Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Malware Privitize VPN

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Valda09
Návštěvník
Návštěvník
Příspěvky: 61
Registrován: 30 dub 2008 09:23

Malware Privitize VPN

#1 Příspěvek od Valda09 »

Prosím o kontrolu logu (RSIT), nainstaloval se mi program Privitize VPN. Díky

Logfile of random's system information tool 1.09 (written by random/random)
Run by dusan.lehocky at 2013-04-28 23:45:15
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 221 GB (75%) free of 294 GB
Total RAM: 1993 MB (34% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:45:59, on 28.4.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16521)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Program Files\Norton AntiVirus\Engine\20.3.1.22\ccSvcHst.exe
C:\Program Files\Norton Identity Safe\Engine\2013.3.3.19\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Pando Networks\Media Booster\PMB.exe
C:\Program Files\Origin\Origin.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Users\dusan.lehocky\Downloads\RSIT.exe
C:\Program Files\trend micro\dusan.lehocky.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMDTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer, enhanced for Bing and MSN
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\20.3.1.22\IPS\IPSBHO.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Norton Identity Protection - {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} - C:\Program Files\Norton Identity Safe\Engine\2013.3.3.19\coIEPlg.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll" (file missing)
O3 - Toolbar: Norton Identity Safe Toolbar - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Program Files\Norton Identity Safe\Engine\2013.3.3.19\coIEPlg.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [picon] "C:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe" -startup
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\2.bin\m3SrchMn.exe" /m=2 /w /h
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKCU\..\Run: [NokiaOviSuite2] C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe -tray
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [EADM] "C:\Program Files\Origin\Origin.exe" -AutoStart
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\AMT\LMS.exe
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwssvc.exe
O23 - Service: Norton AntiVirus (NAV) - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\20.3.1.22\ccSvcHst.exe
O23 - Service: Norton Identity Safe (NCO) - Symantec Corporation - C:\Program Files\Norton Identity Safe\Engine\2013.3.3.19\ccSvcHst.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: UltiDev Cassini Web Server for ASP.NET 2.0 - UltiDev LLC - C:\Program Files\UltiDev\Cassini Web Server for ASP.NET 2.0\UltiDevCassinWebServer2a.exe
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe

--
End of file - 13388 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2838011208-2976497064-341179427-1004Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2838011208-2976497064-341179427-1004UA.job
C:\Windows\tasks\HPCeeScheduleFordusan.lehocky.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44cf-8957-5838F569A31D}]
MyWebSearch Search Assistant BHO - C:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL [2011-03-22 54704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}]
mwsBar BHO - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL [2011-03-22 800272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Norton Vulnerability Protection - C:\Program Files\Norton AntiVirus\Engine\20.3.1.22\IPS\IPSBHO.DLL [2012-11-16 387040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2011-11-10 325408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2012-03-08 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB4C7833-A6EC-433f-B9FE-6B14B1A2F836}]
Norton Identity Protection - C:\Program Files\Norton Identity Safe\Engine\2013.3.3.19\coIEPlg.dll [2013-04-02 509776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-04-15 4529272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-12-21 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll [2012-06-11 1307728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-11-10 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2012-07-09 351136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22 517688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{07B18EA9-A523-4961-B6BB-170DE4475CCA} - My Web Search - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL [2011-03-22 800272]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll [2012-06-11 1307728]
{A13C2648-91D4-4bf3-BC6D-0079707C4389} - Norton Identity Safe Toolbar - C:\Program Files\Norton Identity Safe\Engine\2013.3.3.19\coIEPlg.dll [2013-04-02 509776]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-07-03 7596576]
"picon"=C:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe [2009-07-24 796696]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2010-08-25 136216]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2010-08-25 171032]
"Persistence"=C:\Windows\system32\igfxpers.exe [2010-08-25 170520]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2009-11-18 54576]
""= []
"MyWebSearch Email Plugin"=C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe [2011-03-22 32849]
"My Web Search Bar Search Scope Monitor"=C:\PROGRA~1\MYWEBS~1\bar\2.bin\m3SrchMn.exe [2011-03-22 34336]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2011-08-14 77824]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-06-09 254696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MyWebSearch Email Plugin"=C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe [2011-03-22 32849]
"NokiaOviSuite2"=C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe -tray []
"Pando Media Booster"=C:\Program Files\Pando Networks\Media Booster\PMB.exe [2011-10-30 3077528]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2013-02-28 18642024]
"EADM"=C:\Program Files\Origin\Origin.exe [2013-04-10 3497552]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2010-08-25 228864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.siren"=sirenacm.dll
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"vidc.XVID"=xvidvfw.dll
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - "%1" /S "%3"

======List of files/folders created in the last 1 month======

2013-04-28 23:45:15 ----D---- C:\rsit
2013-04-28 23:45:15 ----D---- C:\Program Files\trend micro
2013-04-28 23:40:33 ----D---- C:\Program Files\Common Files\Skype
2013-04-28 23:40:24 ----D---- C:\Users\dusan.lehocky\AppData\Roaming\HPAppData
2013-04-19 17:38:14 ----D---- C:\Program Files\Origin Games
2013-04-19 17:23:42 ----D---- C:\ProgramData\EA Core
2013-04-10 19:55:54 ----D---- C:\Program Files\Battlelog Web Plugins
2013-04-07 13:01:06 ----A---- C:\Windows\system32\FlashPlayerApp.exe

======List of files/folders modified in the last 1 month======

2013-04-28 23:45:27 ----D---- C:\Windows\Prefetch
2013-04-28 23:45:15 ----RD---- C:\Program Files
2013-04-28 23:45:01 ----D---- C:\Windows\Temp
2013-04-28 23:41:22 ----D---- C:\Users\dusan.lehocky\AppData\Roaming\Skype
2013-04-28 23:40:41 ----SHD---- C:\Windows\Installer
2013-04-28 23:40:41 ----HD---- C:\Config.Msi
2013-04-28 23:40:41 ----D---- C:\ProgramData\Skype
2013-04-28 23:40:33 ----RD---- C:\Program Files\Skype
2013-04-28 23:40:33 ----D---- C:\Program Files\Common Files
2013-04-28 23:39:25 ----D---- C:\Windows\system32\config
2013-04-28 23:39:12 ----A---- C:\Windows\system32\log.txt
2013-04-28 23:39:00 ----D---- C:\Program Files\Google
2013-04-28 23:38:56 ----SHD---- C:\System Volume Information
2013-04-28 23:35:25 ----D---- C:\Windows
2013-04-28 23:35:12 ----D---- C:\Windows\system32\Tasks
2013-04-28 20:53:51 ----D---- C:\Windows\System32
2013-04-28 20:53:51 ----D---- C:\Windows\inf
2013-04-28 20:53:51 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-04-26 03:00:50 ----D---- C:\Windows\system32\catroot2
2013-04-24 17:32:34 ----D---- C:\Windows\system32\catroot
2013-04-23 13:56:49 ----A---- C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-04-19 17:38:10 ----HD---- C:\Program Files\Common Files\EAInstaller
2013-04-19 17:23:43 ----HD---- C:\ProgramData
2013-04-19 17:13:21 ----RSD---- C:\Windows\assembly
2013-04-17 12:32:42 ----D---- C:\Windows\system32\drivers\NAV
2013-04-17 10:30:37 ----D---- C:\Windows\system32\drivers\NST
2013-04-10 19:52:54 ----D---- C:\Program Files\Origin
2013-04-10 13:09:55 ----D---- C:\Windows\winsxs
2013-04-09 17:12:25 ----D---- C:\Windows\Tasks
2013-04-04 22:20:06 ----D---- C:\Zaloha

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iastor.sys [2010-03-04 435736]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [2010-03-19 45648]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 SymDS;Symantec Data Store; C:\Windows\system32\drivers\NAV\1403010.016\SYMDS.SYS [2013-01-22 367704]
R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\NAV\1403010.016\SYMEFA.SYS [2013-01-31 934488]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 BHDrvx86;BHDrvx86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\BASHDefs\20130412.001\BHDrvx86.sys [2013-04-13 1000024]
R1 ccSet_NAV;Norton AntiVirus Settings Manager; C:\Windows\system32\drivers\NAV\1403010.016\ccSetx86.sys [2012-11-16 134304]
R1 ccSet_NST;Norton Identity Safe Settings Manager; C:\Windows\system32\drivers\NST\7DD03030.013\ccSetx86.sys [2012-11-16 134304]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [2012-08-09 376480]
R1 IDSVix86;IDSVix86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\IPSDefs\20130426.001\IDSvix86.sys [2013-02-20 386720]
R1 SRTSP;Symantec Real Time Storage Protection; C:\Windows\System32\Drivers\NAV\1403010.016\SRTSP.SYS [2013-01-29 602712]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL); C:\Windows\system32\drivers\NAV\1403010.016\SRTSPX.SYS [2013-01-29 32344]
R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\NAV\1403010.016\Ironx86.SYS [2012-11-16 175264]
R1 SymNetS;Symantec Network Security WFP Driver; C:\Windows\System32\Drivers\NAV\1403010.016\SYMNETS.SYS [2013-01-31 338592]
R2 regi;regi; C:\Windows\system32\drivers\regi.sys [2007-04-18 11032]
R3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 131072]
R3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2010-11-20 16384]
R3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 36864]
R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K; C:\Windows\system32\DRIVERS\e1k6232.sys [2009-09-02 202408]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-08-09 106656]
R3 HECI;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECI.sys [2009-07-24 40832]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2010-08-25 9024512]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-07-03 2656160]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\VirusDefs\20130427.007\NAVENG.SYS [2013-02-21 93296]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\VirusDefs\20130427.007\NAVEX15.SYS [2013-02-21 1603824]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [2013-02-21 142496]
R3 TPM;TPM; C:\Windows\system32\drivers\tpm.sys [2009-07-14 30720]
R3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 btmhsf;btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [2011-07-19 225280]
S3 EagleXNt;EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2012-03-08 39272]
S3 iBtFltCoex;iBtFltCoex; C:\Windows\system32\DRIVERS\iBtFltCoex.sys [2011-07-20 47104]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmb.sys [2010-12-02 18304]
S3 nmwcdc;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 27648]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 BBSvc;BingBar Service; C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.exe [2012-06-11 193616]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2012-09-27 86528]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 HPSLPSVC;HP Network Devices Support; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-05 112152]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2010-06-16 73728]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files\Intel\AMT\LMS.exe [2009-07-24 174616]
R2 MyWebSearchService;My Web Search Service; C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwssvc.exe [2011-03-22 28762]
R2 NAV;Norton AntiVirus; C:\Program Files\Norton AntiVirus\Engine\20.3.1.22\ccSvcHst.exe [2012-12-24 144520]
R2 NCO;Norton Identity Safe; C:\Program Files\Norton Identity Safe\Engine\2013.3.3.19\ccSvcHst.exe [2012-12-24 144520]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2013-03-12 76888]
R2 PSI_SVC_2;Protexis Licensing V2; C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R2 Skype C2C Service;Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-04-15 3289208]
R2 UltiDev Cassini Web Server for ASP.NET 2.0;UltiDev Cassini Web Server for ASP.NET 2.0; C:\Program Files\UltiDev\Cassini Web Server for ASP.NET 2.0\UltiDevCassinWebServer2a.exe [2010-08-25 49152]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2009-07-24 2066968]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 1713536]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-02-28 161384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-04-07 253656]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 BBUpdate;BBUpdate; C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.exe [2012-06-11 240208]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2012-03-08 1492840]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2012-08-10 1001376]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 RoxMediaDB10;RoxMediaDB10; C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2010-03-19 1120752]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-01-26 652800]
S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2009-10-16 74392]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-02-14 1343400]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]

-----------------EOF-----------------

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Malware Privitize VPN

#2 Příspěvek od Márty84 »

Zdravim :)


:arrow: Udelejte !!!kompletni!!! kontrolu s MBAM http://forum.viry.cz/viewtopic.php?f=29&t=115222 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Valda09
Návštěvník
Návštěvník
Příspěvky: 61
Registrován: 30 dub 2008 09:23

Re: Malware Privitize VPN

#3 Příspěvek od Valda09 »

Tady je MBAM díky:

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Verze: v2013.04.29.09

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16540
dusan.lehocky :: PC-01 [administrátor]

29.4.2013 22:17:01
MBAM-log-2013-04-30 (08-51-14).txt

Typ: Kompletní kontrola (C:\|D:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 431654
Uplynulý čas: 1 hodin, 20 minut, 35 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 1
C:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL (Trojan.BHO) -> Nebyla provedena žádná instrukce.

Nalezené klíče v registru: 15
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110011341191} (PUP.GamePlayLab) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011341191} (PUP.GamePlayLab) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\215 APPS (PUP.CrossFire.SA) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44cf-8957-5838F569A31D} (Trojan.BHO) -> Nebyla provedena žádná instrukce.
HKCR\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D} (Trojan.BHO) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Trojan.BHO) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Trojan.BHO) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Trojan.BHO) -> Nebyla provedena žádná instrukce.
HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Trojan.BHO) -> Nebyla provedena žádná instrukce.
HKCR\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA} (Trojan.BHO) -> Nebyla provedena žádná instrukce.
HKCR\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA} (Trojan.BHO) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Trojan.BHO) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Trojan.BHO) -> Nebyla provedena žádná instrukce.

Nalezené hodnoty v registru: 1
HKCU\Software\InstalledBrowserExtensions\215 Apps|3491 (PUP.CrossFire.SA) -> Data: Vid-Saver -> Nebyla provedena žádná instrukce.

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 4
C:\Program Files\Vid-Saver\Uninstall.exe (Adware.GamePlayLabs) -> Nebyla provedena žádná instrukce.
C:\Windows\System32\f3PSSavr.scr (Trojan.Agent) -> Nebyla provedena žádná instrukce.
C:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL (Trojan.BHO) -> Nebyla provedena žádná instrukce.
C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL (Trojan.BHO) -> Nebyla provedena žádná instrukce.

(konec)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Malware Privitize VPN

#4 Příspěvek od Márty84 »

:arrow: Vsechny nalezy nechte odstranit a pokud vse probehne bez problemu, MBAM odinstalujte.


:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Prohledat a program zacne pracovat.
Az skonci, vyplivne na vas log (pokud ne, najdete ho zde C:\AdwCleaner[R?].txt ), ten mi sem zkopirujte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Valda09
Návštěvník
Návštěvník
Příspěvky: 61
Registrován: 30 dub 2008 09:23

Re: Malware Privitize VPN

#5 Příspěvek od Valda09 »

Konečně jsem se k němu dostal tady je log z AdW

# AdwCleaner v2.300 - Log vytvooen 01/05/2013 v 19:18:47
# Aktualizováno 28/04/2013 Xplode
# Operaení systém : Windows 7 Professional Service Pack 1 (32 bits)
# Uživatel : dusan.lehocky - PC-01
# Spuštin systém : Normální
# Spuštino z : C:\Users\dusan.lehocky\Desktop\adwcleaner.exe
# Volba [Prohledat]


***** [Služby] *****

Nalezeno : MyWebSearchService

***** [Soubory / Složky] *****

Složka Nalezeno : C:\Program Files\FunWebProducts
Složka Nalezeno : C:\Program Files\MyWebSearch
Složka Nalezeno : C:\Program Files\Vid-Saver
Složka Nalezeno : C:\ProgramData\InstallMate
Složka Nalezeno : C:\ProgramData\Premium
Složka Nalezeno : C:\Users\Administrator\AppData\LocalLow\FunWebProducts
Složka Nalezeno : C:\Users\Administrator\AppData\LocalLow\MyWebSearch
Složka Nalezeno : C:\Users\deti\AppData\LocalLow\FunWebProducts
Složka Nalezeno : C:\Users\deti\AppData\LocalLow\MyWebSearch
Složka Nalezeno : C:\Users\dusan.lehocky\AppData\Local\Vid-Saver
Složka Nalezeno : C:\Users\dusan.lehocky\AppData\LocalLow\FunWebProducts
Složka Nalezeno : C:\Users\dusan.lehocky\AppData\LocalLow\MyWebSearch

***** [Registry] *****

Hodnota Nalezeno : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{07B18EA9-A523-4961-B6BB-170DE4475CCA}]
Hodnota Nalezeno : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00A6FAF6-072E-44CF-8957-5838F569A31D}]
Hodnota Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [MyWebSearch Email Plugin]
Hodnota Nalezeno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{07B18EA9-A523-4961-B6BB-170DE4475CCA}]
Hodnota Nalezeno : HKLM\SOFTWARE\Microsoft\Windows Media\Wmsdk\Sources [F3PopularScreenSavers]
Hodnota Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\post platform [FunWebProducts]
Hodnota Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [My Web Search Bar Search Scope Monitor]
Hodnota Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [MyWebSearch Email Plugin]
Hodnota Nalezeno : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [m3ffxtbr@mywebsearch.com]
Klíe Nalezeno : HKCU\Software\AppDataLow\Software\Crossrider
Klíe Nalezeno : HKCU\Software\AppDataLow\Software\Fun Web Products
Klíe Nalezeno : HKCU\Software\AppDataLow\Software\FunWebProducts
Klíe Nalezeno : HKCU\Software\AppDataLow\Software\MyWebSearch
Klíe Nalezeno : HKCU\Software\AppDataLow\Software\Vid-Saver
Klíe Nalezeno : HKCU\Software\InstalledBrowserExtensions
Klíe Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
Klíe Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1E0DE227-5CE4-4EA3-AB0C-8B03E1AA76BC}
Klíe Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF6-072E-44CF-8957-5838F569A31D}
Klíe Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
Klíe Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
Klíe Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
Klíe Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
Klíe Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9FF05104-B030-46FC-94B8-81276E4E27DF}
Klíe Nalezeno : HKCU\Software\MyWebSearch
Klíe Nalezeno : HKCU\Software\StartSearch
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{08858AF6-42AD-4914-95D2-AC3AB0DC8E28}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{1E0DE227-5CE4-4EA3-AB0C-8B03E1AA76BC}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{25560540-9571-4D7B-9389-0F166788785A}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{67FA02C4-AB30-4E77-A640-78EE8EC8673B}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{7473D292-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{7473D294-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{7473D296-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{799391D3-EB86-4BAC-9BD3-CBFEA58A0E15}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{819FFE22-35C7-4925-8CDA-4E0E2DB94302}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{A4730EBE-43A6-443E-9776-36915D323AD3}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{A9571378-68A1-443D-B082-284F960C6D17}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{D858DAFC-9573-4811-B323-7011A3AA7E61}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{E79DFBCA-5697-4FBD-94E5-5B2A9C7C1612}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\FunWebProducts.DataControl
Klíe Nalezeno : HKLM\SOFTWARE\Classes\FunWebProducts.DataControl.1
Klíe Nalezeno : HKLM\SOFTWARE\Classes\FunWebProducts.HistoryKillerScheduler
Klíe Nalezeno : HKLM\SOFTWARE\Classes\FunWebProducts.HistoryKillerScheduler.1
Klíe Nalezeno : HKLM\SOFTWARE\Classes\FunWebProducts.HistorySwatterControlBar
Klíe Nalezeno : HKLM\SOFTWARE\Classes\FunWebProducts.HistorySwatterControlBar.1
Klíe Nalezeno : HKLM\SOFTWARE\Classes\FunWebProducts.HTMLMenu
Klíe Nalezeno : HKLM\SOFTWARE\Classes\FunWebProducts.HTMLMenu.1
Klíe Nalezeno : HKLM\SOFTWARE\Classes\FunWebProducts.HTMLMenu.2
Klíe Nalezeno : HKLM\SOFTWARE\Classes\FunWebProducts.IECookiesManager
Klíe Nalezeno : HKLM\SOFTWARE\Classes\FunWebProducts.IECookiesManager.1
Klíe Nalezeno : HKLM\SOFTWARE\Classes\FunWebProducts.KillerObjManager
Klíe Nalezeno : HKLM\SOFTWARE\Classes\FunWebProducts.KillerObjManager.1
Klíe Nalezeno : HKLM\SOFTWARE\Classes\FunWebProducts.PopSwatterBarButton
Klíe Nalezeno : HKLM\SOFTWARE\Classes\FunWebProducts.PopSwatterBarButton.1
Klíe Nalezeno : HKLM\SOFTWARE\Classes\FunWebProducts.PopSwatterSettingsControl
Klíe Nalezeno : HKLM\SOFTWARE\Classes\FunWebProducts.PopSwatterSettingsControl.1
Klíe Nalezeno : HKLM\Software\Classes\Installer\Features\90C64EA18BA25EE488BF80DCF07F2FFD
Klíe Nalezeno : HKLM\Software\Classes\Installer\Products\90C64EA18BA25EE488BF80DCF07F2FFD
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{01947140-417F-46B6-8751-A3A2B8345E1A}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{120927BF-1700-43BC-810F-FAB92549B390}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{1F52A5FA-A705-4415-B975-88503B291728}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{3E720451-B472-4954-B7AA-33069EB53906}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{3E720453-B472-4954-B7AA-33069EB53906}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{819FFE21-35C7-4925-8CDA-4E0E2DB94302}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{8E9CF769-3D3B-40EB-9E2D-76E7A205E4D2}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{991AAC62-B100-47CE-8B75-253965244F69}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\MyWebSearch.HTMLPanel
Klíe Nalezeno : HKLM\SOFTWARE\Classes\MyWebSearch.HTMLPanel.1
Klíe Nalezeno : HKLM\SOFTWARE\Classes\MyWebSearch.ChatSessionPlugin
Klíe Nalezeno : HKLM\SOFTWARE\Classes\MyWebSearch.ChatSessionPlugin.1
Klíe Nalezeno : HKLM\SOFTWARE\Classes\MyWebSearch.MultipleButton
Klíe Nalezeno : HKLM\SOFTWARE\Classes\MyWebSearch.MultipleButton.1
Klíe Nalezeno : HKLM\SOFTWARE\Classes\MyWebSearch.OutlookAddin
Klíe Nalezeno : HKLM\SOFTWARE\Classes\MyWebSearch.OutlookAddin.1
Klíe Nalezeno : HKLM\SOFTWARE\Classes\MyWebSearch.PseudoTransparentPlugin
Klíe Nalezeno : HKLM\SOFTWARE\Classes\MyWebSearch.PseudoTransparentPlugin.1
Klíe Nalezeno : HKLM\SOFTWARE\Classes\MyWebSearch.ThirdPartyInstaller
Klíe Nalezeno : HKLM\SOFTWARE\Classes\MyWebSearch.ThirdPartyInstaller.1
Klíe Nalezeno : HKLM\SOFTWARE\Classes\MyWebSearch.UrlAlertButton
Klíe Nalezeno : HKLM\SOFTWARE\Classes\MyWebSearch.UrlAlertButton.1
Klíe Nalezeno : HKLM\SOFTWARE\Classes\MyWebSearchToolBar.SettingsPlugin
Klíe Nalezeno : HKLM\SOFTWARE\Classes\MyWebSearchToolBar.SettingsPlugin.1
Klíe Nalezeno : HKLM\SOFTWARE\Classes\MyWebSearchToolBar.ToolbarPlugin
Klíe Nalezeno : HKLM\SOFTWARE\Classes\MyWebSearchToolBar.ToolbarPlugin.1
Klíe Nalezeno : HKLM\SOFTWARE\Classes\ScreenSaverControl.ScreenSaverInstaller
Klíe Nalezeno : HKLM\SOFTWARE\Classes\ScreenSaverControl.ScreenSaverInstaller.1
Klíe Nalezeno : HKLM\SOFTWARE\Classes\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\TypeLib\{819FFE20-35C7-4925-8CDA-4E0E2DB94302}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\TypeLib\{8FFDF636-0D87-4B33-B9E9-79A53F6E1DAE}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}
Klíe Nalezeno : HKLM\SOFTWARE\Classes\TypeLib\{F42228FB-E84E-479E-B922-FBBD096E792C}
Klíe Nalezeno : HKLM\Software\FocusInteractive
Klíe Nalezeno : HKLM\Software\Fun Web Products
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45DD-9B68-D6A12C30E5D7}
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48DD-9B6D-7A13A3E42127}
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40FD-8DAE-FF14757F60C7}
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Tracing\Vid-Saver_RASAPI32
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Tracing\Vid-Saver_RASMANCS
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{08858AF6-42AD-4914-95D2-AC3AB0DC8E28}
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A}
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906}
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473D294-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB}
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF}
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4FBD-94E5-5B2A9C7C1612}
Klíe Nalezeno : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
Klíe Nalezeno : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
Klíe Nalezeno : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\90C64EA18BA25EE488BF80DCF07F2FFD
Klíe Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mywebsearch bar uninstall
Klíe Nalezeno : HKLM\SOFTWARE\MozillaPlugins\@mywebsearch.com/Plugin
Klíe Nalezeno : HKLM\Software\MyWebSearch

***** [Internetové prohlížeee] *****

-\\ Internet Explorer v10.0.9200.16537

[OK] Registry jsou eisté.

*************************

AdwCleaner[R1].txt - [16985 octets] - [01/05/2013 19:18:47]

########## EOF - C:\AdwCleaner[R1].txt - [17046 octets] ##########

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Malware Privitize VPN

#6 Příspěvek od Márty84 »

:arrow: Znovu ukoncete vsechny programy a spustte AdwCleaner jako spravce.
Tentokrat kliknete na Smazat
Program zacne pracovat (muze dojit k restartu pc) a vyplivne dalsi log (pripadne bude zde C:\AdwCleaner [S1].txt ). Ten mi sem zase zkopirujte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Valda09
Návštěvník
Návštěvník
Příspěvky: 61
Registrován: 30 dub 2008 09:23

Re: Malware Privitize VPN

#7 Příspěvek od Valda09 »

Omylem jsem to spustil normálně (ne jako správce...)

# AdwCleaner v2.300 - Log vytvooen 01/05/2013 v 20:55:05
# Aktualizováno 28/04/2013 Xplode
# Operaení systém : Windows 7 Professional Service Pack 1 (32 bits)
# Uživatel : dusan.lehocky - PC-01
# Spuštin systém : Normální
# Spuštino z : C:\Users\dusan.lehocky\Desktop\adwcleaner.exe
# Volba [Vymazat]


***** [Služby] *****

Zastaveno & vymazáno : MyWebSearchService

***** [Soubory / Složky] *****

Složka Vymazáno : C:\Program Files\FunWebProducts
Složka Vymazáno : C:\Program Files\MyWebSearch
Složka Vymazáno : C:\Program Files\Vid-Saver
Složka Vymazáno : C:\ProgramData\InstallMate
Složka Vymazáno : C:\ProgramData\Premium
Složka Vymazáno : C:\Users\Administrator\AppData\LocalLow\FunWebProducts
Složka Vymazáno : C:\Users\Administrator\AppData\LocalLow\MyWebSearch
Složka Vymazáno : C:\Users\deti\AppData\LocalLow\FunWebProducts
Složka Vymazáno : C:\Users\deti\AppData\LocalLow\MyWebSearch
Složka Vymazáno : C:\Users\dusan.lehocky\AppData\Local\Vid-Saver
Složka Vymazáno : C:\Users\dusan.lehocky\AppData\LocalLow\FunWebProducts
Složka Vymazáno : C:\Users\dusan.lehocky\AppData\LocalLow\MyWebSearch

***** [Registry] *****

Hodnota Vymazáno : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{07B18EA9-A523-4961-B6BB-170DE4475CCA}]
Hodnota Vymazáno : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00A6FAF6-072E-44CF-8957-5838F569A31D}]
Hodnota Vymazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [MyWebSearch Email Plugin]
Hodnota Vymazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{07B18EA9-A523-4961-B6BB-170DE4475CCA}]
Hodnota Vymazáno : HKLM\SOFTWARE\Microsoft\Windows Media\Wmsdk\Sources [F3PopularScreenSavers]
Hodnota Vymazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\post platform [FunWebProducts]
Hodnota Vymazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [My Web Search Bar Search Scope Monitor]
Hodnota Vymazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [MyWebSearch Email Plugin]
Hodnota Vymazáno : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [m3ffxtbr@mywebsearch.com]
Klíe Vymazáno : HKCU\Software\AppDataLow\Software\Crossrider
Klíe Vymazáno : HKCU\Software\AppDataLow\Software\Fun Web Products
Klíe Vymazáno : HKCU\Software\AppDataLow\Software\FunWebProducts
Klíe Vymazáno : HKCU\Software\AppDataLow\Software\MyWebSearch
Klíe Vymazáno : HKCU\Software\AppDataLow\Software\Vid-Saver
Klíe Vymazáno : HKCU\Software\InstalledBrowserExtensions
Klíe Vymazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
Klíe Vymazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1E0DE227-5CE4-4EA3-AB0C-8B03E1AA76BC}
Klíe Vymazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF6-072E-44CF-8957-5838F569A31D}
Klíe Vymazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
Klíe Vymazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
Klíe Vymazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
Klíe Vymazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
Klíe Vymazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9FF05104-B030-46FC-94B8-81276E4E27DF}
Klíe Vymazáno : HKCU\Software\MyWebSearch
Klíe Vymazáno : HKCU\Software\StartSearch
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{08858AF6-42AD-4914-95D2-AC3AB0DC8E28}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{1E0DE227-5CE4-4EA3-AB0C-8B03E1AA76BC}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{25560540-9571-4D7B-9389-0F166788785A}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{67FA02C4-AB30-4E77-A640-78EE8EC8673B}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{7473D292-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{7473D294-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{7473D296-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{799391D3-EB86-4BAC-9BD3-CBFEA58A0E15}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{819FFE22-35C7-4925-8CDA-4E0E2DB94302}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{A4730EBE-43A6-443E-9776-36915D323AD3}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{A9571378-68A1-443D-B082-284F960C6D17}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{D858DAFC-9573-4811-B323-7011A3AA7E61}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\CLSID\{E79DFBCA-5697-4FBD-94E5-5B2A9C7C1612}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\FunWebProducts.DataControl
Klíe Vymazáno : HKLM\SOFTWARE\Classes\FunWebProducts.DataControl.1
Klíe Vymazáno : HKLM\SOFTWARE\Classes\FunWebProducts.HistoryKillerScheduler
Klíe Vymazáno : HKLM\SOFTWARE\Classes\FunWebProducts.HistoryKillerScheduler.1
Klíe Vymazáno : HKLM\SOFTWARE\Classes\FunWebProducts.HistorySwatterControlBar
Klíe Vymazáno : HKLM\SOFTWARE\Classes\FunWebProducts.HistorySwatterControlBar.1
Klíe Vymazáno : HKLM\SOFTWARE\Classes\FunWebProducts.HTMLMenu
Klíe Vymazáno : HKLM\SOFTWARE\Classes\FunWebProducts.HTMLMenu.1
Klíe Vymazáno : HKLM\SOFTWARE\Classes\FunWebProducts.HTMLMenu.2
Klíe Vymazáno : HKLM\SOFTWARE\Classes\FunWebProducts.IECookiesManager
Klíe Vymazáno : HKLM\SOFTWARE\Classes\FunWebProducts.IECookiesManager.1
Klíe Vymazáno : HKLM\SOFTWARE\Classes\FunWebProducts.KillerObjManager
Klíe Vymazáno : HKLM\SOFTWARE\Classes\FunWebProducts.KillerObjManager.1
Klíe Vymazáno : HKLM\SOFTWARE\Classes\FunWebProducts.PopSwatterBarButton
Klíe Vymazáno : HKLM\SOFTWARE\Classes\FunWebProducts.PopSwatterBarButton.1
Klíe Vymazáno : HKLM\SOFTWARE\Classes\FunWebProducts.PopSwatterSettingsControl
Klíe Vymazáno : HKLM\SOFTWARE\Classes\FunWebProducts.PopSwatterSettingsControl.1
Klíe Vymazáno : HKLM\Software\Classes\Installer\Features\90C64EA18BA25EE488BF80DCF07F2FFD
Klíe Vymazáno : HKLM\Software\Classes\Installer\Products\90C64EA18BA25EE488BF80DCF07F2FFD
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{01947140-417F-46B6-8751-A3A2B8345E1A}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{120927BF-1700-43BC-810F-FAB92549B390}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{1F52A5FA-A705-4415-B975-88503B291728}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{3E720451-B472-4954-B7AA-33069EB53906}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{3E720453-B472-4954-B7AA-33069EB53906}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{819FFE21-35C7-4925-8CDA-4E0E2DB94302}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{8E9CF769-3D3B-40EB-9E2D-76E7A205E4D2}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{991AAC62-B100-47CE-8B75-253965244F69}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\MyWebSearch.HTMLPanel
Klíe Vymazáno : HKLM\SOFTWARE\Classes\MyWebSearch.HTMLPanel.1
Klíe Vymazáno : HKLM\SOFTWARE\Classes\MyWebSearch.ChatSessionPlugin
Klíe Vymazáno : HKLM\SOFTWARE\Classes\MyWebSearch.ChatSessionPlugin.1
Klíe Vymazáno : HKLM\SOFTWARE\Classes\MyWebSearch.MultipleButton
Klíe Vymazáno : HKLM\SOFTWARE\Classes\MyWebSearch.MultipleButton.1
Klíe Vymazáno : HKLM\SOFTWARE\Classes\MyWebSearch.OutlookAddin
Klíe Vymazáno : HKLM\SOFTWARE\Classes\MyWebSearch.OutlookAddin.1
Klíe Vymazáno : HKLM\SOFTWARE\Classes\MyWebSearch.PseudoTransparentPlugin
Klíe Vymazáno : HKLM\SOFTWARE\Classes\MyWebSearch.PseudoTransparentPlugin.1
Klíe Vymazáno : HKLM\SOFTWARE\Classes\MyWebSearch.ThirdPartyInstaller
Klíe Vymazáno : HKLM\SOFTWARE\Classes\MyWebSearch.ThirdPartyInstaller.1
Klíe Vymazáno : HKLM\SOFTWARE\Classes\MyWebSearch.UrlAlertButton
Klíe Vymazáno : HKLM\SOFTWARE\Classes\MyWebSearch.UrlAlertButton.1
Klíe Vymazáno : HKLM\SOFTWARE\Classes\MyWebSearchToolBar.SettingsPlugin
Klíe Vymazáno : HKLM\SOFTWARE\Classes\MyWebSearchToolBar.SettingsPlugin.1
Klíe Vymazáno : HKLM\SOFTWARE\Classes\MyWebSearchToolBar.ToolbarPlugin
Klíe Vymazáno : HKLM\SOFTWARE\Classes\MyWebSearchToolBar.ToolbarPlugin.1
Klíe Vymazáno : HKLM\SOFTWARE\Classes\ScreenSaverControl.ScreenSaverInstaller
Klíe Vymazáno : HKLM\SOFTWARE\Classes\ScreenSaverControl.ScreenSaverInstaller.1
Klíe Vymazáno : HKLM\SOFTWARE\Classes\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\TypeLib\{819FFE20-35C7-4925-8CDA-4E0E2DB94302}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\TypeLib\{8FFDF636-0D87-4B33-B9E9-79A53F6E1DAE}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}
Klíe Vymazáno : HKLM\SOFTWARE\Classes\TypeLib\{F42228FB-E84E-479E-B922-FBBD096E792C}
Klíe Vymazáno : HKLM\Software\FocusInteractive
Klíe Vymazáno : HKLM\Software\Fun Web Products
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45DD-9B68-D6A12C30E5D7}
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48DD-9B6D-7A13A3E42127}
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40FD-8DAE-FF14757F60C7}
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Tracing\Vid-Saver_RASAPI32
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Tracing\Vid-Saver_RASMANCS
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{08858AF6-42AD-4914-95D2-AC3AB0DC8E28}
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A}
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906}
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473D294-B7BB-4F24-AE82-7E2CE94BB6A9}
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB}
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF}
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4FBD-94E5-5B2A9C7C1612}
Klíe Vymazáno : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
Klíe Vymazáno : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
Klíe Vymazáno : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\90C64EA18BA25EE488BF80DCF07F2FFD
Klíe Vymazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mywebsearch bar uninstall
Klíe Vymazáno : HKLM\SOFTWARE\MozillaPlugins\@mywebsearch.com/Plugin
Klíe Vymazáno : HKLM\Software\MyWebSearch

***** [Internetové prohlížeee] *****

-\\ Internet Explorer v10.0.9200.16537

[OK] Registry jsou eisté.

*************************

AdwCleaner[R1].txt - [17116 octets] - [01/05/2013 19:18:47]
AdwCleaner[R2].txt - [17177 octets] - [01/05/2013 20:54:51]
AdwCleaner[S1].txt - [17117 octets] - [01/05/2013 20:55:05]

########## EOF - C:\AdwCleaner[S1].txt - [17178 octets] ##########

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Malware Privitize VPN

#8 Příspěvek od Márty84 »

Nevadi, smazalo to i tak.


:???: Ten VPN tam porad je?


:arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe , ulozte ho na plochu, kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Probehne kratoucky testik a pak se zpristupni vpravo nahore tlacitko Prohledat. Na to kliknete a probehne dalsi test.
Po dokonceni kliknete na napis Zprava a objevi se log. Ten mi sem vlozte
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Valda09
Návštěvník
Návštěvník
Příspěvky: 61
Registrován: 30 dub 2008 09:23

Re: Malware Privitize VPN

#9 Příspěvek od Valda09 »

To jsem rád.

VPN už tam není...tedy aspoň viditelný.

Log z RogueKilleru, díky za kontrolu:

RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.geekstogo.com/forum/files/fi ... guekiller/
Webové stránky : http://tigzy.geekstogo.com/roguekiller.php
: http://tigzyrk.blogspot.com/

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spuštěno v : Normální režim
Uživatel : dusan.lehocky [Práva správce]
Mód : Kontrola -- Datum : 05/02/2013 10:38:59
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 5 ¤¤¤
[HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> NALEZENO
[HJ] HKLM\[...]\System : EnableLUA (0) -> NALEZENO
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> NALEZENO
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤
SSDT[13] : NtAlertResumeThread @ 0x83116DA5 -> HOOKED (Unknown @ 0x885207D0)
SSDT[14] : NtAlertThread @ 0x83069CC7 -> HOOKED (Unknown @ 0x885208B0)
SSDT[19] : NtAllocateVirtualMemory @ 0x83062CBC -> HOOKED (Unknown @ 0x8852E430)
SSDT[22] : NtAlpcConnectPort @ 0x830AE56E -> HOOKED (Unknown @ 0x87D14710)
SSDT[43] : NtAssignProcessToJobObject @ 0x830380BE -> HOOKED (Unknown @ 0x884FE7F8)
SSDT[74] : NtCreateMutant @ 0x8304934C -> HOOKED (Unknown @ 0x884FEDA0)
SSDT[86] : NtCreateSymbolicLinkObject @ 0x8303A9C6 -> HOOKED (Unknown @ 0x884FE518)
SSDT[87] : NtCreateThread @ 0x83114FE2 -> HOOKED (Unknown @ 0x88520320)
SSDT[88] : NtCreateThreadEx @ 0x830A949B -> HOOKED (Unknown @ 0x884FE608)
SSDT[96] : NtDebugActiveProcess @ 0x830E6EAA -> HOOKED (Unknown @ 0x884FE8D8)
SSDT[111] : NtDuplicateObject @ 0x8306A761 -> HOOKED (Unknown @ 0x8852E600)
SSDT[131] : NtFreeVirtualMemory @ 0x82EF181C -> HOOKED (Unknown @ 0x88520FC0)
SSDT[145] : NtImpersonateAnonymousToken @ 0x8302E962 -> HOOKED (Unknown @ 0x884FEE90)
SSDT[147] : NtImpersonateThread @ 0x830B2962 -> HOOKED (Unknown @ 0x884FEF70)
SSDT[155] : NtLoadDriver @ 0x82FFEC32 -> HOOKED (Unknown @ 0x87D194F0)
SSDT[168] : NtMapViewOfSection @ 0x8307F5F1 -> HOOKED (Unknown @ 0x88520EE0)
SSDT[177] : NtOpenEvent @ 0x83048D48 -> HOOKED (Unknown @ 0x884FECC0)
SSDT[190] : NtOpenProcess @ 0x8304AB93 -> HOOKED (Unknown @ 0x8852E780)
SSDT[191] : NtOpenProcessToken @ 0x8309D36F -> HOOKED (Unknown @ 0x8852E520)
SSDT[194] : NtOpenSection @ 0x830A29EB -> HOOKED (Unknown @ 0x884FEB00)
SSDT[198] : NtOpenThread @ 0x830970EE -> HOOKED (Unknown @ 0x8852E6F0)
SSDT[215] : NtProtectVirtualMemory @ 0x8307B651 -> HOOKED (Unknown @ 0x884FE708)
SSDT[304] : NtResumeThread @ 0x830A96C2 -> HOOKED (Unknown @ 0x88520990)
SSDT[316] : NtSetContextThread @ 0x83116851 -> HOOKED (Unknown @ 0x88520C30)
SSDT[333] : NtSetInformationProcess @ 0x83071875 -> HOOKED (Unknown @ 0x88520D10)
SSDT[350] : NtSetSystemInformation @ 0x8308737A -> HOOKED (Unknown @ 0x884FE9B8)
SSDT[366] : NtSuspendProcess @ 0x83116CDF -> HOOKED (Unknown @ 0x884FEBE0)
SSDT[367] : NtSuspendThread @ 0x830CE19B -> HOOKED (Unknown @ 0x88520A70)
SSDT[370] : NtTerminateProcess @ 0x83093D86 -> HOOKED (Unknown @ 0x8854E4D8)
SSDT[371] : unknown @ 0x830B169B -> HOOKED (Unknown @ 0x88520B50)
SSDT[385] : NtUnmapViewOfSection @ 0x8309D9AA -> HOOKED (Unknown @ 0x88520E00)
SSDT[399] : NtWriteVirtualMemory @ 0x83098A83 -> HOOKED (Unknown @ 0x8852E2D8)
S_SSDT[318] : NtUserAttachThreadInput -> HOOKED (Unknown @ 0x9C21EC40)
S_SSDT[402] : NtUserGetAsyncKeyState -> HOOKED (Unknown @ 0x885AE830)
S_SSDT[434] : NtUserGetKeyboardState -> HOOKED (Unknown @ 0x87BBFD80)
S_SSDT[436] : NtUserGetKeyState -> HOOKED (Unknown @ 0x889A57E8)
S_SSDT[448] : NtUserGetRawInputData -> HOOKED (Unknown @ 0x87BC0390)
S_SSDT[490] : NtUserMessageCall -> HOOKED (Unknown @ 0x9C317238)
S_SSDT[508] : NtUserPostMessage -> HOOKED (Unknown @ 0x9C3140F0)
S_SSDT[509] : NtUserPostThreadMessage -> HOOKED (Unknown @ 0x9C317308)
S_SSDT[585] : NtUserSetWindowsHookEx -> HOOKED (Unknown @ 0x885AE5D0)
S_SSDT[588] : NtUserSetWinEventHook -> HOOKED (Unknown @ 0x9C28C410)

¤¤¤ Soubor HOSTS: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts



¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: WDC WD3200AAJS-60Z0A0 +++++
--- User ---
[MBR] 21ad2619f23ba94a758b731a4c9dba79
[BSP] 906b3c2cb039e78186dffa53fbc6b62d : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 2047 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 4194304 | Size: 294027 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 606361600 | Size: 9160 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: HP Photosmart Premi USB Device +++++
Error reading User MBR!
User = LL1 ... OK!
Error reading LL2 MBR!

+++++ PhysicalDrive3: Generic- SM/xD-Picture USB Device +++++
--- User ---
[MBR] a5b07d75aa1068405479c9be76ba5aeb
[BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code
Partition table:
0 - [ACTIVE] FAT16 (0x06) [VISIBLE] Offset (sectors): 123 | Size: 1999 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Dokončeno : << RKreport[1]_S_05022013_02d1038.txt >>
RKreport[1]_S_05022013_02d1038.txt

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Malware Privitize VPN

#10 Příspěvek od Márty84 »

:arrow: Znovu spustte RogueKiller jako spravce (pokud jste ho jeste nezavrel/a, rovnou kliknete na napis Smazat)
Probehne kratoucky testik a pak se zpristupni vpravo nahore tlacitko Prohledat. Na to kliknete a probehne dalsi test.
Po dokonceni kliknete na napis Smazat.
Pak kliknete na napis Zprava a objevi se log. Ten mi sem vlozte.
Pak kliknete na napis Oprava Host a Zprava.
Objevi se dalsi log. I ten mi sem vlozte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Valda09
Návštěvník
Návštěvník
Příspěvky: 61
Registrován: 30 dub 2008 09:23

Re: Malware Privitize VPN

#11 Příspěvek od Valda09 »

Zpráva po mazání:

RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.geekstogo.com/forum/files/fi ... guekiller/
Webové stránky : http://tigzy.geekstogo.com/roguekiller.php
: http://tigzyrk.blogspot.com/

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spuštěno v : Normální režim
Uživatel : dusan.lehocky [Práva správce]
Mód : Odebrat -- Datum : 05/02/2013 14:33:43
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 5 ¤¤¤
[HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> NAHRAZENO (2)
[HJ] HKLM\[...]\System : EnableLUA (0) -> NAHRAZENO (1)
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> NAHRAZENO (1)
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤
SSDT[13] : NtAlertResumeThread @ 0x83116DA5 -> HOOKED (Unknown @ 0x885207D0)
SSDT[14] : NtAlertThread @ 0x83069CC7 -> HOOKED (Unknown @ 0x885208B0)
SSDT[19] : NtAllocateVirtualMemory @ 0x83062CBC -> HOOKED (Unknown @ 0x8852E430)
SSDT[22] : NtAlpcConnectPort @ 0x830AE56E -> HOOKED (Unknown @ 0x87D14710)
SSDT[43] : NtAssignProcessToJobObject @ 0x830380BE -> HOOKED (Unknown @ 0x884FE7F8)
SSDT[74] : NtCreateMutant @ 0x8304934C -> HOOKED (Unknown @ 0x884FEDA0)
SSDT[86] : NtCreateSymbolicLinkObject @ 0x8303A9C6 -> HOOKED (Unknown @ 0x884FE518)
SSDT[87] : NtCreateThread @ 0x83114FE2 -> HOOKED (Unknown @ 0x88520320)
SSDT[88] : NtCreateThreadEx @ 0x830A949B -> HOOKED (Unknown @ 0x884FE608)
SSDT[96] : NtDebugActiveProcess @ 0x830E6EAA -> HOOKED (Unknown @ 0x884FE8D8)
SSDT[111] : NtDuplicateObject @ 0x8306A761 -> HOOKED (Unknown @ 0x8852E600)
SSDT[131] : NtFreeVirtualMemory @ 0x82EF181C -> HOOKED (Unknown @ 0x88520FC0)
SSDT[145] : NtImpersonateAnonymousToken @ 0x8302E962 -> HOOKED (Unknown @ 0x884FEE90)
SSDT[147] : NtImpersonateThread @ 0x830B2962 -> HOOKED (Unknown @ 0x884FEF70)
SSDT[155] : NtLoadDriver @ 0x82FFEC32 -> HOOKED (Unknown @ 0x87D194F0)
SSDT[168] : NtMapViewOfSection @ 0x8307F5F1 -> HOOKED (Unknown @ 0x88520EE0)
SSDT[177] : NtOpenEvent @ 0x83048D48 -> HOOKED (Unknown @ 0x884FECC0)
SSDT[190] : NtOpenProcess @ 0x8304AB93 -> HOOKED (Unknown @ 0x8852E780)
SSDT[191] : NtOpenProcessToken @ 0x8309D36F -> HOOKED (Unknown @ 0x8852E520)
SSDT[194] : NtOpenSection @ 0x830A29EB -> HOOKED (Unknown @ 0x884FEB00)
SSDT[198] : NtOpenThread @ 0x830970EE -> HOOKED (Unknown @ 0x8852E6F0)
SSDT[215] : NtProtectVirtualMemory @ 0x8307B651 -> HOOKED (Unknown @ 0x884FE708)
SSDT[304] : NtResumeThread @ 0x830A96C2 -> HOOKED (Unknown @ 0x88520990)
SSDT[316] : NtSetContextThread @ 0x83116851 -> HOOKED (Unknown @ 0x88520C30)
SSDT[333] : NtSetInformationProcess @ 0x83071875 -> HOOKED (Unknown @ 0x88520D10)
SSDT[350] : NtSetSystemInformation @ 0x8308737A -> HOOKED (Unknown @ 0x884FE9B8)
SSDT[366] : NtSuspendProcess @ 0x83116CDF -> HOOKED (Unknown @ 0x884FEBE0)
SSDT[367] : NtSuspendThread @ 0x830CE19B -> HOOKED (Unknown @ 0x88520A70)
SSDT[370] : NtTerminateProcess @ 0x83093D86 -> HOOKED (Unknown @ 0x8854E4D8)
SSDT[371] : unknown @ 0x830B169B -> HOOKED (Unknown @ 0x88520B50)
SSDT[385] : NtUnmapViewOfSection @ 0x8309D9AA -> HOOKED (Unknown @ 0x88520E00)
SSDT[399] : NtWriteVirtualMemory @ 0x83098A83 -> HOOKED (Unknown @ 0x8852E2D8)
S_SSDT[318] : NtUserAttachThreadInput -> HOOKED (Unknown @ 0x9C21EC40)
S_SSDT[402] : NtUserGetAsyncKeyState -> HOOKED (Unknown @ 0x885AE830)
S_SSDT[434] : NtUserGetKeyboardState -> HOOKED (Unknown @ 0x87BBFD80)
S_SSDT[436] : NtUserGetKeyState -> HOOKED (Unknown @ 0x889A57E8)
S_SSDT[448] : NtUserGetRawInputData -> HOOKED (Unknown @ 0x87BC0390)
S_SSDT[490] : NtUserMessageCall -> HOOKED (Unknown @ 0x9C317238)
S_SSDT[508] : NtUserPostMessage -> HOOKED (Unknown @ 0x9C3140F0)
S_SSDT[509] : NtUserPostThreadMessage -> HOOKED (Unknown @ 0x9C317308)
S_SSDT[585] : NtUserSetWindowsHookEx -> HOOKED (Unknown @ 0x885AE5D0)
S_SSDT[588] : NtUserSetWinEventHook -> HOOKED (Unknown @ 0x9C28C410)

¤¤¤ Soubor HOSTS: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts



¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: WDC WD3200AAJS-60Z0A0 +++++
--- User ---
[MBR] 21ad2619f23ba94a758b731a4c9dba79
[BSP] 906b3c2cb039e78186dffa53fbc6b62d : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 2047 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 4194304 | Size: 294027 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 606361600 | Size: 9160 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: HP Photosmart Premi USB Device +++++
Error reading User MBR!
User = LL1 ... OK!
Error reading LL2 MBR!

+++++ PhysicalDrive3: Generic- SM/xD-Picture USB Device +++++
--- User ---
[MBR] a5b07d75aa1068405479c9be76ba5aeb
[BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code
Partition table:
0 - [ACTIVE] FAT16 (0x06) [VISIBLE] Offset (sectors): 123 | Size: 1999 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Dokončeno : << RKreport[2]_D_05022013_02d1433.txt >>
RKreport[1]_S_05022013_02d1038.txt ; RKreport[2]_D_05022013_02d1433.txt


Zpráva oprava host:

RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.geekstogo.com/forum/files/fi ... guekiller/
Webové stránky : http://tigzy.geekstogo.com/roguekiller.php
: http://tigzyrk.blogspot.com/

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spuštěno v : Normální režim
Uživatel : dusan.lehocky [Práva správce]
Mód : Oprava HOSTS -- Datum : 05/02/2013 14:34:18
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 0 ¤¤¤

¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts



¤¤¤ Resetovaný HOSTS: ¤¤¤
127.0.0.1 localhost

Dokončeno : << RKreport[3]_H_05022013_02d1434.txt >>
RKreport[1]_S_05022013_02d1038.txt ; RKreport[2]_D_05022013_02d1433.txt ; RKreport[3]_H_05022013_02d1434.txt

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Malware Privitize VPN

#12 Příspěvek od Márty84 »

:!: Pokud nemate, zazalohujte si radeji dulezita data (fotky, dokumenty, atd.) :!:

:!: Nepouzivejte ComboFix bez predchozi domluvy! Je to poruseni pravidel fora a ztratite tim narok na pomoc!

:arrow: Stahnete ComboFix http://download.bleepingcomputer.com/sUBs/ComboFix.exe a ulozte ho na plochu.
Vypnete antivir i dalsi pripadne zabezpeceni.
Kliknete na ComboFix pravym mysidlem a levym na Spustit jako spravce
Odsouhlaste licencni podminky a nechte program pracovat. Jestli vam nabidne instalaci Konzoly pro zotaveni, souhlaste.
Po dobu skenu nic nespoustejte, nikam neklikejte.
Po dokonceni skenovani (muze dojit i k restartu pc) by se mel vytvorit log, ktery bude umisteny zde C:\ComboFix.txt
Jeho obsah sem zkopirujte

:!: Kdyby po restartu nenabehl windows, restartujte znovu, mackejte klavesu F8 a zvolte - Posledni znama funkcni konfigurace
:!: Kdyz windows nabehne, ale pri spousteni programu bude hlasena chyba, staci restartovat pc a bude to v poradku
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Valda09
Návštěvník
Návštěvník
Příspěvky: 61
Registrován: 30 dub 2008 09:23

Re: Malware Privitize VPN

#13 Příspěvek od Valda09 »

Tak vše v pohodě log zde:

ComboFix 13-05-01.03 - dusan.lehocky 03.05.2013 11:25:32.1.2 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.1993.835 [GMT 2:00]
Spuštěný z: c:\users\dusan.lehocky\Desktop\ComboFix.exe
AV: Norton AntiVirus *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Norton AntiVirus *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\81CF8A34EB.sys
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{0066D16F-C0D3-49E9-B4BB-4A9BE1882B43}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{09B6E337-2B84-495B-AE14-0314701D14F6}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{0C57C9EB-CBBB-47A9-9F00-C76F6A8ABEDA}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{0D161D05-03D5-4C53-AA1D-A6D9A8E94D88}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{1071BA64-D276-4D60-93C4-555B671EDD68}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{13714389-2791-49E0-94EE-2D1B536FEFE2}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{17FC09E3-6EFE-4EAC-99A4-C80E79768052}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{1892DF11-CE91-46BD-A78D-E65A090E2D20}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{1B15B8BD-8BC2-4232-9BE6-99CEC79D6872}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{1C1B1A5F-6055-4CD4-AD1A-BB4A0DCFBA78}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{219DA87A-515C-45C5-9641-418E419D61F0}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{2447A10E-63FC-4DA6-AC7C-3F6CEB7640CE}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{24819218-1EA4-47CD-AB44-59C8DFE26494}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{26D39138-A7B0-401B-8970-679715D19F8B}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{2BEE13BD-CD53-425B-9A63-DB1CFC9C7B2C}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{2CBC8CF4-C732-4425-A9F0-B7B417775CDB}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{2F386A16-F2A7-4E4B-A70C-6179BAD9D6E2}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{2F4B40A4-3B5C-4954-8171-E88ED6DA3684}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{31DF3B58-6E87-494F-884F-44001342AB8F}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{33A15216-A20B-42DD-8E66-2E6E9E07467F}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{365F5D31-BB35-446A-8D93-9EED4D7A63D5}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{37459C75-DD69-4673-B2F2-0BD1A25A4EB8}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{3B785409-C753-421E-B525-96925DDF0B25}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{3D8B1F09-DB47-46A4-8F73-43DDAE1C36DD}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{3F5D6286-4E9E-4018-A14C-E55623A87286}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{40453964-C4BB-43FD-B507-B4C17373C399}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{4143C889-8B22-4984-8064-2FF1BF849916}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{43189FA5-8B5A-4B4A-A2A3-BA82FD5CDBE3}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{44A50190-ADEE-46D6-8951-4CF562D4A156}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{4BF6F4BA-98E9-4C73-B2CD-8EEC6E4E2718}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{4CE51380-96EB-4DA0-B3FF-A9045939E4F5}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{4D0289A2-29DC-49B4-BA45-4CB5048BAD32}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{57D686DC-F6B9-43C3-A0E9-CCAAC5DF3F10}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{6002AFCA-71F1-4EBA-8E3C-B6C0EE922C73}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{650E95BC-39AF-4784-BF9D-D84117C8DEC4}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{65FD02F6-06D1-42BF-83DF-7B9273617EE4}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{665E43C5-1203-44F1-997D-B1C5E2FEAEB4}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{6B5C42BB-8365-4A3F-B68B-6B0841B12AF4}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{848D7A40-27F3-4CCA-B8B7-A58403D756FF}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{896B9978-FFB2-425A-BB3D-1A6F11170614}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{8BBA5C7A-8629-4075-8DAB-252D0E13A759}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{8F43BF4F-9D42-4C65-8956-EF59280E8D11}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{934B14D6-30F8-4F39-A451-3051A6C47A2E}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{93BED569-E642-4CBE-8157-0526DDDDEDBB}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{9BEB91EC-FD53-4992-8A12-57782B85DA1C}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{9C63C9EE-5990-42D1-9276-8E0FCAD58A4C}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{A4CA71CB-E1B4-4825-9D9F-823667010D5A}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{AC1108B0-5F6A-4046-945E-D436DE20D64D}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{ADE7B17B-A515-44D2-B172-52FF9638B754}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{B7AD585B-7C9A-42C3-BB19-AD8BE769BB77}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{BAA12B82-7528-4897-B634-1A342D0BBCF7}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{BB874F0E-298E-4CEB-B3E0-80FBEA9B3E1B}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{BC4C0DD8-D841-4629-8AFC-BF8F17B5FC8C}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{C34E05C6-20FA-414F-836B-5822F0B3F85C}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{C79C67F3-070D-4C16-9436-9A44296C6171}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{C8B49EBF-547C-423A-993F-56B19FF7D116}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{CE83A8BE-B5D1-4402-9579-1F79634E8B3F}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{D06DC849-34B5-41D2-849D-1293CBCB1852}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{D12349D8-E305-4A2F-9D5F-25ED0A019F31}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{D5D92DD0-118E-42B5-B0ED-1504C45E3BE0}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{DB676FEE-F930-4140-A3D9-7F6AF36268CE}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{DED6AC65-2A54-400E-900D-89FD6F5208DA}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{DEDC5672-DB89-484C-8F06-85033FCD521D}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{E4AE00EF-E8F4-4C84-ABE6-AB045CB07687}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{E7DAECDB-5774-49F8-A2AE-09BE754E4937}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{E83774AE-13CC-48C5-89E7-56872D21935B}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{EEC5F10F-6402-408C-B44A-CF4A2A512590}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{EF40A937-F8F0-4F15-9782-2A526780DCC8}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{F347D3F1-3A65-47A4-A154-7928814DA3E0}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{F44222A3-5142-49EC-89FC-45143288A7F0}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{FC4DF821-F99F-4111-B04F-B4799FB0FB99}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{FC597E2F-4141-4981-9107-808842D25ABE}.xps
c:\users\deti\AppData\Local\Microsoft\Windows\Temporary Internet Files\{FF180A4E-0DCC-455B-8626-F59683688FD9}.xps
c:\users\dusan.lehocky\AppData\Local\Microsoft\Windows\Temporary Internet Files\{32BE6C26-69BC-4A54-9DA5-B1625E78075A}.xps
c:\users\dusan.lehocky\AppData\Local\Microsoft\Windows\Temporary Internet Files\{76455461-0702-463C-A0F3-63CB6125FB1B}.xps
c:\users\dusan.lehocky\AppData\Local\Microsoft\Windows\Temporary Internet Files\{C067C68B-88E5-4F2F-ACF0-1A1C6198556B}.xps
c:\users\dusan.lehocky\AppData\Local\Microsoft\Windows\Temporary Internet Files\{F7551423-B69A-41F2-AE7D-72004C4C2B84}.xps
c:\users\dusan.lehocky\AppData\Local\Microsoft\Windows\Temporary Internet Files\{FAE28BBF-2A67-492A-9CF1-DD05C8EBC073}.xps
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-04-03 do 2013-05-03 )))))))))))))))))))))))))))))))
.
.
2013-05-03 09:48 . 2013-05-03 09:50 -------- d-----w- c:\users\dusan.lehocky\AppData\Local\temp
2013-05-03 09:48 . 2013-05-03 09:48 -------- d-----w- c:\users\DUSAN~2~LEH\AppData\Local\temp
2013-05-03 09:48 . 2013-05-03 09:48 -------- d-----w- c:\users\deti\AppData\Local\temp
2013-05-03 09:48 . 2013-05-03 09:48 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2013-05-03 05:10 . 2013-05-03 05:10 -------- d-----w- c:\users\dusan.lehocky\AppData\Roaming\HPAppData
2013-05-02 12:52 . 2013-05-02 12:52 -------- d-----w- c:\users\dusan.lehocky\AppData\Local\Mozilla
2013-05-02 12:52 . 2013-05-02 12:52 -------- d-----w- c:\program files\Mozilla Maintenance Service
2013-05-01 19:11 . 2013-05-01 19:11 -------- d-----w- c:\program files\PANDORA.TV
2013-05-01 19:11 . 2013-05-02 17:20 -------- d-----w- c:\program files\The KMPlayer
2013-04-29 20:15 . 2013-04-29 20:16 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2013-04-29 20:15 . 2013-04-29 20:15 -------- d-----w- c:\users\dusan.lehocky\AppData\Roaming\Malwarebytes
2013-04-29 20:15 . 2013-04-29 20:15 -------- d-----w- c:\programdata\Malwarebytes
2013-04-29 20:14 . 2013-04-29 20:14 -------- d-----w- c:\users\dusan.lehocky\AppData\Local\Programs
2013-04-28 21:45 . 2013-04-28 21:46 -------- d-----w- C:\rsit
2013-04-28 21:45 . 2013-04-28 21:45 -------- d-----w- c:\program files\trend micro
2013-04-28 21:40 . 2013-04-28 21:40 -------- d-----w- c:\program files\Common Files\Skype
2013-04-28 21:35 . 2013-04-28 21:35 -------- d-----w- c:\users\Administrator\AppData\Roaming\HPAppData
2013-04-28 21:30 . 2013-04-28 21:30 -------- d-----w- c:\users\Administrator\AppData\Local\Google
2013-04-24 15:34 . 2013-04-12 13:45 1211752 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-04-19 15:38 . 2013-04-19 15:38 -------- d-----w- c:\program files\Origin Games
2013-04-19 15:23 . 2013-04-19 15:23 -------- d-----w- c:\programdata\EA Core
2013-04-16 12:34 . 2013-04-16 12:34 -------- d-----w- c:\windows\system32\drivers\NST\7DD03030.013
2013-04-16 05:51 . 2013-04-17 10:32 -------- d-----w- c:\windows\system32\drivers\NAV\1403010.016
2013-04-10 17:55 . 2013-04-10 17:56 -------- d-----w- c:\program files\Battlelog Web Plugins
2013-04-10 11:10 . 2013-03-01 03:09 2347008 ----a-w- c:\windows\system32\win32k.sys
2013-04-10 11:10 . 2013-01-24 04:47 196328 ----a-w- c:\windows\system32\drivers\fvevol.sys
2013-04-10 11:10 . 2013-03-19 05:04 3968856 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-04-10 11:10 . 2013-03-19 05:04 3913560 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-04-10 11:10 . 2013-03-19 04:48 38912 ----a-w- c:\windows\system32\csrsrv.dll
2013-04-10 11:10 . 2013-03-19 02:49 69632 ----a-w- c:\windows\system32\smss.exe
2013-04-10 11:10 . 2013-02-15 04:37 3217408 ----a-w- c:\windows\system32\mstscax.dll
2013-04-10 11:10 . 2013-02-15 04:34 131584 ----a-w- c:\windows\system32\aaclient.dll
2013-04-10 11:10 . 2013-02-15 03:25 36864 ----a-w- c:\windows\system32\tsgqec.dll
2013-04-07 11:01 . 2013-04-07 11:01 693976 ----a-w- c:\windows\system32\FlashPlayerApp.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-07 11:01 . 2012-03-11 21:13 73432 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-12 19:09 . 2013-03-12 19:09 745472 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-03-12 19:09 . 2013-03-12 19:09 185344 ----a-w- c:\windows\system32\elshyph.dll
2013-03-12 19:09 . 2013-03-12 19:09 158720 ----a-w- c:\windows\system32\msls31.dll
2013-03-12 19:09 . 2013-03-12 19:09 150528 ----a-w- c:\windows\system32\iexpress.exe
2013-03-12 19:09 . 2013-03-12 19:09 138752 ----a-w- c:\windows\system32\wextract.exe
2013-03-12 19:09 . 2013-03-12 19:09 73728 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-03-12 19:09 . 2013-03-12 19:09 719360 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-03-12 19:09 . 2013-03-12 19:09 61952 ----a-w- c:\windows\system32\tdc.ocx
2013-03-12 19:09 . 2013-03-12 19:09 523264 ----a-w- c:\windows\system32\vbscript.dll
2013-03-12 19:09 . 2013-03-12 19:09 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-03-12 19:09 . 2013-03-12 19:09 38400 ----a-w- c:\windows\system32\imgutil.dll
2013-03-12 19:09 . 2013-03-12 19:09 361984 ----a-w- c:\windows\system32\html.iec
2013-03-12 19:09 . 2013-03-12 19:09 23040 ----a-w- c:\windows\system32\licmgr10.dll
2013-03-12 19:09 . 2013-03-12 19:09 1441280 ----a-w- c:\windows\system32\inetcpl.cpl
2013-03-12 19:09 . 2013-03-12 19:09 137216 ----a-w- c:\windows\system32\ieUnatt.exe
2013-03-12 19:09 . 2013-03-12 19:09 12800 ----a-w- c:\windows\system32\mshta.exe
2013-03-12 19:09 . 2013-03-12 19:09 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-03-12 18:27 . 2013-03-12 18:27 138904 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2013-03-12 18:27 . 2013-03-12 18:27 138904 ----a-w- c:\users\dusan.lehocky\AppData\Roaming\PnkBstrK.sys
2013-03-12 18:26 . 2013-03-12 18:26 281872 ----a-w- c:\windows\system32\PnkBstrB.exe
2013-03-12 18:26 . 2013-03-12 18:26 281872 ----a-w- c:\windows\system32\PnkBstrB.ex0
2013-03-12 18:26 . 2013-03-12 18:26 76888 ----a-w- c:\windows\system32\PnkBstrA.exe
2013-02-21 15:58 . 2011-02-14 16:31 142496 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2013-02-12 04:48 . 2013-03-13 07:33 474112 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-02-12 04:48 . 2013-03-13 07:33 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-02-12 03:32 . 2013-03-20 19:21 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-02-08 00:45 . 2013-02-22 13:01 6954968 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{EE3FECC4-7D1D-41ED-8C6B-BA67D5785D22}\mpengine.dll
2013-04-10 06:57 . 2013-05-02 12:51 263064 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2011-10-30 3077528]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-02-28 18642024]
"EADM"="c:\program files\Origin\Origin.exe" [2013-04-10 3497552]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-03 7596576]
"picon"="c:\program files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe" [2009-07-24 796696]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 170520]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2009-11-18 54576]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-11-18 275072]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R2 BBSvc;BingBar Service;c:\program files\Microsoft\BingBar\7.1.391.0\BBSvc.exe [x]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [x]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NAV\1403010.016\SYMDS.SYS [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1403010.016\SYMEFA.SYS [x]
S1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\BASHDefs\20130412.001\BHDrvx86.sys [x]
S1 ccSet_NAV;Norton AntiVirus Settings Manager;c:\windows\system32\drivers\NAV\1403010.016\ccSetx86.sys [x]
S1 ccSet_NST;Norton Identity Safe Settings Manager;c:\windows\system32\drivers\NST\7DD03030.013\ccSetx86.sys [x]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\IPSDefs\20130502.001\IDSvix86.sys [x]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NAV\1403010.016\Ironx86.SYS [x]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NAV\1403010.016\SYMNETS.SYS [x]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x]
S2 NAV;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\20.3.1.22\ccSvcHst.exe [x]
S2 NCO;Norton Identity Safe;c:\program files\Norton Identity Safe\Engine\2013.3.3.19\ccSvcHst.exe [x]
S2 PanService;PandoraService;c:\program files\PANDORA.TV\PanService\PandoraService.exe [x]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [x]
S2 UltiDev Cassini Web Server for ASP.NET 2.0;UltiDev Cassini Web Server for ASP.NET 2.0;c:\program files\UltiDev\Cassini Web Server for ASP.NET 2.0\UltiDevCassinWebServer2a.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files\Common Files\Intel\Privacy Icon\UNS\UNS.exe [x]
S3 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\7.1.391.0\SeaPort.exe [x]
S3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\DRIVERS\e1k6232.sys [x]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - TRUESIGHT
*Deregistered* - TrueSight
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc Mcx2Svc SensrSvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
FontCache
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-06-16 12:38 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-05-03 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-04-07 11:01]
.
2013-05-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2838011208-2976497064-341179427-1004Core.job
- c:\users\deti\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-26 16:33]
.
2013-05-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2838011208-2976497064-341179427-1004UA.job
- c:\users\deti\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-26 16:33]
.
2013-04-30 c:\windows\Tasks\HPCeeScheduleFordusan.lehocky.job
- c:\program files\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html
TCP: DhcpNameServer = 109.235.0.1
FF - ProfilePath - c:\users\dusan.lehocky\AppData\Roaming\Mozilla\Firefox\Profiles\gygslypv.default\
FF - ExtSQL: 2013-05-01 21:02; {F04D2D30-776C-4d02-8627-8E4385ECA58D}; c:\programdata\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2013.2.0.18\coFFPlgn
FF - ExtSQL: 2013-05-02 10:24; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\IPSFFPlgn
FF - ExtSQL: !HIDDEN! 2011-12-18 15:00; smartwebprinting@hp.com; c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKCU-Run-NokiaOviSuite2 - c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
AddRemove-PunkBusterSvc - c:\program files\Origin Games\Medal of Honor Warfighter\pbsvc.exe
AddRemove-{EE202411-2C26-49E8-9784-1BC1DBF7DE96} - c:\program files\InstallShield Installation Information\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}\setup.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NAV]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\20.3.1.22\ccSvcHst.exe\" /s \"NAV\" /m \"c:\program files\Norton AntiVirus\Engine\20.3.1.22\diMaster.dll\" /prefetch:1"
--
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NCO]
"ImagePath"="\"c:\program files\Norton Identity Safe\Engine\2013.3.3.19\ccSvcHst.exe\" /s \"NCO\" /m \"c:\program files\Norton Identity Safe\Engine\2013.3.3.19\diMaster.dll\" /prefetch:1"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2838011208-2976497064-341179427-1001\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2013-05-03 11:51:53
ComboFix-quarantined-files.txt 2013-05-03 09:51
.
Před spuštěním: Volných bajtů: 233 262 473 216
Po spuštění: Volných bajtů: 243 803 459 584
.
- - End Of File - - 9C2EEF3777A249508D9D54408D7BA281

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Malware Privitize VPN

#14 Příspěvek od Márty84 »

Dejte novy log z RSIT
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Valda09
Návštěvník
Návštěvník
Příspěvky: 61
Registrován: 30 dub 2008 09:23

Re: Malware Privitize VPN

#15 Příspěvek od Valda09 »

Tady je:

Logfile of random's system information tool 1.09 (written by random/random)
Run by dusan.lehocky at 2013-05-03 18:49:53
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 232 GB (79%) free of 294 GB
Total RAM: 1993 MB (54% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:50:00, on 3.5.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16537)
Boot mode: Normal

Running processes:
C:\Program Files\Norton Identity Safe\Engine\2013.3.3.19\ccSvcHst.exe
C:\Program Files\Norton AntiVirus\Engine\20.3.1.22\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\PANDORA.TV\PanService\PanElevateExecutor.exe
C:\Windows\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\dusan.lehocky\Desktop\RSIT.exe
C:\Program Files\trend micro\dusan.lehocky.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\20.3.1.22\IPS\IPSBHO.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Norton Identity Protection - {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} - C:\Program Files\Norton Identity Safe\Engine\2013.3.3.19\coIEPlg.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll" (file missing)
O3 - Toolbar: Norton Identity Safe Toolbar - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Program Files\Norton Identity Safe\Engine\2013.3.3.19\coIEPlg.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [picon] "C:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe" -startup
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [EADM] "C:\Program Files\Origin\Origin.exe" -AutoStart
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\AMT\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Norton AntiVirus (NAV) - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\20.3.1.22\ccSvcHst.exe
O23 - Service: Norton Identity Safe (NCO) - Symantec Corporation - C:\Program Files\Norton Identity Safe\Engine\2013.3.3.19\ccSvcHst.exe
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: UltiDev Cassini Web Server for ASP.NET 2.0 - UltiDev LLC - C:\Program Files\UltiDev\Cassini Web Server for ASP.NET 2.0\UltiDevCassinWebServer2a.exe
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe

--
End of file - 11183 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2838011208-2976497064-341179427-1004Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2838011208-2976497064-341179427-1004UA.job
C:\Windows\tasks\HPCeeScheduleFordusan.lehocky.job

=========Mozilla firefox=========

ProfilePath - C:\Users\dusan.lehocky\AppData\Roaming\Mozilla\Firefox\Profiles\gygslypv.default

"smartwebprinting@hp.com"=C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
"{BBDA0591-3099-440a-AA10-41764D9DB4DB}"=C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\IPSFFPlgn\
"{F04D2D30-776C-4d02-8627-8E4385ECA58D}"=C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2013.2.0.18\coFFPlgn\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn.me/esnsonar,version=0.70.4]
"Description"=ESN Sonar browser plugin
"Path"=C:\Program Files\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/esnlaunch,version=2.1.3]
"Description"=
"Path"=C:\Program Files\Battlelog Web Plugins\2.1.3\npesnlaunch.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nexon.net/NxGame]
"Description"=Nexon Game Controller
"Path"=C:\ProgramData\NexonUS\NGM\npNxGameUS.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@ngm.nexoneu.com/NxGame]
"Description"=Nexon Game Controller
"Path"=C:\ProgramData\NexonEU\NGM\npNxGameeu.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Norton Vulnerability Protection - C:\Program Files\Norton AntiVirus\Engine\20.3.1.22\IPS\IPSBHO.DLL [2012-11-16 387040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2011-11-10 325408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2012-03-08 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB4C7833-A6EC-433f-B9FE-6B14B1A2F836}]
Norton Identity Protection - C:\Program Files\Norton Identity Safe\Engine\2013.3.3.19\coIEPlg.dll [2013-04-02 509776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-04-15 4529272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-12-21 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll [2012-06-11 1307728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-11-10 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2012-07-09 351136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22 517688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll [2012-06-11 1307728]
{A13C2648-91D4-4bf3-BC6D-0079707C4389} - Norton Identity Safe Toolbar - C:\Program Files\Norton Identity Safe\Engine\2013.3.3.19\coIEPlg.dll [2013-04-02 509776]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-07-03 7596576]
"picon"=C:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe [2009-07-24 796696]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2010-08-25 136216]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2010-08-25 171032]
"Persistence"=C:\Windows\system32\igfxpers.exe [2010-08-25 170520]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2009-11-18 54576]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-06-09 254696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Pando Media Booster"=C:\Program Files\Pando Networks\Media Booster\PMB.exe [2011-10-30 3077528]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2013-02-28 18642024]
"EADM"=C:\Program Files\Origin\Origin.exe [2013-04-10 3497552]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2010-08-25 228864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.siren"=sirenacm.dll
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"vidc.XVID"=xvidvfw.dll
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2013-05-03 18:17:09 ----D---- C:\Users\dusan.lehocky\AppData\Roaming\HPAppData
2013-05-03 11:52:00 ----SHD---- C:\$RECYCLE.BIN
2013-05-03 11:51:53 ----A---- C:\ComboFix.txt
2013-05-03 11:22:55 ----A---- C:\Windows\zip.exe
2013-05-03 11:22:55 ----A---- C:\Windows\SWSC.exe
2013-05-03 11:22:55 ----A---- C:\Windows\SWREG.exe
2013-05-03 11:22:55 ----A---- C:\Windows\sed.exe
2013-05-03 11:22:55 ----A---- C:\Windows\PEV.exe
2013-05-03 11:22:55 ----A---- C:\Windows\NIRCMD.exe
2013-05-03 11:22:55 ----A---- C:\Windows\MBR.exe
2013-05-03 11:22:55 ----A---- C:\Windows\grep.exe
2013-05-03 11:22:46 ----D---- C:\Qoobox
2013-05-03 11:22:16 ----D---- C:\Windows\erdnt
2013-05-02 14:52:04 ----D---- C:\Users\dusan.lehocky\AppData\Roaming\Mozilla
2013-05-02 14:52:01 ----D---- C:\ProgramData\Mozilla
2013-05-02 14:52:00 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-05-02 14:51:57 ----D---- C:\Program Files\Mozilla Firefox
2013-05-01 21:11:33 ----D---- C:\Program Files\PANDORA.TV
2013-05-01 21:11:11 ----D---- C:\Program Files\The KMPlayer
2013-05-01 21:00:29 ----A---- C:\AdwCleaner[S2].txt
2013-05-01 20:55:05 ----A---- C:\AdwCleaner[S1].txt
2013-05-01 20:54:51 ----A---- C:\AdwCleaner[R2].txt
2013-05-01 19:18:47 ----A---- C:\AdwCleaner[R1].txt
2013-04-29 22:15:28 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2013-04-29 22:15:27 ----D---- C:\Users\dusan.lehocky\AppData\Roaming\Malwarebytes
2013-04-29 22:15:09 ----D---- C:\ProgramData\Malwarebytes
2013-04-28 23:59:58 ----A---- C:\Windows\system32\jsproxy.dll
2013-04-28 23:59:58 ----A---- C:\Windows\system32\jscript9.dll
2013-04-28 23:59:58 ----A---- C:\Windows\system32\jscript.dll
2013-04-28 23:59:58 ----A---- C:\Windows\system32\iesetup.dll
2013-04-28 23:59:57 ----A---- C:\Windows\system32\ieui.dll
2013-04-28 23:59:56 ----A---- C:\Windows\system32\urlmon.dll
2013-04-28 23:59:56 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-04-28 23:59:56 ----A---- C:\Windows\system32\msfeeds.dll
2013-04-28 23:59:56 ----A---- C:\Windows\system32\iesysprep.dll
2013-04-28 23:59:56 ----A---- C:\Windows\system32\iernonce.dll
2013-04-28 23:59:56 ----A---- C:\Windows\system32\ie4uinit.exe
2013-04-28 23:59:55 ----A---- C:\Windows\system32\iertutil.dll
2013-04-28 23:59:54 ----A---- C:\Windows\system32\wininet.dll
2013-04-28 23:59:53 ----A---- C:\Windows\system32\ieframe.dll
2013-04-28 23:59:52 ----A---- C:\Windows\system32\mshtml.dll
2013-04-28 23:45:15 ----D---- C:\rsit
2013-04-28 23:45:15 ----D---- C:\Program Files\trend micro
2013-04-28 23:40:33 ----D---- C:\Program Files\Common Files\Skype
2013-04-24 17:34:07 ----A---- C:\Windows\system32\drivers\ntfs.sys
2013-04-19 17:38:14 ----D---- C:\Program Files\Origin Games
2013-04-19 17:23:42 ----D---- C:\ProgramData\EA Core
2013-04-10 19:55:54 ----D---- C:\Program Files\Battlelog Web Plugins
2013-04-10 13:10:12 ----A---- C:\Windows\system32\win32k.sys
2013-04-10 13:10:11 ----A---- C:\Windows\system32\drivers\fvevol.sys
2013-04-10 13:10:10 ----A---- C:\Windows\system32\ntoskrnl.exe
2013-04-10 13:10:10 ----A---- C:\Windows\system32\ntkrnlpa.exe
2013-04-10 13:10:09 ----A---- C:\Windows\system32\smss.exe
2013-04-10 13:10:09 ----A---- C:\Windows\system32\csrsrv.dll
2013-04-10 13:10:05 ----A---- C:\Windows\system32\tsgqec.dll
2013-04-10 13:10:05 ----A---- C:\Windows\system32\mstscax.dll
2013-04-10 13:10:05 ----A---- C:\Windows\system32\aaclient.dll
2013-04-07 13:01:06 ----A---- C:\Windows\system32\FlashPlayerApp.exe

======List of files/folders modified in the last 1 month======

2013-05-03 18:26:09 ----D---- C:\Windows\system32\config
2013-05-03 18:20:01 ----D---- C:\Windows\System32
2013-05-03 18:20:01 ----D---- C:\Windows\inf
2013-05-03 18:20:01 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-05-03 18:18:41 ----D---- C:\Windows\Temp
2013-05-03 15:12:28 ----D---- C:\Windows\rescache
2013-05-03 14:39:52 ----A---- C:\Windows\system32\log.txt
2013-05-03 11:50:33 ----D---- C:\Windows
2013-05-03 11:50:33 ----A---- C:\Windows\system.ini
2013-05-03 11:50:26 ----D---- C:\Windows\system32\drivers\etc
2013-05-03 11:47:29 ----D---- C:\ProgramData
2013-05-03 11:43:50 ----SHD---- C:\System Volume Information
2013-05-03 11:42:59 ----D---- C:\Windows\system32\drivers
2013-05-03 11:42:59 ----D---- C:\Windows\AppPatch
2013-05-03 11:42:58 ----D---- C:\Program Files\Common Files
2013-05-03 11:04:59 ----D---- C:\Users\dusan.lehocky\AppData\Roaming\Skype
2013-05-02 14:52:00 ----RD---- C:\Program Files
2013-05-02 03:01:17 ----SHD---- C:\Windows\Installer
2013-05-02 03:01:17 ----D---- C:\Config.Msi
2013-05-02 03:01:11 ----D---- C:\ProgramData\Microsoft Help
2013-05-01 21:10:57 ----D---- C:\Program Files\QuickTime
2013-05-01 12:59:41 ----D---- C:\Windows\Prefetch
2013-04-30 16:58:38 ----D---- C:\Windows\Tasks
2013-04-30 16:58:38 ----D---- C:\Windows\system32\Tasks
2013-04-30 16:57:57 ----A---- C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-04-29 22:00:23 ----D---- C:\Zaloha
2013-04-29 18:37:29 ----D---- C:\Windows\winsxs
2013-04-29 18:35:42 ----D---- C:\Program Files\Internet Explorer
2013-04-29 18:35:41 ----D---- C:\Windows\system32\DriverStore
2013-04-29 18:35:15 ----D---- C:\Program Files\Microsoft Silverlight
2013-04-29 00:00:11 ----D---- C:\Windows\system32\catroot
2013-04-29 00:00:10 ----D---- C:\Windows\system32\catroot2
2013-04-28 23:40:41 ----D---- C:\ProgramData\Skype
2013-04-28 23:40:33 ----RD---- C:\Program Files\Skype
2013-04-28 23:39:00 ----D---- C:\Program Files\Google
2013-04-19 17:38:10 ----HD---- C:\Program Files\Common Files\EAInstaller
2013-04-19 17:13:21 ----RSD---- C:\Windows\assembly
2013-04-17 12:32:42 ----D---- C:\Windows\system32\drivers\NAV
2013-04-17 10:30:37 ----D---- C:\Windows\system32\drivers\NST
2013-04-10 19:52:54 ----D---- C:\Program Files\Origin

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iastor.sys [2010-03-04 435736]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [2010-03-19 45648]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 SymDS;Symantec Data Store; C:\Windows\system32\drivers\NAV\1403010.016\SYMDS.SYS [2013-01-22 367704]
R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\NAV\1403010.016\SYMEFA.SYS [2013-01-31 934488]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 BHDrvx86;BHDrvx86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\BASHDefs\20130412.001\BHDrvx86.sys [2013-04-13 1000024]
R1 ccSet_NAV;Norton AntiVirus Settings Manager; C:\Windows\system32\drivers\NAV\1403010.016\ccSetx86.sys [2012-11-16 134304]
R1 ccSet_NST;Norton Identity Safe Settings Manager; C:\Windows\system32\drivers\NST\7DD03030.013\ccSetx86.sys [2012-11-16 134304]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [2012-08-09 376480]
R1 IDSVix86;IDSVix86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\IPSDefs\20130502.001\IDSvix86.sys [2013-02-20 386720]
R1 SRTSP;Symantec Real Time Storage Protection; C:\Windows\System32\Drivers\NAV\1403010.016\SRTSP.SYS [2013-01-29 602712]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL); C:\Windows\system32\drivers\NAV\1403010.016\SRTSPX.SYS [2013-01-29 32344]
R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\NAV\1403010.016\Ironx86.SYS [2012-11-16 175264]
R1 SymNetS;Symantec Network Security WFP Driver; C:\Windows\System32\Drivers\NAV\1403010.016\SYMNETS.SYS [2013-01-31 338592]
R2 regi;regi; C:\Windows\system32\drivers\regi.sys [2007-04-18 11032]
R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K; C:\Windows\system32\DRIVERS\e1k6232.sys [2009-09-02 202408]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-08-09 106656]
R3 HECI;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECI.sys [2009-07-24 40832]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2010-08-25 9024512]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-07-03 2656160]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\VirusDefs\20130502.034\NAVENG.SYS [2013-02-21 93296]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\VirusDefs\20130502.034\NAVEX15.SYS [2013-02-21 1603824]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [2013-02-21 142496]
R3 TPM;TPM; C:\Windows\system32\drivers\tpm.sys [2009-07-14 30720]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 78336]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 btmhsf;btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [2011-07-19 225280]
S3 catchme;catchme; \??\C:\Users\DUSAN~2.LEH\AppData\Local\Temp\catchme.sys []
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 131072]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2010-11-20 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 36864]
S3 EagleXNt;EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2012-03-08 39272]
S3 iBtFltCoex;iBtFltCoex; C:\Windows\system32\DRIVERS\iBtFltCoex.sys [2011-07-20 47104]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [2013-04-29 40776]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmb.sys [2010-12-02 18304]
S3 nmwcdc;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 27648]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2012-09-27 86528]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 HPSLPSVC;HP Network Devices Support; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-05 112152]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2010-06-16 73728]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files\Intel\AMT\LMS.exe [2009-07-24 174616]
R2 NAV;Norton AntiVirus; C:\Program Files\Norton AntiVirus\Engine\20.3.1.22\ccSvcHst.exe [2012-12-24 144520]
R2 NCO;Norton Identity Safe; C:\Program Files\Norton Identity Safe\Engine\2013.3.3.19\ccSvcHst.exe [2012-12-24 144520]
R2 PanService;PandoraService; C:\Program Files\PANDORA.TV\PanService\PandoraService.exe [2012-09-28 625304]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2013-03-12 76888]
R2 PSI_SVC_2;Protexis Licensing V2; C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R2 UltiDev Cassini Web Server for ASP.NET 2.0;UltiDev Cassini Web Server for ASP.NET 2.0; C:\Program Files\UltiDev\Cassini Web Server for ASP.NET 2.0\UltiDevCassinWebServer2a.exe [2010-08-25 49152]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2009-07-24 2066968]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 1713536]
R3 BBUpdate;BBUpdate; C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.exe [2012-06-11 240208]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S2 BBSvc;BingBar Service; C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.exe [2012-06-11 193616]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 Skype C2C Service;Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-04-15 3289208]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-02-28 161384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-04-07 253656]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2012-03-08 1492840]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2012-08-10 1001376]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-04-10 115608]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 RoxMediaDB10;RoxMediaDB10; C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2010-03-19 1120752]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-01-26 652800]
S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2009-10-16 74392]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-02-14 1343400]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]

-----------------EOF-----------------

Zamčeno