Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Malware.Trace chrome_debug.exe

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Snake.PP
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 10 zář 2013 14:47

Malware.Trace chrome_debug.exe

#1 Příspěvek od Snake.PP »

Dobrý den.Superantispyware mi detekoval Malware v registrech, ale po odstranění a restartu pc je tam znovu.
Jo a v dočasných souborech C:\Users\Baby Snake\AppData\Local\Temp se mi objevily soubory Baby Snake7 a Baby Snake8
které nejdou smazat a Win mi hodily chybu spuštění skriptu(už to po restartu žádnou chybu nehlásí).Počítám že to bylo asi od Avastu.
Předem děkuji s případnou pomocí a trpělivostí se mnou.Nejsem zrovna PC expert.

Kód: Vybrat vše

http://imageshack.us/photo/my-images/51/8jwq.jpg/
log z RSIT

Logfile of random's system information tool 1.09 (written by random/random)
Run by Baby Snake at 2013-09-10 16:08:49
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 61 GB (59%) free of 103 GB
Total RAM: 8190 MB (72% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:11:45, on 10.9.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16660)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\OKsoftware\Svátky a výročí\Vyroci.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files (x86)\MenuApp\MenuApp.exe
C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\SysWOW64\explorer.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Baby Snake.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [msunxkSrv] C:\Windows\inf\msunxk.vbe
O4 - HKCU\..\Run: [Svátky a výročí] C:\Program Files (x86)\OKsoftware\Svátky a výročí\Vyroci.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [HKCU] C:\Users\Baby Snake\AppData\Roaming\WinDir\chrome_debug.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: MenuAppServer.lnk = C:\Program Files (x86)\MenuApp\MenuApp.exe
O4 - Startup: Thunderbird.lnk = C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout pomocí &BitSpiritu - C:\Program Files (x86)\BitSpirit\bsurl.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted IP range: http://127.0.0.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Služba Acronis Scheduler2 (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Služba Acronis Nonstop Backup (afcdpsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: JMB36X - Unknown owner - C:\Windows\SysWOW64\XSrvSetup.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\SysWOW64\nlssrv32.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) - AVG - C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8650 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
atieclxx
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\COMODO\COMODO Internet Security\cistray.exe"
"C:\Program Files\Logitech\SetPointP\SetPoint.exe" /launchGaming
"C:\Program Files (x86)\OKsoftware\Svátky a výročí\Vyroci.exe"
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
"C:\Program Files (x86)\MenuApp\MenuApp.exe" -u
"C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe"
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe"
"C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
C:\Windows\SysWOW64\XSrvSetup.exe
KHALMNPR.EXE /API
C:\Windows\SysWOW64\nlssrv32.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe"
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-e17aa7c0-5c27-4e71-bc6c-8c709b164142 -SystemEventPortName:HostProcess-41dd89ba-5031-401b-ac8c-f20d7c2037f6 -IoCancelEventPortName:HostProcess-0b4321c6-a1f9-47a9-a30d-3063f9087068 -NonStateChangingEventPortName:HostProcess-b625e44d-7238-43be-8e13-67a868127153 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:f62088df-8e61-42ac-bbf9-0e843f50e8c6 -DeviceGroupId:WpdFsGroup
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe" /TUStart /pid:3152
explorer.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe" /ModeAvMonitor -Embedding
"C:\Program Files\COMODO\COMODO Internet Security\cis.exe" --alertsUI
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
"D:\Internet\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
taskeng.exe {37032611-9D85-43D4-9835-F9E080A09511}

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Baby Snake\AppData\Roaming\Mozilla\Firefox\Profiles\hh1k882v.default-1357954022107

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz"
prefs.js - "extensions.enabledItems" - "amin.eft_Shutdown@gmail.com:3.6.2D, YoutubeDownloader@PeterOlayev.com:1.5, {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.2, {097d3191-e6fa-4728-9826-b533d755359d}:0.7.13, {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.4.6, {35106bca-6c78-48c7-ac28-56df30b51d2a}:1.3.8, {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.14.2, {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.9.9, {9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}:6.0.4, {a0faa0a4-f1a7-4098-9a74-21efc3a92372}:4.0.1, {A4732521-77D9-447E-A557-B279AC923F06}:0.6.8, {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.10, {c151d79e-e61b-4a90-a887-5a46d38fba99}:2.6.1, {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3, {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8, {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.2, {e968fc70-8f95-4ab9-9e79-304de2a71ee1}:0.7.3, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, bkmrksync@nokia.com:1.0.0.736, {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.4.51, {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.2, {1018e4d6-728f-4b20-ad56-37578a4de76b}:4.1.1, {dc572301-7619-498c-a57d-39143191b318}:0.3.8.5, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.15, {36C13C8F-54F1-412e-8177-2E411719162D}:4.1.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.85 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_85.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.25.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nokia.com/EnablerPlugin]
"Description"=Nokia Suite Enabler Plugin
"Path"=C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nullsoft.com/winampDetector;version=1]
"Description"=Winamp Detector
"Path"=C:\Program Files (x86)\Winamp Detect\npwachk.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.8]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeExManDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.85 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_85.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeExManDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll


C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
nppdf32.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
babylon.xml
fcmdSrch.xml

C:\Users\Baby Snake\AppData\Roaming\Mozilla\Firefox\Profiles\hh1k882v.default-1357954022107\extensions\
{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
{1018e4d6-728f-4b20-ad56-37578a4de76b}
{3d7eb24f-2740-49df-8937-200b1cc08f8a}
{b9db16a4-6edc-47ec-a1f4-b86292ed211d}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF949550-9094-4807-95EC-D1C317803333}]
Logitech SetPoint - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2013-07-31 433944]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-06-28 463272]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF949550-9094-4807-95EC-D1C317803333}]
Logitech SetPoint - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2013-07-31 364824]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-06-28 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-03-29 13513288]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2013-07-08 1502424]
"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2013-07-31 3091224]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Svátky a výročí"=C:\Program Files (x86)\OKsoftware\Svátky a výročí\Vyroci.exe [2006-04-28 1019904]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-03-14 3672640]
""= []
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2013-08-27 5705456]
"HKCU"=C:\Users\Baby Snake\AppData\Roaming\WinDir\chrome_debug.exe [2013-09-10 373760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTibMounterMonitor]
C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-09-20 444904]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS6ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HydraVisionDesktopManager]
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [2012-12-19 393216]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup]
C:\Windows\RaidTool\xInsIDE.exe [2007-03-20 36864]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Download Assistant]
C:\Windows\System32\LogiLDA.dll [2012-09-20 1832760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe]
C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [2013-04-19 1090912]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NUSB3MON]
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2010-11-17 113288]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-07-25 20684656]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Služba Acronis Scheduler2]
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [2010-12-17 391144]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files (x86)\Steam\Steam.exe [2012-11-23 1353080]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12 253816]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [2010-12-17 5566176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Baby Snake^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Registrace produktu.lnk]
C:\PROGRA~2\COMMON~1\LogiShrd\eReg\SetPoint\eReg.exe [2009-11-16 517384]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2013-08-30 4858968]
"msunxkSrv"=C:\Windows\inf\msunxk.vbe [2013-08-27 1558]

C:\Users\Baby Snake\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MenuAppServer.lnk - C:\Program Files (x86)\MenuApp\MenuApp.exe
Thunderbird.lnk - C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2013-06-13 66328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspscan.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspview.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mstore.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\offdiag.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ois.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-09-10 16:08:49 ----D---- C:\rsit
2013-09-10 16:08:49 ----D---- C:\Program Files\trend micro
2013-09-10 15:20:11 ----D---- C:\Users\Baby Snake\AppData\Roaming\WinDir
2013-09-10 15:02:10 ----D---- C:\Users\Baby Snake\AppData\Roaming\SUPERAntiSpyware.com
2013-09-10 15:01:24 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2013-09-10 15:01:24 ----D---- C:\Program Files\SUPERAntiSpyware
2013-09-10 14:04:08 ----D---- C:\Program Files (x86)\VSO
2013-09-09 14:56:39 ----A---- C:\Windows\system32\FNTCACHE.DAT
2013-09-09 13:56:00 ----A---- C:\Windows\system32\TURegOpt.exe
2013-09-09 13:55:58 ----A---- C:\Windows\SYSWOW64\authuitu.dll
2013-09-09 13:55:58 ----A---- C:\Windows\system32\authuitu.dll
2013-09-09 13:55:47 ----D---- C:\Users\Baby Snake\AppData\Roaming\AVG
2013-09-09 13:55:27 ----D---- C:\Program Files (x86)\AVG
2013-09-09 13:53:11 ----D---- C:\ProgramData\AVG
2013-09-09 13:52:55 ----SHD---- C:\Config.Msi
2013-09-09 13:52:08 ----SHD---- C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2013-09-03 20:06:25 ----D---- C:\Users\Baby Snake\AppData\Roaming\The Creative Assembly
2013-08-21 18:23:10 ----D---- C:\Program Files (x86)\Ubisoft
2013-08-17 02:05:03 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-08-14 11:12:27 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-08-14 11:12:27 ----A---- C:\Windows\system32\ieui.dll
2013-08-14 11:12:26 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-08-14 11:12:26 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-08-14 11:12:26 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-08-14 11:12:26 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-08-14 11:12:26 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-08-14 11:12:26 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-14 11:12:26 ----A---- C:\Windows\system32\iesysprep.dll
2013-08-14 11:12:26 ----A---- C:\Windows\system32\iesetup.dll
2013-08-14 11:12:26 ----A---- C:\Windows\system32\iernonce.dll
2013-08-14 11:12:26 ----A---- C:\Windows\system32\ie4uinit.exe
2013-08-14 11:12:25 ----A---- C:\Windows\system32\iertutil.dll
2013-08-14 11:12:24 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-08-14 11:12:24 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-08-14 11:12:24 ----A---- C:\Windows\system32\msfeeds.dll
2013-08-14 11:12:24 ----A---- C:\Windows\system32\jscript.dll
2013-08-14 11:12:23 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-08-14 11:12:23 ----A---- C:\Windows\system32\jscript9.dll
2013-08-14 11:12:22 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-08-14 11:12:22 ----A---- C:\Windows\system32\urlmon.dll
2013-08-14 11:12:21 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-08-14 11:12:21 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-08-14 11:12:21 ----A---- C:\Windows\system32\jsproxy.dll
2013-08-14 11:12:20 ----A---- C:\Windows\system32\wininet.dll
2013-08-14 11:12:19 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-08-14 11:12:18 ----A---- C:\Windows\system32\ieframe.dll
2013-08-14 11:12:17 ----A---- C:\Windows\system32\mshtml.dll
2013-08-14 11:12:15 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-08-14 11:05:04 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2013-08-14 11:05:04 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2013-08-14 11:05:04 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-08-14 11:05:04 ----A---- C:\Windows\system32\wintrust.dll
2013-08-14 11:05:04 ----A---- C:\Windows\system32\crypt32.dll
2013-08-14 11:05:03 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2013-08-14 11:05:03 ----A---- C:\Windows\system32\cryptsvc.dll
2013-08-14 11:05:03 ----A---- C:\Windows\system32\cryptnet.dll
2013-08-14 11:04:56 ----A---- C:\Windows\SYSWOW64\tzres.dll
2013-08-14 11:04:56 ----A---- C:\Windows\system32\tzres.dll
2013-08-14 11:04:52 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2013-08-14 11:04:52 ----A---- C:\Windows\system32\WMVDECOD.DLL
2013-08-14 11:04:51 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2013-08-14 11:04:51 ----A---- C:\Windows\system32\rpcrt4.dll
2013-08-14 11:04:49 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2013-08-14 11:04:48 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2013-08-14 11:04:48 ----A---- C:\Windows\system32\ntoskrnl.exe
2013-08-14 11:04:48 ----A---- C:\Windows\system32\ntdll.dll
2013-08-14 11:04:47 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2013-08-14 11:04:47 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2013-08-14 11:04:47 ----A---- C:\Windows\system32\wow64.dll
2013-08-14 11:04:45 ----A---- C:\Windows\SYSWOW64\wow32.dll
2013-08-14 11:04:45 ----A---- C:\Windows\SYSWOW64\user.exe
2013-08-14 11:04:45 ----A---- C:\Windows\SYSWOW64\setup16.exe
2013-08-14 11:04:45 ----A---- C:\Windows\SYSWOW64\instnm.exe
2013-08-14 11:04:44 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2013-08-14 11:04:43 ----A---- C:\Windows\system32\drivers\tcpip.sys

======List of files/folders modified in the last 1 month======

2013-09-10 16:09:02 ----D---- C:\Windows\Prefetch
2013-09-10 16:08:49 ----RD---- C:\Program Files
2013-09-10 15:24:37 ----D---- C:\Windows\system32\config
2013-09-10 15:13:08 ----D---- C:\Windows\Temp
2013-09-10 15:05:31 ----D---- C:\Windows\system32\catroot2
2013-09-10 15:02:10 ----HD---- C:\ProgramData
2013-09-10 14:35:10 ----D---- C:\Windows\system32\Tasks
2013-09-10 14:25:24 ----RD---- C:\Program Files (x86)
2013-09-10 14:24:50 ----D---- C:\Windows\inf
2013-09-10 14:04:17 ----D---- C:\Users\Baby Snake\AppData\Roaming\Vso
2013-09-10 14:04:16 ----A---- C:\Users\Baby Snake\AppData\Roaming\inst.exe
2013-09-10 13:56:01 ----D---- C:\Windows\SysWOW64
2013-09-10 13:40:47 ----D---- C:\ProgramData\VSO
2013-09-09 14:57:04 ----AD---- C:\Windows
2013-09-09 14:56:47 ----D---- C:\Windows\debug
2013-09-09 14:56:39 ----D---- C:\Windows\System32
2013-09-09 13:56:05 ----SHD---- C:\Windows\Installer
2013-09-08 12:48:50 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-09-08 11:26:35 ----D---- C:\Windows\Logs
2013-09-07 16:13:32 ----D---- C:\Users\Baby Snake\AppData\Roaming\vlc
2013-09-07 13:17:02 ----RSD---- C:\Windows\assembly
2013-09-07 13:07:56 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2013-09-06 16:27:30 ----D---- C:\ProgramData\Orbit
2013-09-04 00:49:08 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-09-03 21:28:59 ----D---- C:\Program Files\WinRAR
2013-09-03 20:00:47 ----D---- C:\Windows\winsxs
2013-08-30 13:27:30 ----D---- C:\Users\Baby Snake\AppData\Roaming\DAEMON Tools Lite
2013-08-30 13:21:11 ----D---- C:\Program Files (x86)\Flash Player Pro
2013-08-30 09:47:14 ----A---- C:\Windows\system32\aswBoot.exe
2013-08-29 15:19:41 ----D---- C:\Users\Baby Snake\AppData\Roaming\Skype
2013-08-29 01:12:10 ----D---- C:\Users\Baby Snake\AppData\Roaming\Winamp
2013-08-26 22:06:02 ----D---- C:\Program Files (x86)\Steam
2013-08-26 21:58:57 ----D---- C:\Program Files\CCleaner
2013-08-18 10:08:27 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-16 15:11:44 ----D---- C:\ProgramData\Steam
2013-08-15 17:16:04 ----D---- C:\Windows\rescache
2013-08-14 13:19:23 ----D---- C:\Windows\Microsoft.NET
2013-08-14 12:08:07 ----D---- C:\Windows\Panther
2013-08-14 11:58:43 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-08-14 11:58:43 ----D---- C:\Windows\system32\drivers
2013-08-14 11:58:43 ----D---- C:\Windows\system32\cs-CZ
2013-08-14 11:58:43 ----D---- C:\Windows\AppPatch
2013-08-14 11:58:43 ----D---- C:\Program Files\Internet Explorer
2013-08-14 11:58:43 ----D---- C:\Program Files (x86)\Internet Explorer
2013-08-14 11:12:37 ----D---- C:\Windows\system32\catroot
2013-08-14 11:10:38 ----D---- C:\ProgramData\Microsoft Help
2013-08-14 11:10:03 ----D---- C:\Windows\system32\MRT
2013-08-14 11:06:10 ----A---- C:\Windows\system32\MRT.exe
2013-08-13 21:42:35 ----D---- C:\Users\Baby Snake\AppData\Roaming\Logishrd
2013-08-13 21:42:34 ----D---- C:\ProgramData\Skype
2013-08-13 21:42:34 ----D---- C:\Program Files\ATI Technologies
2013-08-13 21:42:21 ----D---- C:\Program Files (x86)\Mozilla Thunderbird

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2013-08-30 65336]
R0 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2013-08-30 204880]
R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2009-10-07 115312]
R0 mv91cons;Marvell 91xx Config Device Driver; C:\Windows\system32\DRIVERS\mv91cons.sys [2009-10-27 22568]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 snapman;Acronis Snapshots Manager; C:\Windows\system32\DRIVERS\snapman.sys [2012-11-28 277088]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2012-11-22 564824]
R0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273); C:\Windows\system32\DRIVERS\tdrpm273.sys [2012-11-28 1263200]
R0 timounter;Acronis Backup Archive Explorer; C:\Windows\system32\DRIVERS\timntr.sys [2012-11-28 970336]
R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [2013-08-30 72016]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2013-08-30 1030952]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2013-08-30 378944]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2013-08-30 64288]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\Windows\System32\DRIVERS\cmderd.sys [2013-06-18 23168]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\system32\DRIVERS\cmdguard.sys [2013-07-08 708632]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2013-06-18 48360]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-03-14 283200]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2013-06-18 96800]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
R2 AODDriver4.2;AODDriver4.2; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-11-20 57512]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2013-08-30 33400]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2013-08-30 80816]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2013-06-23 88480]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2013-06-23 46400]
R3 afcdp;afcdp; C:\Windows\system32\DRIVERS\afcdp.sys [2012-11-28 285280]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-07-24 12721664]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2013-07-24 617472]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2013-07-05 96256]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2013-03-29 3379272]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter; C:\Windows\system32\DRIVERS\LEqdUsb.Sys [2013-05-23 77592]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter; C:\Windows\system32\DRIVERS\LHidEqd.Sys [2013-05-23 13080]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2013-05-23 76568]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2013-05-23 59160]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2010-11-19 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2010-11-19 181248]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-09-29 646248]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [2013-08-21 14112]
S3 aoythijl;aoythijl; C:\Windows\system32\drivers\aoythijl.sys []
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys []
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2013-01-23 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2013-01-23 27136]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2012-10-17 26112]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2012-06-05 237968]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2013-01-23 9216]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2013-01-23 9216]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2013-05-23 143120]
R2 AcrSch2Svc;Služba Acronis Scheduler2; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [2010-12-17 1112664]
R2 afcdpsrv;Služba Acronis Nonstop Backup; C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2012-11-28 3246040]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2013-07-24 239616]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-07-23 344064]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-08-30 46808]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2013-07-08 6199520]
R2 JMB36X;JMB36X; C:\Windows\SysWOW64\XSrvSetup.exe [2009-08-06 65536]
R2 nlsX86cc;Nalpeiron Licensing Service; C:\Windows\SysWOW64\nlssrv32.exe [2012-09-05 66560]
R2 TuneUp.UtilitiesSvc;AVG PC TuneUp Service; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2013-08-30 2099512]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-04 257416]
S3 cmdvirth;COMODO Virtual Service Manager; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2013-06-18 158936]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2013-06-13 357144]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-08-17 117656]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2012-11-23 529744]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-11-21 1255736]
S4 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-11 65640]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-08 51648]
S4 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S4 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-07-25 162672]
S4 Správce výběru OS;Aktivátor Správce výběru OS Acronis; C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe [2010-10-28 2156952]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119530
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Malware.Trace chrome_debug.exe

#2 Příspěvek od Rudy »

Zdravím!
Stáhněte FRST: http://vyosek.ic.cz/pro_usery/FRSTLauncher.exe a uložte na plochu. Spusťte a klikněte na >Scan<. Po skončení skenu se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Snake.PP
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 10 zář 2013 14:47

Re: Malware.Trace chrome_debug.exe

#3 Příspěvek od Snake.PP »

FRST log

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-09-2013 01
Ran by Baby Snake (administrator) on BLACKWIDOW on 10-09-2013 17:28:30
Running from C:\Users\Baby Snake\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Igor Gottwald - OKsoftware) C:\Program Files (x86)\OKsoftware\Svátky a výročí\Vyroci.exe
(Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
(desktopApps) C:\Program Files (x86)\MenuApp\MenuApp.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
() C:\Windows\SysWOW64\XSrvSetup.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
(Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe
(AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
(AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor)
HKLM\...\Run: [COMODO Internet Security] - C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1502424 2013-07-08] (COMODO)
HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [3091224 2013-07-31] (Logitech, Inc.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKLM\...\Policies\Explorer: [NoActiveDesktop] 1
HKLM\...\Policies\Explorer: [NoActiveDesktopChanges] 1
HKCU\...\Run: [Svátky a výročí] - C:\Program Files (x86)\OKsoftware\Svátky a výročí\Vyroci.exe [1019904 2006-04-28] (Igor Gottwald - OKsoftware)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
HKCU\...\Run: [] - [x]
HKCU\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [5705456 2013-08-27] (SUPERAntiSpyware)
HKCU\...\Run: [HKCU] - C:\Users\Baby Snake\AppData\Roaming\WinDir\chrome_debug.exe [373760 2013-09-10] (Sysinternals - www.sysinternals.com)
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-30] (AVAST Software)
HKLM-x32\...\Run: [msunxkSrv] - C:\Windows\inf\msunxk.vbe [1558 2013-08-27] ()
HKU\Default\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\Default User\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
AppInit_DLLs: [0 ] ()
IMEO\excel.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IMEO\mspscan.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IMEO\mspview.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IMEO\mstore.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IMEO\offdiag.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IMEO\ois.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IMEO\powerpnt.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IMEO\winword.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
Startup: C:\Users\Baby Snake\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MenuAppServer.lnk
ShortcutTarget: MenuAppServer.lnk -> C:\Program Files (x86)\MenuApp\MenuApp.exe (desktopApps)
Startup: C:\Users\Baby Snake\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Thunderbird.lnk
ShortcutTarget: Thunderbird.lnk -> C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
SearchScopes: HKCU - {EF832FC3-8C0B-4816-9DF6-A8CA5F0FAD18} URL = http://search.seznam.cz/?q={searchTerms ... chmodule_2
BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37

FireFox:
========
FF ProfilePath: C:\Users\Baby Snake\AppData\Roaming\Mozilla\Firefox\Profiles\hh1k882v.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_85.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_85.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nokia.com/EnablerPlugin - C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 - C:\Program Files (x86)\Winamp Detect\npwachk.dll (Nullsoft, Inc.)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin-x32: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrch.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt

==================== Services (Whitelisted) =================

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [143120 2013-05-23] (SUPERAntiSpyware.com)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-07-23] (Advanced Micro Devices, Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software)
R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [6199520 2013-07-08] (COMODO)
S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [158936 2013-06-18] (COMODO)
R2 JMB36X; C:\Windows\SysWOW64\XSrvSetup.exe [65536 2009-08-06] ()
S4 Správce výběru OS; C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe [2156952 2010-10-28] ()
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2099512 2013-08-30] (AVG)

==================== Drivers (Whitelisted) ====================

R2 AODDriver4.2; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [57512 2012-11-20] (Advanced Micro Devices)
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] ()
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [88480 2013-06-23] ()
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [23168 2013-06-18] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [708632 2013-07-08] (COMODO)
R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [48360 2013-06-18] (COMODO)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-03-14] (DT Soft Ltd)
R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [96800 2013-06-18] (COMODO)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [46400 2013-06-23] ()
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2012-11-22] (Duplex Secure Ltd.)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [14112 2013-08-21] (TuneUp Software)
U3 aoythijl; C:\Windows\System32\Drivers\aoythijl.sys [0 ] (Microsoft Corporation)
S3 gdrv; \??\C:\Windows\gdrv.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-09-10 17:28 - 2013-09-10 17:28 - 00000000 ____D C:\FRST
2013-09-10 17:27 - 2013-09-10 17:27 - 00000000 ____D C:\Users\BABYSN~1\AppData\Local\qb7DC286.B5
2013-09-10 17:27 - 2013-09-09 16:56 - 01949196 _____ (Farbar) C:\Users\Baby Snake\Desktop\FRST64.exe
2013-09-10 17:26 - 2013-09-10 17:26 - 00000000 ____D C:\Users\BABYSN~1\AppData\Local\qb7C9973.48
2013-09-10 16:23 - 2013-09-10 16:23 - 00001419 _____ C:\Users\Baby Snake\Desktop\hijackthis.exe – zástupce.lnk
2013-09-10 16:08 - 2013-09-10 16:11 - 00000000 ____D C:\rsit
2013-09-10 16:08 - 2013-09-10 16:11 - 00000000 ____D C:\Program Files\trend micro
2013-09-10 15:20 - 2013-09-10 15:20 - 00000000 ____D C:\Users\Baby Snake\AppData\Roaming\WinDir
2013-09-10 15:11 - 2013-09-10 15:11 - 00000000 _____ C:\Users\Baby Snake\regbcm
2013-09-10 15:02 - 2013-09-10 15:02 - 00000000 ____D C:\Users\Baby Snake\AppData\Roaming\SUPERAntiSpyware.com
2013-09-10 15:01 - 2013-09-10 15:04 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-09-10 15:01 - 2013-09-10 15:01 - 00001808 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2013-09-10 15:01 - 2013-09-10 15:01 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2013-09-10 14:35 - 2013-09-10 14:35 - 00002762 _____ C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013
2013-09-10 14:04 - 2013-09-10 14:04 - 00000000 ____D C:\Program Files (x86)\VSO
2013-09-10 13:40 - 2013-09-10 13:40 - 00000000 ____D C:\Users\Baby Snake\Documents\PcSetup
2013-09-09 14:58 - 2013-09-09 14:58 - 00118304 _____ C:\Users\BABYSN~1\AppData\Local\GDIPFONTCACHEV1.DAT
2013-09-09 14:57 - 2013-09-10 15:10 - 00000280 _____ C:\Windows\setupact.log
2013-09-09 14:57 - 2013-09-09 14:57 - 00000000 _____ C:\Windows\setuperr.log
2013-09-09 14:56 - 2013-09-10 15:10 - 00000926 _____ C:\Windows\PFRO.log
2013-09-09 14:56 - 2013-09-09 14:56 - 05029280 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-09 14:47 - 2013-09-09 14:47 - 00000000 ____D C:\Users\BABYSN~1\AppData\Local\Avg2014
2013-09-09 13:56 - 2013-08-30 11:40 - 00040248 _____ (AVG) C:\Windows\system32\TURegOpt.exe
2013-09-09 13:55 - 2013-09-09 13:55 - 00000000 ____D C:\Users\Baby Snake\AppData\Roaming\AVG
2013-09-09 13:55 - 2013-09-09 13:55 - 00000000 ____D C:\Program Files (x86)\AVG
2013-09-09 13:55 - 2013-08-30 11:40 - 00029496 _____ (AVG) C:\Windows\system32\authuitu.dll
2013-09-09 13:55 - 2013-08-30 11:40 - 00025400 _____ (AVG) C:\Windows\SysWOW64\authuitu.dll
2013-09-09 13:53 - 2013-09-09 14:03 - 00000000 ____D C:\ProgramData\AVG
2013-09-09 13:52 - 2013-09-09 14:53 - 00000000 __SHD C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2013-09-03 18:56 - 2013-09-03 18:56 - 00000000 ____D C:\Users\Baby Snake\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2013-08-30 13:52 - 2013-08-31 14:28 - 00000000 ____D C:\Users\Baby Snake\Documents\Rayman Legends
2013-08-21 19:07 - 2013-08-21 19:07 - 00000000 ____D C:\Users\Baby Snake\Documents\Ubisoft
2013-08-21 18:23 - 2013-08-21 18:23 - 00000000 ____D C:\Users\Baby Snake\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2013-08-21 18:23 - 2013-08-21 18:23 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2013-08-17 02:05 - 2013-08-26 22:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-14 11:12 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-14 11:12 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-14 11:12 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-14 11:12 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-14 11:12 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-14 11:12 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-14 11:12 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-14 11:12 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-14 11:12 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-14 11:12 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-14 11:12 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-14 11:12 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-14 11:12 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-14 11:12 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-14 11:12 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-14 11:12 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-14 11:12 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-14 11:12 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-14 11:12 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-14 11:12 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-14 11:12 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-14 11:12 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-14 11:12 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-14 11:12 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-08-14 11:12 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-08-14 11:12 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-14 11:12 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-14 11:12 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-08-14 11:12 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-14 11:12 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-14 11:12 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-08-14 11:05 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-14 11:05 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-14 11:05 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-14 11:05 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-14 11:05 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-14 11:05 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-14 11:05 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-14 11:05 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-14 11:04 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-14 11:04 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-14 11:04 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-14 11:04 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-14 11:04 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-14 11:04 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-14 11:04 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-08-14 11:04 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-14 11:04 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-14 11:04 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-14 11:04 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-08-14 11:04 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-14 11:04 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-14 11:04 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-14 11:04 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-14 11:04 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-14 11:04 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-14 11:04 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-14 11:04 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys

==================== One Month Modified Files and Folders =======

2013-09-10 17:28 - 2013-09-10 17:28 - 00000000 ____D C:\FRST
2013-09-10 17:28 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default
2013-09-10 17:27 - 2013-09-10 17:27 - 00000000 ____D C:\Users\BABYSN~1\AppData\Local\qb7DC286.B5
2013-09-10 17:26 - 2013-09-10 17:26 - 00000000 ____D C:\Users\BABYSN~1\AppData\Local\qb7C9973.48
2013-09-10 17:12 - 2012-11-21 15:11 - 01565655 _____ C:\Windows\WindowsUpdate.log
2013-09-10 17:02 - 2005-04-08 04:16 - 00014154 ____H C:\Users\Baby Snake\AppData\Roaming\Baby Snakelog.dat
2013-09-10 16:48 - 2012-11-21 16:58 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-10 16:23 - 2013-09-10 16:23 - 00001419 _____ C:\Users\Baby Snake\Desktop\hijackthis.exe – zástupce.lnk
2013-09-10 16:23 - 2012-11-21 15:20 - 00000000 ____D C:\Users\BABYSN~1\AppData\Local\VirtualStore
2013-09-10 16:11 - 2013-09-10 16:08 - 00000000 ____D C:\rsit
2013-09-10 16:11 - 2013-09-10 16:08 - 00000000 ____D C:\Program Files\trend micro
2013-09-10 15:20 - 2013-09-10 15:20 - 00000000 ____D C:\Users\Baby Snake\AppData\Roaming\WinDir
2013-09-10 15:18 - 2009-07-14 06:45 - 00015168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-10 15:18 - 2009-07-14 06:45 - 00015168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-10 15:13 - 2012-12-10 15:23 - 00000000 ____D C:\Users\BABYSN~1\AppData\Local\CrashDumps
2013-09-10 15:11 - 2013-09-10 15:11 - 00000000 _____ C:\Users\Baby Snake\regbcm
2013-09-10 15:11 - 2012-11-21 15:20 - 00000000 ____D C:\Users\Baby Snake
2013-09-10 15:10 - 2013-09-09 14:57 - 00000280 _____ C:\Windows\setupact.log
2013-09-10 15:10 - 2013-09-09 14:56 - 00000926 _____ C:\Windows\PFRO.log
2013-09-10 15:10 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-10 15:04 - 2013-09-10 15:01 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-09-10 15:02 - 2013-09-10 15:02 - 00000000 ____D C:\Users\Baby Snake\AppData\Roaming\SUPERAntiSpyware.com
2013-09-10 15:01 - 2013-09-10 15:01 - 00001808 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2013-09-10 15:01 - 2013-09-10 15:01 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2013-09-10 14:35 - 2013-09-10 14:35 - 00002762 _____ C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013
2013-09-10 14:04 - 2013-09-10 14:04 - 00000000 ____D C:\Program Files (x86)\VSO
2013-09-10 14:04 - 2012-11-22 19:18 - 00099384 _____ C:\Users\Baby Snake\AppData\Roaming\inst.exe
2013-09-10 14:04 - 2012-11-22 19:18 - 00082816 _____ (VSO Software) C:\Users\Baby Snake\AppData\Roaming\pcouffin.sys
2013-09-10 14:04 - 2012-11-22 19:18 - 00007859 _____ C:\Users\Baby Snake\AppData\Roaming\pcouffin.cat
2013-09-10 14:04 - 2012-11-22 19:18 - 00000055 _____ C:\Users\Baby Snake\AppData\Roaming\pcouffin.log
2013-09-10 14:04 - 2012-11-22 19:18 - 00000000 ____D C:\Users\Baby Snake\AppData\Roaming\Vso
2013-09-10 13:40 - 2013-09-10 13:40 - 00000000 ____D C:\Users\Baby Snake\Documents\PcSetup
2013-09-10 13:40 - 2012-11-22 19:18 - 00000000 ____D C:\ProgramData\VSO
2013-09-09 23:31 - 2012-11-21 15:54 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-09-09 16:56 - 2013-09-10 17:27 - 01949196 _____ (Farbar) C:\Users\Baby Snake\Desktop\FRST64.exe
2013-09-09 14:58 - 2013-09-09 14:58 - 00118304 _____ C:\Users\BABYSN~1\AppData\Local\GDIPFONTCACHEV1.DAT
2013-09-09 14:57 - 2013-09-09 14:57 - 00000000 _____ C:\Windows\setuperr.log
2013-09-09 14:56 - 2013-09-09 14:56 - 05029280 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-09 14:53 - 2013-09-09 13:52 - 00000000 __SHD C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2013-09-09 14:47 - 2013-09-09 14:47 - 00000000 ____D C:\Users\BABYSN~1\AppData\Local\Avg2014
2013-09-09 14:03 - 2013-09-09 13:53 - 00000000 ____D C:\ProgramData\AVG
2013-09-09 13:55 - 2013-09-09 13:55 - 00000000 ____D C:\Users\Baby Snake\AppData\Roaming\AVG
2013-09-09 13:55 - 2013-09-09 13:55 - 00000000 ____D C:\Program Files (x86)\AVG
2013-09-08 12:48 - 2009-07-14 17:18 - 00668866 _____ C:\Windows\system32\perfh005.dat
2013-09-08 12:48 - 2009-07-14 17:18 - 00141526 _____ C:\Windows\system32\perfc005.dat
2013-09-08 12:48 - 2009-07-14 07:13 - 01584554 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-07 16:13 - 2012-11-21 17:05 - 00000000 ____D C:\Users\Baby Snake\AppData\Roaming\vlc
2013-09-07 13:07 - 2012-11-21 16:08 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-09-06 16:27 - 2013-07-20 16:16 - 00000000 ____D C:\ProgramData\Orbit
2013-09-06 15:37 - 2013-04-30 13:55 - 00000000 ____D C:\Users\BABYSN~1\AppData\Local\Deployment
2013-09-04 22:42 - 2012-11-22 21:13 - 00000000 ____D C:\Users\Baby Snake\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Přehrávače
2013-09-04 22:27 - 2012-11-21 15:54 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-09-04 00:49 - 2012-11-21 16:58 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-09-04 00:49 - 2012-11-21 16:57 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-09-04 00:49 - 2012-11-21 16:57 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-03 21:28 - 2012-11-21 16:59 - 00000000 ____D C:\Program Files\WinRAR
2013-09-03 18:56 - 2013-09-03 18:56 - 00000000 ____D C:\Users\Baby Snake\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2013-08-31 14:28 - 2013-08-30 13:52 - 00000000 ____D C:\Users\Baby Snake\Documents\Rayman Legends
2013-08-31 09:31 - 2012-11-21 16:56 - 00000000 ____D C:\Users\BABYSN~1\AppData\Local\Adobe
2013-08-30 13:27 - 2012-11-22 18:59 - 00000000 ____D C:\Users\Baby Snake\AppData\Roaming\DAEMON Tools Lite
2013-08-30 13:21 - 2012-11-22 19:04 - 00000000 ____D C:\Program Files (x86)\Flash Player Pro
2013-08-30 11:40 - 2013-09-09 13:56 - 00040248 _____ (AVG) C:\Windows\system32\TURegOpt.exe
2013-08-30 11:40 - 2013-09-09 13:55 - 00029496 _____ (AVG) C:\Windows\system32\authuitu.dll
2013-08-30 11:40 - 2013-09-09 13:55 - 00025400 _____ (AVG) C:\Windows\SysWOW64\authuitu.dll
2013-08-30 09:48 - 2013-03-01 04:55 - 00204880 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-08-30 09:48 - 2013-03-01 04:54 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2013-08-30 09:48 - 2012-11-21 15:54 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-08-30 09:48 - 2012-11-21 15:54 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2013-08-30 09:48 - 2012-11-21 15:54 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2013-08-30 09:48 - 2012-11-21 15:54 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2013-08-30 09:48 - 2012-11-21 15:54 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2013-08-30 09:48 - 2012-11-21 15:54 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys
2013-08-30 09:47 - 2012-11-21 15:54 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2013-08-30 09:47 - 2012-11-21 15:53 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-08-29 15:19 - 2012-11-22 19:05 - 00000000 ____D C:\Users\Baby Snake\AppData\Roaming\Skype
2013-08-29 01:12 - 2012-11-21 17:08 - 00000000 ____D C:\Users\Baby Snake\AppData\Roaming\Winamp
2013-08-26 22:06 - 2012-11-23 01:38 - 00000000 ____D C:\Program Files (x86)\Steam
2013-08-26 22:05 - 2013-08-17 02:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-26 21:59 - 2013-03-29 23:03 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-08-26 21:58 - 2012-11-22 18:53 - 00000000 ____D C:\Program Files\CCleaner
2013-08-21 19:07 - 2013-08-21 19:07 - 00000000 ____D C:\Users\Baby Snake\Documents\Ubisoft
2013-08-21 18:23 - 2013-08-21 18:23 - 00000000 ____D C:\Users\Baby Snake\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2013-08-21 18:23 - 2013-08-21 18:23 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2013-08-21 18:23 - 2012-11-28 18:35 - 00000000 ____D C:\Users\BABYSN~1\AppData\Local\Ubisoft Game Launcher
2013-08-18 10:08 - 2013-04-11 18:54 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-16 15:11 - 2013-05-28 16:51 - 00000000 ____D C:\ProgramData\Steam
2013-08-16 14:24 - 2012-11-23 00:22 - 00000000 ____D C:\Users\Baby Snake\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GAMES
2013-08-15 17:16 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-08-14 19:01 - 2013-01-10 04:07 - 00003696 _____ C:\Windows\System32\Tasks\Adobe online aktualizační program
2013-08-14 12:08 - 2012-11-21 15:07 - 00000000 ____D C:\Windows\Panther
2013-08-14 11:10 - 2013-07-11 11:56 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 11:10 - 2012-11-21 16:02 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-08-14 11:06 - 2012-11-21 17:30 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-13 21:54 - 2013-03-25 20:38 - 00000000 ____D C:\Users\Baby Snake\Documents\My Games
2013-08-13 21:42 - 2013-08-07 14:24 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-08-13 21:42 - 2012-11-22 20:31 - 00000000 ____D C:\Users\Baby Snake\AppData\Roaming\Logishrd
2013-08-13 21:42 - 2012-11-22 19:05 - 00000000 ____D C:\ProgramData\Skype
2013-08-13 21:42 - 2012-11-21 16:24 - 00000000 ____D C:\Program Files\ATI Technologies

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit



==================== Alternate Data Streams (whitelisted) ====

AlternateDataStreams: C:\Windows:nlsPreferences

==================== Loaded Modules (whitelisted) ============

2010-12-17 11:29 - 2010-12-17 11:29 - 01238336 _____ (Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll
2010-08-10 14:06 - 2010-08-10 14:06 - 00293728 _____ (Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\timounter64.dll
2012-11-21 16:59 - 2012-06-09 19:20 - 00196096 _____ (Alexander Roshal) C:\Program Files\WinRAR\rarext.dll
2010-12-17 11:30 - 2010-12-17 11:30 - 00142176 _____ (Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\x64\versions_page.dll
2013-08-30 11:40 - 2013-08-30 11:40 - 00031544 _____ (AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\SDShelEx-x64.dll
2012-11-22 18:55 - 2009-10-22 17:01 - 00139664 _____ (EZB Systems, Inc.) C:\Program Files (x86)\UltraISO\isoshl64.dll
2013-05-23 22:00 - 2013-05-23 22:00 - 00213264 _____ (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCTXMN64.DLL
2012-12-22 16:48 - 2012-12-22 16:48 - 00331776 _____ (Florian Heidenreich) C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll
2013-08-30 11:40 - 2013-08-30 11:40 - 00026424 _____ (AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\DseShExt-x64.dll
2013-06-18 16:15 - 2013-06-18 16:15 - 05033176 _____ (Terra Informatica Software, Inc.) C:\Program Files\COMODO\COMODO Internet Security\cmdhtml.dll
2013-03-14 10:23 - 2013-03-14 10:23 - 04856384 _____ (Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTCommonRes.dll
2013-03-14 10:22 - 2013-03-14 10:22 - 03916352 _____ (Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\Engine.dll
2013-02-18 14:58 - 2013-02-18 14:58 - 00393344 _____ (Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\imgengine.dll
2013-08-07 14:24 - 2013-08-07 14:24 - 02244504 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll
2013-08-07 14:24 - 2013-08-07 14:24 - 00158104 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
2013-08-07 14:24 - 2013-08-07 14:24 - 00022424 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
2013-08-07 14:24 - 2013-08-07 14:24 - 00579480 _____ (sqlite.org) C:\Program Files (x86)\Mozilla Thunderbird\mozsqlite3.dll
2013-06-20 20:05 - 2012-11-21 07:26 - 00008704 _____ () C:\Users\Baby Snake\AppData\Roaming\Thunderbird\Profiles\w2pzp56p.default\extensions\mintrayr@tn123.ath.cx\lib\tray_x86-msvc.dll
2013-08-17 02:05 - 2013-08-17 02:05 - 03551640 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

==================== Scheduled Tasks (whitelisted) ===========

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Supplementary Scan (All) ================

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTibMounterMonitor
C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS6ServiceManager
"C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HydraVisionDesktopManager
"C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup
C:\Windows\RaidTool\xInsIDE.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Download Assistant
C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe
C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe -tray [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NUSB3MON
"C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Slu�ba Acronis Scheduler2
"C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam
"C:\Program Files (x86)\Steam\Steam.exe" -silent [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard
C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe
"C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe"


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=dword:00000005
"ConsentPromptBehaviorUser"=dword:00000003
"EnableInstallerDetection"=dword:00000001
"EnableLUA"=dword:00000001
"EnableSecureUIAPaths"=dword:00000001
"EnableUIADesktopToggle"=dword:00000000
"EnableVirtualization"=dword:00000001
"PromptOnSecureDesktop"=dword:00000000
"ValidateAdminCodeSignatures"=dword:00000000
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"scforceoption"=dword:00000000
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"FilterAdministratorToken"=dword:00000000
"EnableLinkedConnections"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=dword:00000001
"NoActiveDesktopChanges"=dword:00000001
"ForceActiveDesktopOn"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval"=dword:00000001
"AntiVirusOverride"=dword:00000000
"AntiSpywareOverride"=dword:00000000
"FirewallOverride"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"="msrle32.dll"
"vidc.msvc"="msvidc32.dll"
"msacm.imaadpcm"="imaadp32.acm"
"msacm.msg711"="msg711.acm"
"msacm.msgsm610"="msgsm32.acm"
"msacm.msadpcm"="msadp32.acm"
"midimapper"="midimap.dll"
"wavemapper"="msacm32.drv"
"vidc.uyvy"="msyuv.dll"
"vidc.yuy2"="msyuv.dll"
"vidc.yvyu"="msyuv.dll"
"vidc.iyuv"="iyuv_32.dll"
"vidc.i420"="iyuv_32.dll"
"vidc.yvu9"="tsbyuv.dll"
"msacm.l3acm"="C:\\Windows\\System32\\l3codeca.acm"
"wave"="wdmaud.drv"
"midi"="wdmaud.drv"
"mixer"="wdmaud.drv"
"aux"="wdmaud.drv"
"wave1"="wdmaud.drv"
"midi1"="wdmaud.drv"
"mixer1"="wdmaud.drv"
"aux1"="wdmaud.drv"


==================== Drive and Memory info ===================

Drive c: () (Fixed) (Total:100.62 GB) (Free:59.65 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: () (Fixed) (Total:271.98 GB) (Free:107.74 GB) NTFS
Drive e: () (Fixed) (Total:465.76 GB) (Free:55.31 GB) NTFS

Available physical RAM: 5886.7 MB
Total physical RAM: 8190.49 MB
Percentage of memory in use: 28%

LastRegBack: 2013-09-09 18:13

==================== End Of Log ==============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119530
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Malware.Trace chrome_debug.exe

#4 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Start
HKLM-x32\...\Run: [msunxkSrv] - C:\Windows\inf\msunxk.vbe [1558 2013-08-27] ()
C:\Windows\inf\msunxk.vbe
HKLM\...\Policies\Explorer: [NoActiveDesktop] 1
HKLM\...\Policies\Explorer: [NoActiveDesktopChanges] 1
U3 aoythijl; C:\Windows\System32\Drivers\aoythijl.sys [0 ] (Microsoft Corporation)
C:\Users\BABYSN~1\AppData\Local\qb7DC286.B5
C:\Users\BABYSN~1\AppData\Local\qb7C9973.48
AlternateDataStreams: C:\Windows:nlsPreferences
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Snake.PP
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 10 zář 2013 14:47

Re: Malware.Trace chrome_debug.exe

#5 Příspěvek od Snake.PP »

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-09-2013 01
Ran by Baby Snake at 2013-09-10 17:44:14 Run:1
Running from C:\Users\Baby Snake\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
HKLM-x32\...\Run: [msunxkSrv] - C:\Windows\inf\msunxk.vbe [1558 2013-08-27] ()
C:\Windows\inf\msunxk.vbe
HKLM\...\Policies\Explorer: [NoActiveDesktop] 1
HKLM\...\Policies\Explorer: [NoActiveDesktopChanges] 1
U3 aoythijl; C:\Windows\System32\Drivers\aoythijl.sys [0 ] (Microsoft Corporation)
C:\Users\BABYSN~1\AppData\Local\qb7DC286.B5
C:\Users\BABYSN~1\AppData\Local\qb7C9973.48
AlternateDataStreams: C:\Windows:nlsPreferences
End
*****************

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\msunxkSrv => Value deleted successfully.
C:\Windows\inf\msunxk.vbe => Moved successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoActiveDesktop => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoActiveDesktopChanges => Value deleted successfully.
aoythijl => Service deleted successfully.
C:\Users\BABYSN~1\AppData\Local\qb7DC286.B5 => Moved successfully.
C:\Users\BABYSN~1\AppData\Local\qb7C9973.48 => Moved successfully.
C:\Windows => ":nlsPreferences" ADS removed successfully.

==== End of Fixlog ====

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119530
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Malware.Trace chrome_debug.exe

#6 Příspěvek od Rudy »

Log je již OK. Jdou už ty soubory smazat?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Snake.PP
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 10 zář 2013 14:47

Re: Malware.Trace chrome_debug.exe

#7 Příspěvek od Snake.PP »

Boužel ne "C:\Users\Baby Snake\AppData\Roaming\WinDir\chrome_debug.exe" když ho smažu tak se tam zas za cca 5s zase objeví to samé i když smažu složku "WinDir"
a "C:\Users\Baby Snake\AppData\Local\Temp\Baby Snake8" ten smazat jde, ale taky se tam hned znova objeví a ten druhý "Baby Snake7" ten nejde ani označit (natož smazat). :(
Po restartu PC to samé a Avast doporučil "chrome_debug.exe" otevřít v sendboxu - dal jsem stornovat otevření

Jestli se s tím nechceš "crcat" tak to hold celé schodím a budu si dva dni hrát s instalačkama - i tak díky za ochotu.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119530
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Malware.Trace chrome_debug.exe

#8 Příspěvek od Rudy »

O to nejde. Pravděpodobně to tam ukládá GoogleChrome. Máte ho nainstalovaný?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Snake.PP
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 10 zář 2013 14:47

Re: Malware.Trace chrome_debug.exe

#9 Příspěvek od Snake.PP »

Ne nemám.Jdu to celé schodit.Díky za čas a ochotu.Nemám na to nervy a omlouvám se, že jsem tě okrádal o čas.
Toto téma můžete smazat.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119530
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Malware.Trace chrome_debug.exe

#10 Příspěvek od Rudy »

Není zač!
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno