Hidrag.A

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Hidrag.A

#16 Příspěvek od vyosek »

:arrow: Odinstalujte Advanced SystemCare 5 a nasledne i vse od IOBit - jsou to cinske smejdy a spise jen skodi nez jsou uzitkem. Hledaji nesmyslne a neexistujici problemy, databazi haveti ukradli jine renomovane spolecnosti

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Collect::
    c:\windows\svchost.exe
    
    DDS::
    uStart Page = hxxp://www.ask.com/?l=dis&o=15187
    
    RegLock::
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    
    RegNull::
    [HKEY_USERS\S-1-5-21-1985331280-3213936348-3091441614-1000\Software\SecuROM\License information*]
    
    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{00000000-6E41-4FD3-8538-502F5495E5FC}"=-
    "{0F3DC9E0-C459-4a40-BCF8-747BD9322E10}"=-
    [-HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
    [-HKEY_CLASSES_ROOT\clsid\{0f3dc9e0-c459-4a40-bcf8-747bd9322e10}]
    [-HKEY_CLASSES_ROOT\AddressBarSearch.SearchHook.1]
    [-HKEY_CLASSES_ROOT\TypeLib\{4E8E0178-00EF-413d-9324-E7B3E31572E3}]
    [-HKEY_CLASSES_ROOT\AddressBarSearch.SearchHook]
    [-HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Advanced SystemCare 5"=-
    "Headup Games"="c:\users\Darf\AppData\Roaming\Headup Games\upd.exe" [2011-12-26 979563]
    "DAEMON Tools Lite"=-
    "ZyngaGamesAgent"=-
    "SunJavaUpdateSched"=-
    
    Driver::
    gupdate
    gupdatem
    
    File::
    c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1985331280-3213936348-3091441614-1000Core.job
    c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1985331280-3213936348-3091441614-1000UA.job
    
    Folder::
    c:\program files (x86)\IObit
    c:\program files (x86)\Ask.com
    
    ClearJavaCache::
    
    Replicator::
    
    AtJob::
    
    Reboot::
    
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

darf
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 30 Led 2012 13:24

Re: Hidrag.A

#17 Příspěvek od darf »

ComboFix 12-01-30.02 - Darf 31.01.2012 16:50:39.2.8 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.8109.6327 [GMT 1:00]
Spuštěný z: c:\users\Darf\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Darf\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1985331280-3213936348-3091441614-1000Core.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1985331280-3213936348-3091441614-1000UA.job"
.
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Ask.com
c:\program files (x86)\Ask.com\assets\oobe\b.png
c:\program files (x86)\Ask.com\assets\oobe\bl.png
c:\program files (x86)\Ask.com\assets\oobe\br.png
c:\program files (x86)\Ask.com\assets\oobe\l.png
c:\program files (x86)\Ask.com\assets\oobe\pointer.png
c:\program files (x86)\Ask.com\assets\oobe\r.png
c:\program files (x86)\Ask.com\assets\oobe\t.png
c:\program files (x86)\Ask.com\assets\oobe\tl.png
c:\program files (x86)\Ask.com\assets\oobe\tr.png
c:\program files (x86)\Ask.com\cobrand.ico
c:\program files (x86)\Ask.com\config.xml
c:\program files (x86)\Ask.com\favicon.ico
c:\program files (x86)\Ask.com\fv_1638.ico
c:\program files (x86)\Ask.com\GenericAskToolbar.dll
c:\program files (x86)\Ask.com\mupcfg.xml
c:\program files (x86)\Ask.com\precache.exe
c:\program files (x86)\Ask.com\SaUpdate.exe
c:\program files (x86)\Ask.com\Updater\config.xml
c:\program files (x86)\Ask.com\Updater\Updater.exe
c:\program files (x86)\Ask.com\UpdateTask.exe
c:\program files (x86)\IObit
c:\program files (x86)\IObit\Advanced SystemCare 5\ActiveBoost.db
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCService_Log.txt
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-15.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-16.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-17.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-18.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-19.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-20.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-21.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-22.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-23.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-24.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-25.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-26.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-27.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-28.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-29.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-30.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog\2012-01-31.log
c:\program files (x86)\IObit\Advanced SystemCare 5\ASCv5ExtMenu_64.tmp
c:\program files (x86)\IObit\Advanced SystemCare 5\BackupList.txt
c:\program files (x86)\IObit\Advanced SystemCare 5\BootTimeLog\Defrag2011-12-28(02-58-53).log
c:\program files (x86)\IObit\Advanced SystemCare 5\BootTimeLog\Defrag2012-01-27(14-29-20).log
c:\program files (x86)\IObit\Advanced SystemCare 5\Ext.dbd
c:\program files (x86)\IObit\Advanced SystemCare 5\checkinfo.txt
c:\program files (x86)\IObit\Advanced SystemCare 5\LatestNews\imagenews.jpg
c:\program files (x86)\IObit\Advanced SystemCare 5\LatestNews\imagenews.png
c:\program files (x86)\IObit\Advanced SystemCare 5\LatestNews\LatestNews.ini
c:\program files (x86)\IObit\Advanced SystemCare 5\License.dat
c:\program files (x86)\IObit\Advanced SystemCare 5\Register.log
c:\program files (x86)\IObit\Advanced SystemCare 5\SecurityHole_Backup\KB2505438.cab
c:\program files (x86)\IObit\Advanced SystemCare 5\SecurityHole_Backup\KB2585542.cab
c:\program files (x86)\IObit\Advanced SystemCare 5\SecurityHole_Backup\KB2607576.cab
c:\program files (x86)\IObit\Advanced SystemCare 5\SecurityHole_Backup\KB915597.exe
c:\program files (x86)\IObit\Advanced SystemCare 5\SecurityHoleScan.log
c:\program files (x86)\IObit\Advanced SystemCare 5\sh.dat
c:\program files (x86)\IObit\Advanced SystemCare 5\TempResult.txt
c:\program files (x86)\IObit\Advanced SystemCare 5\Update\Update.Ini
c:\program files (x86)\IObit\Advanced SystemCare 5\UpdateHistory.txt
c:\windows\svchost.exe
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1985331280-3213936348-3091441614-1000Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1985331280-3213936348-3091441614-1000UA.job
.
----- Souboroví replikátoři -----
.
c:\programdata\Adobe\ARM\Reader_10.1.0\10183\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10183\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10183\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10183\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10838\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10838\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10838\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10838\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10844\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10844\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10844\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\10844\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\12544\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\12544\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\12544\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\12544\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\13937\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\13937\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\13937\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\13937\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\14849\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\14849\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\14849\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\14849\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15556\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15556\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15556\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15556\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15814\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15814\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15814\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\15814\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17070\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17070\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17070\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17070\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17624\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17624\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17624\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\17624\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\19362\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\19362\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\19362\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\19362\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\21579\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\21579\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\21579\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\21579\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23412\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23412\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23412\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23412\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23696\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23696\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23696\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\23696\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\24938\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\24938\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\24938\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\24938\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\25907\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\25907\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\25907\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\25907\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\28695\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\28695\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\28695\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\28695\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\440\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\440\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\440\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\440\ReaderUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\452\AcrobatUpdater.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\452\AdobeARM.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\452\AdobeARMHelper.exe
c:\programdata\Adobe\ARM\Reader_10.1.0\452\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10183\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10183\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10183\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10183\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10838\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10838\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10838\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10838\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10844\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10844\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10844\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\10844\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\12544\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\12544\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\12544\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\12544\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\13937\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\13937\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\13937\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\13937\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\14849\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\14849\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\14849\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\14849\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15556\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15556\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15556\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15556\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15814\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15814\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15814\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\15814\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17070\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17070\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17070\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17070\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17624\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17624\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17624\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\17624\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\19362\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\19362\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\19362\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\19362\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\21579\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\21579\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\21579\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\21579\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23412\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23412\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23412\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23412\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23696\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23696\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23696\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\23696\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\24938\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\24938\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\24938\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\24938\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\25907\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\25907\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\25907\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\25907\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\28695\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\28695\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\28695\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\28695\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\440\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\440\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\440\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\440\ReaderUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\452\AcrobatUpdater.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\452\AdobeARM.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\452\AdobeARMHelper.exe
c:\users\All Users\Adobe\ARM\Reader_10.1.0\452\ReaderUpdater.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_PowerManager
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-28 do 2012-01-31 )))))))))))))))))))))))))))))))
.
.
2012-01-31 15:53 . 2012-01-31 15:53 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-01-31 15:53 . 2012-01-31 15:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-31 15:14 . 2012-01-31 15:14 -------- d-----w- c:\program files (x86)\PhotoFilter
2012-01-31 09:11 . 2012-01-06 05:15 8602168 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3BB1A3A9-1D1B-4058-953A-C2BFEDE7B562}\mpengine.dll
2012-01-30 13:05 . 2012-01-30 14:32 -------- d-----w- c:\program files\trend micro
2012-01-30 13:05 . 2012-01-30 13:05 -------- d-----w- C:\rsit
2012-01-30 10:52 . 2012-01-30 10:52 -------- d-----w- c:\programdata\Kaspersky Lab
2012-01-30 04:23 . 2012-01-30 04:23 -------- d-----w- c:\users\Darf\AppData\Roaming\AVG2012
2012-01-30 04:22 . 2012-01-30 10:32 -------- d-----w- c:\windows\SysWow64\drivers\AVG
2012-01-30 04:22 . 2012-01-30 10:32 -------- d-----w- c:\windows\system32\drivers\AVG
2012-01-29 21:24 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\PCSafeDoctor
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- C:\sh4ldr
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- c:\program files\Enigma Software Group
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- c:\windows\5B210B8AB66E4702B44D0D6F388D29EB.TMP
2012-01-29 21:03 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2012-01-29 20:50 . 2012-01-30 10:32 -------- d-----w- c:\programdata\Spyware Terminator
2012-01-29 20:50 . 2012-01-29 20:50 -------- d-----w- c:\users\Darf\AppData\Roaming\Spyware Terminator
2012-01-29 20:49 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\Spyware Terminator
2012-01-29 18:27 . 2012-01-29 18:27 -------- d-----w- C:\$AVG
2012-01-29 18:24 . 2012-01-29 18:24 -------- d-----w- c:\programdata\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 20:36 -------- d-----w- c:\program files (x86)\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 20:36 -------- d-----w- c:\program files (x86)\Common Files\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 18:24 -------- d--h--w- c:\programdata\Common Files
2012-01-29 18:23 . 2012-01-30 04:22 -------- d-----w- c:\programdata\AVG2012
2012-01-29 18:22 . 2012-01-29 18:22 -------- d-----w- c:\program files (x86)\AVG
2012-01-29 18:19 . 2012-01-30 10:32 -------- d-----w- c:\programdata\MFAData
2012-01-29 00:27 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Pontifex II
2012-01-28 02:29 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Enlight
2012-01-28 02:23 . 2012-01-28 02:23 -------- d-----w- c:\users\Darf\AppData\Local\Bridge!
2012-01-28 02:22 . 2012-01-30 14:28 -------- d-----w- c:\program files (x86)\Aerosoft
2012-01-28 02:22 . 2012-01-30 10:32 -------- d-----w- C:\ToxSickLabs
2012-01-28 00:57 . 2012-01-28 00:57 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-01-28 00:57 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2012-01-28 00:10 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Bridge Constructor
2012-01-28 00:10 . 2012-01-30 14:32 -------- d-----w- c:\users\Darf\AppData\Roaming\Headup Games
2012-01-21 00:04 . 2012-01-21 00:04 -------- d-----w- c:\users\Darf\AppData\Local\BCR
2012-01-21 00:04 . 2012-01-21 00:04 -------- d-----w- c:\programdata\BCR
2012-01-19 20:40 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Microsoft Application Compatibility Toolkit
2012-01-19 16:29 . 2012-01-30 14:32 -------- d-----w- c:\users\Darf\AppData\Roaming\TS3Client
2012-01-19 16:29 . 2012-01-30 14:32 -------- d-----w- c:\program files\TeamSpeak 3 Client
2012-01-17 18:54 . 2009-11-11 14:37 3248128 ----a-w- c:\windows\SysWow64\DVAPfg.exe
2012-01-17 18:53 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\ffdshow
2012-01-17 18:53 . 2009-07-05 20:33 85504 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2012-01-17 18:53 . 2009-07-05 20:33 60273 ----a-w- c:\windows\SysWow64\pthreadGC2.dll
2012-01-15 15:20 . 2012-01-15 15:20 -------- d-----w- c:\users\Darf\AppData\Local\kaneandlynch
2012-01-15 15:12 . 2012-01-15 15:12 -------- d--h--r- c:\users\Darf\AppData\Roaming\SecuROM
2012-01-15 15:04 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Eidos
2012-01-15 02:54 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Driver San Francisco
2012-01-15 00:45 . 2012-01-15 00:45 -------- d--h--w- c:\users\Darf\InstallAnywhere
2012-01-15 00:21 . 2012-01-30 14:32 -------- d-----w- c:\windows\USB Vibration
2012-01-15 00:21 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\USB Vibration
2012-01-15 00:21 . 2012-01-15 00:21 270468 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\Setup.dll
2012-01-15 00:21 . 2012-01-15 00:21 159876 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\IGdi.dll
2012-01-15 00:21 . 2002-08-05 09:46 57344 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\ctor.dll
2012-01-15 00:21 . 2002-08-02 02:10 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\DotNetInstaller.exe
2012-01-15 00:21 . 2002-08-02 01:20 634880 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iKernel.dll
2012-01-15 00:21 . 2002-08-02 01:20 237568 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iscript.dll
2012-01-15 00:21 . 2002-08-02 01:20 151552 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iuser.dll
2012-01-11 14:41 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 14:41 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 14:41 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-01-11 14:41 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-01-11 14:41 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 14:41 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-01-11 14:41 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2012-01-11 14:41 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-01-08 13:54 . 2012-01-08 13:54 -------- d-----w- c:\users\Darf\AppData\Local\Logitech
2012-01-08 13:48 . 2012-01-08 13:48 -------- d-----w- c:\programdata\Codemasters
2012-01-08 13:38 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\OpenAL
2012-01-08 13:38 . 2012-01-28 01:00 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2012-01-08 13:38 . 2012-01-28 01:00 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-01-08 13:38 . 2012-01-28 01:00 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2012-01-08 13:38 . 2012-01-28 01:00 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2012-01-08 13:38 . 2008-07-12 07:18 467984 ----a-w- c:\windows\SysWow64\d3dx10_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 1493528 ----a-w- c:\windows\SysWow64\D3DCompiler_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 540688 ----a-w- c:\windows\system32\d3dx10_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 1942552 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 4992520 ----a-w- c:\windows\system32\D3DX9_39.dll
2012-01-08 13:28 . 2012-01-30 14:28 -------- d-----w- c:\program files (x86)\Codemasters
2012-01-07 20:20 . 2012-01-30 14:30 -------- d-----w- c:\users\Darf\AppData\Roaming\Mikrotik
2012-01-07 16:59 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Google
2012-01-07 11:01 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Disney Interactive Studios
2012-01-04 16:55 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\18 WoS Extreme Trucker 2
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-29 11:23 . 2011-11-28 16:01 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-01-29 11:23 . 2011-11-27 09:40 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-01-29 11:22 . 2011-11-27 09:40 282880 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-01-28 11:45 . 2011-11-29 20:04 78848 ----a-w- c:\windows\KMSEmulator.exe
2012-01-13 16:15 . 2012-01-13 16:15 340992 ----a-w- c:\windows\system32\schannel.dll
2012-01-13 16:15 . 2012-01-13 16:15 224768 ----a-w- c:\windows\SysWow64\schannel.dll
2012-01-08 16:33 . 2011-11-26 20:23 25640 ----a-w- c:\windows\gdrv.sys
2012-01-03 18:18 . 2011-11-27 09:40 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-12-28 00:54 . 2011-12-28 00:54 902656 ----a-w- c:\windows\system32\d2d1.dll
2011-12-28 00:54 . 2011-12-28 00:54 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2011-12-28 00:54 . 2011-12-28 00:54 1544192 ----a-w- c:\windows\system32\DWrite.dll
2011-12-28 00:54 . 2011-12-28 00:54 1139200 ----a-w- c:\windows\system32\FntCache.dll
2011-12-28 00:54 . 2011-12-28 00:54 1076736 ----a-w- c:\windows\SysWow64\DWrite.dll
2011-12-07 09:39 . 2011-11-26 20:16 279096 ------w- c:\windows\system32\MpSigStub.exe
2011-11-28 20:16 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-11-28 20:16 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-11-27 13:04 . 2011-11-26 20:23 30528 ----a-w- c:\windows\GVTDrv64.sys
2011-11-26 22:44 . 2011-11-26 22:44 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-11-24 04:52 . 2011-12-14 19:58 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-11-05 05:41 . 2011-12-14 20:08 1188864 ----a-w- c:\windows\system32\wininet.dll
2011-11-05 05:32 . 2011-12-14 20:08 2048 ----a-w- c:\windows\system32\tzres.dll
2011-11-05 04:35 . 2011-12-14 20:08 981504 ----a-w- c:\windows\SysWow64\wininet.dll
2011-11-05 04:26 . 2011-12-14 20:08 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-11-05 03:32 . 2011-12-14 20:08 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-11-05 02:48 . 2011-12-14 20:08 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-30_15.21.59 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-11-26 23:13 . 2012-01-31 15:12 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-11-26 23:13 . 2012-01-30 15:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-11-26 23:13 . 2012-01-31 15:12 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-11-26 23:13 . 2012-01-30 15:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-01-31 12:04 . 2012-01-31 12:04 25600 c:\windows\Installer\46d4690.msi
- 2012-01-30 15:21 . 2012-01-30 15:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-31 15:54 . 2012-01-31 15:54 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-01-30 15:21 . 2012-01-30 15:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-01-31 15:54 . 2012-01-31 15:54 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-01-31 15:54 . 2012-01-31 12:04 180648 c:\windows\temp\GoogleCrashHandler.exe
- 2009-07-14 02:36 . 2012-01-30 14:54 615810 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-01-31 15:09 615810 c:\windows\system32\perfh009.dat
- 2009-07-14 15:18 . 2012-01-30 14:54 631054 c:\windows\system32\perfh005.dat
+ 2009-07-14 15:18 . 2012-01-31 15:09 631054 c:\windows\system32\perfh005.dat
+ 2009-07-14 02:36 . 2012-01-31 15:09 106190 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2012-01-30 14:54 106190 c:\windows\system32\perfc009.dat
- 2009-07-14 15:18 . 2012-01-30 14:54 121708 c:\windows\system32\perfc005.dat
+ 2009-07-14 15:18 . 2012-01-31 15:09 121708 c:\windows\system32\perfc005.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Headup Games"="c:\users\Darf\AppData\Roaming\Headup Games\upd.exe" [2011-12-26 979563]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"STCAgent"="c:\program files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe" [2011-03-04 812416]
"ZyngaGamesAgent"="c:\program files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe" [2010-11-15 877896]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Adobe ARM"="c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe" [2011-06-06 937920]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 291888]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
2;2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [x]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys [2011-11-27 30528]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536]
R3 netr28ux;RT2870 USB Wireless LAN Card Driver pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28ux.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WCUService_STC_FF;Splashtop Connect Firefox Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe [2011-03-24 493384]
R3 WCUService_STC_IE;Splashtop Connect IE Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe [2011-03-22 497480]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 SCBackService;Splashtop Connect Service;c:\program files (x86)\Splashtop\Splashtop Connect\BackService.exe [2010-11-15 477000]
S2 Smart TimeLock;Smart TimeLock Service;c:\program files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [2009-10-13 114688]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-14 381248]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{45d30484-7ded-43d9-957a-d2fd1f046511}]
2010-11-05 01:57 444752 ----a-w- c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{1d09c093-f71e-43c3-b948-19316cbd695e}"= "mscoree.dll" [2010-11-05 444752]
.
[HKEY_CLASSES_ROOT\CLSID\{1d09c093-f71e-43c3-b948-19316cbd695e}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-12 168216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-12 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-12 416024]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-02-11 11776104]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
"Logitech Download Assistant"="c:\windows\system32\rundll32.exe" [2009-07-14 45568]
"Start WingMan Profiler"="c:\program files\logitech\gaming software\lwemon.exe" [2010-06-14 190536]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1 192.168.3.254 172.20.0.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files (x86)\Ask.com\GenericAskToolbar.dll
Wow6432Node-HKLM-Run-ApnUpdater - c:\program files (x86)\ask.com\updater\updater.exe
Wow6432Node-HKLM-Run-facemoods - c:\program files (x86)\facemoods.com\facemoods\1.4.17.7\facemoodssrv.exe
Wow6432Node-HKLM-Run-DVAPTray - c:\windows\system32\dvaptray.exe
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\windows\svchost.exe
.
**************************************************************************
.
Celkový čas: 2012-01-31 16:57:26 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-01-31 15:57
ComboFix2.txt 2012-01-30 15:24
ComboFix3.txt 2012-01-30 14:23
.
Před spuštěním: Volných bajtů: 305 794 441 216
Po spuštění: Volných bajtů: 306 807 357 440
.
- - End Of File - - B5FCFD25D74B897EBE79AD0ED9483547
Nahr nˇ probŘhlo ŁspŘçnŘ

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Hidrag.A

#18 Příspěvek od vyosek »

:arrow: Stahnete SytemLook (viz muj podpis) a ulozte jej na plochu
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    :regfind
    svchost.exe
  • Kliknete na Look
  • Tlacitko Look se zmeni na Scanning a zsedne
  • Pockejte pokud se tlacitko Scanning opet nezmeni na Look - tak poznate ze SystemLook dokoncil svou praci
  • Vyskoci na Vas log s nazvem SystemLook (pripadne bude ulozen na plose), jeho obsah mi sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

darf
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 30 Led 2012 13:24

Re: Hidrag.A

#19 Příspěvek od darf »

Log přesahuje max počet znaků.

Kód: Vybrat vše

http://uloz.to/12985714/log-2-txt
nebo to hodit do několika příspěvků?

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Hidrag.A

#20 Příspěvek od vyosek »

:arrow: Stahnete AVZ http://z-oleg.com/avz4.zip a ulozte jej na plochu
  • Rozbalte stazeny rar, tak aby byla jen jedna slozka avz4 a spustte avz.exe
  • Kliknete nahore na File a nasledne vyberte Custom scripts
  • Do okenka nakopirujte skript, ktery mate nize
  • Kód: Vybrat vše

    begin
    SetAVZGuardStatus(True);
    SearchRootkit(true, true);
    ClearQuarantine;
    DeleteFile('c:\windows\svchost.exe');
    BC_DeleteFile('c:\windows\svchost.exe');
    StopService('PowerManager');
    DeleteService('PowerManager');
    RebootWindows(true);
    end.
  • Nyni kliknete na Run cimz akci spustite
  • po restartu PC je mozne, ze se nacte pruvodce hardwarem, s klidem stornujte (klik na STORNO)
:arrow: Poprosim o novy log z ComboFixu - jen jej spustte bez skriptu
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

darf
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 30 Led 2012 13:24

Re: Hidrag.A

#21 Příspěvek od darf »

ComboFix 12-01-30.02 - Darf 31.01.2012 19:50:43.3.8 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.8109.6966 [GMT 1:00]
Spuštěný z: c:\users\Darf\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\svchost.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_PowerManager
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-28 do 2012-01-31 )))))))))))))))))))))))))))))))
.
.
2012-01-31 18:54 . 2012-01-31 18:54 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-01-31 18:54 . 2012-01-31 18:54 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-31 15:14 . 2012-01-31 15:14 -------- d-----w- c:\program files (x86)\PhotoFilter
2012-01-31 09:11 . 2012-01-06 05:15 8602168 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3BB1A3A9-1D1B-4058-953A-C2BFEDE7B562}\mpengine.dll
2012-01-30 13:05 . 2012-01-30 14:32 -------- d-----w- c:\program files\trend micro
2012-01-30 13:05 . 2012-01-30 13:05 -------- d-----w- C:\rsit
2012-01-30 10:52 . 2012-01-30 10:52 -------- d-----w- c:\programdata\Kaspersky Lab
2012-01-30 04:23 . 2012-01-30 04:23 -------- d-----w- c:\users\Darf\AppData\Roaming\AVG2012
2012-01-30 04:22 . 2012-01-30 10:32 -------- d-----w- c:\windows\SysWow64\drivers\AVG
2012-01-30 04:22 . 2012-01-30 10:32 -------- d-----w- c:\windows\system32\drivers\AVG
2012-01-29 21:24 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\PCSafeDoctor
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- C:\sh4ldr
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- c:\program files\Enigma Software Group
2012-01-29 21:03 . 2012-01-29 21:03 -------- d-----w- c:\windows\5B210B8AB66E4702B44D0D6F388D29EB.TMP
2012-01-29 21:03 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2012-01-29 20:50 . 2012-01-30 10:32 -------- d-----w- c:\programdata\Spyware Terminator
2012-01-29 20:50 . 2012-01-29 20:50 -------- d-----w- c:\users\Darf\AppData\Roaming\Spyware Terminator
2012-01-29 20:49 . 2012-01-30 10:32 -------- d-----w- c:\program files (x86)\Spyware Terminator
2012-01-29 18:27 . 2012-01-29 18:27 -------- d-----w- C:\$AVG
2012-01-29 18:24 . 2012-01-29 18:24 -------- d-----w- c:\programdata\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 20:36 -------- d-----w- c:\program files (x86)\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 20:36 -------- d-----w- c:\program files (x86)\Common Files\AVG Secure Search
2012-01-29 18:24 . 2012-01-29 18:24 -------- d--h--w- c:\programdata\Common Files
2012-01-29 18:23 . 2012-01-30 04:22 -------- d-----w- c:\programdata\AVG2012
2012-01-29 18:22 . 2012-01-29 18:22 -------- d-----w- c:\program files (x86)\AVG
2012-01-29 18:19 . 2012-01-30 10:32 -------- d-----w- c:\programdata\MFAData
2012-01-29 00:27 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Pontifex II
2012-01-28 02:29 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Enlight
2012-01-28 02:23 . 2012-01-28 02:23 -------- d-----w- c:\users\Darf\AppData\Local\Bridge!
2012-01-28 02:22 . 2012-01-30 14:28 -------- d-----w- c:\program files (x86)\Aerosoft
2012-01-28 02:22 . 2012-01-30 10:32 -------- d-----w- C:\ToxSickLabs
2012-01-28 00:57 . 2012-01-28 00:57 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-01-28 00:57 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2012-01-28 00:10 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Bridge Constructor
2012-01-28 00:10 . 2012-01-30 14:32 -------- d-----w- c:\users\Darf\AppData\Roaming\Headup Games
2012-01-21 00:04 . 2012-01-21 00:04 -------- d-----w- c:\users\Darf\AppData\Local\BCR
2012-01-21 00:04 . 2012-01-21 00:04 -------- d-----w- c:\programdata\BCR
2012-01-19 20:40 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Microsoft Application Compatibility Toolkit
2012-01-19 16:29 . 2012-01-30 14:32 -------- d-----w- c:\users\Darf\AppData\Roaming\TS3Client
2012-01-19 16:29 . 2012-01-30 14:32 -------- d-----w- c:\program files\TeamSpeak 3 Client
2012-01-17 18:54 . 2009-11-11 14:37 3248128 ----a-w- c:\windows\SysWow64\DVAPfg.exe
2012-01-17 18:53 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\ffdshow
2012-01-17 18:53 . 2009-07-05 20:33 85504 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2012-01-17 18:53 . 2009-07-05 20:33 60273 ----a-w- c:\windows\SysWow64\pthreadGC2.dll
2012-01-15 15:20 . 2012-01-15 15:20 -------- d-----w- c:\users\Darf\AppData\Local\kaneandlynch
2012-01-15 15:12 . 2012-01-15 15:12 -------- d--h--r- c:\users\Darf\AppData\Roaming\SecuROM
2012-01-15 15:04 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Eidos
2012-01-15 02:54 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\Driver San Francisco
2012-01-15 00:45 . 2012-01-15 00:45 -------- d--h--w- c:\users\Darf\InstallAnywhere
2012-01-15 00:21 . 2012-01-30 14:32 -------- d-----w- c:\windows\USB Vibration
2012-01-15 00:21 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\USB Vibration
2012-01-15 00:21 . 2012-01-15 00:21 270468 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\Setup.dll
2012-01-15 00:21 . 2012-01-15 00:21 159876 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\IGdi.dll
2012-01-15 00:21 . 2002-08-05 09:46 57344 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\ctor.dll
2012-01-15 00:21 . 2002-08-02 02:10 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\DotNetInstaller.exe
2012-01-15 00:21 . 2002-08-02 01:20 634880 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iKernel.dll
2012-01-15 00:21 . 2002-08-02 01:20 237568 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iscript.dll
2012-01-15 00:21 . 2002-08-02 01:20 151552 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0700\Intel32\iuser.dll
2012-01-11 14:41 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 14:41 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 14:41 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-01-11 14:41 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-01-11 14:41 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 14:41 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-01-11 14:41 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2012-01-11 14:41 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-01-08 13:54 . 2012-01-08 13:54 -------- d-----w- c:\users\Darf\AppData\Local\Logitech
2012-01-08 13:48 . 2012-01-08 13:48 -------- d-----w- c:\programdata\Codemasters
2012-01-08 13:38 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\OpenAL
2012-01-08 13:38 . 2012-01-28 01:00 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2012-01-08 13:38 . 2012-01-28 01:00 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-01-08 13:38 . 2012-01-28 01:00 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2012-01-08 13:38 . 2012-01-28 01:00 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2012-01-08 13:38 . 2008-07-12 07:18 467984 ----a-w- c:\windows\SysWow64\d3dx10_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 1493528 ----a-w- c:\windows\SysWow64\D3DCompiler_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 540688 ----a-w- c:\windows\system32\d3dx10_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 1942552 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
2012-01-08 13:38 . 2008-07-12 07:18 4992520 ----a-w- c:\windows\system32\D3DX9_39.dll
2012-01-08 13:28 . 2012-01-30 14:28 -------- d-----w- c:\program files (x86)\Codemasters
2012-01-07 20:20 . 2012-01-30 14:30 -------- d-----w- c:\users\Darf\AppData\Roaming\Mikrotik
2012-01-07 16:59 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Google
2012-01-07 11:01 . 2012-01-30 14:29 -------- d-----w- c:\program files (x86)\Disney Interactive Studios
2012-01-04 16:55 . 2012-01-30 14:32 -------- d-----w- c:\program files (x86)\18 WoS Extreme Trucker 2
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-29 11:23 . 2011-11-28 16:01 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-01-29 11:23 . 2011-11-27 09:40 282864 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-01-29 11:22 . 2011-11-27 09:40 282880 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-01-28 11:45 . 2011-11-29 20:04 78848 ----a-w- c:\windows\KMSEmulator.exe
2012-01-13 16:15 . 2012-01-13 16:15 340992 ----a-w- c:\windows\system32\schannel.dll
2012-01-13 16:15 . 2012-01-13 16:15 224768 ----a-w- c:\windows\SysWow64\schannel.dll
2012-01-08 16:33 . 2011-11-26 20:23 25640 ----a-w- c:\windows\gdrv.sys
2012-01-03 18:18 . 2011-11-27 09:40 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-12-28 00:54 . 2011-12-28 00:54 902656 ----a-w- c:\windows\system32\d2d1.dll
2011-12-28 00:54 . 2011-12-28 00:54 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2011-12-28 00:54 . 2011-12-28 00:54 1544192 ----a-w- c:\windows\system32\DWrite.dll
2011-12-28 00:54 . 2011-12-28 00:54 1139200 ----a-w- c:\windows\system32\FntCache.dll
2011-12-28 00:54 . 2011-12-28 00:54 1076736 ----a-w- c:\windows\SysWow64\DWrite.dll
2011-12-07 09:39 . 2011-11-26 20:16 279096 ------w- c:\windows\system32\MpSigStub.exe
2011-11-28 20:16 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-11-28 20:16 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-11-27 13:04 . 2011-11-26 20:23 30528 ----a-w- c:\windows\GVTDrv64.sys
2011-11-26 22:44 . 2011-11-26 22:44 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-11-24 04:52 . 2011-12-14 19:58 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-11-05 05:41 . 2011-12-14 20:08 1188864 ----a-w- c:\windows\system32\wininet.dll
2011-11-05 05:32 . 2011-12-14 20:08 2048 ----a-w- c:\windows\system32\tzres.dll
2011-11-05 04:35 . 2011-12-14 20:08 981504 ----a-w- c:\windows\SysWow64\wininet.dll
2011-11-05 04:26 . 2011-12-14 20:08 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-11-05 03:32 . 2011-12-14 20:08 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-11-05 02:48 . 2011-12-14 20:08 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-30_15.21.59 )))))))))))))))))))))))))))))))))))))))))
.
- 2011-11-26 23:13 . 2012-01-30 15:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-11-26 23:13 . 2012-01-31 18:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-11-26 23:13 . 2012-01-30 15:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-11-26 23:13 . 2012-01-31 18:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-01-31 12:04 . 2012-01-31 12:04 25600 c:\windows\Installer\46d4690.msi
- 2012-01-30 15:21 . 2012-01-30 15:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-31 18:55 . 2012-01-31 18:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-31 18:55 . 2012-01-31 18:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-01-30 15:21 . 2012-01-30 15:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 02:36 . 2012-01-31 18:53 615810 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2012-01-30 14:54 615810 c:\windows\system32\perfh009.dat
+ 2009-07-14 15:18 . 2012-01-31 18:53 631054 c:\windows\system32\perfh005.dat
- 2009-07-14 15:18 . 2012-01-30 14:54 631054 c:\windows\system32\perfh005.dat
+ 2009-07-14 02:36 . 2012-01-31 18:53 106190 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2012-01-30 14:54 106190 c:\windows\system32\perfc009.dat
- 2009-07-14 15:18 . 2012-01-30 14:54 121708 c:\windows\system32\perfc005.dat
+ 2009-07-14 15:18 . 2012-01-31 18:53 121708 c:\windows\system32\perfc005.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
c:\program files (x86)\Ask.com\GenericAskToolbar.dll [BU]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Headup Games"="c:\users\Darf\AppData\Roaming\Headup Games\upd.exe" [2011-12-26 979563]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"STCAgent"="c:\program files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe" [2011-03-04 812416]
"ZyngaGamesAgent"="c:\program files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe" [2010-11-15 877896]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Adobe ARM"="c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe" [2011-06-06 937920]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 291888]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
2;2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [x]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys [2011-11-27 30528]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536]
R3 netr28ux;RT2870 USB Wireless LAN Card Driver pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28ux.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WCUService_STC_FF;Splashtop Connect Firefox Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe [2011-03-24 493384]
R3 WCUService_STC_IE;Splashtop Connect IE Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe [2011-03-22 497480]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 SCBackService;Splashtop Connect Service;c:\program files (x86)\Splashtop\Splashtop Connect\BackService.exe [2010-11-15 477000]
S2 Smart TimeLock;Smart TimeLock Service;c:\program files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [2009-10-13 114688]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-14 381248]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{45d30484-7ded-43d9-957a-d2fd1f046511}]
2010-11-05 01:57 444752 ----a-w- c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{1d09c093-f71e-43c3-b948-19316cbd695e}"= "mscoree.dll" [2010-11-05 444752]
.
[HKEY_CLASSES_ROOT\CLSID\{1d09c093-f71e-43c3-b948-19316cbd695e}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-12 168216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-12 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-12 416024]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-02-11 11776104]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
"Logitech Download Assistant"="c:\windows\system32\rundll32.exe" [2009-07-14 45568]
"Start WingMan Profiler"="c:\program files\logitech\gaming software\lwemon.exe" [2010-06-14 190536]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1 192.168.3.254 172.20.0.1
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
.
**************************************************************************
.
Celkový čas: 2012-01-31 19:58:14 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-01-31 18:58
ComboFix2.txt 2012-01-31 15:58
ComboFix3.txt 2012-01-30 15:24
ComboFix4.txt 2012-01-30 14:23
.
Před spuštěním: Volných bajtů: 306 568 650 752
Po spuštění: Volných bajtů: 306 221 404 160
.
- - End Of File - - 761658520E5F463997372203554714E3

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Hidrag.A

#22 Příspěvek od vyosek »

Skript pro SystemLook
:filefind
svchost.exe

:service
PowerManager
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

darf
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 30 Led 2012 13:24

Re: Hidrag.A

#23 Příspěvek od darf »

SystemLook 30.07.11 by jpshortstuff
Log created at 20:10 on 31/01/2012 by Darf
Administrator - Elevation successful
WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results.

========== filefind ==========

Searching for "svchost.exe"
C:\Windows\ERDNT\cache64\svchost.exe --a---- 27136 bytes [15:24 30/01/2012] [01:39 14/07/2009] C78655BC80301D76ED4FEF1C1EA40A7D
C:\Windows\ERDNT\cache86\svchost.exe --a---- 20992 bytes [15:24 30/01/2012] [01:14 14/07/2009] 54A47F6B5E09A77E61649109C6A08866
C:\Windows\System32\svchost.exe --a---- 20992 bytes [23:19 13/07/2009] [01:14 14/07/2009] 54A47F6B5E09A77E61649109C6A08866
C:\Windows\SysWOW64\svchost.exe --a---- 20992 bytes [23:19 13/07/2009] [01:14 14/07/2009] 54A47F6B5E09A77E61649109C6A08866
C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe --a---- 27136 bytes [23:31 13/07/2009] [01:39 14/07/2009] C78655BC80301D76ED4FEF1C1EA40A7D
C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe --a---- 20992 bytes [23:19 13/07/2009] [01:14 14/07/2009] 54A47F6B5E09A77E61649109C6A08866

========== service ==========

PowerManager - Unable to open Service Handle.

-= EOF =-

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Hidrag.A

#24 Příspěvek od vyosek »

Tak mrcha je pryc, co PC jak se chova :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

darf
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 30 Led 2012 13:24

Re: Hidrag.A

#25 Příspěvek od darf »

Bohužel AVG mi stále hlásí Hidrag.A

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Hidrag.A

#26 Příspěvek od vyosek »

Ona ta svine je totiz nakazila...

Zkuste pustit avptool ale na obrazku nize zaskrtnete jen Disinfect
Obrázek
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

darf
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 30 Led 2012 13:24

Re: Hidrag.A

#27 Příspěvek od darf »

Neopraví ani jediné exe které má v sobe Hidrag.a

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Hidrag.A

#28 Příspěvek od vyosek »

"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

darf
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 30 Led 2012 13:24

Re: Hidrag.A

#29 Příspěvek od darf »

Sice to najde infikované soubory ale nedokáže je to vyléčit.

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Hidrag.A

#30 Příspěvek od vyosek »

:arrow: No reknu to asi takhle, Hidrag\Jeefo je pekna mrcha typu fileinfector - napada exe soubory a leceni je velmi obtizne o cemz jsme se uz presvedcili

:arrow: Bud muzem jeste dale zkouset a hledat nastroje, ktere to mozna poleci, ale uspech neni vubec zarucen a ja tez nejsem o tom presvedcen, nebo mozna bude rozumnejsi zazalohovat data a provest format s reinstalem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět