchost.exe
DDS::
uStart Page = hxxp://www.ask.com/?l=dis&o=15187
RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
RegNull::
[HKEY_USERS\S-1-5-21-1985331280-3213936348-3091441614-1000\Software\SecuROM\License information*]
Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"=-
"{0F3DC9E0-C459-4a40-BCF8-747BD9322E10}"=-
[-HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
[-HKEY_CLASSES_ROOT\clsid\{0f3dc9e0-c459-4a40-bcf8-747bd9322e10}]
[-HKEY_CLASSES_ROOT\AddressBarSearch.SearchHook.1]
[-HKEY_CLASSES_ROOT\TypeLib\{4E8E0178-00EF-413d-9324-E7B3E31572E3}]
[-HKEY_CLASSES_ROOT\AddressBarSearch.SearchHook]
[-HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 5"=-
"Headup Games"="c:\users\Darf\AppData\Roaming\Headup Games\upd.exe" [2011-12-26 979563]
"DAEMON Tools Lite"=-
"ZyngaGamesAgent"=-
"SunJavaUpdateSched"=-
Driver::
gupdate
gupdatem
File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1985331280-3213936348-3091441614-1000Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1985331280-3213936348-3091441614-1000UA.job
Folder::
c:\program files (x86)\IObit
c:\program files (x86)\Ask.com
ClearJavaCache::
Replicator::
AtJob::
Reboot::
Ulozte vytvoreny TXT jako CFScript.txt
Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte
Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen od 1. února 2011.
darf
Návštěvník
Příspěvky: 15 Registrován: 30 led 2012 13:24
#17
Příspěvek
od darf » 31 led 2012 17:18
ComboFix 12-01-30.02 - Darf 31.01.2012 16:50:39.2.8 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.8109.6327 [GMT 1:00]
Spuštěný z: c:\users\Darf\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Darf\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1985331280-3213936348-3091441614-1000Core.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1985331280-3213936348-3091441614-1000UA.job"
.
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Ask.com
c:\program files (x86)\Ask.com\assets\oobe\b.png
c:\program files (x86)\Ask.com\assets\oobe\bl.png
c:\program files (x86)\Ask.com\assets\oobe\br.png
c:\program files (x86)\Ask.com\assets\oobe\l.png
c:\program files (x86)\Ask.com\assets\oobe\pointer.png
c:\program files (x86)\Ask.com\assets\oobe\r.png
c:\program files (x86)\Ask.com\assets\oobe\t.png
c:\program files (x86)\Ask.com\assets\oobe\tl.png
c:\program files (x86)\Ask.com\assets\oobe\tr.png
c:\program files (x86)\Ask.com\cobrand.ico
c:\program files (x86)\Ask.com\config.xml
c:\program files (x86)\Ask.com\favicon.ico
c:\program files (x86)\Ask.com\fv_1638.ico
c:\program files (x86)\Ask.com\GenericAskToolbar.dll
c:\program files (x86)\Ask.com\mupcfg.xml
c:\program files (x86)\Ask.com\precache.exe
c:\program files (x86)\Ask.com\SaUpdate.exe
c:\program files (x86)\Ask.com\Updater\config.xml
c:\program files (x86)\Ask.com\Updater\Updater.exe
c:\program files (x86)\Ask.com\UpdateTask.exe
c:\program files (x86)\IObit
c:\program files (x86)\IObit\Advanced SystemCare 5\ActiveBoost.db
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCService_Log.txt
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-15.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-16.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-17.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-18.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-19.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-20.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-21.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-22.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-23.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-24.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-25.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-26.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-27.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-28.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-29.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-30.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-31.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCv5ExtMenu_64.tmp
c:\program files (x86)\IObit\Advanced SystemCare 5\BackupList.txt
c:\program files (x86)\IObit\Advanced SystemCare 5\BootTimeLog\Defrag2011-12-28(02-58-53).log
c:\program files (x86)\IObit\Advanced SystemCare 5\BootTimeLog\Defrag2012-01-27(14-29-20).log
c:\program files (x86)\IObit\Advanced SystemCare 5\Ext.dbd
c:\program files (x86)\IObit\Advanced SystemCare 5\checkinfo.txt
c:\program files (x86)\IObit\Advanced SystemCare 5\LatestNews\imagenews.jpg
c:\program files (x86)\IObit\Advanced SystemCare 5\LatestNews\imagenews.png
c:\program files (x86)\IObit\Advanced SystemCare 5\LatestNews\LatestNews.ini
c:\program files (x86)\IObit\Advanced SystemCare 5\License.dat
c:\program files (x86)\IObit\Advanced SystemCare 5\Register.log
c:\program files (x86)\IObit\Advanced SystemCare 5\SecurityHole_Backup\KB2505438.cab
c:\program files (x86)\IObit\Advanced SystemCare 5\SecurityHole_Backup\KB2585542.cab
c:\program files (x86)\IObit\Advanced SystemCare 5\SecurityHole_Backup\KB2607576.cab
c:\program files (x86)\IObit\Advanced SystemCare 5\SecurityHole_Backup\KB915597.exe
c:\program files (x86)\IObit\Advanced SystemCare 5\SecurityHoleScan.log
c:\program files (x86)\IObit\Advanced SystemCare 5\sh.dat
c:\program files (x86)\IObit\Advanced SystemCare 5\TempResult.txt
c:\program files (x86)\IObit\Advanced SystemCare 5\Update\Update.Ini
c:\program files (x86)\IObit\Advanced SystemCare 5\UpdateHistory.txt
c:\windows\svchost.exe
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1985331280-3213936348-3091441614-1000Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1985331280-3213936348-3091441614-1000UA.job
.
----- Souboroví replikátoři -----
.
c:\programdata\Adobe\ARM\Reader_10.1.0\10183\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10183\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10183\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10183\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10838\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10838\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10838\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10838\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10844\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10844\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10844\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10844\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\12544\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\12544\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\12544\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\12544\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\13937\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\13937\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\13937\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\13937\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\14849\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\14849\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\14849\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\14849\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15556\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15556\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15556\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15556\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15814\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15814\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15814\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15814\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17070\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17070\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17070\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17070\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17624\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17624\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17624\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17624\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\19362\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\19362\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\19362\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\19362\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\21579\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\21579\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\21579\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\21579\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23412\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23412\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23412\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23412\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23696\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23696\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23696\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23696\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\24938\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\24938\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\24938\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\24938\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\25907\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\25907\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\25907\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\25907\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\28695\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\28695\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\28695\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\28695\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\440\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\440\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\440\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\440\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\452\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\452\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\452\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\452\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10183\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10183\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10183\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10183\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10838\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10838\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10838\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10838\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10844\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10844\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10844\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10844\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\12544\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\12544\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\12544\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\12544\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\13937\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\13937\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\13937\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\13937\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\14849\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\14849\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\14849\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\14849\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15556\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15556\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15556\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15556\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15814\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15814\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15814\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15814\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17070\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17070\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17070\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17070\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17624\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17624\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17624\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17624\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\19362\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\19362\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\19362\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\19362\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\21579\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\21579\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\21579\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\21579\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23412\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23412\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23412\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23412\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23696\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23696\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23696\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23696\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\24938\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\24938\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\24938\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\24938\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\25907\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\25907\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\25907\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\25907\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\28695\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\28695\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\28695\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\28695\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\440\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\440\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\440\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\440\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\452\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\452\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\452\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\452\ReaderUpdater.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_PowerManager
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-28 do 2012-01-31 )))))))))))))))))))))))))))))))
.
.
2012-01-31 15:53 . 2012-01-31 15:53 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-01-31 15:53 . 2012-01-31 15:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-31 15:14 . 2012-01-31 15:14 -------- d-----w- c:\program files (x86)\PhotoFilter
2012-01-31 09:11 . 2012-01-06 05:15 8602168 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3BB1A3A9-1D1B-4058-953A-C2BFEDE7B562}\mpengine.dll
2012-01-30 13:05 . 2012-01-30 14:32 -------- d-----w- c:\program files\trend micro
2012-01-30 13:05 . 2012-01-30 13:05 -------- d-----w- C:\rsit
2012-01-30 10:52 . 2012-01-30 10:52 -------- d-----w- c:\programdata\Kaspersky Lab
2012-01-30 04:23 . 2012-01-30 04:23 -------- d-----w- c:\users\Darf\AppData\Roaming\AVG2012
2012-01-30 04:22 . 2012-01-30 10:32 -------- d-----w- c:\windows\SysWow64\drivers\AVG
2012-01-30 04:22 . 2012-01-30 10:32 -------- d-----w- c:\windows\system32\drivers\AVG
2012-01-29 21:24 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\PCSafeDoctor
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- C:\sh4ldr
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- c:\program files\Enigma Software Group
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- c:\windows\5B210B8AB66E4702B44D0D6F388D29EB.TMP
2012-01-29 21:03 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2012-01-29 20:50 . 2012-01-30 10:32 -------- d-----w- c:\programdata\Spyware Terminator
2012-01-29 20:50 . 2012-01-29 20:50 -------- d-----w- c:\users\Darf\AppData\Roaming\Spyware Terminator
2012-01-29 20:49 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\Spyware Terminator
2012-01-29 18:27 . 2012-01-29 18:27 -------- d-----w- C:\$AVG
2012-01-29 18:24 . 2012-01-29 18:24 -------- d-----w- c:\programdata\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 20:36 -------- d-----w- c:\program files (x86)\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 20:36 -------- d-----w- c:\program files (x86)\Common Files\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 18:24 -------- d--h--w- c:\programdata\Common Files
2012-01-29 18:23 . 2012-01-30 04:22 -------- d-----w- c:\programdata\AVG2012
2012-01-29 18:22 . 2012-01-29 18:22 -------- d-----w- c:\program files (x86)\AVG
2012-01-29 18:19 . 2012-01-30 10:32 -------- d-----w- c:\programdata\MFAData
2012-01-29 00:27 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Pontifex II
2012-01-28 02:29 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Enlight
2012-01-28 02:23 . 2012-01-28 02:23 -------- d-----w- c:\users\Darf\AppData\Local\Bridge!
2012-01-28 02:22 . 2012-01-30 14:28 -------- d-----w- c:\program files (x86)\Aerosoft
2012-01-28 02:22 . 2012-01-30 10:32 -------- d-----w- C:\ToxSickLabs
2012-01-28 00:57 . 2012-01-28 00:57 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-01-28 00:57 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2012-01-28 00:10 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Bridge Constructor
2012-01-28 00:10 . 2012-01-30 14:32 -------- d-----w- c:\users\Darf\AppData\Roaming\Headup Games
2012-01-21 00:04 . 2012-01-21 00:04 -------- d-----w- c:\users\Darf\AppData\Local\BCR
2012-01-21 00:04 . 2012-01-21 00:04 -------- d-----w- c:\programdata\BCR
2012-01-19 20:40 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Microsoft Application Compatibility Toolkit
2012-01-19 16:29 . 2012-01-30 14:32 -------- d-----w- c:\users\Darf\AppData\Roaming\TS3Client
2012-01-19 16:29 . 2012-01-30 14:32 -------- d-----w- c:\program files\TeamSpeak 3 Client
2012-01-17 18:54 . 2009-11-11 14:37 3248128 ----a-w- c:\windows\SysWow64\DVAPfg.exe
2012-01-17 18:53 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\ffdshow
2012-01-17 18:53 . 2009-07-05 20:33 85504 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2012-01-17 18:53 . 2009-07-05 20:33 60273 ----a-w- c:\windows\SysWow64\pthreadGC2.dll
2012-01-15 15:20 . 2012-01-15 15:20 -------- d-----w- c:\users\Darf\AppData\Local\kaneandlynch
2012-01-15 15:12 . 2012-01-15 15:12 -------- d--h--r- c:\users\Darf\AppData\Roaming\SecuROM
2012-01-15 15:04 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Eidos
2012-01-15 02:54 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Driver San Francisco
2012-01-15 00:45 . 2012-01-15 00:45 -------- d--h--w- c:\users\Darf\InstallAnywhere
2012-01-15 00:21 . 2012-01-30 14:32 -------- d-----w- c:\windows\USB Vibration
2012-01-15 00:21 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\USB Vibration
2012-01-15 00:21 . 2012-01-15 00:21 270468 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\Setup.dll
2012-01-15 00:21 . 2012-01-15 00:21 159876 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\IGdi.dll
2012-01-15 00:21 . 2002-08-05 09:46 57344 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\ctor.dll
2012-01-15 00:21 . 2002-08-02 02:10 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\DotNetInstaller.exe
2012-01-15 00:21 . 2002-08-02 01:20 634880 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iKernel.dll
2012-01-15 00:21 . 2002-08-02 01:20 237568 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iscript.dll
2012-01-15 00:21 . 2002-08-02 01:20 151552 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iuser.dll
2012-01-11 14:41 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 14:41 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 14:41 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-01-11 14:41 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-01-11 14:41 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 14:41 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-01-11 14:41 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2012-01-11 14:41 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-01-08 13:54 . 2012-01-08 13:54 -------- d-----w- c:\users\Darf\AppData\Local\Logitech
2012-01-08 13:48 . 2012-01-08 13:48 -------- d-----w- c:\programdata\Codemasters
2012-01-08 13:38 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\OpenAL
2012-01-08 13:38 . 2012-01-28 01:00 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2012-01-08 13:38 . 2012-01-28 01:00 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-01-08 13:38 . 2012-01-28 01:00 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2012-01-08 13:38 . 2012-01-28 01:00 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2012-01-08 13:38 . 2008-07-12 07:18 467984 ----a-w- c:\windows\SysWow64\d3dx10_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 1493528 ----a-w- c:\windows\SysWow64\D3DCompiler_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 540688 ----a-w- c:\windows\system32\d3dx10_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 1942552 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 4992520 ----a-w- c:\windows\system32\D3DX9_39.dll
2012-01-08 13:28 . 2012-01-30 14:28 -------- d-----w- c:\program files (x86)\Codemasters
2012-01-07 20:20 . 2012-01-30 14:30 -------- d-----w- c:\users\Darf\AppData\Roaming\Mikrotik
2012-01-07 16:59 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Google
2012-01-07 11:01 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Disney Interactive Studios
2012-01-04 16:55 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\18 WoS Extreme Trucker 2
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-29 11:23 . 2011-11-28 16:01 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-01-29 11:23 . 2011-11-27 09:40 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-01-29 11:22 . 2011-11-27 09:40 282880 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-01-28 11:45 . 2011-11-29 20:04 78848 ----a-w- c:\windows\KMSEmulator.exe
2012-01-13 16:15 . 2012-01-13 16:15 340992 ----a-w- c:\windows\system32\schannel.dll
2012-01-13 16:15 . 2012-01-13 16:15 224768 ----a-w- c:\windows\SysWow64\schannel.dll
2012-01-08 16:33 . 2011-11-26 20:23 25640 ----a-w- c:\windows\gdrv.sys
2012-01-03 18:18 . 2011-11-27 09:40 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-12-28 00:54 . 2011-12-28 00:54 902656 ----a-w- c:\windows\system32\d2d1.dll
2011-12-28 00:54 . 2011-12-28 00:54 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2011-12-28 00:54 . 2011-12-28 00:54 1544192 ----a-w- c:\windows\system32\DWrite.dll
2011-12-28 00:54 . 2011-12-28 00:54 1139200 ----a-w- c:\windows\system32\FntCache.dll
2011-12-28 00:54 . 2011-12-28 00:54 1076736 ----a-w- c:\windows\SysWow64\DWrite.dll
2011-12-07 09:39 . 2011-11-26 20:16 279096 ------w- c:\windows\system32\MpSigStub.exe
2011-11-28 20:16 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-11-28 20:16 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-11-27 13:04 . 2011-11-26 20:23 30528 ----a-w- c:\windows\GVTDrv64.sys
2011-11-26 22:44 . 2011-11-26 22:44 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-11-24 04:52 . 2011-12-14 19:58 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-11-05 05:41 . 2011-12-14 20:08 1188864 ----a-w- c:\windows\system32\wininet.dll
2011-11-05 05:32 . 2011-12-14 20:08 2048 ----a-w- c:\windows\system32\tzres.dll
2011-11-05 04:35 . 2011-12-14 20:08 981504 ----a-w- c:\windows\SysWow64\wininet.dll
2011-11-05 04:26 . 2011-12-14 20:08 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-11-05 03:32 . 2011-12-14 20:08 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-11-05 02:48 . 2011-12-14 20:08 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-30_15.21.59 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-11-26 23:13 . 2012-01-31 15:12 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-11-26 23:13 . 2012-01-30 15:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-11-26 23:13 . 2012-01-31 15:12 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-11-26 23:13 . 2012-01-30 15:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-01-31 12:04 . 2012-01-31 12:04 25600 c:\windows\Installer\46d4690.msi
- 2012-01-30 15:21 . 2012-01-30 15:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-31 15:54 . 2012-01-31 15:54 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-01-30 15:21 . 2012-01-30 15:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-01-31 15:54 . 2012-01-31 15:54 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-01-31 15:54 . 2012-01-31 12:04 180648 c:\windows\temp\GoogleCrashHandler.exe
- 2009-07-14 02:36 . 2012-01-30 14:54 615810 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-01-31 15:09 615810 c:\windows\system32\perfh009.dat
- 2009-07-14 15:18 . 2012-01-30 14:54 631054 c:\windows\system32\perfh005.dat
+ 2009-07-14 15:18 . 2012-01-31 15:09 631054 c:\windows\system32\perfh005.dat
+ 2009-07-14 02:36 . 2012-01-31 15:09 106190 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2012-01-30 14:54 106190 c:\windows\system32\perfc009.dat
- 2009-07-14 15:18 . 2012-01-30 14:54 121708 c:\windows\system32\perfc005.dat
+ 2009-07-14 15:18 . 2012-01-31 15:09 121708 c:\windows\system32\perfc005.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Headup Games"="c:\users\Darf\AppData\Roaming\Headup Games\upd.exe" [2011-12-26 979563]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"STCAgent"="c:\program files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe" [2011-03-04 812416]
"ZyngaGamesAgent"="c:\program files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe" [2010-11-15 877896]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Adobe ARM"="c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe" [2011-06-06 937920]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 291888]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
2;2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [x]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys [2011-11-27 30528]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536]
R3 netr28ux;RT2870 USB Wireless LAN Card Driver pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28ux.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WCUService_STC_FF;Splashtop Connect Firefox Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe [2011-03-24 493384]
R3 WCUService_STC_IE;Splashtop Connect IE Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe [2011-03-22 497480]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 SCBackService;Splashtop Connect Service;c:\program files (x86)\Splashtop\Splashtop Connect\BackService.exe [2010-11-15 477000]
S2 Smart TimeLock;Smart TimeLock Service;c:\program files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [2009-10-13 114688]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-14 381248]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{45d30484-7ded-43d9-957a-d2fd1f046511}]
2010-11-05 01:57 444752 ----a-w- c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{1d09c093-f71e-43c3-b948-19316cbd695e}"= "mscoree.dll" [2010-11-05 444752]
.
[HKEY_CLASSES_ROOT\CLSID\{1d09c093-f71e-43c3-b948-19316cbd695e}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-12 168216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-12 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-12 416024]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-02-11 11776104]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
"Logitech Download Assistant"="c:\windows\system32\rundll32.exe" [2009-07-14 45568]
"Start WingMan Profiler"="c:\program files\logitech\gaming software\lwemon.exe" [2010-06-14 190536]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1 192.168.3.254 172.20.0.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files (x86)\Ask.com\GenericAskToolbar.dll
Wow6432Node-HKLM-Run-ApnUpdater - c:\program files (x86)\ask.com\updater\updater.exe
Wow6432Node-HKLM-Run-facemoods - c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodssrv.exe
Wow6432Node-HKLM-Run-DVAPTray - c:\windows\system32\dvaptray.exe
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\windows\svchost.exe
.
**************************************************************************
.
Celkový čas: 2012-01-31 16:57:26 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-01-31 15:57
ComboFix2.txt 2012-01-30 15:24
ComboFix3.txt 2012-01-30 14:23
.
Před spuštěním: Volných bajtů: 305 794 441 216
Po spuštění: Volných bajtů: 306 807 357 440
.
- - End Of File - - B5FCFD25D74B897EBE79AD0ED9483547
Nahr nˇ probŘhlo ŁspŘçnŘ
vyosek
VIP
Příspěvky: 56373 Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno
#18
Příspěvek
od vyosek » 31 led 2012 19:21
Stahnete
SytemLook (viz muj podpis) a ulozte jej na plochu
Do okna vlozte skript nize
Kliknete na Look
Tlacitko Look se zmeni na Scanning a zsedne
Pockejte pokud se tlacitko Scanning opet nezmeni na Look - tak poznate ze SystemLook dokoncil svou praci
Vyskoci na Vas log s nazvem SystemLook (pripadne bude ulozen na plose), jeho obsah mi sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen od 1. února 2011.
darf
Návštěvník
Příspěvky: 15 Registrován: 30 led 2012 13:24
#19
Příspěvek
od darf » 31 led 2012 19:26
Log přesahuje max počet znaků.
nebo to hodit do několika příspěvků?
vyosek
VIP
Příspěvky: 56373 Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno
#20
Příspěvek
od vyosek » 31 led 2012 19:41
Stahnete
AVZ http://z-oleg.com/avz4.zip a ulozte jej na plochu
Rozbalte stazeny rar, tak aby byla jen jedna slozka avz4 a spustte avz.exe
Kliknete nahore na File a nasledne vyberte Custom scripts
Do okenka nakopirujte skript, ktery mate nize
Kód: Vybrat vše
begin
SetAVZGuardStatus(True);
SearchRootkit(true, true);
ClearQuarantine;
DeleteFile('c:\windows\svchost.exe');
BC_DeleteFile('c:\windows\svchost.exe');
StopService('PowerManager');
DeleteService('PowerManager');
RebootWindows(true);
end.
Nyni kliknete na Run cimz akci spustite
po restartu PC je mozne, ze se nacte pruvodce hardwarem, s klidem stornujte (klik na STORNO)
Poprosim o novy log z ComboFixu - jen jej spustte bez skriptu
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen od 1. února 2011.
darf
Návštěvník
Příspěvky: 15 Registrován: 30 led 2012 13:24
#21
Příspěvek
od darf » 31 led 2012 20:00
ComboFix 12-01-30.02 - Darf 31.01.2012 19:50:43.3.8 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.8109.6966 [GMT 1:00]
Spuštěný z: c:\users\Darf\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\svchost.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_PowerManager
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-28 do 2012-01-31 )))))))))))))))))))))))))))))))
.
.
2012-01-31 18:54 . 2012-01-31 18:54 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-01-31 18:54 . 2012-01-31 18:54 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-31 15:14 . 2012-01-31 15:14 -------- d-----w- c:\program files (x86)\PhotoFilter
2012-01-31 09:11 . 2012-01-06 05:15 8602168 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3BB1A3A9-1D1B-4058-953A-C2BFEDE7B562}\mpengine.dll
2012-01-30 13:05 . 2012-01-30 14:32 -------- d-----w- c:\program files\trend micro
2012-01-30 13:05 . 2012-01-30 13:05 -------- d-----w- C:\rsit
2012-01-30 10:52 . 2012-01-30 10:52 -------- d-----w- c:\programdata\Kaspersky Lab
2012-01-30 04:23 . 2012-01-30 04:23 -------- d-----w- c:\users\Darf\AppData\Roaming\AVG2012
2012-01-30 04:22 . 2012-01-30 10:32 -------- d-----w- c:\windows\SysWow64\drivers\AVG
2012-01-30 04:22 . 2012-01-30 10:32 -------- d-----w- c:\windows\system32\drivers\AVG
2012-01-29 21:24 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\PCSafeDoctor
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- C:\sh4ldr
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- c:\program files\Enigma Software Group
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- c:\windows\5B210B8AB66E4702B44D0D6F388D29EB.TMP
2012-01-29 21:03 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2012-01-29 20:50 . 2012-01-30 10:32 -------- d-----w- c:\programdata\Spyware Terminator
2012-01-29 20:50 . 2012-01-29 20:50 -------- d-----w- c:\users\Darf\AppData\Roaming\Spyware Terminator
2012-01-29 20:49 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\Spyware Terminator
2012-01-29 18:27 . 2012-01-29 18:27 -------- d-----w- C:\$AVG
2012-01-29 18:24 . 2012-01-29 18:24 -------- d-----w- c:\programdata\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 20:36 -------- d-----w- c:\program files (x86)\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 20:36 -------- d-----w- c:\program files (x86)\Common Files\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 18:24 -------- d--h--w- c:\programdata\Common Files
2012-01-29 18:23 . 2012-01-30 04:22 -------- d-----w- c:\programdata\AVG2012
2012-01-29 18:22 . 2012-01-29 18:22 -------- d-----w- c:\program files (x86)\AVG
2012-01-29 18:19 . 2012-01-30 10:32 -------- d-----w- c:\programdata\MFAData
2012-01-29 00:27 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Pontifex II
2012-01-28 02:29 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Enlight
2012-01-28 02:23 . 2012-01-28 02:23 -------- d-----w- c:\users\Darf\AppData\Local\Bridge!
2012-01-28 02:22 . 2012-01-30 14:28 -------- d-----w- c:\program files (x86)\Aerosoft
2012-01-28 02:22 . 2012-01-30 10:32 -------- d-----w- C:\ToxSickLabs
2012-01-28 00:57 . 2012-01-28 00:57 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-01-28 00:57 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2012-01-28 00:10 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Bridge Constructor
2012-01-28 00:10 . 2012-01-30 14:32 -------- d-----w- c:\users\Darf\AppData\Roaming\Headup Games
2012-01-21 00:04 . 2012-01-21 00:04 -------- d-----w- c:\users\Darf\AppData\Local\BCR
2012-01-21 00:04 . 2012-01-21 00:04 -------- d-----w- c:\programdata\BCR
2012-01-19 20:40 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Microsoft Application Compatibility Toolkit
2012-01-19 16:29 . 2012-01-30 14:32 -------- d-----w- c:\users\Darf\AppData\Roaming\TS3Client
2012-01-19 16:29 . 2012-01-30 14:32 -------- d-----w- c:\program files\TeamSpeak 3 Client
2012-01-17 18:54 . 2009-11-11 14:37 3248128 ----a-w- c:\windows\SysWow64\DVAPfg.exe
2012-01-17 18:53 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\ffdshow
2012-01-17 18:53 . 2009-07-05 20:33 85504 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2012-01-17 18:53 . 2009-07-05 20:33 60273 ----a-w- c:\windows\SysWow64\pthreadGC2.dll
2012-01-15 15:20 . 2012-01-15 15:20 -------- d-----w- c:\users\Darf\AppData\Local\kaneandlynch
2012-01-15 15:12 . 2012-01-15 15:12 -------- d--h--r- c:\users\Darf\AppData\Roaming\SecuROM
2012-01-15 15:04 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Eidos
2012-01-15 02:54 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Driver San Francisco
2012-01-15 00:45 . 2012-01-15 00:45 -------- d--h--w- c:\users\Darf\InstallAnywhere
2012-01-15 00:21 . 2012-01-30 14:32 -------- d-----w- c:\windows\USB Vibration
2012-01-15 00:21 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\USB Vibration
2012-01-15 00:21 . 2012-01-15 00:21 270468 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\Setup.dll
2012-01-15 00:21 . 2012-01-15 00:21 159876 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\IGdi.dll
2012-01-15 00:21 . 2002-08-05 09:46 57344 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\ctor.dll
2012-01-15 00:21 . 2002-08-02 02:10 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\DotNetInstaller.exe
2012-01-15 00:21 . 2002-08-02 01:20 634880 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iKernel.dll
2012-01-15 00:21 . 2002-08-02 01:20 237568 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iscript.dll
2012-01-15 00:21 . 2002-08-02 01:20 151552 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iuser.dll
2012-01-11 14:41 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 14:41 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 14:41 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-01-11 14:41 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-01-11 14:41 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 14:41 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-01-11 14:41 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2012-01-11 14:41 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-01-08 13:54 . 2012-01-08 13:54 -------- d-----w- c:\users\Darf\AppData\Local\Logitech
2012-01-08 13:48 . 2012-01-08 13:48 -------- d-----w- c:\programdata\Codemasters
2012-01-08 13:38 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\OpenAL
2012-01-08 13:38 . 2012-01-28 01:00 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2012-01-08 13:38 . 2012-01-28 01:00 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-01-08 13:38 . 2012-01-28 01:00 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2012-01-08 13:38 . 2012-01-28 01:00 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2012-01-08 13:38 . 2008-07-12 07:18 467984 ----a-w- c:\windows\SysWow64\d3dx10_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 1493528 ----a-w- c:\windows\SysWow64\D3DCompiler_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 540688 ----a-w- c:\windows\system32\d3dx10_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 1942552 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 4992520 ----a-w- c:\windows\system32\D3DX9_39.dll
2012-01-08 13:28 . 2012-01-30 14:28 -------- d-----w- c:\program files (x86)\Codemasters
2012-01-07 20:20 . 2012-01-30 14:30 -------- d-----w- c:\users\Darf\AppData\Roaming\Mikrotik
2012-01-07 16:59 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Google
2012-01-07 11:01 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Disney Interactive Studios
2012-01-04 16:55 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\18 WoS Extreme Trucker 2
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-29 11:23 . 2011-11-28 16:01 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-01-29 11:23 . 2011-11-27 09:40 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-01-29 11:22 . 2011-11-27 09:40 282880 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-01-28 11:45 . 2011-11-29 20:04 78848 ----a-w- c:\windows\KMSEmulator.exe
2012-01-13 16:15 . 2012-01-13 16:15 340992 ----a-w- c:\windows\system32\schannel.dll
2012-01-13 16:15 . 2012-01-13 16:15 224768 ----a-w- c:\windows\SysWow64\schannel.dll
2012-01-08 16:33 . 2011-11-26 20:23 25640 ----a-w- c:\windows\gdrv.sys
2012-01-03 18:18 . 2011-11-27 09:40 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-12-28 00:54 . 2011-12-28 00:54 902656 ----a-w- c:\windows\system32\d2d1.dll
2011-12-28 00:54 . 2011-12-28 00:54 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2011-12-28 00:54 . 2011-12-28 00:54 1544192 ----a-w- c:\windows\system32\DWrite.dll
2011-12-28 00:54 . 2011-12-28 00:54 1139200 ----a-w- c:\windows\system32\FntCache.dll
2011-12-28 00:54 . 2011-12-28 00:54 1076736 ----a-w- c:\windows\SysWow64\DWrite.dll
2011-12-07 09:39 . 2011-11-26 20:16 279096 ------w- c:\windows\system32\MpSigStub.exe
2011-11-28 20:16 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-11-28 20:16 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-11-27 13:04 . 2011-11-26 20:23 30528 ----a-w- c:\windows\GVTDrv64.sys
2011-11-26 22:44 . 2011-11-26 22:44 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-11-24 04:52 . 2011-12-14 19:58 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-11-05 05:41 . 2011-12-14 20:08 1188864 ----a-w- c:\windows\system32\wininet.dll
2011-11-05 05:32 . 2011-12-14 20:08 2048 ----a-w- c:\windows\system32\tzres.dll
2011-11-05 04:35 . 2011-12-14 20:08 981504 ----a-w- c:\windows\SysWow64\wininet.dll
2011-11-05 04:26 . 2011-12-14 20:08 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-11-05 03:32 . 2011-12-14 20:08 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-11-05 02:48 . 2011-12-14 20:08 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-30_15.21.59 )))))))))))))))))))))))))))))))))))))))))
.
- 2011-11-26 23:13 . 2012-01-30 15:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-11-26 23:13 . 2012-01-31 18:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-11-26 23:13 . 2012-01-30 15:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-11-26 23:13 . 2012-01-31 18:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-01-31 12:04 . 2012-01-31 12:04 25600 c:\windows\Installer\46d4690.msi
- 2012-01-30 15:21 . 2012-01-30 15:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-31 18:55 . 2012-01-31 18:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-31 18:55 . 2012-01-31 18:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-01-30 15:21 . 2012-01-30 15:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 02:36 . 2012-01-31 18:53 615810 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2012-01-30 14:54 615810 c:\windows\system32\perfh009.dat
+ 2009-07-14 15:18 . 2012-01-31 18:53 631054 c:\windows\system32\perfh005.dat
- 2009-07-14 15:18 . 2012-01-30 14:54 631054 c:\windows\system32\perfh005.dat
+ 2009-07-14 02:36 . 2012-01-31 18:53 106190 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2012-01-30 14:54 106190 c:\windows\system32\perfc009.dat
- 2009-07-14 15:18 . 2012-01-30 14:54 121708 c:\windows\system32\perfc005.dat
+ 2009-07-14 15:18 . 2012-01-31 18:53 121708 c:\windows\system32\perfc005.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
c:\program files (x86)\Ask.com\GenericAskToolbar.dll [BU]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Headup Games"="c:\users\Darf\AppData\Roaming\Headup Games\upd.exe" [2011-12-26 979563]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"STCAgent"="c:\program files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe" [2011-03-04 812416]
"ZyngaGamesAgent"="c:\program files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe" [2010-11-15 877896]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Adobe ARM"="c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe" [2011-06-06 937920]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 291888]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
2;2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [x]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys [2011-11-27 30528]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536]
R3 netr28ux;RT2870 USB Wireless LAN Card Driver pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28ux.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WCUService_STC_FF;Splashtop Connect Firefox Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe [2011-03-24 493384]
R3 WCUService_STC_IE;Splashtop Connect IE Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe [2011-03-22 497480]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 SCBackService;Splashtop Connect Service;c:\program files (x86)\Splashtop\Splashtop Connect\BackService.exe [2010-11-15 477000]
S2 Smart TimeLock;Smart TimeLock Service;c:\program files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [2009-10-13 114688]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-14 381248]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{45d30484-7ded-43d9-957a-d2fd1f046511}]
2010-11-05 01:57 444752 ----a-w- c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{1d09c093-f71e-43c3-b948-19316cbd695e}"= "mscoree.dll" [2010-11-05 444752]
.
[HKEY_CLASSES_ROOT\CLSID\{1d09c093-f71e-43c3-b948-19316cbd695e}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-12 168216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-12 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-12 416024]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-02-11 11776104]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
"Logitech Download Assistant"="c:\windows\system32\rundll32.exe" [2009-07-14 45568]
"Start WingMan Profiler"="c:\program files\logitech\gaming software\lwemon.exe" [2010-06-14 190536]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1 192.168.3.254 172.20.0.1
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
.
**************************************************************************
.
Celkový čas: 2012-01-31 19:58:14 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-01-31 18:58
ComboFix2.txt 2012-01-31 15:58
ComboFix3.txt 2012-01-30 15:24
ComboFix4.txt 2012-01-30 14:23
.
Před spuštěním: Volných bajtů: 306 568 650 752
Po spuštění: Volných bajtů: 306 221 404 160
.
- - End Of File - - 761658520E5F463997372203554714E3
vyosek
VIP
Příspěvky: 56373 Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno
#22
Příspěvek
od vyosek » 31 led 2012 20:08
Skript pro SystemLook
:filefind
svchost.exe
:service
PowerManager
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen od 1. února 2011.
darf
Návštěvník
Příspěvky: 15 Registrován: 30 led 2012 13:24
#23
Příspěvek
od darf » 31 led 2012 20:11
SystemLook 30.07.11 by jpshortstuff
Log created at 20:10 on 31/01/2012 by Darf
Administrator - Elevation successful
WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results.
========== filefind ==========
Searching for "svchost.exe"
C:\Windows\ERDNT\cache64\svchost.exe --a---- 27136 bytes [15:24 30/01/2012] [01:39 14/07/2009] C78655BC80301D76ED4FEF1C1EA40A7D
C:\Windows\ERDNT\cache86\svchost.exe --a---- 20992 bytes [15:24 30/01/2012] [01:14 14/07/2009] 54A47F6B5E09A77E61649109C6A08866
C:\Windows\System32\svchost.exe --a---- 20992 bytes [23:19 13/07/2009] [01:14 14/07/2009] 54A47F6B5E09A77E61649109C6A08866
C:\Windows\SysWOW64\svchost.exe --a---- 20992 bytes [23:19 13/07/2009] [01:14 14/07/2009] 54A47F6B5E09A77E61649109C6A08866
C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe --a---- 27136 bytes [23:31 13/07/2009] [01:39 14/07/2009] C78655BC80301D76ED4FEF1C1EA40A7D
C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe --a---- 20992 bytes [23:19 13/07/2009] [01:14 14/07/2009] 54A47F6B5E09A77E61649109C6A08866
========== service ==========
PowerManager - Unable to open Service Handle.
-= EOF =-
vyosek
VIP
Příspěvky: 56373 Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno
#24
Příspěvek
od vyosek » 31 led 2012 20:17
Tak mrcha je pryc, co PC jak se chova
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen od 1. února 2011.
darf
Návštěvník
Příspěvky: 15 Registrován: 30 led 2012 13:24
#25
Příspěvek
od darf » 31 led 2012 20:38
Bohužel AVG mi stále hlásí Hidrag.A
vyosek
VIP
Příspěvky: 56373 Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno
#26
Příspěvek
od vyosek » 31 led 2012 20:41
Ona ta svine je totiz nakazila...
Zkuste pustit avptool ale na obrazku nize zaskrtnete jen Disinfect
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen od 1. února 2011.
darf
Návštěvník
Příspěvky: 15 Registrován: 30 led 2012 13:24
#27
Příspěvek
od darf » 01 úno 2012 06:17
Neopraví ani jediné exe které má v sobe Hidrag.a
vyosek
VIP
Příspěvky: 56373 Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno
#28
Příspěvek
od vyosek » 01 úno 2012 08:40
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen od 1. února 2011.
darf
Návštěvník
Příspěvky: 15 Registrován: 30 led 2012 13:24
#29
Příspěvek
od darf » 01 úno 2012 15:59
Sice to najde infikované soubory ale nedokáže je to vyléčit.
vyosek
VIP
Příspěvky: 56373 Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno
#30
Příspěvek
od vyosek » 01 úno 2012 16:01
No reknu to asi takhle, Hidrag\Jeefo je pekna mrcha typu fileinfector - napada exe soubory a leceni je velmi obtizne o cemz jsme se uz presvedcili
Bud muzem jeste dale zkouset a hledat nastroje, ktere to mozna poleci, ale uspech neni vubec zarucen a ja tez nejsem o tom presvedcen, nebo mozna bude rozumnejsi zazalohovat data a provest format s reinstalem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen od 1. února 2011.