Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Problém s tzv. Skype virem

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Larsnip
Návštěvník
Návštěvník
Příspěvky: 32
Registrován: 07 říj 2008 15:46

Re: Problém s tzv. Skype virem

#16 Příspěvek od Larsnip »

Tak snad už poslední LOG

RSIT:

Logfile of random's system information tool 1.09 (written by random/random)
Run by Uživatel at 2012-10-10 14:38:50
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 120 GB (50%) free of 238 GB
Total RAM: 2012 MB (45% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:38:52, on 10.10.2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16450)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe
C:\Users\Uživatel\Desktop\RSIT.exe
C:\Program Files\trend micro\Uživatel.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {472734EA-242A-422b-ADF8-83D1E48CC825} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

--
End of file - 6067 bytes

=========Mozilla firefox=========

ProfilePath - C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\22kf9mou.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "{20a82645-c095-46ed-80e3-08825760534b}:1.1, {4B3803EA-5230-4DC3-A7FC-33638F3D3542}:1.4, dealio@mybrowserbar.com:4.4, wtxpcom@mybrowserbar.com:4.4, wrc@avast.com:20110101, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"

"{20a82645-c095-46ed-80e3-08825760534b}"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}"=C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.265 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.7.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@ngm.nexoneu.com/NxGame]
"Description"=Nexon Game Controller
"Path"=C:\ProgramData\NexonEU\NGM\npNxGameeu.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
npijjiFFPlugin1.xpt

C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
npijjiFFPlugin1.dll
nppdf32.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
yahoo.xml

C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\22kf9mou.default\extensions\
jid1-uabu5A9hduqzCw@jetpack
{2458abc0-f443-11dd-87af-0800200c9a66}
{5e5ab302-7f65-44cd-8211-c1d4caaccea3}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-03-26 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-09-01 449512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2012-03-08 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-12-21 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-09-01 157672]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-08-18 7711264]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-02-11 171032]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]

C:\Users\Uživatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk - C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-02-11 228864]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=149
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe"="C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3"
"C:\Users\Uživatel\Desktop\P17535732.JPG-www.facebook.exe"="C:\Windows\nvsvc32.exe:*:Enabled:NVIDIA driver monitor"
"C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe"="C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe:*:Enabled:NEXON_EU_Downloader_Engine.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"VIDC.FPS1"=frapsvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.ACDV"=ACDV.dll
"msacm.lhacm"=lhacm.acm
"msacm.siren"=sirenacm.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2012-10-10 08:16:59 ----AC---- C:\AdwCleaner[S1].txt
2012-10-09 16:06:59 ----AC---- C:\AdwCleaner[R1].txt
2012-10-09 13:00:51 ----D---- C:\Windows\temp
2012-10-09 13:00:49 ----AC---- C:\ComboFix.txt
2012-10-09 12:57:35 ----DC---- C:\$RECYCLE.BIN
2012-10-09 12:50:40 ----DC---- C:\ComboFix
2012-10-09 10:59:17 ----A---- C:\Windows\zip.exe
2012-10-09 10:59:17 ----A---- C:\Windows\SWSC.exe
2012-10-09 10:59:17 ----A---- C:\Windows\SWREG.exe
2012-10-09 10:59:17 ----A---- C:\Windows\sed.exe
2012-10-09 10:59:17 ----A---- C:\Windows\PEV.exe
2012-10-09 10:59:17 ----A---- C:\Windows\NIRCMD.exe
2012-10-09 10:59:17 ----A---- C:\Windows\MBR.exe
2012-10-09 10:59:17 ----A---- C:\Windows\grep.exe
2012-10-09 10:59:13 ----DC---- C:\Qoobox
2012-10-09 10:58:16 ----R---- C:\ComboFix.exe
2012-10-08 14:06:33 ----D---- C:\Program Files\trend micro
2012-10-08 14:06:32 ----DC---- C:\rsit
2012-10-08 13:56:11 ----D---- C:\Users\Uživatel\AppData\Roaming\Malwarebytes
2012-10-08 13:56:05 ----D---- C:\ProgramData\Malwarebytes
2012-10-08 13:56:04 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2012-10-08 13:56:04 ----A---- C:\Windows\system32\drivers\mbam.sys
2012-10-08 12:57:21 ----A---- C:\Windows\system32\XpsPrint.dll
2012-10-07 17:25:15 ----A---- C:\Windows\system32\FntCache.dll
2012-10-07 17:25:14 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2012-10-07 17:25:05 ----A---- C:\Windows\system32\gameux.dll
2012-10-07 17:25:03 ----A---- C:\Windows\system32\Apphlpdm.dll
2012-10-07 17:25:01 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2012-10-07 17:24:53 ----A---- C:\Windows\system32\kernel32.dll
2012-10-07 17:22:50 ----A---- C:\Windows\system32\xmllite.dll
2012-10-07 17:05:30 ----A---- C:\Windows\system32\psisdecd.dll
2012-10-07 17:05:27 ----A---- C:\Windows\system32\winmm.dll
2012-10-07 17:05:26 ----A---- C:\Windows\system32\mciseq.dll
2012-10-07 17:05:20 ----A---- C:\Windows\system32\odbc32.dll
2012-10-07 16:55:24 ----D---- C:\Program Files\MSECache
2012-10-07 16:08:44 ----A---- C:\Windows\system32\wmi.dll
2012-10-07 16:08:44 ----A---- C:\Windows\system32\wintrust.dll
2012-10-07 16:08:44 ----A---- C:\Windows\system32\imagehlp.dll
2012-10-07 16:08:44 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2012-10-07 16:00:25 ----A---- C:\Windows\system32\win32k.sys
2012-10-07 15:59:38 ----A---- C:\Windows\system32\wininet.dll
2012-10-07 15:59:38 ----A---- C:\Windows\system32\urlmon.dll
2012-10-07 15:59:38 ----A---- C:\Windows\system32\url.dll
2012-10-07 15:59:38 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2012-10-07 15:59:38 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2012-10-07 15:59:38 ----A---- C:\Windows\system32\msrating.dll
2012-10-07 15:59:38 ----A---- C:\Windows\system32\msls31.dll
2012-10-07 15:59:38 ----A---- C:\Windows\system32\mshtmler.dll
2012-10-07 15:59:38 ----A---- C:\Windows\system32\jsproxy.dll
2012-10-07 15:59:38 ----A---- C:\Windows\system32\ieui.dll
2012-10-07 15:59:38 ----A---- C:\Windows\system32\iesysprep.dll
2012-10-07 15:59:38 ----A---- C:\Windows\system32\iesetup.dll
2012-10-07 15:59:38 ----A---- C:\Windows\system32\iertutil.dll
2012-10-07 15:59:38 ----A---- C:\Windows\system32\iernonce.dll
2012-10-07 15:59:38 ----A---- C:\Windows\system32\ieframe.dll
2012-10-07 15:59:38 ----A---- C:\Windows\system32\ieapfltr.dll
2012-10-07 15:59:38 ----A---- C:\Windows\system32\ieapfltr.dat
2012-10-07 15:59:38 ----A---- C:\Windows\system32\ie4uinit.exe
2012-10-07 15:59:38 ----A---- C:\Windows\system32\icardie.dll
2012-10-07 15:59:38 ----A---- C:\Windows\system32\dxtrans.dll
2012-10-07 15:59:38 ----A---- C:\Windows\system32\dxtmsft.dll
2012-10-07 15:59:37 ----A---- C:\Windows\system32\wextract.exe
2012-10-07 15:59:37 ----A---- C:\Windows\system32\webcheck.dll
2012-10-07 15:59:37 ----A---- C:\Windows\system32\vbscript.dll
2012-10-07 15:59:37 ----A---- C:\Windows\system32\pngfilt.dll
2012-10-07 15:59:37 ----A---- C:\Windows\system32\occache.dll
2012-10-07 15:59:37 ----A---- C:\Windows\system32\mshtmled.dll
2012-10-07 15:59:37 ----A---- C:\Windows\system32\mshtml.dll
2012-10-07 15:59:37 ----A---- C:\Windows\system32\mshta.exe
2012-10-07 15:59:37 ----A---- C:\Windows\system32\msfeedssync.exe
2012-10-07 15:59:37 ----A---- C:\Windows\system32\msfeedsbs.dll
2012-10-07 15:59:37 ----A---- C:\Windows\system32\msfeeds.dll
2012-10-07 15:59:37 ----A---- C:\Windows\system32\licmgr10.dll
2012-10-07 15:59:37 ----A---- C:\Windows\system32\jscript9.dll
2012-10-07 15:59:37 ----A---- C:\Windows\system32\jscript.dll
2012-10-07 15:59:37 ----A---- C:\Windows\system32\inseng.dll
2012-10-07 15:59:37 ----A---- C:\Windows\system32\imgutil.dll
2012-10-07 15:59:37 ----A---- C:\Windows\system32\iexpress.exe
2012-10-07 15:59:37 ----A---- C:\Windows\system32\ieUnatt.exe
2012-10-07 15:59:37 ----A---- C:\Windows\system32\iepeers.dll
2012-10-07 15:59:37 ----A---- C:\Windows\system32\iedkcs32.dll
2012-10-07 15:59:37 ----A---- C:\Windows\system32\ieakui.dll
2012-10-07 15:59:37 ----A---- C:\Windows\system32\ieaksie.dll
2012-10-07 15:59:37 ----A---- C:\Windows\system32\ieakeng.dll
2012-10-07 15:59:37 ----A---- C:\Windows\system32\IEAdvpack.dll
2012-10-07 15:59:37 ----A---- C:\Windows\system32\advpack.dll
2012-10-07 15:59:37 ----A---- C:\Windows\system32\admparse.dll
2012-10-07 15:58:43 ----A---- C:\Windows\system32\MFHEAACdec.dll
2012-10-07 15:58:43 ----A---- C:\Windows\system32\MFH264Dec.dll
2012-10-07 15:58:42 ----A---- C:\Windows\system32\stobject.dll
2012-10-07 15:58:42 ----A---- C:\Windows\system32\shdocvw.dll
2012-10-07 15:58:42 ----A---- C:\Windows\system32\mfreadwrite.dll
2012-10-07 15:58:42 ----A---- C:\Windows\system32\mfps.dll
2012-10-07 15:58:42 ----A---- C:\Windows\system32\mfplat.dll
2012-10-07 15:58:42 ----A---- C:\Windows\system32\mfmp4src.dll
2012-10-07 15:58:42 ----A---- C:\Windows\system32\mf.dll
2012-10-07 15:58:41 ----A---- C:\Windows\system32\XpsRasterService.dll
2012-10-07 15:58:41 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2012-10-07 15:58:41 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2012-10-07 15:58:41 ----A---- C:\Windows\system32\dxgi.dll
2012-10-07 15:58:41 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2012-10-07 15:58:41 ----A---- C:\Windows\system32\d3d10level9.dll
2012-10-07 15:58:41 ----A---- C:\Windows\system32\d3d10core.dll
2012-10-07 15:58:41 ----A---- C:\Windows\system32\d3d10.dll
2012-10-07 15:58:41 ----A---- C:\Windows\system32\cdd.dll
2012-10-07 15:58:40 ----A---- C:\Windows\system32\xpsservices.dll
2012-10-07 15:58:40 ----A---- C:\Windows\system32\OpcServices.dll
2012-10-07 15:36:18 ----A---- C:\Windows\system32\atmfd.dll
2012-10-07 15:36:17 ----A---- C:\Windows\system32\fontsub.dll
2012-10-07 15:36:16 ----A---- C:\Windows\system32\atmlib.dll
2012-10-07 15:35:39 ----A---- C:\Windows\system32\localspl.dll
2012-10-07 15:35:19 ----A---- C:\Windows\system32\mfc42u.dll
2012-10-07 15:35:18 ----A---- C:\Windows\system32\mfc42.dll
2012-10-07 15:34:57 ----A---- C:\Windows\system32\crypt32.dll
2012-10-07 15:34:56 ----A---- C:\Windows\system32\cryptsvc.dll
2012-10-07 15:34:56 ----A---- C:\Windows\system32\cryptnet.dll
2012-10-07 15:34:25 ----A---- C:\Windows\system32\drivers\bowser.sys
2012-10-07 15:34:04 ----A---- C:\Windows\system32\drivers\dfsc.sys
2012-10-07 15:33:56 ----A---- C:\Windows\system32\drivers\srv.sys
2012-10-07 15:33:49 ----A---- C:\Windows\system32\ntdll.dll
2012-10-07 15:33:45 ----A---- C:\Windows\system32\netapi32.dll
2012-10-07 15:33:40 ----A---- C:\Windows\system32\iphlpsvc.dll
2012-10-07 15:33:40 ----A---- C:\Windows\system32\drivers\tunnel.sys
2012-10-07 15:31:01 ----A---- C:\Windows\system32\shsvcs.dll
2012-10-07 15:30:32 ----A---- C:\Windows\system32\UIAutomationCore.dll
2012-10-07 15:30:32 ----A---- C:\Windows\system32\oleaut32.dll
2012-10-07 15:30:32 ----A---- C:\Windows\system32\oleacc.dll
2012-10-07 15:30:31 ----A---- C:\Windows\system32\oleaccrc.dll
2012-10-07 15:28:39 ----A---- C:\Windows\system32\drivers\tcpip.sys
2012-10-07 15:28:35 ----A---- C:\Windows\system32\msxml6.dll
2012-10-07 15:28:34 ----A---- C:\Windows\system32\msxml3.dll
2012-10-07 15:28:31 ----A---- C:\Windows\system32\drivers\srvnet.sys
2012-10-07 15:28:31 ----A---- C:\Windows\system32\drivers\srv2.sys
2012-10-07 15:28:25 ----A---- C:\Windows\system32\taskschd.dll
2012-10-07 15:28:25 ----A---- C:\Windows\system32\schedsvc.dll
2012-10-07 15:28:24 ----A---- C:\Windows\system32\wmicmiplugin.dll
2012-10-07 15:28:24 ----A---- C:\Windows\system32\taskeng.exe
2012-10-07 15:28:24 ----A---- C:\Windows\system32\taskcomp.dll
2012-10-07 15:28:10 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2012-10-07 15:27:40 ----A---- C:\Windows\system32\drivers\afd.sys
2012-10-07 15:27:26 ----A---- C:\Windows\system32\shell32.dll
2012-10-07 15:27:19 ----A---- C:\Windows\system32\EncDec.dll
2012-10-07 15:27:17 ----A---- C:\Windows\system32\inetcomm.dll
2012-10-07 15:27:16 ----A---- C:\Windows\system32\consent.exe
2012-10-07 15:27:14 ----A---- C:\Windows\system32\sdclt.exe
2012-10-07 15:27:11 ----A---- C:\Windows\system32\dnsrslvr.dll
2012-10-07 15:27:11 ----A---- C:\Windows\system32\dnsapi.dll
2012-10-07 15:27:10 ----A---- C:\Windows\system32\dnscacheugc.exe
2012-10-07 15:27:09 ----A---- C:\Windows\system32\msvcrt.dll
2012-10-07 15:27:04 ----A---- C:\Windows\system32\tzres.dll
2012-10-07 15:26:34 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-10-07 15:26:34 ----A---- C:\Windows\system32\ntkrnlpa.exe
2012-10-07 15:26:27 ----A---- C:\Windows\system32\shlwapi.dll
2012-10-07 15:26:25 ----A---- C:\Windows\system32\quartz.dll
2012-10-07 15:26:25 ----A---- C:\Windows\system32\qdvd.dll
2012-10-07 15:25:53 ----A---- C:\Windows\system32\winhttp.dll
2012-10-07 15:25:51 ----A---- C:\Windows\system32\DWrite.dll
2012-10-07 15:25:51 ----A---- C:\Windows\system32\d3d10_1core.dll
2012-10-07 15:25:51 ----A---- C:\Windows\system32\d3d10_1.dll
2012-10-07 15:25:51 ----A---- C:\Windows\system32\d2d1.dll
2012-10-07 15:25:50 ----A---- C:\Windows\system32\d3d10warp.dll
2012-10-07 15:25:48 ----A---- C:\Windows\system32\mstscax.dll
2012-10-07 15:25:47 ----A---- C:\Windows\system32\mstsc.exe
2012-10-07 15:25:45 ----A---- C:\Windows\system32\drivers\partmgr.sys
2012-10-07 15:25:41 ----A---- C:\Windows\system32\sbeio.dll
2012-10-07 15:25:41 ----A---- C:\Windows\system32\sbe.dll
2012-10-07 15:25:38 ----A---- C:\Windows\system32\csrsrv.dll
2012-10-07 15:25:35 ----A---- C:\Windows\system32\rdpencom.dll
2012-10-07 15:25:33 ----A---- C:\Windows\system32\packager.dll
2012-10-07 15:25:28 ----A---- C:\Windows\system32\winsrv.dll
2012-10-07 15:25:24 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2012-10-07 15:25:24 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2012-10-07 15:25:24 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2012-10-07 15:16:32 ----A---- C:\Windows\system32\schannel.dll
2012-10-07 15:16:32 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2012-10-07 15:16:31 ----A---- C:\Windows\system32\secur32.dll
2012-10-07 15:16:31 ----A---- C:\Windows\system32\ncrypt.dll
2012-10-07 15:16:31 ----A---- C:\Windows\system32\lsass.exe
2012-10-07 15:16:31 ----A---- C:\Windows\system32\lsasrv.dll
2012-10-07 15:05:06 ----A---- C:\Windows\system32\wups2.dll
2012-10-07 15:05:06 ----A---- C:\Windows\system32\wucltux.dll
2012-10-07 15:05:06 ----A---- C:\Windows\system32\wuaueng.dll
2012-10-07 15:05:06 ----A---- C:\Windows\system32\wuauclt.exe
2012-10-07 00:58:16 ----A---- C:\Windows\system32\wups.dll
2012-10-07 00:58:16 ----A---- C:\Windows\system32\wudriver.dll
2012-10-07 00:58:16 ----A---- C:\Windows\system32\wuapi.dll
2012-10-07 00:58:00 ----A---- C:\Windows\system32\wuwebv.dll
2012-10-07 00:58:00 ----A---- C:\Windows\system32\wuapp.exe
2012-10-07 00:49:58 ----A---- C:\Windows\wininit.ini
2012-10-06 23:08:02 ----D---- C:\Windows\erdnt
2012-10-04 21:28:58 ----D---- C:\Program Files\Metin2
2012-09-26 15:43:51 ----D---- C:\Program Files\LaRoXion MT2

======List of files/folders modified in the last 1 month======

2012-10-10 14:38:52 ----D---- C:\Windows\Prefetch
2012-10-10 12:25:21 ----SHD---- C:\System Volume Information
2012-10-10 12:16:36 ----D---- C:\Windows\tracing
2012-10-10 08:26:14 ----D---- C:\Windows\System32
2012-10-10 08:26:14 ----D---- C:\Windows\inf
2012-10-10 08:26:14 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-10-10 08:00:14 ----D---- C:\Windows\system32\catroot
2012-10-10 08:00:12 ----D---- C:\Windows\winsxs
2012-10-10 07:59:42 ----D---- C:\Windows\system32\catroot2
2012-10-09 13:00:52 ----D---- C:\Windows\system32\drivers
2012-10-09 13:00:51 ----D---- C:\Windows
2012-10-09 12:57:37 ----AC---- C:\Windows\system.ini
2012-10-09 12:57:32 ----D---- C:\Windows\system32\drivers\etc
2012-10-09 12:54:16 ----D---- C:\Windows\AppPatch
2012-10-09 12:54:15 ----D---- C:\Program Files\Common Files
2012-10-09 11:05:49 ----D---- C:\Windows\system32\config
2012-10-09 11:05:02 ----RD---- C:\Program Files
2012-10-09 11:05:02 ----D---- C:\ProgramData
2012-10-09 11:05:01 ----D---- C:\Windows\Tasks
2012-10-09 11:04:53 ----D---- C:\Program Files\Facicons
2012-10-09 10:43:50 ----D---- C:\Intel
2012-10-09 08:17:05 ----SHD---- C:\Windows\Installer
2012-10-09 08:09:15 ----SD---- C:\ProgramData\Microsoft
2012-10-09 08:09:15 ----D---- C:\Program Files\Microsoft
2012-10-08 15:01:42 ----D---- C:\Program Files\Arean2
2012-10-08 13:02:38 ----D---- C:\Windows\system32\Tasks
2012-10-07 23:47:39 ----RSD---- C:\Windows\assembly
2012-10-07 23:47:39 ----D---- C:\Windows\Microsoft.NET
2012-10-07 18:08:38 ----D---- C:\Windows\rescache
2012-10-07 17:49:11 ----RSD---- C:\Windows\Fonts
2012-10-07 17:49:11 ----D---- C:\Program Files\Windows Mail
2012-10-07 16:56:13 ----D---- C:\Program Files\Common Files\microsoft shared
2012-10-07 16:56:03 ----D---- C:\Program Files\Microsoft Office
2012-10-07 16:31:03 ----HD---- C:\Windows\system32\GroupPolicy
2012-10-07 16:21:50 ----D---- C:\Windows\system32\cs-CZ
2012-10-07 16:21:46 ----D---- C:\Program Files\Windows Journal
2012-10-07 16:21:44 ----RD---- C:\Windows\Offline Web Pages
2012-10-07 16:21:44 ----D---- C:\Windows\system32\wbem
2012-10-07 16:21:44 ----D---- C:\Windows\system32\migration
2012-10-07 16:21:44 ----D---- C:\Windows\system32\en-US
2012-10-07 16:21:44 ----D---- C:\Windows\PolicyDefinitions
2012-10-07 16:21:44 ----D---- C:\Program Files\Internet Explorer
2012-10-07 16:21:42 ----SD---- C:\Windows\Downloaded Program Files
2012-10-07 16:21:38 ----D---- C:\Windows\ehome
2012-10-07 16:21:35 ----D---- C:\Program Files\Common Files\System
2012-10-07 16:04:32 ----D---- C:\Windows\Debug
2012-10-07 15:59:57 ----D---- C:\Windows\Logs
2012-10-07 15:46:46 ----D---- C:\Windows\system32\XPSViewer
2012-10-07 15:36:04 ----D---- C:\ProgramData\Skype
2012-10-06 23:14:19 ----AD---- C:\ProgramData\TEMP
2012-09-26 15:15:30 ----HD---- C:\Program Files\InstallShield Installation Information
2012-09-26 15:14:23 ----D---- C:\Program Files\Microsoft Games
2012-09-26 14:32:55 ----D---- C:\Users\Uživatel\AppData\Roaming\LaRoXion
2012-09-20 21:21:09 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2012-09-20 16:08:19 ----A---- C:\Windows\NeroDigital.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 prohlp02;StarForce Protection Helper Driver v2; C:\Windows\System32\drivers\prohlp02.sys [2004-05-13 111808]
R0 prosync1;StarForce Protection Synchronization Driver v1; C:\Windows\System32\drivers\prosync1.sys [2003-09-06 6944]
R0 sfhlp01;StarForce Protection Helper Driver; C:\Windows\System32\drivers\sfhlp01.sys [2003-12-01 4832]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2012-08-21 35928]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2012-08-21 729752]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2012-08-21 355632]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2012-08-21 54232]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\Windows\System32\drivers\prodrv06.sys [2004-05-13 79488]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2012-08-21 21256]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2012-08-21 58680]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2011-02-11 9036800]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-08-18 2752352]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1E60x86.sys [2009-08-05 48640]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2006-10-18 7680]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 EagleNT;EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys []
S3 EagleXNt;EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2012-03-08 39272]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-10 236544]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 WPRO_40_1340;WinPcap Packet Driver (WPRO_40_1340); C:\Windows\system32\drivers\WPRO_40_1340.sys []
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2012-08-21 44808]
R2 ezGOSvc;Easybits GO Services for Windows; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 1713536]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-02-25 136176]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2012-03-08 1492840]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-02-25 136176]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-08 114144]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\system32\GameMon.des [2010-12-15 3994768]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WPFFontCache_v0400;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]

-----------------EOF-----------------

Uživatelský avatar
Mc_Murphy
VIP in memoriam
VIP in memoriam
Příspěvky: 6706
Registrován: 03 lis 2008 15:55
Bydliště: Plzeň [ZČ]
Kontaktovat uživatele:

Re: Problém s tzv. Skype virem

#17 Příspěvek od Mc_Murphy »

:arrow: Fixni v HJT níže uvedené položky.
  • Fixnout znamená, že spustíš HJT, zvolíš možnost [Do a system scan only] a zaškrtneš čtvereček vlevo od mnou vypsaných položek.
  • Poté klikneš na [Fix checked] a odsouhlasíš [ANO].
  • Položky, které v seznamu nenajdeš, prostě přeskoč.
  • HJT najdeš zde: C:\Program Files\trend micro\Uživatel.exe
:!: Bude-li Avast křičet, že to chce otevřít v Sandboxu, nedovol to! Vyber možnost Otevřít normálně!

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {472734EA-242A-422b-ADF8-83D1E48CC825} - (no file)



:arrow: Dále stáhni utilitu OTM z jednoho z těchto odkazů: Ulož ji na Plochu a dvojklikem spusť.

:!: Bude-li Avast křičet, že to chce otevřít v Sandboxu, nedovol to! Vyber možnost Otevřít normálně!

Do levého okna Paste Instructions for Items to be Moved zkopíruj tento script (pouze zelená písmenka v bílém poli, včetně té dvojtečky před Commands!):

Kód: Vybrat vše

:Commands
[ClearAllRestorePoints]
[ResetHosts]
[Purity]
[EmptyTemp]
[EmptyFlash]

:Services
gupdate
gupdatem
NBService
NMIndexingService
SwitchBoard
catchme
ezGOSvc

:Files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp /s
C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
C:\Program Files\Mozilla Firefox\searchplugins\yahoo.xml
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\22kf9mou.default\extensions\jid1-uabu5A9hduqzCw@jetpack
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\22kf9mou.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}
C:\Users\Uživatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk

:Reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Nyní klikni na tlačítko [MoveIt!], čímž vše spustíš.
Po restartu mi sem hoď log, který najdeš v C:\_OTM\MovedFiles\
Obrázek-Obrázek
Obrázek-Obrázek

  • ... I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me love, I've found my identity, found my identity.

    I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me hope, I've found my identity in Christ...

Larsnip
Návštěvník
Návštěvník
Příspěvky: 32
Registrován: 07 říj 2008 15:46

Re: Problém s tzv. Skype virem

#18 Příspěvek od Larsnip »

Log z OTM:

All processes killed
========== COMMANDS ==========

Restore point Set: OTM Restore Point
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 41620 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: Uživatel
->Temp folder emptied: 64885 bytes
->Temporary Internet Files folder emptied: 360696 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 120977174 bytes
->Google Chrome cache emptied: 415133143 bytes
->Flash cache emptied: 523 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 270639133 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 24107288 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 793,00 mb


[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Public

User: Uživatel
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0,00 mb

========== SERVICES/DRIVERS ==========
Service gupdate stopped successfully!
Service gupdate deleted successfully!
Service gupdatem stopped successfully!
Service gupdatem deleted successfully!
Service NBService stopped successfully!
Service NBService deleted successfully!
Service NMIndexingService stopped successfully!
Service NMIndexingService deleted successfully!
Service SwitchBoard stopped successfully!
Service SwitchBoard deleted successfully!
Service catchme stopped successfully!
Service catchme deleted successfully!
Error: Unable to stop service ezGOSvc!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ezGOSvc deleted successfully.
========== FILES ==========
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP10C2.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2DF2.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP5C42.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP6769.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP7464.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP81A.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP9024.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPAB2D.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPC300.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPD5DA.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPE752.tmp folder moved successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPEEF0.tmp folder moved successfully.
C:\Windows\Installer\MSI4CAD.tmp moved successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACBDDA.tmp moved successfully.
C:\Windows\SoftwareDistribution\Download\1aea66133858524c6aedf223b4cd79b4\BITDC46.tmp moved successfully.
C:\Windows\SoftwareDistribution\Download\96b868dad08b24916b0d3faa4a40930e\$dpx$.tmp folder moved successfully.
C:\Windows\SoftwareDistribution\Download\9980c08d3662767ad74469b3ae2b3cff\BITE06D.tmp moved successfully.
C:\Windows\SoftwareDistribution\Download\bac92d0344afd44e0ba00994088a3d61\BITDAEE.tmp moved successfully.
C:\Windows\SoftwareDistribution\Download\e6514c6beafa7418e6d849a3135bbbd8\BITD205.tmp moved successfully.
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Application Updater\temp\~wt12F.tmp moved successfully.
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Application Updater\temp\~wt3F6D.tmp moved successfully.
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Application Updater\temp\~wt5A4A.tmp moved successfully.
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Application Updater\temp\~wt62D7.tmp moved successfully.
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Application Updater\temp\~wt802F.tmp moved successfully.
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Application Updater\temp\~wt8924.tmp moved successfully.
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Application Updater\temp\~wt9B35.tmp moved successfully.
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Application Updater\temp\~wtA0EF.tmp moved successfully.
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Application Updater\temp\~wtA2C3.tmp moved successfully.
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Application Updater\temp\~wtA997.tmp moved successfully.
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Application Updater\temp\~wtAFAF.tmp moved successfully.
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Application Updater\temp\~wtB6B1.tmp moved successfully.
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Application Updater\temp\~wtBB71.tmp moved successfully.
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Application Updater\temp\~wtBFC5.tmp moved successfully.
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Application Updater\temp\~wtC71A.tmp moved successfully.
C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml moved successfully.
C:\Program Files\Mozilla Firefox\searchplugins\yahoo.xml moved successfully.
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\22kf9mou.default\extensions\jid1-uabu5A9hduqzCw@jetpack\resources\jid1-uabu5a9hduqzcw-at-jetpack-speedfox-tests folder moved successfully.
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\22kf9mou.default\extensions\jid1-uabu5A9hduqzCw@jetpack\resources\jid1-uabu5a9hduqzcw-at-jetpack-speedfox-lib folder moved successfully.
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\22kf9mou.default\extensions\jid1-uabu5A9hduqzCw@jetpack\resources\jid1-uabu5a9hduqzcw-at-jetpack-speedfox-data folder moved successfully.
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\22kf9mou.default\extensions\jid1-uabu5A9hduqzCw@jetpack\resources\jid1-uabu5a9hduqzcw-at-jetpack-api-utils-lib\windows folder moved successfully.
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\22kf9mou.default\extensions\jid1-uabu5A9hduqzCw@jetpack\resources\jid1-uabu5a9hduqzcw-at-jetpack-api-utils-lib\utils folder moved successfully.
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\22kf9mou.default\extensions\jid1-uabu5A9hduqzCw@jetpack\resources\jid1-uabu5a9hduqzcw-at-jetpack-api-utils-lib\traits folder moved successfully.
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\22kf9mou.default\extensions\jid1-uabu5A9hduqzCw@jetpack\resources\jid1-uabu5a9hduqzcw-at-jetpack-api-utils-lib\tabs folder moved successfully.
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\22kf9mou.default\extensions\jid1-uabu5A9hduqzCw@jetpack\resources\jid1-uabu5a9hduqzcw-at-jetpack-api-utils-lib\events folder moved successfully.
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\22kf9mou.default\extensions\jid1-uabu5A9hduqzCw@jetpack\resources\jid1-uabu5a9hduqzcw-at-jetpack-api-utils-lib\dom folder moved successfully.
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\22kf9mou.default\extensions\jid1-uabu5A9hduqzCw@jetpack\resources\jid1-uabu5a9hduqzcw-at-jetpack-api-utils-lib\content folder moved successfully.
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\22kf9mou.default\extensions\jid1-uabu5A9hduqzCw@jetpack\resources\jid1-uabu5a9hduqzcw-at-jetpack-api-utils-lib folder moved successfully.
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\22kf9mou.default\extensions\jid1-uabu5A9hduqzCw@jetpack\resources\jid1-uabu5a9hduqzcw-at-jetpack-api-utils-data folder moved successfully.
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\22kf9mou.default\extensions\jid1-uabu5A9hduqzCw@jetpack\resources\jid1-uabu5a9hduqzcw-at-jetpack-addon-kit-lib folder moved successfully.
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\22kf9mou.default\extensions\jid1-uabu5A9hduqzCw@jetpack\resources\jid1-uabu5a9hduqzcw-at-jetpack-addon-kit-data folder moved successfully.
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\22kf9mou.default\extensions\jid1-uabu5A9hduqzCw@jetpack\resources folder moved successfully.
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\22kf9mou.default\extensions\jid1-uabu5A9hduqzCw@jetpack\components folder moved successfully.
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\22kf9mou.default\extensions\jid1-uabu5A9hduqzCw@jetpack folder moved successfully.
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\22kf9mou.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\META-INF folder moved successfully.
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\22kf9mou.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3} folder moved successfully.
C:\Users\Uživatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\ deleted successfully.

OTM by OldTimer - Version 3.1.21.0 log created on 10112012_084918

Uživatelský avatar
Mc_Murphy
VIP in memoriam
VIP in memoriam
Příspěvky: 6706
Registrován: 03 lis 2008 15:55
Bydliště: Plzeň [ZČ]
Kontaktovat uživatele:

Re: Problém s tzv. Skype virem

#19 Příspěvek od Mc_Murphy »

:arrow: Super, OTM provedlo, co mělo.

:???: Jak se chová počítač nyní? Myslím si, že by mělo být hotovo a můžeme jen dočistit po použitých utilitách.
Obrázek-Obrázek
Obrázek-Obrázek

  • ... I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me love, I've found my identity, found my identity.

    I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me hope, I've found my identity in Christ...

Larsnip
Návštěvník
Návštěvník
Příspěvky: 32
Registrován: 07 říj 2008 15:46

Re: Problém s tzv. Skype virem

#20 Příspěvek od Larsnip »

Tak PC se zdá už být OK. Nainstaloval jsem znovu Skype a žádný vir se zatím neprojevil.
Díky za pomoc

Uživatelský avatar
Mc_Murphy
VIP in memoriam
VIP in memoriam
Příspěvky: 6706
Registrován: 03 lis 2008 15:55
Bydliště: Plzeň [ZČ]
Kontaktovat uživatele:

Re: Problém s tzv. Skype virem

#21 Příspěvek od Mc_Murphy »

Super, to moc rád čtu. :thumbsup:
Tak po sobě ještě uklidím a máme hotovo. ;)


:arrow: Nejprve odinstalujeme ComboFix.
  • Přejmenuj ComboFix na Uninstall.
  • Spusť jej.
:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stáhni a spusť.
  • Pro potvrzení volby mačkej A, Enter.
  • Po použití utilitu smaž ručně.
  • Antiviry mohou tuto utilitu chybně označit jako vir - jedná se o falešný poplach - takže v pohodě stáhni (případně vypni při stahování antivir)!

A pak ještě tohle, prosím...

:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stáhni a spusť.
  • Klikni na CleanUp a potvrď YES.
  • Program uklidí a může (nemusí) restartovat PC.
:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stáhni a spusť.
  • Klikni na Start a potvrď OK.
  • Program uklidí a může (nemusí) restartovat PC.
  • Po použití utilitu smaž ručně.
:arrow: Pokud nemáš, stáhni CCleaner z tohoto odkazu.
  • Panel čistič
  • Vše nech jak je, jen dej Analyzovat a poté Spustit CCleaner.
  • Panel registry
  • Klikni na Hledej problémy.
  • Následně na Opravit problémy - zálohu registrů doporučuji udělat, oprav všechny problémy.
  • Postup opakuj, dokud nebude bez problémů - většinou cca 3x.
  • Panel nástroje
  • Zde můžeš odinstalovat nepotřebné programy.
Obrázek CCleaner doporučuji používat cca jednou za týden.

... a pokud nejsou žádné dotazy, bylo by to z mé strany vše. :James008:
Obrázek-Obrázek
Obrázek-Obrázek

  • ... I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me love, I've found my identity, found my identity.

    I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me hope, I've found my identity in Christ...

Larsnip
Návštěvník
Návštěvník
Příspěvky: 32
Registrován: 07 říj 2008 15:46

Re: Problém s tzv. Skype virem

#22 Příspěvek od Larsnip »

Díky za pomoc ;-)

Uživatelský avatar
Mc_Murphy
VIP in memoriam
VIP in memoriam
Příspěvky: 6706
Registrován: 03 lis 2008 15:55
Bydliště: Plzeň [ZČ]
Kontaktovat uživatele:

Re: Problém s tzv. Skype virem

#23 Příspěvek od Mc_Murphy »

Není vůbec zač a rádo se stalo. :85: Přeji pěkný den. :fez:

:closed:
Obrázek-Obrázek
Obrázek-Obrázek

  • ... I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me love, I've found my identity, found my identity.

    I'm moving on, I'm moving on, I'm moving on by the Spirit.
    • You gave me hope, I've found my identity in Christ...

Zamčeno