virus policia SR

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Odpovědět
Zpráva
Autor
likes
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 01 Pro 2013 18:42

virus policia SR

#1 Příspěvek od likes »

Prosim Vas som zufaly :( mam dolezite veci v pc a napadol ma tento virus, zatial vsetko funguje len okno sa neda zavrit, prosim pomozte :( budem sa riadit vasimi prikazmi, prepacte ak je to v zlej sekcii neviem nic najst a bojim sa bez rady daco spravit dakujem vam velmi pekne
log s FRST
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-12-2013
Ran by user (administrator) on USER-NB on 01-12-2013 18:51:06
Running from C:\Users\user\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
(ATK) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ATK) C:\Program Files\P4G\BatteryLife.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(syncables, LLC) C:\Program Files (x86)\syncables\syncables desktop\syncables.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
(Boingo Wireless, Inc.) C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
() C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(asus) C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(forum.viry.cz) C:\Users\user\Downloads\FRSTLauncher(2).exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [649608 2010-04-13] (ELAN Microelectronic Corp.)
HKLM\...\Run: [ASUS WebStorage] - C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe
HKLM\...\Run: [Setwallpaper] - c:\programdata\SetWallpaper.cmd
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [Eraser] - C:\Program Files\Eraser\Eraser.exe [980920 2012-05-22] (The Eraser Project)
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [5618456 2013-09-12] (ESET)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
HKLM-x32\...\Winlogon: [Userinit] C:\Windows\sysWOW64\userinit.exe [26624 2010-11-20] (Microsoft Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [Facebook Update] - C:\Users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-10-16] (Facebook Inc.)
HKCU\...\Run: [Syncables] - C:\Program Files (x86)\syncables\syncables desktop\syncables.exe [370480 2010-04-05] (syncables, LLC)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18678376 2013-04-19] (Skype Technologies S.A.)
MountPoints2: {ba6b132a-0f92-11e0-acb6-1c4bd61be8be} - F:\.autorun\autorun.exe
HKLM-x32\...\Run: [RemoteControl9] - C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe [87336 2009-07-06] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateLBPShortCut] - C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] - C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [Boingo Wi-Fi] - C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk [2429 2010-10-15] ()
HKLM-x32\...\Run: [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [7350912 2010-02-04] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-01-05] (ASUS)
HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1597440 2010-07-02] ()
HKLM-x32\...\Run: [SessionLogon] - C:\ExpressGateUtil\SessionLogon.exe
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-04] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1673680 2013-10-23] (APN)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll [239720 2011-05-21] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [200808 2011-05-21] (NVIDIA Corporation)
Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Photosmart 5510 series.lnk
ShortcutTarget: Sledovat výstrahy inkoustu - HP Photosmart 5510 series.lnk -> C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL =
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
Toolbar: HKLM-x32 - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\m6guis4w.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_149.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.11.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.11.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8051.1204 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\user\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\atlas-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\azet-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\dunaj-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slovnik-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\zoznam-sk.xml
FF Extension: toolbar_AVIRA-V7 - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\m6guis4w.default\Extensions\toolbar_AVIRA-V7@apn.ask.com.xpi
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird

==================== Services (Whitelisted) =================

S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2013-01-10] (Adobe Systems)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-10-23] (APN LLC.)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1337752 2013-09-12] (ESET)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [66872 2011-03-26] ()
R3 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2010-04-06] ()

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-08-11] (Avira Operations GmbH & Co. KG)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-09-17] (ESET)
S0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [239296 2013-09-17] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [168256 2013-09-17] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [220232 2013-09-17] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44120 2013-09-17] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [62136 2013-09-17] (ESET)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-12-24] ()
U3 aldgjng9; C:\Windows\System32\Drivers\aldgjng9.sys [0 ] (Microsoft Corporation)
U3 tmlwf;
U3 tmwfp;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-12-01 18:51 - 2013-12-01 18:52 - 00018798 _____ C:\Users\user\Desktop\FRST.txt
2013-12-01 18:50 - 2013-12-01 18:50 - 00112640 _____ (forum.viry.cz) C:\Users\user\Downloads\FRSTLauncher(2).exe
2013-12-01 18:50 - 2013-12-01 18:50 - 00000000 ____D C:\FRST
2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Roaming\ESET
2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Local\ESET
2013-12-01 18:47 - 2013-12-01 18:47 - 00112640 _____ (forum.viry.cz) C:\Users\user\Downloads\FRSTLauncher(1).exe
2013-12-01 18:46 - 2013-12-01 18:46 - 00112640 _____ (forum.viry.cz) C:\Users\user\Downloads\FRSTLauncher.exe
2013-12-01 18:46 - 2013-12-01 18:45 - 01959184 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2013-12-01 18:45 - 2013-12-01 18:45 - 01959184 _____ (Farbar) C:\Users\user\Downloads\FRST64.exe
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\ProgramData\ESET
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\Program Files\ESET
2013-12-01 18:33 - 2013-12-01 18:33 - 01581896 _____ (ESET) C:\Users\user\Downloads\eset_smart_security_live_installer_.exe
2013-12-01 18:21 - 2013-12-01 18:21 - 00001111 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\Users\user\AppData\Roaming\Malwarebytes
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-01 18:21 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-12-01 18:20 - 2013-12-01 18:20 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\user\Downloads\mbam-setup-1.75.0.1300.exe
2013-11-24 22:41 - 2013-11-24 22:41 - 105952601 _____ C:\Windows\SysWOW64\驧笌¡
2013-11-20 18:45 - 2013-11-20 18:45 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud(1).pps
2013-11-19 23:07 - 2013-11-19 23:07 - 105275480 _____ C:\Windows\SysWOW64\[䅏¡
2013-11-19 20:00 - 2013-11-19 20:01 - 00000000 ____D C:\Users\user\Desktop\DCIM30
2013-11-18 23:46 - 2013-11-18 23:46 - 105004989 _____ C:\Windows\SysWOW64\᷒齍‹
2013-11-18 20:38 - 2013-11-18 20:39 - 19696439 _____ C:\Users\user\Downloads\dentalne materialy.zip
2013-11-18 20:38 - 2013-11-18 20:38 - 05671495 _____ C:\Users\user\Downloads\dentalnie materialy zivice a plasty.rar
2013-11-18 20:38 - 2013-11-18 20:38 - 05092838 _____ C:\Users\user\Downloads\Dentalne materialy.rar
2013-11-18 20:37 - 2013-11-18 20:37 - 05165110 _____ C:\Users\user\Downloads\Nový priečinok.rar
2013-11-18 20:36 - 2013-11-18 20:36 - 06878569 _____ C:\Users\user\Downloads\dentelne_materialy.rar
2013-11-17 22:47 - 2013-11-17 22:47 - 104760117 _____ C:\Windows\SysWOW64\束Ⓠ£
2013-11-17 17:10 - 2013-11-17 17:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-14 23:52 - 2013-11-14 23:52 - 00000000 ____D C:\Users\user\Desktop\kluc_A
2013-11-14 22:28 - 2013-11-14 23:43 - 00000000 ____D C:\Users\user\Desktop\histology_2year
2013-11-14 21:57 - 2013-11-14 21:57 - 104278918 _____ C:\Windows\SysWOW64\죠䡽ª
2013-11-12 22:04 - 2013-11-12 22:04 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud.pps
2013-11-11 22:22 - 2013-11-11 22:25 - 19341362 _____ C:\Users\user\Downloads\3(1).rar
2013-11-11 22:22 - 2013-11-11 22:25 - 17717501 _____ C:\Users\user\Downloads\1.rar
2013-11-11 22:22 - 2013-11-11 22:25 - 14875731 _____ C:\Users\user\Downloads\2.rar
2013-11-11 21:56 - 2013-11-11 21:56 - 19341362 _____ C:\Users\user\Downloads\3.rar
2013-11-11 19:07 - 2013-11-11 19:07 - 00000000 ____D C:\Users\user\Desktop\DCIM20
2013-11-11 17:55 - 2013-11-11 17:55 - 103792856 _____ C:\Windows\SysWOW64\ᨡ锓”
2013-11-10 23:00 - 2013-11-10 23:00 - 103551423 _____ C:\Windows\SysWOW64\⑴篷“
2013-11-10 22:21 - 2013-11-10 22:21 - 00000000 ____D C:\Users\user\Downloads\dent_mat_otazky
2013-11-10 22:20 - 2013-11-10 22:20 - 04042707 _____ C:\Users\user\Downloads\dent_Mat.zip
2013-11-06 11:18 - 2013-11-06 11:18 - 102722523 _____ C:\Windows\SysWOW64\䖩ఄ«
2013-11-05 18:19 - 2013-11-05 18:19 - 105048247 _____ C:\Windows\SysWOW64\榠︚N
2013-11-04 21:03 - 2013-11-04 21:03 - 104964650 _____ C:\Windows\SysWOW64\㣮ᵞF

==================== One Month Modified Files and Folders =======

2013-12-01 18:52 - 2013-12-01 18:51 - 00018798 _____ C:\Users\user\Desktop\FRST.txt
2013-12-01 18:51 - 2010-10-15 19:16 - 01508089 _____ C:\Windows\WindowsUpdate.log
2013-12-01 18:50 - 2013-12-01 18:50 - 00112640 _____ (forum.viry.cz) C:\Users\user\Downloads\FRSTLauncher(2).exe
2013-12-01 18:50 - 2013-12-01 18:50 - 00000000 ____D C:\FRST
2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Roaming\ESET
2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Local\ESET
2013-12-01 18:47 - 2013-12-01 18:47 - 00112640 _____ (forum.viry.cz) C:\Users\user\Downloads\FRSTLauncher(1).exe
2013-12-01 18:46 - 2013-12-01 18:46 - 00112640 _____ (forum.viry.cz) C:\Users\user\Downloads\FRSTLauncher.exe
2013-12-01 18:45 - 2013-12-01 18:46 - 01959184 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2013-12-01 18:45 - 2013-12-01 18:45 - 01959184 _____ (Farbar) C:\Users\user\Downloads\FRST64.exe
2013-12-01 18:45 - 2011-01-08 13:40 - 00000000 ____D C:\Users\user\AppData\Roaming\Skype
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\ProgramData\ESET
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\Program Files\ESET
2013-12-01 18:33 - 2013-12-01 18:33 - 01581896 _____ (ESET) C:\Users\user\Downloads\eset_smart_security_live_installer_.exe
2013-12-01 18:21 - 2013-12-01 18:21 - 00001111 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\Users\user\AppData\Roaming\Malwarebytes
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-01 18:20 - 2013-12-01 18:20 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\user\Downloads\mbam-setup-1.75.0.1300.exe
2013-12-01 18:17 - 2011-11-08 09:26 - 00000932 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-01 17:43 - 2012-10-16 19:38 - 00000924 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1241329632-66754793-2357093618-1002UA.job
2013-12-01 17:10 - 2009-07-14 05:45 - 00010240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-01 17:10 - 2009-07-14 05:45 - 00010240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-01 17:01 - 2011-11-08 09:26 - 00000928 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-01 17:01 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-01 17:01 - 2009-07-14 05:51 - 00077422 _____ C:\Windows\setupact.log
2013-11-28 16:21 - 2009-08-03 21:00 - 00626776 _____ C:\Windows\system32\perfh005.dat
2013-11-28 16:21 - 2009-08-03 21:00 - 00125050 _____ C:\Windows\system32\perfc005.dat
2013-11-28 16:21 - 2009-07-14 06:13 - 01484558 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-28 09:51 - 2013-04-18 22:50 - 00000000 ____D C:\Users\user\AppData\Local\Eraser 6
2013-11-27 20:43 - 2012-10-16 19:38 - 00000902 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1241329632-66754793-2357093618-1002Core.job
2013-11-27 00:09 - 2011-11-17 12:10 - 00000000 ____D C:\Users\user\AppData\Roaming\SoftGrid Client
2013-11-26 21:11 - 2013-05-10 13:14 - 00000000 ____D C:\Users\user\AppData\Local\PokerStars
2013-11-24 22:41 - 2013-11-24 22:41 - 105952601 _____ C:\Windows\SysWOW64\驧笌¡
2013-11-20 18:45 - 2013-11-20 18:45 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud(1).pps
2013-11-19 23:07 - 2013-11-19 23:07 - 105275480 _____ C:\Windows\SysWOW64\[䅏¡
2013-11-19 20:01 - 2013-11-19 20:00 - 00000000 ____D C:\Users\user\Desktop\DCIM30
2013-11-19 17:05 - 2012-09-26 15:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-18 23:46 - 2013-11-18 23:46 - 105004989 _____ C:\Windows\SysWOW64\᷒齍‹
2013-11-18 20:39 - 2013-11-18 20:38 - 19696439 _____ C:\Users\user\Downloads\dentalne materialy.zip
2013-11-18 20:38 - 2013-11-18 20:38 - 05671495 _____ C:\Users\user\Downloads\dentalnie materialy zivice a plasty.rar
2013-11-18 20:38 - 2013-11-18 20:38 - 05092838 _____ C:\Users\user\Downloads\Dentalne materialy.rar
2013-11-18 20:37 - 2013-11-18 20:37 - 05165110 _____ C:\Users\user\Downloads\Nový priečinok.rar
2013-11-18 20:36 - 2013-11-18 20:36 - 06878569 _____ C:\Users\user\Downloads\dentelne_materialy.rar
2013-11-17 23:37 - 2011-10-28 20:27 - 00675328 ___SH C:\Users\user\Thumbs.db
2013-11-17 22:47 - 2013-11-17 22:47 - 104760117 _____ C:\Windows\SysWOW64\束Ⓠ£
2013-11-17 17:10 - 2013-11-17 17:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-14 23:52 - 2013-11-14 23:52 - 00000000 ____D C:\Users\user\Desktop\kluc_A
2013-11-14 23:43 - 2013-11-14 22:28 - 00000000 ____D C:\Users\user\Desktop\histology_2year
2013-11-14 21:57 - 2013-11-14 21:57 - 104278918 _____ C:\Windows\SysWOW64\죠䡽ª
2013-11-12 22:04 - 2013-11-12 22:04 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud.pps
2013-11-11 22:25 - 2013-11-11 22:22 - 19341362 _____ C:\Users\user\Downloads\3(1).rar
2013-11-11 22:25 - 2013-11-11 22:22 - 17717501 _____ C:\Users\user\Downloads\1.rar
2013-11-11 22:25 - 2013-11-11 22:22 - 14875731 _____ C:\Users\user\Downloads\2.rar
2013-11-11 21:56 - 2013-11-11 21:56 - 19341362 _____ C:\Users\user\Downloads\3.rar
2013-11-11 19:07 - 2013-11-11 19:07 - 00000000 ____D C:\Users\user\Desktop\DCIM20
2013-11-11 17:55 - 2013-11-11 17:55 - 103792856 _____ C:\Windows\SysWOW64\ᨡ锓”
2013-11-10 23:00 - 2013-11-10 23:00 - 103551423 _____ C:\Windows\SysWOW64\⑴篷“
2013-11-10 22:21 - 2013-11-10 22:21 - 00000000 ____D C:\Users\user\Downloads\dent_mat_otazky
2013-11-10 22:20 - 2013-11-10 22:20 - 04042707 _____ C:\Users\user\Downloads\dent_Mat.zip
2013-11-06 11:18 - 2013-11-06 11:18 - 102722523 _____ C:\Windows\SysWOW64\䖩ఄ«
2013-11-05 18:19 - 2013-11-05 18:19 - 105048247 _____ C:\Windows\SysWOW64\榠︚N
2013-11-04 21:03 - 2013-11-04 21:03 - 104964650 _____ C:\Windows\SysWOW64\㣮ᵞF

Files to move or delete:
====================
C:\Users\user\SkypeSetup.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================


==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: ESET Smart Security 7.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AV: Avira Desktop (Disabled - Out of date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Disabled - Out of date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 7.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET personal firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\user\Desktop" je 25604 MB.


***** Startup Programs *****

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer
"C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [x]


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================
Dakujem velmi pekne

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: virus policia SR

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Spustte tam HitmanPro with KickStart http://forum.viry.cz/viewtopic.php?f=29&t=132523
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

likes
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 01 Pro 2013 18:42

Re: virus policia SR

#3 Příspěvek od likes »

dobry vecer prajem, dakujem Vam velmi pekne za pomoc.
nejak sa mi nepodarilo dostat sa do toho USB boot menu :( ale nejak sa mi podarilo spravit bod obnovy na 27.11.2013 a vyzera byt vsetko normalne. Podla Vas odisiel virus? alebo co mam spravit? dakujem velmi pekne

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: virus policia SR

#4 Příspěvek od vyosek »

:arrow: Bodem obnovy se mohl malware odstranit, ale proverime to. Navic je v PC hooodne zbytecneho nezadouciho reklamniho balastu - tez vycistime

:arrow: Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
  • Ulozte nejlepe na plochu
  • Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
  • Probehne vytvoreni zalohy a nasledne prohledavani
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

likes
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 01 Pro 2013 18:42

Re: virus policia SR

#5 Příspěvek od likes »

# AdwCleaner v3.014 - Report created 01/12/2013 at 21:31:14
# Updated 01/12/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : user - USER-NB
# Running from : C:\Users\user\Downloads\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32099AAC-C132-4136-9E9A-4E364A424E17}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32099AAC-C132-4136-9E9A-4E364A424E17}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}
Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}]

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16476


-\\ Mozilla Firefox v25.0.1 (sk)

[ File : C:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\m6guis4w.default\prefs.js ]


*************************

AdwCleaner[R0].txt - [1939 octets] - [01/12/2013 21:29:07]
AdwCleaner[S0].txt - [1878 octets] - [01/12/2013 21:31:14]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1938 octets] ##########





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Home Premium x64
Ran by user on ne 01. 12. 2013 at 21:19:16,91
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\apntbmon



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{3E288F79-03E4-4983-A48E-0D879B51FF19}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\dt soft\daemon tools toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\dt soft\daemon tools toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\dttoolbar.toolbandobj
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\dttoolbar.toolbandobj.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\daemon tools toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\v9software
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\APNSetup_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\APNSetup_RASMANCS



~~~ Files

Successfully deleted: [File] C:\Windows\syswow64\sho451A.tmp



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\ProgramData\partner"
Successfully deleted: [Folder] "C:\Program Files (x86)\daemon tools toolbar"



~~~ FireFox

Successfully deleted: [File] C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\m6guis4w.default\extensions\toolbar_avira-v7@apn.ask.com.xpi
Emptied folder: C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\m6guis4w.default\minidumps [398 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ne 01. 12. 2013 at 21:25:32,33
End of JRT log


Ako to vyzerá prosím Vás pan doktor? :)
Dakujem Vam velmi pekne :)

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: virus policia SR

#6 Příspěvek od vyosek »

Spustte znovu FRSTLauncher a nechte udelat log, ten rad uvidim
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

likes
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 01 Pro 2013 18:42

Re: virus policia SR

#7 Příspěvek od likes »

Dakujem Vam velmi pekne
nech sa paci log :)
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-12-2013
Ran by user (administrator) on USER-NB on 02-12-2013 20:09:35
Running from C:\Users\user\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
(ATK) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ATK) C:\Program Files\P4G\BatteryLife.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(The Eraser Project) C:\Program Files\Eraser\Eraser.exe
(syncables, LLC) C:\Program Files (x86)\syncables\syncables desktop\syncables.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
(Boingo Wireless, Inc.) C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
() C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(asus) C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_149.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_149.exe
(forum.viry.cz) C:\Users\user\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\PING.EXE

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [649608 2010-04-13] (ELAN Microelectronic Corp.)
HKLM\...\Run: [ASUS WebStorage] - C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe
HKLM\...\Run: [Setwallpaper] - c:\programdata\SetWallpaper.cmd
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [Eraser] - C:\Program Files\Eraser\Eraser.exe [980920 2012-05-22] (The Eraser Project)
HKLM-x32\...\Winlogon: [Userinit] C:\Windows\sysWOW64\userinit.exe [26624 2010-11-20] (Microsoft Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [Facebook Update] - C:\Users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-10-16] (Facebook Inc.)
HKCU\...\Run: [Syncables] - C:\Program Files (x86)\syncables\syncables desktop\syncables.exe [370480 2010-04-05] (syncables, LLC)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18678376 2013-04-19] (Skype Technologies S.A.)
MountPoints2: {ba6b132a-0f92-11e0-acb6-1c4bd61be8be} - F:\.autorun\autorun.exe
HKLM-x32\...\Run: [RemoteControl9] - C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe [87336 2009-07-06] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateLBPShortCut] - C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] - C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [Boingo Wi-Fi] - C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk [2429 2010-10-15] ()
HKLM-x32\...\Run: [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [7350912 2010-02-04] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-01-05] (ASUS)
HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1597440 2010-07-02] ()
HKLM-x32\...\Run: [SessionLogon] - C:\ExpressGateUtil\SessionLogon.exe
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-04] (Avira Operations GmbH & Co. KG)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll [239720 2011-05-21] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [200808 2011-05-21] (NVIDIA Corporation)
Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Photosmart 5510 series.lnk
ShortcutTarget: Sledovat výstrahy inkoustu - HP Photosmart 5510 series.lnk -> C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL =
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
Toolbar: HKLM-x32 - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\m6guis4w.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_149.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.11.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.11.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8051.1204 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\user\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\atlas-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\azet-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\dunaj-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slovnik-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\zoznam-sk.xml

==================== Services (Whitelisted) =================

S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2013-01-10] (Adobe Systems)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-10-23] (APN LLC.)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [66872 2011-03-26] ()
R3 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2010-04-06] ()

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-08-11] (Avira Operations GmbH & Co. KG)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-12-24] ()
U3 a82suxqo; C:\Windows\System32\Drivers\a82suxqo.sys [0 ] (Microsoft Corporation)
U3 tmlwf;
U3 tmwfp;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-12-02 20:09 - 2013-12-02 20:09 - 00015688 _____ C:\Users\user\Desktop\FRST.txt
2013-12-02 20:09 - 2013-12-02 20:09 - 00015327 _____ C:\Users\user\Desktop\LM.bat
2013-12-02 20:09 - 2013-12-02 20:08 - 01959184 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2013-12-02 20:09 - 2013-12-02 20:08 - 00112640 _____ C:\Users\user\Desktop\FRSTLauncher.exe
2013-12-02 20:08 - 2013-12-02 20:09 - 00029696 _____ C:\Users\user\AppData\Local\MSGBOX.EXE
2013-12-02 20:08 - 2013-12-02 20:08 - 00112640 _____ C:\Users\user\Downloads\FRSTLauncher.exe
2013-12-02 20:07 - 2013-12-02 20:08 - 01959184 _____ (Farbar) C:\Users\user\Downloads\FRST64.exe
2013-12-01 21:29 - 2013-12-01 21:31 - 00000000 ____D C:\AdwCleaner
2013-12-01 21:19 - 2013-12-01 21:19 - 00000000 ____D C:\Windows\ERUNT
2013-12-01 21:17 - 2013-12-01 21:17 - 01110034 _____ C:\Users\user\Downloads\adwcleaner.exe
2013-12-01 21:17 - 2013-12-01 21:17 - 01034531 _____ (Thisisu) C:\Users\user\Downloads\JRT.exe
2013-12-01 19:23 - 2013-12-01 19:23 - 00000000 ____D C:\ProgramData\HitmanPro
2013-12-01 18:50 - 2013-12-01 18:50 - 00000000 ____D C:\FRST
2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Roaming\ESET
2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Local\ESET
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\ProgramData\ESET
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\Program Files\ESET
2013-12-01 18:21 - 2013-12-02 04:39 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\Users\user\AppData\Roaming\Malwarebytes
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-24 22:41 - 2013-11-24 22:41 - 105952601 _____ C:\Windows\SysWOW64\驧笌¡
2013-11-20 18:45 - 2013-11-20 18:45 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud(1).pps
2013-11-19 23:07 - 2013-11-19 23:07 - 105275480 _____ C:\Windows\SysWOW64\[䅏¡
2013-11-19 20:00 - 2013-11-19 20:01 - 00000000 ____D C:\Users\user\Desktop\DCIM30
2013-11-18 23:46 - 2013-11-18 23:46 - 105004989 _____ C:\Windows\SysWOW64\᷒齍‹
2013-11-18 20:38 - 2013-11-18 20:39 - 19696439 _____ C:\Users\user\Downloads\dentalne materialy.zip
2013-11-18 20:38 - 2013-11-18 20:38 - 05671495 _____ C:\Users\user\Downloads\dentalnie materialy zivice a plasty.rar
2013-11-18 20:38 - 2013-11-18 20:38 - 05092838 _____ C:\Users\user\Downloads\Dentalne materialy.rar
2013-11-18 20:37 - 2013-11-18 20:37 - 05165110 _____ C:\Users\user\Downloads\Nový priečinok.rar
2013-11-18 20:36 - 2013-11-18 20:36 - 06878569 _____ C:\Users\user\Downloads\dentelne_materialy.rar
2013-11-17 22:47 - 2013-11-17 22:47 - 104760117 _____ C:\Windows\SysWOW64\束Ⓠ£
2013-11-17 17:10 - 2013-11-17 17:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-14 23:52 - 2013-11-14 23:52 - 00000000 ____D C:\Users\user\Desktop\kluc_A
2013-11-14 22:28 - 2013-11-14 23:43 - 00000000 ____D C:\Users\user\Desktop\histology_2year
2013-11-14 21:57 - 2013-11-14 21:57 - 104278918 _____ C:\Windows\SysWOW64\죠䡽ª
2013-11-12 22:04 - 2013-11-12 22:04 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud.pps
2013-11-11 22:22 - 2013-11-11 22:25 - 19341362 _____ C:\Users\user\Downloads\3(1).rar
2013-11-11 22:22 - 2013-11-11 22:25 - 17717501 _____ C:\Users\user\Downloads\1.rar
2013-11-11 22:22 - 2013-11-11 22:25 - 14875731 _____ C:\Users\user\Downloads\2.rar
2013-11-11 21:56 - 2013-11-11 21:56 - 19341362 _____ C:\Users\user\Downloads\3.rar
2013-11-11 19:07 - 2013-11-11 19:07 - 00000000 ____D C:\Users\user\Desktop\DCIM20
2013-11-11 17:55 - 2013-11-11 17:55 - 103792856 _____ C:\Windows\SysWOW64\ᨡ锓”
2013-11-10 23:00 - 2013-11-10 23:00 - 103551423 _____ C:\Windows\SysWOW64\⑴篷“
2013-11-10 22:21 - 2013-11-10 22:21 - 00000000 ____D C:\Users\user\Downloads\dent_mat_otazky
2013-11-10 22:20 - 2013-11-10 22:20 - 04042707 _____ C:\Users\user\Downloads\dent_Mat.zip
2013-11-06 11:18 - 2013-11-06 11:18 - 102722523 _____ C:\Windows\SysWOW64\䖩ఄ«
2013-11-05 18:19 - 2013-11-05 18:19 - 105048247 _____ C:\Windows\SysWOW64\榠︚N
2013-11-04 21:03 - 2013-11-04 21:03 - 104964650 _____ C:\Windows\SysWOW64\㣮ᵞF

==================== One Month Modified Files and Folders =======

2013-12-02 20:10 - 2013-12-02 20:09 - 00015688 _____ C:\Users\user\Desktop\FRST.txt
2013-12-02 20:09 - 2013-12-02 20:09 - 00015327 _____ C:\Users\user\Desktop\LM.bat
2013-12-02 20:09 - 2013-12-02 20:08 - 00029696 _____ C:\Users\user\AppData\Local\MSGBOX.EXE
2013-12-02 20:08 - 2013-12-02 20:09 - 01959184 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2013-12-02 20:08 - 2013-12-02 20:09 - 00112640 _____ C:\Users\user\Desktop\FRSTLauncher.exe
2013-12-02 20:08 - 2013-12-02 20:08 - 00112640 _____ C:\Users\user\Downloads\FRSTLauncher.exe
2013-12-02 20:08 - 2013-12-02 20:07 - 01959184 _____ (Farbar) C:\Users\user\Downloads\FRST64.exe
2013-12-02 20:05 - 2013-05-10 13:14 - 00000000 ____D C:\Users\user\AppData\Local\PokerStars
2013-12-02 19:57 - 2011-01-08 13:40 - 00000000 ____D C:\Users\user\AppData\Roaming\Skype
2013-12-02 19:17 - 2011-11-08 09:26 - 00000932 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-02 17:47 - 2009-07-14 05:45 - 00010240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-02 17:47 - 2009-07-14 05:45 - 00010240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-02 17:43 - 2012-10-16 19:38 - 00000924 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1241329632-66754793-2357093618-1002UA.job
2013-12-02 17:39 - 2011-11-08 09:26 - 00000928 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-02 17:39 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-02 17:39 - 2009-07-14 05:51 - 00077478 _____ C:\Windows\setupact.log
2013-12-02 04:39 - 2013-12-01 18:21 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-02 04:39 - 2010-12-22 17:53 - 00000000 ___RD C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-12-02 04:39 - 2010-10-15 20:14 - 00000000 ____D C:\ProgramData\P4G
2013-12-02 04:39 - 2009-07-14 08:44 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-12-02 04:39 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
2013-12-02 00:25 - 2010-10-15 19:16 - 01456965 _____ C:\Windows\WindowsUpdate.log
2013-12-01 21:31 - 2013-12-01 21:29 - 00000000 ____D C:\AdwCleaner
2013-12-01 21:19 - 2013-12-01 21:19 - 00000000 ____D C:\Windows\ERUNT
2013-12-01 21:17 - 2013-12-01 21:17 - 01110034 _____ C:\Users\user\Downloads\adwcleaner.exe
2013-12-01 21:17 - 2013-12-01 21:17 - 01034531 _____ (Thisisu) C:\Users\user\Downloads\JRT.exe
2013-12-01 20:43 - 2012-10-16 19:38 - 00000902 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1241329632-66754793-2357093618-1002Core.job
2013-12-01 19:23 - 2013-12-01 19:23 - 00000000 ____D C:\ProgramData\HitmanPro
2013-12-01 18:50 - 2013-12-01 18:50 - 00000000 ____D C:\FRST
2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Roaming\ESET
2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Local\ESET
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\ProgramData\ESET
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\Program Files\ESET
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\Users\user\AppData\Roaming\Malwarebytes
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-28 09:51 - 2013-04-18 22:50 - 00000000 ____D C:\Users\user\AppData\Local\Eraser 6
2013-11-27 19:32 - 2009-08-03 21:00 - 00626776 _____ C:\Windows\system32\perfh005.dat
2013-11-27 19:32 - 2009-08-03 21:00 - 00125050 _____ C:\Windows\system32\perfc005.dat
2013-11-27 19:32 - 2009-07-14 06:13 - 01484558 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-27 00:09 - 2011-11-17 12:10 - 00000000 ____D C:\Users\user\AppData\Roaming\SoftGrid Client
2013-11-24 22:41 - 2013-11-24 22:41 - 105952601 _____ C:\Windows\SysWOW64\驧笌¡
2013-11-20 18:45 - 2013-11-20 18:45 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud(1).pps
2013-11-19 23:07 - 2013-11-19 23:07 - 105275480 _____ C:\Windows\SysWOW64\[䅏¡
2013-11-19 20:01 - 2013-11-19 20:00 - 00000000 ____D C:\Users\user\Desktop\DCIM30
2013-11-19 17:05 - 2012-09-26 15:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-18 23:46 - 2013-11-18 23:46 - 105004989 _____ C:\Windows\SysWOW64\᷒齍‹
2013-11-18 20:39 - 2013-11-18 20:38 - 19696439 _____ C:\Users\user\Downloads\dentalne materialy.zip
2013-11-18 20:38 - 2013-11-18 20:38 - 05671495 _____ C:\Users\user\Downloads\dentalnie materialy zivice a plasty.rar
2013-11-18 20:38 - 2013-11-18 20:38 - 05092838 _____ C:\Users\user\Downloads\Dentalne materialy.rar
2013-11-18 20:37 - 2013-11-18 20:37 - 05165110 _____ C:\Users\user\Downloads\Nový priečinok.rar
2013-11-18 20:36 - 2013-11-18 20:36 - 06878569 _____ C:\Users\user\Downloads\dentelne_materialy.rar
2013-11-17 23:37 - 2011-10-28 20:27 - 00675328 ___SH C:\Users\user\Thumbs.db
2013-11-17 22:47 - 2013-11-17 22:47 - 104760117 _____ C:\Windows\SysWOW64\束Ⓠ£
2013-11-17 17:10 - 2013-11-17 17:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-14 23:52 - 2013-11-14 23:52 - 00000000 ____D C:\Users\user\Desktop\kluc_A
2013-11-14 23:43 - 2013-11-14 22:28 - 00000000 ____D C:\Users\user\Desktop\histology_2year
2013-11-14 21:57 - 2013-11-14 21:57 - 104278918 _____ C:\Windows\SysWOW64\죠䡽ª
2013-11-12 22:04 - 2013-11-12 22:04 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud.pps
2013-11-11 22:25 - 2013-11-11 22:22 - 19341362 _____ C:\Users\user\Downloads\3(1).rar
2013-11-11 22:25 - 2013-11-11 22:22 - 17717501 _____ C:\Users\user\Downloads\1.rar
2013-11-11 22:25 - 2013-11-11 22:22 - 14875731 _____ C:\Users\user\Downloads\2.rar
2013-11-11 21:56 - 2013-11-11 21:56 - 19341362 _____ C:\Users\user\Downloads\3.rar
2013-11-11 19:07 - 2013-11-11 19:07 - 00000000 ____D C:\Users\user\Desktop\DCIM20
2013-11-11 17:55 - 2013-11-11 17:55 - 103792856 _____ C:\Windows\SysWOW64\ᨡ锓”
2013-11-10 23:00 - 2013-11-10 23:00 - 103551423 _____ C:\Windows\SysWOW64\⑴篷“
2013-11-10 22:21 - 2013-11-10 22:21 - 00000000 ____D C:\Users\user\Downloads\dent_mat_otazky
2013-11-10 22:20 - 2013-11-10 22:20 - 04042707 _____ C:\Users\user\Downloads\dent_Mat.zip
2013-11-06 11:18 - 2013-11-06 11:18 - 102722523 _____ C:\Windows\SysWOW64\䖩ఄ«
2013-11-05 18:19 - 2013-11-05 18:19 - 105048247 _____ C:\Windows\SysWOW64\榠︚N
2013-11-04 21:03 - 2013-11-04 21:03 - 104964650 _____ C:\Windows\SysWOW64\㣮ᵞF

Files to move or delete:
====================
C:\Users\user\SkypeSetup.exe


Some content of TEMP:
====================
C:\Users\user\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-27 21:19

==================== End Of Log ============================

este raz Vam velmi pekne dakujem

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: virus policia SR

#8 Příspěvek od vyosek »

:arrow: Mate tam ESET a Aviru, jeden z nich musi pryc

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKCU\...\Run: [Facebook Update] - C:\Users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-10-16] (Facebook Inc.)
    HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18678376 2013-04-19] (Skype Technologies S.A.)
    MountPoints2: {ba6b132a-0f92-11e0-acb6-1c4bd61be8be} - F:\.autorun\autorun.exe
    HKLM-x32\...\Run: [RemoteControl9] - C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe [87336 2009-07-06] (CyberLink Corp.)
    HKLM-x32\...\Run: [UpdateLBPShortCut] - C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
    HKLM-x32\...\Run: [UpdateP2GoShortCut] - C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
    HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
    HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
    Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
    Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Photosmart 5510 series.lnk
    
    SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL =
    SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
    BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
    BHO-x32: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
    Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
    Toolbar: HKLM-x32 - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
    Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
    Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
    
    R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-10-23] (APN LLC.)
    U3 tmlwf;
    U3 tmwfp; 
    
    2013-12-01 19:23 - 2013-12-01 19:23 - 00000000 ____D C:\ProgramData\HitmanPro
    C:\Program Files (x86)\AskPartnerNetwork
    2013-12-02 20:09 - 2013-12-02 20:09 - 00015327 _____ C:\Users\user\Desktop\LM.bat
    2013-12-02 20:09 - 2013-12-02 20:08 - 00029696 _____ C:\Users\user\AppData\Local\MSGBOX.EXE
    2013-12-02 20:08 - 2013-12-02 20:09 - 00112640 _____ C:\Users\user\Desktop\FRSTLauncher.exe
    2013-12-02 20:08 - 2013-12-02 20:08 - 00112640 _____ C:\Users\user\Downloads\FRSTLauncher.exe
    2013-12-02 20:08 - 2013-12-02 20:07 - 01959184 _____ (Farbar) C:\Users\user\Downloads\FRST64.exe
    C:\Users\user\AppData\Local\Temp\Quarantine.exe
    C:\Users\user\SkypeSetup.exe
    
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer" /f
    
    Hosts:
    CMD: shutdown /r /f /t 2
    
    End
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

likes
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 01 Pro 2013 18:42

Re: virus policia SR

#9 Příspěvek od likes »

Dakujem :)
nech sa paci log :)
Inak nemam NOD len Aviru, neviem ako sa tam dostala ani v spustenych ho nemam ani v prog. liste
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 03-12-2013 02
Ran by user at 2013-12-04 10:46:40 Run:1
Running from C:\Users\user\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
HKCU\...\Run: [Facebook Update] - C:\Users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-10-16] (Facebook Inc.)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18678376 2013-04-19] (Skype Technologies S.A.)
MountPoints2: {ba6b132a-0f92-11e0-acb6-1c4bd61be8be} - F:\.autorun\autorun.exe
HKLM-x32\...\Run: [RemoteControl9] - C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe [87336 2009-07-06] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateLBPShortCut] - C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] - C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Photosmart 5510 series.lnk

SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL =
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
BHO-x32: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
Toolbar: HKLM-x32 - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File

R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-10-23] (APN LLC.)
U3 tmlwf;
U3 tmwfp;

2013-12-01 19:23 - 2013-12-01 19:23 - 00000000 ____D C:\ProgramData\HitmanPro
C:\Program Files (x86)\AskPartnerNetwork
2013-12-02 20:09 - 2013-12-02 20:09 - 00015327 _____ C:\Users\user\Desktop\LM.bat
2013-12-02 20:09 - 2013-12-02 20:08 - 00029696 _____ C:\Users\user\AppData\Local\MSGBOX.EXE
2013-12-02 20:08 - 2013-12-02 20:09 - 00112640 _____ C:\Users\user\Desktop\FRSTLauncher.exe
2013-12-02 20:08 - 2013-12-02 20:08 - 00112640 _____ C:\Users\user\Downloads\FRSTLauncher.exe
2013-12-02 20:08 - 2013-12-02 20:07 - 01959184 _____ (Farbar) C:\Users\user\Downloads\FRST64.exe
C:\Users\user\AppData\Local\Temp\Quarantine.exe
C:\Users\user\SkypeSetup.exe

REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer" /f

Hosts:
CMD: shutdown /r /f /t 2

End
*****************

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Facebook Update => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Skype => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ba6b132a-0f92-11e0-acb6-1c4bd61be8be} => Key deleted successfully.
HKCR\CLSID\{ba6b132a-0f92-11e0-acb6-1c4bd61be8be} => Key not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\RemoteControl9 => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\UpdateLBPShortCut => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\UpdateP2GoShortCut => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk => Moved successfully.
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Photosmart 5510 series.lnk => Moved successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => Key deleted successfully.
HKCR\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully.
HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7} => Key deleted successfully.
HKCR\CLSID\{41564952-412D-5637-00A7-7A786E7484D7} => Key deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{41564952-412D-5637-00A7-7A786E7484D7} => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{41564952-412D-5637-00A7-7A786E7484D7} => Value deleted successfully.
HKCR\CLSID\{41564952-412D-5637-00A7-7A786E7484D7} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{41564952-412D-5637-00A7-7A786E7484D7} => Value deleted successfully.
HKCR\Wow6432Node\CLSID\{41564952-412D-5637-00A7-7A786E7484D7} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Value deleted successfully.
HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Key not found.
HKCR\PROTOCOLS\Filter\text/xml => Key deleted successfully.
HKCR\CLSID\{807553E5-5146-11D5-A672-00B0D022E945} => Key not found.
APNMCP => Service deleted successfully.
tmlwf => Service deleted successfully.
tmwfp => Service deleted successfully.
C:\ProgramData\HitmanPro => Moved successfully.
C:\Program Files (x86)\AskPartnerNetwork => Moved successfully.
"C:\Users\user\Desktop\LM.bat" => File/Directory not found.
C:\Users\user\AppData\Local\MSGBOX.EXE => Moved successfully.
"C:\Users\user\Desktop\FRSTLauncher.exe" => File/Directory not found.
"C:\Users\user\Downloads\FRSTLauncher.exe" => File/Directory not found.
C:\Users\user\Downloads\FRST64.exe => Moved successfully.
C:\Users\user\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\user\SkypeSetup.exe => Moved successfully.

========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========

"C:\Windows\System32\Drivers\etc\hosts" => Could not move.
Could not reset Hosts.

========= shutdown /r /f /t 2 =========


========= End of CMD: =========



The system needs a manual reboot.

==== End of Fixlog ====

Dakujem Vam velmi pekne :)

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: virus policia SR

#10 Příspěvek od vyosek »

Tak jeste jeden fixlist, postup stejny

Kód: Vybrat vše

Start
U3 a82suxqo; C:\Windows\System32\Drivers\a82suxqo.sys [0 ] (Microsoft Corporation)
U3 tmlwf;
U3 tmwfp;

2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Roaming\ESET
2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Local\ESET
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\ProgramData\ESET
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\Program Files\ESET
End
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

likes
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 01 Pro 2013 18:42

Re: virus policia SR

#11 Příspěvek od likes »

Dakujem spravil som to :) nech sa paci log :
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 03-12-2013 02
Ran by user at 2013-12-05 13:02:57 Run:2
Running from C:\Users\user\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
U3 a82suxqo; C:\Windows\System32\Drivers\a82suxqo.sys [0 ] (Microsoft Corporation)
U3 tmlwf;
U3 tmwfp;

2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Roaming\ESET
2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Local\ESET
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\ProgramData\ESET
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\Program Files\ESET
End
*****************

a82suxqo => Service not found.
tmlwf => Service deleted successfully.
tmwfp => Service deleted successfully.
C:\Users\user\AppData\Roaming\ESET => Moved successfully.
C:\Users\user\AppData\Local\ESET => Moved successfully.
C:\ProgramData\ESET => Moved successfully.
C:\Program Files\ESET => Moved successfully.

==== End of Fixlog ====

Vieme sa prosim Vas este raz pozriet nejak, ci je uplne vonku ten virus? dakujem velmi pekne :)
toto je najnovsi log v terajsom aktualnom stave, neviem ci pomoze :
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-12-2013 02
Ran by user (administrator) on USER-NB on 05-12-2013 13:05:13
Running from C:\Users\user\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(ATK) C:\Program Files\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
(ATK) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(The Eraser Project) C:\Program Files\Eraser\Eraser.exe
(syncables, LLC) C:\Program Files (x86)\syncables\syncables desktop\syncables.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Sun Microsystems, Inc.) C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Boingo Wireless, Inc.) C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
() C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(asus) C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Farbar) C:\Users\user\Desktop\FRST64(1).exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [649608 2010-04-13] (ELAN Microelectronic Corp.)
HKLM\...\Run: [ASUS WebStorage] - C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe
HKLM\...\Run: [Setwallpaper] - c:\programdata\SetWallpaper.cmd
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [Eraser] - C:\Program Files\Eraser\Eraser.exe [980920 2012-05-22] (The Eraser Project)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [Syncables] - C:\Program Files (x86)\syncables\syncables desktop\syncables.exe [370480 2010-04-05] (syncables, LLC)
HKLM-x32\...\Run: [Boingo Wi-Fi] - C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk [2429 2010-10-15] ()
HKLM-x32\...\Run: [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [7350912 2010-02-04] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-01-05] (ASUS)
HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1597440 2010-07-02] ()
HKLM-x32\...\Run: [SessionLogon] - C:\ExpressGateUtil\SessionLogon.exe
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-04] (Avira Operations GmbH & Co. KG)
HKU\UpdatusUser\...\Run: [swg] - "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
AppInit_DLLs: C:\Windows\System32\nvinitx.dll [239720 2011-05-21] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [200808 2011-05-21] (NVIDIA Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\m6guis4w.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_149.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.11.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.11.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8051.1204 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\user\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\atlas-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\azet-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\dunaj-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slovnik-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\zoznam-sk.xml

==================== Services (Whitelisted) =================

S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2013-01-10] (Adobe Systems)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [66872 2011-03-26] ()
R3 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2010-04-06] ()

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-08-11] (Avira Operations GmbH & Co. KG)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-12-24] ()
U3 a3995hj6; C:\Windows\System32\Drivers\a3995hj6.sys [0 ] (Microsoft Corporation)
U4 a82suxqo;
U4 APNMCP;
U4 tmlwf;
U4 tmwfp;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-12-05 13:05 - 2013-12-05 13:05 - 00012477 _____ C:\Users\user\Desktop\FRST.txt
2013-12-05 13:01 - 2013-12-05 13:01 - 00000000 ____D C:\Users\user\Desktop\topographical anatomy of H+N for dentistry students
2013-12-05 13:00 - 2013-12-05 13:00 - 105576360 _____ C:\Windows\SysWOW64\⋽ЩŸ
2013-12-04 10:15 - 2013-12-04 10:10 - 01959614 _____ (Farbar) C:\Users\user\Desktop\FRST64(1).exe
2013-12-04 10:10 - 2013-12-04 10:10 - 01959614 _____ (Farbar) C:\Users\user\Downloads\FRST64(1).exe
2013-12-03 19:49 - 2013-12-03 19:49 - 09273864 _____ C:\Users\user\Downloads\Dentálne materiály 7.11.2013, cast.rar
2013-12-01 21:29 - 2013-12-01 21:31 - 00000000 ____D C:\AdwCleaner
2013-12-01 21:19 - 2013-12-01 21:19 - 00000000 ____D C:\Windows\ERUNT
2013-12-01 21:17 - 2013-12-01 21:17 - 01110034 _____ C:\Users\user\Downloads\adwcleaner.exe
2013-12-01 21:17 - 2013-12-01 21:17 - 01034531 _____ (Thisisu) C:\Users\user\Downloads\JRT.exe
2013-12-01 18:50 - 2013-12-04 10:46 - 00000000 ____D C:\FRST
2013-12-01 18:21 - 2013-12-02 04:39 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\Users\user\AppData\Roaming\Malwarebytes
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-24 22:41 - 2013-11-24 22:41 - 105952601 _____ C:\Windows\SysWOW64\驧笌¡
2013-11-20 18:45 - 2013-11-20 18:45 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud(1).pps
2013-11-19 23:07 - 2013-11-19 23:07 - 105275480 _____ C:\Windows\SysWOW64\[䅏¡
2013-11-19 20:00 - 2013-11-19 20:01 - 00000000 ____D C:\Users\user\Desktop\DCIM30
2013-11-18 23:46 - 2013-11-18 23:46 - 105004989 _____ C:\Windows\SysWOW64\᷒齍‹
2013-11-18 20:38 - 2013-11-18 20:39 - 19696439 _____ C:\Users\user\Downloads\dentalne materialy.zip
2013-11-18 20:38 - 2013-11-18 20:38 - 05671495 _____ C:\Users\user\Downloads\dentalnie materialy zivice a plasty.rar
2013-11-18 20:38 - 2013-11-18 20:38 - 05092838 _____ C:\Users\user\Downloads\Dentalne materialy.rar
2013-11-18 20:37 - 2013-11-18 20:37 - 05165110 _____ C:\Users\user\Downloads\Nový priečinok.rar
2013-11-18 20:36 - 2013-11-18 20:36 - 06878569 _____ C:\Users\user\Downloads\dentelne_materialy.rar
2013-11-17 22:47 - 2013-11-17 22:47 - 104760117 _____ C:\Windows\SysWOW64\束Ⓠ£
2013-11-17 17:10 - 2013-11-17 17:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-14 23:52 - 2013-11-14 23:52 - 00000000 ____D C:\Users\user\Desktop\kluc_A
2013-11-14 22:28 - 2013-11-14 23:43 - 00000000 ____D C:\Users\user\Desktop\histology_2year
2013-11-14 21:57 - 2013-11-14 21:57 - 104278918 _____ C:\Windows\SysWOW64\죠䡽ª
2013-11-12 22:04 - 2013-11-12 22:04 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud.pps
2013-11-11 22:22 - 2013-11-11 22:25 - 19341362 _____ C:\Users\user\Downloads\3(1).rar
2013-11-11 22:22 - 2013-11-11 22:25 - 17717501 _____ C:\Users\user\Downloads\1.rar
2013-11-11 22:22 - 2013-11-11 22:25 - 14875731 _____ C:\Users\user\Downloads\2.rar
2013-11-11 21:56 - 2013-11-11 21:56 - 19341362 _____ C:\Users\user\Downloads\3.rar
2013-11-11 19:07 - 2013-11-11 19:07 - 00000000 ____D C:\Users\user\Desktop\DCIM20
2013-11-11 17:55 - 2013-11-11 17:55 - 103792856 _____ C:\Windows\SysWOW64\ᨡ锓”
2013-11-10 23:00 - 2013-11-10 23:00 - 103551423 _____ C:\Windows\SysWOW64\⑴篷“
2013-11-10 22:21 - 2013-11-10 22:21 - 00000000 ____D C:\Users\user\Downloads\dent_mat_otazky
2013-11-10 22:20 - 2013-11-10 22:20 - 04042707 _____ C:\Users\user\Downloads\dent_Mat.zip
2013-11-06 11:18 - 2013-11-06 11:18 - 102722523 _____ C:\Windows\SysWOW64\䖩ఄ«
2013-11-05 18:19 - 2013-11-05 18:19 - 105048247 _____ C:\Windows\SysWOW64\榠︚N

==================== One Month Modified Files and Folders =======

2013-12-05 13:05 - 2013-12-05 13:05 - 00012477 _____ C:\Users\user\Desktop\FRST.txt
2013-12-05 13:05 - 2009-07-14 05:45 - 00010240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-05 13:05 - 2009-07-14 05:45 - 00010240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-05 13:01 - 2013-12-05 13:01 - 00000000 ____D C:\Users\user\Desktop\topographical anatomy of H+N for dentistry students
2013-12-05 13:00 - 2013-12-05 13:00 - 105576360 _____ C:\Windows\SysWOW64\⋽ЩŸ
2013-12-05 12:56 - 2011-11-08 09:26 - 00000928 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-05 12:56 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-05 12:56 - 2009-07-14 05:51 - 00077926 _____ C:\Windows\setupact.log
2013-12-05 08:32 - 2010-10-15 19:16 - 01699707 _____ C:\Windows\WindowsUpdate.log
2013-12-05 08:17 - 2011-11-08 09:26 - 00000932 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-04 23:43 - 2012-10-16 19:38 - 00000924 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1241329632-66754793-2357093618-1002UA.job
2013-12-04 22:42 - 2011-01-08 13:40 - 00000000 ____D C:\Users\user\AppData\Roaming\Skype
2013-12-04 20:43 - 2012-10-16 19:38 - 00000902 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1241329632-66754793-2357093618-1002Core.job
2013-12-04 10:46 - 2013-12-01 18:50 - 00000000 ____D C:\FRST
2013-12-04 10:46 - 2010-12-22 17:53 - 00000000 ___RD C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-12-04 10:10 - 2013-12-04 10:15 - 01959614 _____ (Farbar) C:\Users\user\Desktop\FRST64(1).exe
2013-12-04 10:10 - 2013-12-04 10:10 - 01959614 _____ (Farbar) C:\Users\user\Downloads\FRST64(1).exe
2013-12-04 00:52 - 2011-11-17 12:10 - 00000000 ____D C:\Users\user\AppData\Roaming\SoftGrid Client
2013-12-03 19:49 - 2013-12-03 19:49 - 09273864 _____ C:\Users\user\Downloads\Dentálne materiály 7.11.2013, cast.rar
2013-12-03 19:03 - 2012-12-13 19:48 - 00000000 ____D C:\Advanced Tram Simulator 0.57b
2013-12-03 18:59 - 2009-08-03 21:00 - 00626776 _____ C:\Windows\system32\perfh005.dat
2013-12-03 18:59 - 2009-08-03 21:00 - 00125050 _____ C:\Windows\system32\perfc005.dat
2013-12-03 18:59 - 2009-07-14 06:13 - 01484558 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-02 20:05 - 2013-05-10 13:14 - 00000000 ____D C:\Users\user\AppData\Local\PokerStars
2013-12-02 04:39 - 2013-12-01 18:21 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-02 04:39 - 2010-10-15 20:14 - 00000000 ____D C:\ProgramData\P4G
2013-12-02 04:39 - 2009-07-14 08:44 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-12-02 04:39 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
2013-12-01 21:31 - 2013-12-01 21:29 - 00000000 ____D C:\AdwCleaner
2013-12-01 21:19 - 2013-12-01 21:19 - 00000000 ____D C:\Windows\ERUNT
2013-12-01 21:17 - 2013-12-01 21:17 - 01110034 _____ C:\Users\user\Downloads\adwcleaner.exe
2013-12-01 21:17 - 2013-12-01 21:17 - 01034531 _____ (Thisisu) C:\Users\user\Downloads\JRT.exe
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\Users\user\AppData\Roaming\Malwarebytes
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-28 09:51 - 2013-04-18 22:50 - 00000000 ____D C:\Users\user\AppData\Local\Eraser 6
2013-11-24 22:41 - 2013-11-24 22:41 - 105952601 _____ C:\Windows\SysWOW64\驧笌¡
2013-11-20 18:45 - 2013-11-20 18:45 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud(1).pps
2013-11-19 23:07 - 2013-11-19 23:07 - 105275480 _____ C:\Windows\SysWOW64\[䅏¡
2013-11-19 20:01 - 2013-11-19 20:00 - 00000000 ____D C:\Users\user\Desktop\DCIM30
2013-11-19 17:05 - 2012-09-26 15:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-18 23:46 - 2013-11-18 23:46 - 105004989 _____ C:\Windows\SysWOW64\᷒齍‹
2013-11-18 20:39 - 2013-11-18 20:38 - 19696439 _____ C:\Users\user\Downloads\dentalne materialy.zip
2013-11-18 20:38 - 2013-11-18 20:38 - 05671495 _____ C:\Users\user\Downloads\dentalnie materialy zivice a plasty.rar
2013-11-18 20:38 - 2013-11-18 20:38 - 05092838 _____ C:\Users\user\Downloads\Dentalne materialy.rar
2013-11-18 20:37 - 2013-11-18 20:37 - 05165110 _____ C:\Users\user\Downloads\Nový priečinok.rar
2013-11-18 20:36 - 2013-11-18 20:36 - 06878569 _____ C:\Users\user\Downloads\dentelne_materialy.rar
2013-11-17 23:37 - 2011-10-28 20:27 - 00675328 ___SH C:\Users\user\Thumbs.db
2013-11-17 22:47 - 2013-11-17 22:47 - 104760117 _____ C:\Windows\SysWOW64\束Ⓠ£
2013-11-17 17:10 - 2013-11-17 17:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-14 23:52 - 2013-11-14 23:52 - 00000000 ____D C:\Users\user\Desktop\kluc_A
2013-11-14 23:43 - 2013-11-14 22:28 - 00000000 ____D C:\Users\user\Desktop\histology_2year
2013-11-14 21:57 - 2013-11-14 21:57 - 104278918 _____ C:\Windows\SysWOW64\죠䡽ª
2013-11-12 22:04 - 2013-11-12 22:04 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud.pps
2013-11-11 22:25 - 2013-11-11 22:22 - 19341362 _____ C:\Users\user\Downloads\3(1).rar
2013-11-11 22:25 - 2013-11-11 22:22 - 17717501 _____ C:\Users\user\Downloads\1.rar
2013-11-11 22:25 - 2013-11-11 22:22 - 14875731 _____ C:\Users\user\Downloads\2.rar
2013-11-11 21:56 - 2013-11-11 21:56 - 19341362 _____ C:\Users\user\Downloads\3.rar
2013-11-11 19:07 - 2013-11-11 19:07 - 00000000 ____D C:\Users\user\Desktop\DCIM20
2013-11-11 17:55 - 2013-11-11 17:55 - 103792856 _____ C:\Windows\SysWOW64\ᨡ锓”
2013-11-10 23:00 - 2013-11-10 23:00 - 103551423 _____ C:\Windows\SysWOW64\⑴篷“
2013-11-10 22:21 - 2013-11-10 22:21 - 00000000 ____D C:\Users\user\Downloads\dent_mat_otazky
2013-11-10 22:20 - 2013-11-10 22:20 - 04042707 _____ C:\Users\user\Downloads\dent_Mat.zip
2013-11-06 11:18 - 2013-11-06 11:18 - 102722523 _____ C:\Windows\SysWOW64\䖩ఄ«
2013-11-05 18:19 - 2013-11-05 18:19 - 105048247 _____ C:\Windows\SysWOW64\榠︚N

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-27 21:19

==================== End Of Log ============================
Dakujem Velmi pekne

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: virus policia SR

#12 Příspěvek od vyosek »

Log vypada OK, jak se chova PC??
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

likes
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 01 Pro 2013 18:42

Re: virus policia SR

#13 Příspěvek od likes »

uplne normalne :) a este je aj trocha rychlejsi ako pred tým :)
Dakujem Vam velmi pekne :)

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: virus policia SR

#14 Příspěvek od vyosek »

Tak jeste uklidime :James008:

:arrow: T-Cleaner http://vyosek.tym.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět