Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Vir v PC

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
prochyn.vit
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 04 úno 2012 18:31

Vir v PC

#1 Příspěvek od prochyn.vit »

mam problem s pocitacem...kdyz najedu na plochu a kliknu na nejakou ikonu tak se mi oznaci vsechny,nebo kdyz neco pisu tak mi nejdou psat velke pismena a prijde mi jak kdyby se zapnul caps lock a shift...a kdyz jsem chtel obnovit pc tak vir smazal vsechny body obnoveni....nekdy mi to jede normalne nekdy ne...uvital bych nejakou radu pridam log z rsit....

Logfile of random's system information tool 1.09 (written by random/random)
Run by Prochyn at 2012-02-04 18:40:13
Microsoft Windows 7 Ultimate
System drive C: has 14 GB (10%) free of 146 GB
Total RAM: 3071 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:40:19 PM, on 2/4/2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\SweetIM\Messenger\SweetIM.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\BitTorrent\BitTorrent.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Opera\opera.exe
G:\RSIT.exe
C:\Program Files\trend micro\Prochyn.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.garena.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\prxtbBitT.dll
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
O2 - BHO: bflix - {0C9F4179-6CE2-4c6a-A3E5-67FF3592A12E} - C:\Program Files\TheBflix\TheBflix.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL
O2 - BHO: BitTorrentBar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\prxtbBitT.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll
O3 - Toolbar: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\prxtbBitT.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O4 - HKLM\..\Run: [4StoryPrePatch] C:\Program Files\Gameforge4D\4Story\PrePatch.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
O4 - HKLM\..\Run: [ROC_roc_dec12] "C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [NBAgent] "C:\Program Files\Nero\Nero 11\Nero BackItUp\NBAgent.exe" /WinStart
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\BitTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount
O4 - HKUS\S-1-5-21-1713205610-778408625-3204417612-1001\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1713205610-778408625-3204417612-1001\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Search the Web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GRA32A~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\10.0.6\ViProtocol.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\Lenovo\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\Lenovo\ATK Hotkey\GFNEXSrv.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Service of LFKA (LFKAS) - Unknown owner - C:\Program Files\Lenovo\ATK Hotkey\LFKAS.exe
O23 - Service: @C:\Program Files\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files\Nero\Update\NASvc.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files\Tunngle\TnglCtrl.exe
O23 - Service: vToolbarUpdater - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe
O23 - Service: XYNTService - Unknown owner - C:\Users\Prochyn\AppData\Local\Temp\{4C75A12E-899F-4069-8C74-5BB5B4EEA4CF}\{061A431C-86E7-4DB4-92B8-36DE783865CF}\STK2135\Win2KXP\stk2135bsrv.exe

--
End of file - 9465 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0C9F4179-6CE2-4c6a-A3E5-67FF3592A12E}]
bflix Class - C:\Program Files\TheBflix\TheBflix.dll [2011-12-19 167936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-01-03 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG2012\avgssie.dll [2011-11-11 1378144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
BitTorrentBar Toolbar - C:\Program Files\BitTorrentBar\prxtbBitT.dll [2011-05-09 176936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
AVG Security Toolbar - C:\Program Files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll [2012-01-16 1811296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-10-10 3834016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-11-16 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
SweetIM Toolbar Helper - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2011-08-24 1299248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{95B7759C-8C7F-4BF1-B163-73684A933233} - AVG Security Toolbar - C:\Program Files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll [2012-01-16 1811296]
{88c7f2aa-f93f-432c-8f0e-b7d85967a527} - BitTorrentBar Toolbar - C:\Program Files\BitTorrentBar\prxtbBitT.dll [2011-05-09 176936]
{EEE6C35B-6118-11DC-9C72-001320C79847} - SweetIM Toolbar for Internet Explorer - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2011-08-24 1299248]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"4StoryPrePatch"=C:\Program Files\Gameforge4D\4Story\PrePatch.exe [2012-01-18 327680]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-26 31016]
"AVG_TRAY"=C:\Program Files\AVG\AVG2012\avgtray.exe [2012-01-24 2416480]
"vProt"=C:\Program Files\AVG Secure Search\vprot.exe [2012-01-16 939872]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-06-09 254696]
"SweetIM"=C:\Program Files\SweetIM\Messenger\SweetIM.exe [2011-08-01 114992]
"ROC_roc_dec12"=C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe [2012-01-16 928096]
"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE [2010-04-12 180224]
"NBAgent"=C:\Program Files\Nero\Nero 11\Nero BackItUp\NBAgent.exe [2011-11-18 1492264]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2011-10-13 19979400]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-08-02 4910912]
"BitTorrent"=C:\Program Files\BitTorrent\BitTorrent.exe [2011-10-27 5960560]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [2010-08-20 33120]

C:\Users\Prochyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MagicDisc.lnk - C:\Program Files\MagicDisc\MagicDisc.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"VIDC.FPS1"=frapsvid.dll
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv
"msacm.vorbis"=vorbis.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-02-04 17:43:21 ----A---- C:\Windows\zip.exe
2012-02-04 17:43:21 ----A---- C:\Windows\SWSC.exe
2012-02-04 17:43:21 ----A---- C:\Windows\SWREG.exe
2012-02-04 17:43:21 ----A---- C:\Windows\sed.exe
2012-02-04 17:43:21 ----A---- C:\Windows\PEV.exe
2012-02-04 17:43:21 ----A---- C:\Windows\MBR.exe
2012-02-04 17:43:21 ----A---- C:\Windows\grep.exe
2012-02-04 17:43:13 ----D---- C:\Windows\ERDNT
2012-02-04 17:43:12 ----SD---- C:\ComboFix
2012-02-04 17:14:53 ----D---- C:\Program Files\trend micro
2012-02-02 19:05:51 ----D---- C:\Program Files\GamePark
2012-02-02 12:03:00 ----A---- C:\Windows\SetACL.exe
2012-02-02 11:48:23 ----D---- C:\Program Files\Qtracker
2012-02-02 10:05:50 ----D---- C:\Program Files\Activision
2012-02-01 22:03:22 ----D---- C:\Users\Prochyn\AppData\Roaming\Nero
2012-02-01 21:53:24 ----D---- C:\ProgramData\Nero
2012-02-01 21:35:48 ----D---- C:\Program Files\Common Files\Nero
2012-02-01 21:29:26 ----A---- C:\Windows\system32\drivers\NBVolUp.sys
2012-02-01 21:29:20 ----DC---- C:\Windows\system32\DRVSTORE
2012-02-01 21:29:20 ----A---- C:\Windows\system32\drivers\NBVol.sys
2012-02-01 21:29:19 ----D---- C:\Program Files\Nero
2012-02-01 21:27:02 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2012-02-01 21:27:02 ----A---- C:\Windows\system32\PresentationHost.exe
2012-02-01 21:27:01 ----A---- C:\Windows\system32\netfxperf.dll
2012-02-01 21:27:01 ----A---- C:\Windows\system32\mscoree.dll
2012-02-01 21:27:01 ----A---- C:\Windows\system32\dfshim.dll
2012-01-31 23:14:25 ----A---- C:\Windows\system32\drivers\mcdbus.sys
2012-01-31 23:14:22 ----D---- C:\Program Files\MagicDisc
2012-01-31 23:11:12 ----D---- C:\Program Files\MagicISO
2012-01-31 22:48:39 ----D---- C:\Program Files\Alcohol Soft
2012-01-31 22:42:50 ----A---- C:\Windows\system32\drivers\sptd.sys
2012-01-31 20:25:36 ----D---- C:\Program Files\PowerISO
2012-01-30 17:31:14 ----D---- C:\Program Files\ASIO4ALL v2
2012-01-30 17:31:06 ----D---- C:\Program Files\VstPlugins
2012-01-30 17:31:06 ----A---- C:\Windows\system32\rewire.dll
2012-01-30 17:30:37 ----D---- C:\Program Files\Outsim
2012-01-30 17:27:45 ----D---- C:\Program Files\Image-Line
2012-01-30 17:27:01 ----A---- C:\Windows\system32\mrvcl32.exe
2012-01-29 22:24:26 ----A---- C:\Windows\LENDIG.sys
2012-01-29 22:24:21 ----D---- C:\Program Files\Steinberg
2012-01-29 21:08:29 ----D---- C:\Program Files\VirtualDJ
2012-01-29 20:54:38 ----D---- C:\Users\Prochyn\AppData\Roaming\com.24veces.oksampler.151ABB9B89C96DCBC4570A9FE5575F3A3D725051.1
2012-01-29 20:54:28 ----D---- C:\Program Files\Common Files\Adobe AIR
2012-01-27 16:03:38 ----D---- C:\AV_LOGS
2012-01-27 16:01:49 ----A---- C:\Windows\system32\drivers\vcsvad.sys
2012-01-26 21:23:56 ----D---- C:\Users\Prochyn\AppData\Roaming\GHISLER
2012-01-26 21:23:56 ----D---- C:\totalcmd
2012-01-26 21:23:56 ----A---- C:\Windows\UC.PIF
2012-01-26 21:23:56 ----A---- C:\Windows\RAR.PIF
2012-01-26 21:23:56 ----A---- C:\Windows\PKZIP.PIF
2012-01-26 21:23:56 ----A---- C:\Windows\PKUNZIP.PIF
2012-01-26 21:23:56 ----A---- C:\Windows\NOCLOSE.PIF
2012-01-26 21:23:56 ----A---- C:\Windows\LHA.PIF
2012-01-26 21:23:56 ----A---- C:\Windows\ARJ.PIF
2012-01-23 20:47:20 ----D---- C:\Users\Prochyn\AppData\Roaming\Tunngle
2012-01-23 20:47:20 ----D---- C:\ProgramData\Tunngle
2012-01-23 20:47:16 ----A---- C:\Windows\system32\drivers\tap0901t.sys
2012-01-23 20:47:15 ----D---- C:\Program Files\Tunngle
2012-01-22 17:30:33 ----D---- C:\Users\Prochyn\AppData\Roaming\.minecraft
2012-01-21 21:53:37 ----AH---- C:\Windows\system32\hamachi.sys
2012-01-15 09:41:35 ----D---- C:\Program Files\2K Games
2012-01-14 17:41:40 ----D---- C:\Windows\system32\appmgmt
2012-01-13 22:03:12 ----D---- C:\Program Files\GameSpy Arcade
2012-01-12 16:43:11 ----D---- C:\Program Files\LogMeIn Hamachi
2012-01-08 13:01:41 ----D---- C:\ProgramData\Uniblue
2012-01-08 11:55:56 ----D---- C:\Program Files\Valve
2012-01-07 14:48:28 ----D---- C:\Program Files\Half-life

======List of files/folders modified in the last 1 month======

2012-02-04 18:38:59 ----D---- C:\Users\Prochyn\AppData\Roaming\BitTorrent
2012-02-04 18:14:34 ----D---- C:\Users\Prochyn\AppData\Roaming\Skype
2012-02-04 18:02:40 ----D---- C:\Windows\Temp
2012-02-04 17:57:41 ----D---- C:\ProgramData\NVIDIA
2012-02-04 17:53:59 ----D---- C:\Windows\system32\wfp
2012-02-04 17:53:57 ----D---- C:\Windows\system32\wbem
2012-02-04 17:53:57 ----D---- C:\Windows
2012-02-04 17:52:59 ----D---- C:\Windows\system32\config
2012-02-04 17:52:48 ----D---- C:\Windows\Tasks
2012-02-04 17:52:48 ----D---- C:\Windows\system32\DriverStore
2012-02-04 17:52:48 ----D---- C:\Windows\system32\catroot2
2012-02-04 17:52:48 ----D---- C:\Windows\System32
2012-02-04 17:52:42 ----D---- C:\Windows\registration
2012-02-04 17:50:52 ----SHD---- C:\System Volume Information
2012-02-04 17:49:37 ----D---- C:\ProgramData\DAEMON Tools Lite
2012-02-04 17:43:33 ----D---- C:\Qoobox
2012-02-04 17:42:48 ----D---- C:\Windows\system32\drivers
2012-02-04 17:16:26 ----D---- C:\Windows\inf
2012-02-04 17:16:26 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-02-04 17:14:53 ----RD---- C:\Program Files
2012-02-04 17:14:30 ----D---- C:\Windows\Prefetch
2012-02-04 10:08:00 ----A---- C:\Windows\system32\PnkBstrB.exe
2012-02-04 08:03:20 ----D---- C:\ProgramData\MFAData
2012-02-04 08:03:16 ----D---- C:\Windows\system32\drivers\AVG
2012-02-02 19:16:11 ----A---- C:\Windows\system32\PnkBstrA.exe
2012-02-02 11:32:59 ----SHD---- C:\Windows\Installer
2012-02-02 11:32:52 ----D---- C:\Config.Msi
2012-02-02 11:09:20 ----RSD---- C:\Windows\assembly
2012-02-02 10:12:59 ----A---- C:\Windows\game.ini
2012-02-02 10:12:54 ----HD---- C:\Program Files\InstallShield Installation Information
2012-02-02 00:04:23 ----D---- C:\Windows\Microsoft.NET
2012-02-01 22:01:56 ----D---- C:\Windows\Cursors
2012-02-01 21:53:24 ----HD---- C:\ProgramData
2012-02-01 21:41:55 ----D---- C:\Windows\winsxs
2012-02-01 21:35:48 ----D---- C:\Program Files\Common Files
2012-02-01 21:29:26 ----D---- C:\Windows\system32\catroot
2012-02-01 21:27:33 ----D---- C:\Windows\system32\en-US
2012-02-01 21:27:32 ----D---- C:\Program Files\Microsoft.NET
2012-02-01 21:27:18 ----D---- C:\Windows\SoftwareDistribution
2012-02-01 21:23:47 ----D---- C:\Windows\Logs
2012-01-30 18:54:30 ----SD---- C:\ProgramData\Microsoft
2012-01-29 21:08:33 ----SD---- C:\Users\Prochyn\AppData\Roaming\Microsoft
2012-01-29 21:08:30 ----RSD---- C:\Windows\Fonts
2012-01-29 20:54:38 ----D---- C:\ProgramData\Adobe
2012-01-29 20:54:28 ----D---- C:\Program Files\Adobe
2012-01-29 20:54:03 ----D---- C:\Users\Prochyn\AppData\Roaming\Adobe
2012-01-27 12:08:33 ----D---- C:\Program Files\Opera
2012-01-17 07:06:32 ----D---- C:\Windows\system32\NDF
2012-01-16 17:30:35 ----D---- C:\ProgramData\AVG Secure Search
2012-01-16 17:30:34 ----D---- C:\Program Files\AVG Secure Search
2012-01-15 09:41:15 ----D---- C:\Users\Prochyn\AppData\Roaming\DAEMON Tools Lite
2012-01-14 20:17:29 ----D---- C:\Users\Prochyn\AppData\Roaming\TS3Client
2012-01-14 17:41:49 ----D---- C:\Windows\system32\Tasks
2012-01-14 17:40:54 ----D---- C:\Program Files\Pando Networks
2012-01-14 17:29:50 ----D---- C:\Windows\system32\drivers\etc
2012-01-14 17:29:48 ----D---- C:\Windows\system32\drivers\UMDF
2012-01-14 17:29:47 ----D---- C:\Windows\AppCompat
2012-01-14 17:29:45 ----D---- C:\Program Files\Common Files\AVG Secure Search
2012-01-14 17:24:40 ----D---- C:\Users\Prochyn\AppData\Roaming\Opera
2012-01-05 19:43:19 ----D---- C:\Program Files\Common Files\Steam

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSEH;AVGIDSEH; C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [2011-07-11 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx86.sys [2011-09-13 32592]
R0 NBVol;Nero Backup Volume Filter Driver; C:\Windows\system32\DRIVERS\NBVol.sys [2011-12-01 56496]
R0 NBVolUp;Nero Backup Volume Upper Filter Driver; C:\Windows\system32\DRIVERS\NBVolUp.sys [2011-12-01 12464]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2012-01-31 428088]
R1 Avgldx86;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx86.sys [2011-10-07 230608]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx86.sys [2011-08-08 40016]
R1 Avgtdix;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdix.sys [2011-07-11 295248]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-10-21 232512]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2010-04-12 59388]
R2 ASMMAP;ASMMAP; \??\C:\Program Files\Lenovo\ATK Hotkey\ASMMAP.sys [2007-07-24 13880]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2009-09-07 48128]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2009-09-15 44544]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2009-09-15 38400]
R3 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [2011-07-11 134736]
R3 AVGIDSFilter;AVGIDSFilter; C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [2011-07-11 24272]
R3 AVGIDSShim;AVGIDSShim; C:\Windows\system32\DRIVERS\AVGIDSShim.Sys [2011-10-04 16720]
R3 DCamUSBGene;Integrated Camera; C:\Windows\system32\DRIVERS\usbstk.sys [2008-07-31 173584]
R3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\Windows\system32\DRIVERS\mcdbus.sys [2009-02-24 116736]
R3 MTsensor32;PU ACPI UTILITY; C:\Windows\system32\DRIVERS\PuAcpi32.sys [2009-06-04 14344]
R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2011-05-10 139368]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-07-14 84992]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\Windows\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM); C:\Windows\system32\DRIVERS\vcsvad.sys [2008-12-10 17792]
R3 WinUsb;WinUSB Driver; C:\Windows\system32\DRIVERS\WinUSB.sys [2009-07-14 34944]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 aqumjg1v;aqumjg1v; C:\Windows\system32\drivers\aqumjg1v.sys []
S3 asur4cax;asur4cax; C:\Windows\system32\drivers\asur4cax.sys []
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 78336]
S3 EagleXNt;EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys []
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files\Garena Classic\safedrv.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-09-23 26176]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
R2 ASLDRService;ASLDR Service; C:\Program Files\Lenovo\ATK Hotkey\ASLDRSrv.exe [2009-02-13 94208]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\Lenovo\ATK Hotkey\GFNEXSrv.exe [2009-02-13 94208]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 LFKAS;Service of LFKA; C:\Program Files\Lenovo\ATK Hotkey\LFKAS.exe [2009-04-15 208896]
R2 NAUpdate;@C:\Program Files\Nero\Update\NASvc.exe,-200; C:\Program Files\Nero\Update\NASvc.exe [2011-11-25 687400]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2011-08-03 599144]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-08-03 2255464]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2012-02-02 75136]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-08-03 379496]
R2 vToolbarUpdater;vToolbarUpdater; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe [2012-01-16 909152]
R2 XYNTService;XYNTService; C:\Users\Prochyn\AppData\Local\Temp\{4C75A12E-899F-4069-8C74-5BB5B4EEA4CF}\{061A431C-86E7-4DB4-92B8-36DE783865CF}\STK2135\Win2KXP\stk2135bsrv.exe [2009-03-27 86016]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-12-09 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 gupdatem;Google Update Service (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-12-09 136176]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-26 65824]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\system32\GameMon.des [2011-05-22 4690480]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 TunngleService;TunngleService; C:\Program Files\Tunngle\TnglCtrl.exe [2011-12-12 751464]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119515
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vir v PC

#2 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Program Files\SweetIM
C:\Program Files\BitTorrentBar
C:\Program Files\TheBflix
C:\Program Files\BitTorrentBar
C:\Program Files\Skype\Toolbars
C:\Program Files\Google\Update
C:\Users\Prochyn\AppData\Local\Temp\{4C75A12E-899F-4069-8C74-5BB5B4EEA4CF}\{061A431C-86E7-4DB4-92B8-36DE783865CF}\STK2135\Win2KXP\stk2135bsrv.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

:services
gupdate
gupdatem
XYNTService

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0C9F4179-6CE2-4c6a-A3E5-67FF3592A12E}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"=-
"{EEE6C35B-6118-11DC-9C72-001320C79847}"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SweetIM"=-

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na MoveIt!. Po skenu restartujte PC.
Dnes jste dělal sken ComboFix. Rád bych viděl log z něho. Najdete ho v C:\combofix.txt.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

prochyn.vit
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 04 úno 2012 18:31

Re: Vir v PC

#3 Příspěvek od prochyn.vit »

v combofix jsem se snazil udelat ale jelikoz se pri instalaci parkrat ukazala tabulka ze se nejde neco nainstalovat a ja dal ignorovat tak asi instalace nebyla uplna ted udelam to otm.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119515
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vir v PC

#4 Příspěvek od Rudy »

OK.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

prochyn.vit
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 04 úno 2012 18:31

Re: Vir v PC

#5 Příspěvek od prochyn.vit »

PROBLEM PRETRVAVA ..MOZNA JE TO JESTE HORSI ...mam se pokusit udelat log z combofix

prochyn.vit
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 04 úno 2012 18:31

Re: Vir v PC

#6 Příspěvek od prochyn.vit »

ComboFix 12-02-03.02 - Prochyn 02/04/2012 19:56:25.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3071.2125 [GMT 1:00]
Running from: c:\users\Prochyn\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\RECYCLER(2)
c:\recycler(2)\S-1-5-21-973156877-1925734409-459318573-1006(2)\Dc2.rar
c:\recycler(2)\S-1-5-21-973156877-1925734409-459318573-1006(2)\Dc5.iso
c:\recycler(2)\S-1-5-21-973156877-1925734409-459318573-1006(2)\INFO2
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
.
.
((((((((((((((((((((((((( Files Created from 2012-01-04 to 2012-02-04 )))))))))))))))))))))))))))))))
.
.
2012-02-04 19:03 . 2012-02-04 19:03 -------- d-----w- c:\users\Prochyn\AppData\Local\temp
2012-02-04 19:03 . 2012-02-04 19:03 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-02-04 19:03 . 2012-02-04 19:03 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-02-04 18:48 . 2012-02-04 18:48 -------- d-----w- c:\program files\AVG Secure Search
2012-02-04 18:38 . 2012-02-04 18:38 -------- d-----w- C:\_OTM
2012-02-04 16:14 . 2012-02-04 17:40 -------- d-----w- c:\program files\trend micro
2012-02-02 18:05 . 2012-02-02 18:05 -------- d-----w- c:\program files\GamePark
2012-02-02 11:03 . 2003-07-14 00:33 163840 ----a-w- c:\windows\SetACL.exe
2012-02-02 10:48 . 2012-02-02 10:48 -------- d-----w- c:\program files\Qtracker
2012-02-02 09:05 . 2012-02-02 09:05 -------- d-----w- c:\program files\Activision
2012-02-01 21:58 . 2012-02-01 22:07 -------- d-----w- c:\users\Prochyn\AppData\Local\Nero
2012-02-01 21:03 . 2012-02-01 21:03 -------- d-----w- c:\users\Prochyn\AppData\Roaming\Nero
2012-02-01 20:53 . 2012-02-01 21:02 -------- d-----w- c:\programdata\Nero
2012-02-01 20:35 . 2012-02-01 20:57 -------- d-----w- c:\program files\Common Files\Nero
2012-02-01 20:29 . 2011-12-01 10:40 12464 ----a-w- c:\windows\system32\drivers\NBVolUp.sys
2012-02-01 20:29 . 2012-02-01 20:29 -------- dc----w- c:\windows\system32\DRVSTORE
2012-02-01 20:29 . 2011-12-01 10:40 56496 ----a-w- c:\windows\system32\drivers\NBVol.sys
2012-02-01 20:29 . 2012-02-01 21:01 -------- d-----w- c:\program files\Nero
2012-02-01 20:27 . 2009-11-25 11:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2012-02-01 20:27 . 2009-11-25 11:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2012-02-01 20:27 . 2009-11-25 11:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2012-02-01 20:27 . 2009-11-25 11:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2012-02-01 20:27 . 2009-11-25 11:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2012-01-31 22:14 . 2009-02-24 17:42 116736 ----a-w- c:\windows\system32\drivers\mcdbus.sys
2012-01-31 22:14 . 2012-01-31 22:15 -------- d-----w- c:\program files\MagicDisc
2012-01-31 22:11 . 2012-01-31 22:11 -------- d-----w- c:\program files\MagicISO
2012-01-31 21:48 . 2012-01-31 21:48 -------- d-----w- c:\program files\Alcohol Soft
2012-01-31 21:42 . 2012-01-31 21:42 428088 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-01-31 19:25 . 2012-01-31 19:25 -------- d-----w- c:\program files\PowerISO
2012-01-30 16:31 . 2012-01-30 16:31 -------- d-----w- c:\program files\ASIO4ALL v2
2012-01-30 16:31 . 2012-01-30 16:31 -------- d-----w- c:\program files\VstPlugins
2012-01-30 16:31 . 2006-06-20 08:56 225280 ----a-w- c:\windows\system32\rewire.dll
2012-01-30 16:30 . 2009-09-15 09:14 1554944 ----a-w- c:\windows\system32\vorbis.acm
2012-01-30 16:30 . 2012-01-30 16:30 -------- d-----w- c:\program files\Outsim
2012-01-30 16:27 . 2012-02-01 22:27 -------- d-----w- c:\program files\Image-Line
2012-01-30 16:27 . 2012-01-30 16:27 679297 ----a-w- c:\windows\system32\mrvcl32.exe
2012-01-29 21:24 . 2006-09-14 00:21 2240 ----a-w- c:\windows\LENDIG.sys
2012-01-29 21:24 . 2012-01-29 21:24 -------- d-----w- c:\program files\Steinberg
2012-01-29 20:08 . 2012-01-29 20:09 -------- d-----w- c:\program files\VirtualDJ
2012-01-29 20:03 . 2012-01-29 20:03 -------- d-----w- c:\users\Prochyn\Mis documentos
2012-01-29 19:54 . 2012-01-29 19:54 -------- d-----w- c:\users\Prochyn\AppData\Roaming\com.24veces.oksampler.151ABB9B89C96DCBC4570A9FE5575F3A3D725051.1
2012-01-29 19:54 . 2012-01-29 19:54 -------- d-----w- c:\program files\Common Files\Adobe AIR
2012-01-27 15:03 . 2012-01-27 15:03 -------- d-----w- C:\AV_LOGS
2012-01-27 15:01 . 2008-12-10 15:56 17792 ----a-w- c:\windows\system32\drivers\vcsvad.sys
2012-01-26 20:23 . 2012-01-26 20:24 -------- d-----w- C:\totalcmd
2012-01-26 20:23 . 2012-01-26 20:23 -------- d-----w- c:\users\Prochyn\AppData\Roaming\GHISLER
2012-01-26 20:23 . 2010-12-17 06:56 545 ----a-w- c:\windows\UC.PIF
2012-01-26 20:23 . 2010-12-17 06:56 545 ----a-w- c:\windows\RAR.PIF
2012-01-26 20:23 . 2010-12-17 06:56 545 ----a-w- c:\windows\NOCLOSE.PIF
2012-01-26 20:23 . 2010-12-17 06:56 545 ----a-w- c:\windows\LHA.PIF
2012-01-26 20:23 . 2010-12-17 06:56 545 ----a-w- c:\windows\ARJ.PIF
2012-01-23 19:47 . 2012-02-03 19:32 -------- d-----w- c:\users\Prochyn\AppData\Roaming\Tunngle
2012-01-23 19:47 . 2012-02-03 18:24 -------- d-----w- c:\programdata\Tunngle
2012-01-23 19:47 . 2009-09-16 06:02 27136 ----a-w- c:\windows\system32\drivers\tap0901t.sys
2012-01-23 19:47 . 2012-01-23 19:48 -------- d-----w- c:\program files\Tunngle
2012-01-22 16:30 . 2012-02-03 10:27 -------- d-----w- c:\users\Prochyn\AppData\Roaming\.minecraft
2012-01-21 20:53 . 2009-03-18 16:35 26176 ---ha-w- c:\windows\system32\hamachi.sys
2012-01-15 09:10 . 2012-01-15 09:10 -------- d-----w- c:\users\Prochyn\AppData\Local\2K Games
2012-01-15 08:41 . 2012-01-15 08:41 -------- d-----w- c:\program files\2K Games
2012-01-13 21:03 . 2012-01-14 16:29 -------- d-----w- c:\program files\GameSpy Arcade
2012-01-12 15:43 . 2012-02-01 22:26 -------- d-----w- c:\program files\LogMeIn Hamachi
2012-01-08 12:01 . 2012-01-08 12:01 -------- d-----w- c:\programdata\Uniblue
2012-01-08 10:55 . 2012-02-01 22:24 -------- d-----w- c:\program files\Valve
2012-01-07 13:48 . 2012-01-14 16:24 -------- d-----w- c:\program files\Half-life
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-04 09:08 . 2011-10-21 15:54 140496 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-02-04 09:08 . 2011-10-21 16:10 280736 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-02-04 09:08 . 2011-10-21 15:53 280736 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-02-04 09:06 . 2011-10-21 15:53 215128 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-02-02 18:16 . 2011-10-21 15:53 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2012-02-02 09:13 . 2011-10-21 15:54 22328 ----a-w- c:\users\Prochyn\AppData\Roaming\PnkBstrK.sys
2012-02-01 20:29 . 2011-10-21 15:58 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-16 21:42 . 2011-11-16 21:42 472808 ----a-w- c:\windows\system32\deployJava1.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2012-02-04 18:48 1811296 ----a-w- c:\program files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll" [2012-02-04 1811296]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 19979400]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-08-02 4910912]
"BitTorrent"="c:\program files\BitTorrent\BitTorrent.exe" [2011-10-27 5960560]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" [2010-08-20 33120]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"4StoryPrePatch"="c:\program files\Gameforge4D\4Story\PrePatch.exe" [2012-01-18 327680]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-01-24 2416480]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-02-04 939872]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2010-04-12 180224]
"NBAgent"="c:\program files\Nero\Nero 11\Nero BackItUp\NBAgent.exe" [2011-11-18 1492264]
.
c:\users\Prochyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2012-1-31 576000]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer3"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files\Garena Classic\safedrv.sys [x]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2011-05-22 4690480]
R3 TunngleService;TunngleService;c:\program files\Tunngle\TnglCtrl.exe [2011-12-12 751464]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2011-07-10 23120]
S0 NBVol;Nero Backup Volume Filter Driver;c:\windows\system32\DRIVERS\NBVol.sys [2011-12-01 56496]
S0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows\system32\DRIVERS\NBVolUp.sys [2011-12-01 12464]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2011-07-10 295248]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-10-21 232512]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776]
S2 LFKAS;Service of LFKA;c:\program files\Lenovo\ATK Hotkey\LFKAS.exe [2009-04-15 208896]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2011-11-25 687400]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-08-03 2255464]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-08-03 379496]
S2 vToolbarUpdater;vToolbarUpdater;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe [2012-01-16 909152]
S3 DCamUSBGene;Integrated Camera;c:\windows\system32\DRIVERS\usbstk.sys [2008-07-31 173584]
S3 MTsensor32;PU ACPI UTILITY;c:\windows\system32\DRIVERS\PuAcpi32.sys [2009-06-04 14344]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2011-05-10 139368]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
S3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\system32\DRIVERS\vcsvad.sys [2008-12-10 17792]
.
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.garena.com/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Search the Web - c:\program files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
TCP: DhcpNameServer = 10.0.0.138
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\10.0.6\ViProtocol.dll
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file)
URLSearchHooks-{EEE6C35D-6118-11DC-9C72-001320C79847} - c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
WebBrowser-{88C7F2AA-F93F-432C-8F0E-B7D85967A527} - (no file)
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
HKLM-Run-ROC_roc_dec12 - c:\program files\AVG Secure Search\ROC_roc_dec12.exe
AddRemove-BitTorrentBar Toolbar - c:\program files\BitTorrentBar\uninstall.exe
AddRemove-TheBflix - c:\program files\TheBflix\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1713205610-778408625-3204417612-1000\Software\SecuROM\License information*]
"datasecu"=hex:0b,62,42,e4,99,66,35,2a,2b,2c,f1,f2,36,ae,dc,d2,45,14,9c,7c,a3,
2a,2f,48,ba,23,f0,6f,e4,cc,bc,ac,d8,a3,f5,b3,de,61,54,80,a7,c4,df,a3,59,90,\
"rkeysecu"=hex:f7,7d,0c,a6,f6,df,04,a3,90,9e,61,08,32,84,8f,1b
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-02-04 20:04:36
ComboFix-quarantined-files.txt 2012-02-04 19:04
ComboFix2.txt 2011-09-04 18:34
ComboFix3.txt 2011-09-04 15:37
ComboFix4.txt 2011-08-30 18:49
ComboFix5.txt 2012-02-04 16:43
.
Pre-Run: Volných bajtu: 25,557,233,664
Post-Run: Volných bajtu: 27,734,851,584
.
- - End Of File - - 7D0636A8B889114603439112FB58CE8A
zde je log

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119515
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vir v PC

#7 Příspěvek od Rudy »

Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:
RegLock::
[HKEY_USERS\S-1-5-21-1713205610-778408625-3204417612-1000\Software\SecuROM\License information*]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
Uložte na plochu jako CFScript.txt. pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

prochyn.vit
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 04 úno 2012 18:31

Re: Vir v PC

#8 Příspěvek od prochyn.vit »

ComboFix 12-02-03.02 - Prochyn 02/04/2012 20:57:28.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3071.1947 [GMT 1:00]
Running from: c:\users\Prochyn\Desktop\ComboFix.exe
Command switches used :: c:\users\Prochyn\Desktop\CFScript.txt
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2012-01-04 to 2012-02-04 )))))))))))))))))))))))))))))))
.
.
2012-02-04 20:03 . 2012-02-04 20:03 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-02-04 20:03 . 2012-02-04 20:03 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-02-04 20:03 . 2012-02-04 20:03 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2012-02-04 19:04 . 2012-02-04 20:03 -------- d-----w- c:\users\Prochyn\AppData\Local\temp
2012-02-04 18:48 . 2012-02-04 18:48 -------- d-----w- c:\program files\AVG Secure Search
2012-02-04 18:38 . 2012-02-04 18:38 -------- d-----w- C:\_OTM
2012-02-04 16:14 . 2012-02-04 17:40 -------- d-----w- c:\program files\trend micro
2012-02-02 18:05 . 2012-02-02 18:05 -------- d-----w- c:\program files\GamePark
2012-02-02 11:03 . 2003-07-14 00:33 163840 ----a-w- c:\windows\SetACL.exe
2012-02-02 10:48 . 2012-02-02 10:48 -------- d-----w- c:\program files\Qtracker
2012-02-02 09:05 . 2012-02-02 09:05 -------- d-----w- c:\program files\Activision
2012-02-01 21:58 . 2012-02-01 22:07 -------- d-----w- c:\users\Prochyn\AppData\Local\Nero
2012-02-01 21:03 . 2012-02-01 21:03 -------- d-----w- c:\users\Prochyn\AppData\Roaming\Nero
2012-02-01 20:53 . 2012-02-01 21:02 -------- d-----w- c:\programdata\Nero
2012-02-01 20:35 . 2012-02-01 20:57 -------- d-----w- c:\program files\Common Files\Nero
2012-02-01 20:29 . 2011-12-01 10:40 12464 ----a-w- c:\windows\system32\drivers\NBVolUp.sys
2012-02-01 20:29 . 2012-02-01 20:29 -------- dc----w- c:\windows\system32\DRVSTORE
2012-02-01 20:29 . 2011-12-01 10:40 56496 ----a-w- c:\windows\system32\drivers\NBVol.sys
2012-02-01 20:29 . 2012-02-01 21:01 -------- d-----w- c:\program files\Nero
2012-02-01 20:27 . 2009-11-25 11:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2012-02-01 20:27 . 2009-11-25 11:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2012-02-01 20:27 . 2009-11-25 11:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2012-02-01 20:27 . 2009-11-25 11:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2012-02-01 20:27 . 2009-11-25 11:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2012-01-31 22:14 . 2009-02-24 17:42 116736 ----a-w- c:\windows\system32\drivers\mcdbus.sys
2012-01-31 22:14 . 2012-01-31 22:15 -------- d-----w- c:\program files\MagicDisc
2012-01-31 22:11 . 2012-01-31 22:11 -------- d-----w- c:\program files\MagicISO
2012-01-31 21:48 . 2012-01-31 21:48 -------- d-----w- c:\program files\Alcohol Soft
2012-01-31 21:42 . 2012-01-31 21:42 428088 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-01-31 19:25 . 2012-01-31 19:25 -------- d-----w- c:\program files\PowerISO
2012-01-30 16:31 . 2012-01-30 16:31 -------- d-----w- c:\program files\ASIO4ALL v2
2012-01-30 16:31 . 2012-01-30 16:31 -------- d-----w- c:\program files\VstPlugins
2012-01-30 16:31 . 2006-06-20 08:56 225280 ----a-w- c:\windows\system32\rewire.dll
2012-01-30 16:30 . 2009-09-15 09:14 1554944 ----a-w- c:\windows\system32\vorbis.acm
2012-01-30 16:30 . 2012-01-30 16:30 -------- d-----w- c:\program files\Outsim
2012-01-30 16:27 . 2012-02-01 22:27 -------- d-----w- c:\program files\Image-Line
2012-01-30 16:27 . 2012-01-30 16:27 679297 ----a-w- c:\windows\system32\mrvcl32.exe
2012-01-29 21:24 . 2006-09-14 00:21 2240 ----a-w- c:\windows\LENDIG.sys
2012-01-29 21:24 . 2012-01-29 21:24 -------- d-----w- c:\program files\Steinberg
2012-01-29 20:08 . 2012-01-29 20:09 -------- d-----w- c:\program files\VirtualDJ
2012-01-29 20:03 . 2012-01-29 20:03 -------- d-----w- c:\users\Prochyn\Mis documentos
2012-01-29 19:54 . 2012-01-29 19:54 -------- d-----w- c:\users\Prochyn\AppData\Roaming\com.24veces.oksampler.151ABB9B89C96DCBC4570A9FE5575F3A3D725051.1
2012-01-29 19:54 . 2012-01-29 19:54 -------- d-----w- c:\program files\Common Files\Adobe AIR
2012-01-27 15:03 . 2012-01-27 15:03 -------- d-----w- C:\AV_LOGS
2012-01-27 15:01 . 2008-12-10 15:56 17792 ----a-w- c:\windows\system32\drivers\vcsvad.sys
2012-01-26 20:23 . 2012-01-26 20:24 -------- d-----w- C:\totalcmd
2012-01-26 20:23 . 2012-01-26 20:23 -------- d-----w- c:\users\Prochyn\AppData\Roaming\GHISLER
2012-01-26 20:23 . 2010-12-17 06:56 545 ----a-w- c:\windows\UC.PIF
2012-01-26 20:23 . 2010-12-17 06:56 545 ----a-w- c:\windows\RAR.PIF
2012-01-26 20:23 . 2010-12-17 06:56 545 ----a-w- c:\windows\NOCLOSE.PIF
2012-01-26 20:23 . 2010-12-17 06:56 545 ----a-w- c:\windows\LHA.PIF
2012-01-26 20:23 . 2010-12-17 06:56 545 ----a-w- c:\windows\ARJ.PIF
2012-01-23 19:47 . 2012-02-03 19:32 -------- d-----w- c:\users\Prochyn\AppData\Roaming\Tunngle
2012-01-23 19:47 . 2012-02-03 18:24 -------- d-----w- c:\programdata\Tunngle
2012-01-23 19:47 . 2009-09-16 06:02 27136 ----a-w- c:\windows\system32\drivers\tap0901t.sys
2012-01-23 19:47 . 2012-01-23 19:48 -------- d-----w- c:\program files\Tunngle
2012-01-22 16:30 . 2012-02-03 10:27 -------- d-----w- c:\users\Prochyn\AppData\Roaming\.minecraft
2012-01-21 20:53 . 2009-03-18 16:35 26176 ---ha-w- c:\windows\system32\hamachi.sys
2012-01-15 09:10 . 2012-01-15 09:10 -------- d-----w- c:\users\Prochyn\AppData\Local\2K Games
2012-01-15 08:41 . 2012-01-15 08:41 -------- d-----w- c:\program files\2K Games
2012-01-13 21:03 . 2012-01-14 16:29 -------- d-----w- c:\program files\GameSpy Arcade
2012-01-12 15:43 . 2012-02-01 22:26 -------- d-----w- c:\program files\LogMeIn Hamachi
2012-01-08 12:01 . 2012-01-08 12:01 -------- d-----w- c:\programdata\Uniblue
2012-01-08 10:55 . 2012-02-01 22:24 -------- d-----w- c:\program files\Valve
2012-01-07 13:48 . 2012-01-14 16:24 -------- d-----w- c:\program files\Half-life
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-04 19:53 . 2011-10-21 15:54 140496 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-02-04 19:53 . 2011-10-21 16:10 280736 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-02-04 19:53 . 2011-10-21 15:53 280736 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-02-04 19:52 . 2011-10-21 15:53 215128 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-02-02 18:16 . 2011-10-21 15:53 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2012-02-02 09:13 . 2011-10-21 15:54 22328 ----a-w- c:\users\Prochyn\AppData\Roaming\PnkBstrK.sys
2012-02-01 20:29 . 2011-10-21 15:58 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-16 21:42 . 2011-11-16 21:42 472808 ----a-w- c:\windows\system32\deployJava1.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2012-02-04 18:48 1811296 ----a-w- c:\program files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll" [2012-02-04 1811296]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 19979400]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-08-02 4910912]
"BitTorrent"="c:\program files\BitTorrent\BitTorrent.exe" [2011-10-27 5960560]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" [2010-08-20 33120]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"4StoryPrePatch"="c:\program files\Gameforge4D\4Story\PrePatch.exe" [2012-01-18 327680]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-01-24 2416480]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-02-04 939872]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2010-04-12 180224]
"NBAgent"="c:\program files\Nero\Nero 11\Nero BackItUp\NBAgent.exe" [2011-11-18 1492264]
.
c:\users\Prochyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2012-1-31 576000]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer3"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files\Garena Classic\safedrv.sys [x]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2011-05-22 4690480]
R3 TunngleService;TunngleService;c:\program files\Tunngle\TnglCtrl.exe [2011-12-12 751464]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2011-07-10 23120]
S0 NBVol;Nero Backup Volume Filter Driver;c:\windows\system32\DRIVERS\NBVol.sys [2011-12-01 56496]
S0 NBVolUp;Nero Backup Volume Upper Filter Driver;c:\windows\system32\DRIVERS\NBVolUp.sys [2011-12-01 12464]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2011-07-10 295248]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-10-21 232512]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776]
S2 LFKAS;Service of LFKA;c:\program files\Lenovo\ATK Hotkey\LFKAS.exe [2009-04-15 208896]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2011-11-25 687400]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-08-03 2255464]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-08-03 379496]
S2 vToolbarUpdater;vToolbarUpdater;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe [2012-01-16 909152]
S3 DCamUSBGene;Integrated Camera;c:\windows\system32\DRIVERS\usbstk.sys [2008-07-31 173584]
S3 MTsensor32;PU ACPI UTILITY;c:\windows\system32\DRIVERS\PuAcpi32.sys [2009-06-04 14344]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2011-05-10 139368]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
S3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\system32\DRIVERS\vcsvad.sys [2008-12-10 17792]
.
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.garena.com/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Search the Web - c:\program files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
TCP: DhcpNameServer = 10.0.0.138
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\10.0.6\ViProtocol.dll
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1713205610-778408625-3204417612-1000\Software\SecuROM\License information*]
"datasecu"=hex:0b,62,42,e4,99,66,35,2a,2b,2c,f1,f2,36,ae,dc,d2,45,14,9c,7c,a3,
2a,2f,48,ba,23,f0,6f,e4,cc,bc,ac,d8,a3,f5,b3,de,61,54,80,a7,c4,df,a3,59,90,\
"rkeysecu"=hex:f7,7d,0c,a6,f6,df,04,a3,90,9e,61,08,32,84,8f,1b
.
Completion time: 2012-02-04 21:04:33
ComboFix-quarantined-files.txt 2012-02-04 20:04
ComboFix2.txt 2012-02-04 19:04
ComboFix3.txt 2011-09-04 18:34
ComboFix4.txt 2011-09-04 15:37
ComboFix5.txt 2012-02-04 19:56
.
Pre-Run: Volných bajtu: 27,766,824,960
Post-Run: Volných bajtu: 27,713,323,008
.
- - End Of File - - A63916E31AE1F0A23926B015915E2008




Jeste sem hodim ten posledni LOG takze ted by mel byt PC v pohode ?

prochyn.vit
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 04 úno 2012 18:31

Re: Vir v PC

#9 Příspěvek od prochyn.vit »

problem porad pretrvava kdyz restartnu pocitac vsechno se hodi z5 kdyz jsem udelal ten sfscript nebo jak to je jelo to pekne vsechno restartoval jsem pc a uz to zase nejede ALE POkazde kdyz se zapne combofix staci pak tabulku vypnout tak je vse OK az na to psani ...

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119515
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vir v PC

#10 Příspěvek od Rudy »

Udělejte skem AVPTool: http://www.viry.cz/forum/viewtopic.php?f=29&t=58179 a dejte log.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

prochyn.vit
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 04 úno 2012 18:31

Re: Vir v PC

#11 Příspěvek od prochyn.vit »

Scan delam ale zastavilo se to ve 49% na polozce c:/windows/system32/dllhost.exe mam to nechat bezet ?

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119515
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vir v PC

#12 Příspěvek od Rudy »

Pokud se opravdu zasekl, zrušte a zkuste v nouz. režimu.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

prochyn.vit
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 04 úno 2012 18:31

Re: Vir v PC

#13 Příspěvek od prochyn.vit »

Cas a tak se tam vsechno hybe. Ale uz nejak dlouho je to na jedne polozce.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119515
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vir v PC

#14 Příspěvek od Rudy »

Pokud je to tam více, než takových 20min, resetněte, restartujte a spusťte v nouz. režimu.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

prochyn.vit
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 04 úno 2012 18:31

Re: Vir v PC

#15 Příspěvek od prochyn.vit »

Tak sken v nouzovem rezimu probehl uspesne. Ale jelikoz sem ten prvni sken vypnul tak sem ho neulozil bylo tam detekovano nejakych 14 souboru ale log z toho prvniho scanu nemam ...mam log pouze z druheho scanu z nouzoveho rezimu ktery uz nasel ale jen dva detekovane soubory ...

Status: Detected (events: 2)
2/5/2012 3:50:03 PM Detected Trojan program Trojan.Win32.Chifrax.d F:\Euro Truck Simulator\Euro Truck Simulator.iso//setup.exe.exe High
2/5/2012 3:50:41 PM Detected Trojan program Backdoor.Win32.SdBot.jrr F:\W610i\Euro Truck Simulator 2008 PC\ETS2008.z01//setup.exe High


jinak pocitac se zda byt uz v pohode resetnu a uvidim....

Odpovědět