Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

virus policia SR

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
likes
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 01 pro 2013 18:42

virus policia SR

#1 Příspěvek od likes »

Prosim Vas som zufaly :( mam dolezite veci v pc a napadol ma tento virus, zatial vsetko funguje len okno sa neda zavrit, prosim pomozte :( budem sa riadit vasimi prikazmi, prepacte ak je to v zlej sekcii neviem nic najst a bojim sa bez rady daco spravit dakujem vam velmi pekne
log s FRST
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-12-2013
Ran by user (administrator) on USER-NB on 01-12-2013 18:51:06
Running from C:\Users\user\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
(ATK) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ATK) C:\Program Files\P4G\BatteryLife.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(syncables, LLC) C:\Program Files (x86)\syncables\syncables desktop\syncables.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
(Boingo Wireless, Inc.) C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
() C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(asus) C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(forum.viry.cz) C:\Users\user\Downloads\FRSTLauncher(2).exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [649608 2010-04-13] (ELAN Microelectronic Corp.)
HKLM\...\Run: [ASUS WebStorage] - C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe
HKLM\...\Run: [Setwallpaper] - c:\programdata\SetWallpaper.cmd
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [Eraser] - C:\Program Files\Eraser\Eraser.exe [980920 2012-05-22] (The Eraser Project)
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [5618456 2013-09-12] (ESET)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
HKLM-x32\...\Winlogon: [Userinit] C:\Windows\sysWOW64\userinit.exe [26624 2010-11-20] (Microsoft Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [Facebook Update] - C:\Users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-10-16] (Facebook Inc.)
HKCU\...\Run: [Syncables] - C:\Program Files (x86)\syncables\syncables desktop\syncables.exe [370480 2010-04-05] (syncables, LLC)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18678376 2013-04-19] (Skype Technologies S.A.)
MountPoints2: {ba6b132a-0f92-11e0-acb6-1c4bd61be8be} - F:\.autorun\autorun.exe
HKLM-x32\...\Run: [RemoteControl9] - C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe [87336 2009-07-06] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateLBPShortCut] - C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] - C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [Boingo Wi-Fi] - C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk [2429 2010-10-15] ()
HKLM-x32\...\Run: [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [7350912 2010-02-04] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-01-05] (ASUS)
HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1597440 2010-07-02] ()
HKLM-x32\...\Run: [SessionLogon] - C:\ExpressGateUtil\SessionLogon.exe
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-04] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1673680 2013-10-23] (APN)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll [239720 2011-05-21] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [200808 2011-05-21] (NVIDIA Corporation)
Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Photosmart 5510 series.lnk
ShortcutTarget: Sledovat výstrahy inkoustu - HP Photosmart 5510 series.lnk -> C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL =
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
Toolbar: HKLM-x32 - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\m6guis4w.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_149.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.11.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.11.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8051.1204 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\user\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\atlas-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\azet-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\dunaj-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slovnik-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\zoznam-sk.xml
FF Extension: toolbar_AVIRA-V7 - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\m6guis4w.default\Extensions\toolbar_AVIRA-V7@apn.ask.com.xpi
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird

==================== Services (Whitelisted) =================

S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2013-01-10] (Adobe Systems)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-10-23] (APN LLC.)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1337752 2013-09-12] (ESET)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [66872 2011-03-26] ()
R3 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2010-04-06] ()

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-08-11] (Avira Operations GmbH & Co. KG)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-09-17] (ESET)
S0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [239296 2013-09-17] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [168256 2013-09-17] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [220232 2013-09-17] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44120 2013-09-17] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [62136 2013-09-17] (ESET)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-12-24] ()
U3 aldgjng9; C:\Windows\System32\Drivers\aldgjng9.sys [0 ] (Microsoft Corporation)
U3 tmlwf;
U3 tmwfp;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-12-01 18:51 - 2013-12-01 18:52 - 00018798 _____ C:\Users\user\Desktop\FRST.txt
2013-12-01 18:50 - 2013-12-01 18:50 - 00112640 _____ (forum.viry.cz) C:\Users\user\Downloads\FRSTLauncher(2).exe
2013-12-01 18:50 - 2013-12-01 18:50 - 00000000 ____D C:\FRST
2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Roaming\ESET
2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Local\ESET
2013-12-01 18:47 - 2013-12-01 18:47 - 00112640 _____ (forum.viry.cz) C:\Users\user\Downloads\FRSTLauncher(1).exe
2013-12-01 18:46 - 2013-12-01 18:46 - 00112640 _____ (forum.viry.cz) C:\Users\user\Downloads\FRSTLauncher.exe
2013-12-01 18:46 - 2013-12-01 18:45 - 01959184 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2013-12-01 18:45 - 2013-12-01 18:45 - 01959184 _____ (Farbar) C:\Users\user\Downloads\FRST64.exe
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\ProgramData\ESET
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\Program Files\ESET
2013-12-01 18:33 - 2013-12-01 18:33 - 01581896 _____ (ESET) C:\Users\user\Downloads\eset_smart_security_live_installer_.exe
2013-12-01 18:21 - 2013-12-01 18:21 - 00001111 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\Users\user\AppData\Roaming\Malwarebytes
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-01 18:21 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-12-01 18:20 - 2013-12-01 18:20 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\user\Downloads\mbam-setup-1.75.0.1300.exe
2013-11-24 22:41 - 2013-11-24 22:41 - 105952601 _____ C:\Windows\SysWOW64\驧笌¡
2013-11-20 18:45 - 2013-11-20 18:45 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud(1).pps
2013-11-19 23:07 - 2013-11-19 23:07 - 105275480 _____ C:\Windows\SysWOW64\[䅏¡
2013-11-19 20:00 - 2013-11-19 20:01 - 00000000 ____D C:\Users\user\Desktop\DCIM30
2013-11-18 23:46 - 2013-11-18 23:46 - 105004989 _____ C:\Windows\SysWOW64\᷒齍‹
2013-11-18 20:38 - 2013-11-18 20:39 - 19696439 _____ C:\Users\user\Downloads\dentalne materialy.zip
2013-11-18 20:38 - 2013-11-18 20:38 - 05671495 _____ C:\Users\user\Downloads\dentalnie materialy zivice a plasty.rar
2013-11-18 20:38 - 2013-11-18 20:38 - 05092838 _____ C:\Users\user\Downloads\Dentalne materialy.rar
2013-11-18 20:37 - 2013-11-18 20:37 - 05165110 _____ C:\Users\user\Downloads\Nový priečinok.rar
2013-11-18 20:36 - 2013-11-18 20:36 - 06878569 _____ C:\Users\user\Downloads\dentelne_materialy.rar
2013-11-17 22:47 - 2013-11-17 22:47 - 104760117 _____ C:\Windows\SysWOW64\束Ⓠ£
2013-11-17 17:10 - 2013-11-17 17:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-14 23:52 - 2013-11-14 23:52 - 00000000 ____D C:\Users\user\Desktop\kluc_A
2013-11-14 22:28 - 2013-11-14 23:43 - 00000000 ____D C:\Users\user\Desktop\histology_2year
2013-11-14 21:57 - 2013-11-14 21:57 - 104278918 _____ C:\Windows\SysWOW64\죠䡽ª
2013-11-12 22:04 - 2013-11-12 22:04 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud.pps
2013-11-11 22:22 - 2013-11-11 22:25 - 19341362 _____ C:\Users\user\Downloads\3(1).rar
2013-11-11 22:22 - 2013-11-11 22:25 - 17717501 _____ C:\Users\user\Downloads\1.rar
2013-11-11 22:22 - 2013-11-11 22:25 - 14875731 _____ C:\Users\user\Downloads\2.rar
2013-11-11 21:56 - 2013-11-11 21:56 - 19341362 _____ C:\Users\user\Downloads\3.rar
2013-11-11 19:07 - 2013-11-11 19:07 - 00000000 ____D C:\Users\user\Desktop\DCIM20
2013-11-11 17:55 - 2013-11-11 17:55 - 103792856 _____ C:\Windows\SysWOW64\ᨡ锓”
2013-11-10 23:00 - 2013-11-10 23:00 - 103551423 _____ C:\Windows\SysWOW64\⑴篷“
2013-11-10 22:21 - 2013-11-10 22:21 - 00000000 ____D C:\Users\user\Downloads\dent_mat_otazky
2013-11-10 22:20 - 2013-11-10 22:20 - 04042707 _____ C:\Users\user\Downloads\dent_Mat.zip
2013-11-06 11:18 - 2013-11-06 11:18 - 102722523 _____ C:\Windows\SysWOW64\䖩ఄ«
2013-11-05 18:19 - 2013-11-05 18:19 - 105048247 _____ C:\Windows\SysWOW64\榠︚N
2013-11-04 21:03 - 2013-11-04 21:03 - 104964650 _____ C:\Windows\SysWOW64\㣮ᵞF

==================== One Month Modified Files and Folders =======

2013-12-01 18:52 - 2013-12-01 18:51 - 00018798 _____ C:\Users\user\Desktop\FRST.txt
2013-12-01 18:51 - 2010-10-15 19:16 - 01508089 _____ C:\Windows\WindowsUpdate.log
2013-12-01 18:50 - 2013-12-01 18:50 - 00112640 _____ (forum.viry.cz) C:\Users\user\Downloads\FRSTLauncher(2).exe
2013-12-01 18:50 - 2013-12-01 18:50 - 00000000 ____D C:\FRST
2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Roaming\ESET
2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Local\ESET
2013-12-01 18:47 - 2013-12-01 18:47 - 00112640 _____ (forum.viry.cz) C:\Users\user\Downloads\FRSTLauncher(1).exe
2013-12-01 18:46 - 2013-12-01 18:46 - 00112640 _____ (forum.viry.cz) C:\Users\user\Downloads\FRSTLauncher.exe
2013-12-01 18:45 - 2013-12-01 18:46 - 01959184 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2013-12-01 18:45 - 2013-12-01 18:45 - 01959184 _____ (Farbar) C:\Users\user\Downloads\FRST64.exe
2013-12-01 18:45 - 2011-01-08 13:40 - 00000000 ____D C:\Users\user\AppData\Roaming\Skype
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\ProgramData\ESET
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\Program Files\ESET
2013-12-01 18:33 - 2013-12-01 18:33 - 01581896 _____ (ESET) C:\Users\user\Downloads\eset_smart_security_live_installer_.exe
2013-12-01 18:21 - 2013-12-01 18:21 - 00001111 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\Users\user\AppData\Roaming\Malwarebytes
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-01 18:20 - 2013-12-01 18:20 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\user\Downloads\mbam-setup-1.75.0.1300.exe
2013-12-01 18:17 - 2011-11-08 09:26 - 00000932 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-01 17:43 - 2012-10-16 19:38 - 00000924 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1241329632-66754793-2357093618-1002UA.job
2013-12-01 17:10 - 2009-07-14 05:45 - 00010240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-01 17:10 - 2009-07-14 05:45 - 00010240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-01 17:01 - 2011-11-08 09:26 - 00000928 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-01 17:01 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-01 17:01 - 2009-07-14 05:51 - 00077422 _____ C:\Windows\setupact.log
2013-11-28 16:21 - 2009-08-03 21:00 - 00626776 _____ C:\Windows\system32\perfh005.dat
2013-11-28 16:21 - 2009-08-03 21:00 - 00125050 _____ C:\Windows\system32\perfc005.dat
2013-11-28 16:21 - 2009-07-14 06:13 - 01484558 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-28 09:51 - 2013-04-18 22:50 - 00000000 ____D C:\Users\user\AppData\Local\Eraser 6
2013-11-27 20:43 - 2012-10-16 19:38 - 00000902 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1241329632-66754793-2357093618-1002Core.job
2013-11-27 00:09 - 2011-11-17 12:10 - 00000000 ____D C:\Users\user\AppData\Roaming\SoftGrid Client
2013-11-26 21:11 - 2013-05-10 13:14 - 00000000 ____D C:\Users\user\AppData\Local\PokerStars
2013-11-24 22:41 - 2013-11-24 22:41 - 105952601 _____ C:\Windows\SysWOW64\驧笌¡
2013-11-20 18:45 - 2013-11-20 18:45 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud(1).pps
2013-11-19 23:07 - 2013-11-19 23:07 - 105275480 _____ C:\Windows\SysWOW64\[䅏¡
2013-11-19 20:01 - 2013-11-19 20:00 - 00000000 ____D C:\Users\user\Desktop\DCIM30
2013-11-19 17:05 - 2012-09-26 15:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-18 23:46 - 2013-11-18 23:46 - 105004989 _____ C:\Windows\SysWOW64\᷒齍‹
2013-11-18 20:39 - 2013-11-18 20:38 - 19696439 _____ C:\Users\user\Downloads\dentalne materialy.zip
2013-11-18 20:38 - 2013-11-18 20:38 - 05671495 _____ C:\Users\user\Downloads\dentalnie materialy zivice a plasty.rar
2013-11-18 20:38 - 2013-11-18 20:38 - 05092838 _____ C:\Users\user\Downloads\Dentalne materialy.rar
2013-11-18 20:37 - 2013-11-18 20:37 - 05165110 _____ C:\Users\user\Downloads\Nový priečinok.rar
2013-11-18 20:36 - 2013-11-18 20:36 - 06878569 _____ C:\Users\user\Downloads\dentelne_materialy.rar
2013-11-17 23:37 - 2011-10-28 20:27 - 00675328 ___SH C:\Users\user\Thumbs.db
2013-11-17 22:47 - 2013-11-17 22:47 - 104760117 _____ C:\Windows\SysWOW64\束Ⓠ£
2013-11-17 17:10 - 2013-11-17 17:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-14 23:52 - 2013-11-14 23:52 - 00000000 ____D C:\Users\user\Desktop\kluc_A
2013-11-14 23:43 - 2013-11-14 22:28 - 00000000 ____D C:\Users\user\Desktop\histology_2year
2013-11-14 21:57 - 2013-11-14 21:57 - 104278918 _____ C:\Windows\SysWOW64\죠䡽ª
2013-11-12 22:04 - 2013-11-12 22:04 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud.pps
2013-11-11 22:25 - 2013-11-11 22:22 - 19341362 _____ C:\Users\user\Downloads\3(1).rar
2013-11-11 22:25 - 2013-11-11 22:22 - 17717501 _____ C:\Users\user\Downloads\1.rar
2013-11-11 22:25 - 2013-11-11 22:22 - 14875731 _____ C:\Users\user\Downloads\2.rar
2013-11-11 21:56 - 2013-11-11 21:56 - 19341362 _____ C:\Users\user\Downloads\3.rar
2013-11-11 19:07 - 2013-11-11 19:07 - 00000000 ____D C:\Users\user\Desktop\DCIM20
2013-11-11 17:55 - 2013-11-11 17:55 - 103792856 _____ C:\Windows\SysWOW64\ᨡ锓”
2013-11-10 23:00 - 2013-11-10 23:00 - 103551423 _____ C:\Windows\SysWOW64\⑴篷“
2013-11-10 22:21 - 2013-11-10 22:21 - 00000000 ____D C:\Users\user\Downloads\dent_mat_otazky
2013-11-10 22:20 - 2013-11-10 22:20 - 04042707 _____ C:\Users\user\Downloads\dent_Mat.zip
2013-11-06 11:18 - 2013-11-06 11:18 - 102722523 _____ C:\Windows\SysWOW64\䖩ఄ«
2013-11-05 18:19 - 2013-11-05 18:19 - 105048247 _____ C:\Windows\SysWOW64\榠︚N
2013-11-04 21:03 - 2013-11-04 21:03 - 104964650 _____ C:\Windows\SysWOW64\㣮ᵞF

Files to move or delete:
====================
C:\Users\user\SkypeSetup.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================


==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: ESET Smart Security 7.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AV: Avira Desktop (Disabled - Out of date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Disabled - Out of date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 7.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET personal firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\user\Desktop" je 25604 MB.


***** Startup Programs *****

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer
"C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [x]


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================
Dakujem velmi pekne

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: virus policia SR

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Spustte tam HitmanPro with KickStart http://forum.viry.cz/viewtopic.php?f=29&t=132523
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

likes
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 01 pro 2013 18:42

Re: virus policia SR

#3 Příspěvek od likes »

dobry vecer prajem, dakujem Vam velmi pekne za pomoc.
nejak sa mi nepodarilo dostat sa do toho USB boot menu :( ale nejak sa mi podarilo spravit bod obnovy na 27.11.2013 a vyzera byt vsetko normalne. Podla Vas odisiel virus? alebo co mam spravit? dakujem velmi pekne

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: virus policia SR

#4 Příspěvek od vyosek »

:arrow: Bodem obnovy se mohl malware odstranit, ale proverime to. Navic je v PC hooodne zbytecneho nezadouciho reklamniho balastu - tez vycistime

:arrow: Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
  • Ulozte nejlepe na plochu
  • Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
  • Probehne vytvoreni zalohy a nasledne prohledavani
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

likes
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 01 pro 2013 18:42

Re: virus policia SR

#5 Příspěvek od likes »

# AdwCleaner v3.014 - Report created 01/12/2013 at 21:31:14
# Updated 01/12/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : user - USER-NB
# Running from : C:\Users\user\Downloads\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32099AAC-C132-4136-9E9A-4E364A424E17}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32099AAC-C132-4136-9E9A-4E364A424E17}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}
Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}]

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16476


-\\ Mozilla Firefox v25.0.1 (sk)

[ File : C:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\m6guis4w.default\prefs.js ]


*************************

AdwCleaner[R0].txt - [1939 octets] - [01/12/2013 21:29:07]
AdwCleaner[S0].txt - [1878 octets] - [01/12/2013 21:31:14]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1938 octets] ##########





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Home Premium x64
Ran by user on ne 01. 12. 2013 at 21:19:16,91
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\apntbmon



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{3E288F79-03E4-4983-A48E-0D879B51FF19}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\dt soft\daemon tools toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\dt soft\daemon tools toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\dttoolbar.toolbandobj
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\dttoolbar.toolbandobj.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\daemon tools toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\v9software
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\APNSetup_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\APNSetup_RASMANCS



~~~ Files

Successfully deleted: [File] C:\Windows\syswow64\sho451A.tmp



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\ProgramData\partner"
Successfully deleted: [Folder] "C:\Program Files (x86)\daemon tools toolbar"



~~~ FireFox

Successfully deleted: [File] C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\m6guis4w.default\extensions\toolbar_avira-v7@apn.ask.com.xpi
Emptied folder: C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\m6guis4w.default\minidumps [398 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ne 01. 12. 2013 at 21:25:32,33
End of JRT log


Ako to vyzerá prosím Vás pan doktor? :)
Dakujem Vam velmi pekne :)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: virus policia SR

#6 Příspěvek od vyosek »

Spustte znovu FRSTLauncher a nechte udelat log, ten rad uvidim
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

likes
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 01 pro 2013 18:42

Re: virus policia SR

#7 Příspěvek od likes »

Dakujem Vam velmi pekne
nech sa paci log :)
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-12-2013
Ran by user (administrator) on USER-NB on 02-12-2013 20:09:35
Running from C:\Users\user\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
(ATK) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ATK) C:\Program Files\P4G\BatteryLife.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(The Eraser Project) C:\Program Files\Eraser\Eraser.exe
(syncables, LLC) C:\Program Files (x86)\syncables\syncables desktop\syncables.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
(Boingo Wireless, Inc.) C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
() C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(asus) C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_149.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_149.exe
(forum.viry.cz) C:\Users\user\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\PING.EXE

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [649608 2010-04-13] (ELAN Microelectronic Corp.)
HKLM\...\Run: [ASUS WebStorage] - C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe
HKLM\...\Run: [Setwallpaper] - c:\programdata\SetWallpaper.cmd
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [Eraser] - C:\Program Files\Eraser\Eraser.exe [980920 2012-05-22] (The Eraser Project)
HKLM-x32\...\Winlogon: [Userinit] C:\Windows\sysWOW64\userinit.exe [26624 2010-11-20] (Microsoft Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [Facebook Update] - C:\Users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-10-16] (Facebook Inc.)
HKCU\...\Run: [Syncables] - C:\Program Files (x86)\syncables\syncables desktop\syncables.exe [370480 2010-04-05] (syncables, LLC)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18678376 2013-04-19] (Skype Technologies S.A.)
MountPoints2: {ba6b132a-0f92-11e0-acb6-1c4bd61be8be} - F:\.autorun\autorun.exe
HKLM-x32\...\Run: [RemoteControl9] - C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe [87336 2009-07-06] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateLBPShortCut] - C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] - C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [Boingo Wi-Fi] - C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk [2429 2010-10-15] ()
HKLM-x32\...\Run: [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [7350912 2010-02-04] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-01-05] (ASUS)
HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1597440 2010-07-02] ()
HKLM-x32\...\Run: [SessionLogon] - C:\ExpressGateUtil\SessionLogon.exe
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-04] (Avira Operations GmbH & Co. KG)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll [239720 2011-05-21] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [200808 2011-05-21] (NVIDIA Corporation)
Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Photosmart 5510 series.lnk
ShortcutTarget: Sledovat výstrahy inkoustu - HP Photosmart 5510 series.lnk -> C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL =
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
Toolbar: HKLM-x32 - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\m6guis4w.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_149.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.11.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.11.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8051.1204 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\user\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\atlas-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\azet-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\dunaj-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slovnik-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\zoznam-sk.xml

==================== Services (Whitelisted) =================

S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2013-01-10] (Adobe Systems)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-10-23] (APN LLC.)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [66872 2011-03-26] ()
R3 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2010-04-06] ()

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-08-11] (Avira Operations GmbH & Co. KG)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-12-24] ()
U3 a82suxqo; C:\Windows\System32\Drivers\a82suxqo.sys [0 ] (Microsoft Corporation)
U3 tmlwf;
U3 tmwfp;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-12-02 20:09 - 2013-12-02 20:09 - 00015688 _____ C:\Users\user\Desktop\FRST.txt
2013-12-02 20:09 - 2013-12-02 20:09 - 00015327 _____ C:\Users\user\Desktop\LM.bat
2013-12-02 20:09 - 2013-12-02 20:08 - 01959184 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2013-12-02 20:09 - 2013-12-02 20:08 - 00112640 _____ C:\Users\user\Desktop\FRSTLauncher.exe
2013-12-02 20:08 - 2013-12-02 20:09 - 00029696 _____ C:\Users\user\AppData\Local\MSGBOX.EXE
2013-12-02 20:08 - 2013-12-02 20:08 - 00112640 _____ C:\Users\user\Downloads\FRSTLauncher.exe
2013-12-02 20:07 - 2013-12-02 20:08 - 01959184 _____ (Farbar) C:\Users\user\Downloads\FRST64.exe
2013-12-01 21:29 - 2013-12-01 21:31 - 00000000 ____D C:\AdwCleaner
2013-12-01 21:19 - 2013-12-01 21:19 - 00000000 ____D C:\Windows\ERUNT
2013-12-01 21:17 - 2013-12-01 21:17 - 01110034 _____ C:\Users\user\Downloads\adwcleaner.exe
2013-12-01 21:17 - 2013-12-01 21:17 - 01034531 _____ (Thisisu) C:\Users\user\Downloads\JRT.exe
2013-12-01 19:23 - 2013-12-01 19:23 - 00000000 ____D C:\ProgramData\HitmanPro
2013-12-01 18:50 - 2013-12-01 18:50 - 00000000 ____D C:\FRST
2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Roaming\ESET
2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Local\ESET
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\ProgramData\ESET
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\Program Files\ESET
2013-12-01 18:21 - 2013-12-02 04:39 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\Users\user\AppData\Roaming\Malwarebytes
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-24 22:41 - 2013-11-24 22:41 - 105952601 _____ C:\Windows\SysWOW64\驧笌¡
2013-11-20 18:45 - 2013-11-20 18:45 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud(1).pps
2013-11-19 23:07 - 2013-11-19 23:07 - 105275480 _____ C:\Windows\SysWOW64\[䅏¡
2013-11-19 20:00 - 2013-11-19 20:01 - 00000000 ____D C:\Users\user\Desktop\DCIM30
2013-11-18 23:46 - 2013-11-18 23:46 - 105004989 _____ C:\Windows\SysWOW64\᷒齍‹
2013-11-18 20:38 - 2013-11-18 20:39 - 19696439 _____ C:\Users\user\Downloads\dentalne materialy.zip
2013-11-18 20:38 - 2013-11-18 20:38 - 05671495 _____ C:\Users\user\Downloads\dentalnie materialy zivice a plasty.rar
2013-11-18 20:38 - 2013-11-18 20:38 - 05092838 _____ C:\Users\user\Downloads\Dentalne materialy.rar
2013-11-18 20:37 - 2013-11-18 20:37 - 05165110 _____ C:\Users\user\Downloads\Nový priečinok.rar
2013-11-18 20:36 - 2013-11-18 20:36 - 06878569 _____ C:\Users\user\Downloads\dentelne_materialy.rar
2013-11-17 22:47 - 2013-11-17 22:47 - 104760117 _____ C:\Windows\SysWOW64\束Ⓠ£
2013-11-17 17:10 - 2013-11-17 17:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-14 23:52 - 2013-11-14 23:52 - 00000000 ____D C:\Users\user\Desktop\kluc_A
2013-11-14 22:28 - 2013-11-14 23:43 - 00000000 ____D C:\Users\user\Desktop\histology_2year
2013-11-14 21:57 - 2013-11-14 21:57 - 104278918 _____ C:\Windows\SysWOW64\죠䡽ª
2013-11-12 22:04 - 2013-11-12 22:04 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud.pps
2013-11-11 22:22 - 2013-11-11 22:25 - 19341362 _____ C:\Users\user\Downloads\3(1).rar
2013-11-11 22:22 - 2013-11-11 22:25 - 17717501 _____ C:\Users\user\Downloads\1.rar
2013-11-11 22:22 - 2013-11-11 22:25 - 14875731 _____ C:\Users\user\Downloads\2.rar
2013-11-11 21:56 - 2013-11-11 21:56 - 19341362 _____ C:\Users\user\Downloads\3.rar
2013-11-11 19:07 - 2013-11-11 19:07 - 00000000 ____D C:\Users\user\Desktop\DCIM20
2013-11-11 17:55 - 2013-11-11 17:55 - 103792856 _____ C:\Windows\SysWOW64\ᨡ锓”
2013-11-10 23:00 - 2013-11-10 23:00 - 103551423 _____ C:\Windows\SysWOW64\⑴篷“
2013-11-10 22:21 - 2013-11-10 22:21 - 00000000 ____D C:\Users\user\Downloads\dent_mat_otazky
2013-11-10 22:20 - 2013-11-10 22:20 - 04042707 _____ C:\Users\user\Downloads\dent_Mat.zip
2013-11-06 11:18 - 2013-11-06 11:18 - 102722523 _____ C:\Windows\SysWOW64\䖩ఄ«
2013-11-05 18:19 - 2013-11-05 18:19 - 105048247 _____ C:\Windows\SysWOW64\榠︚N
2013-11-04 21:03 - 2013-11-04 21:03 - 104964650 _____ C:\Windows\SysWOW64\㣮ᵞF

==================== One Month Modified Files and Folders =======

2013-12-02 20:10 - 2013-12-02 20:09 - 00015688 _____ C:\Users\user\Desktop\FRST.txt
2013-12-02 20:09 - 2013-12-02 20:09 - 00015327 _____ C:\Users\user\Desktop\LM.bat
2013-12-02 20:09 - 2013-12-02 20:08 - 00029696 _____ C:\Users\user\AppData\Local\MSGBOX.EXE
2013-12-02 20:08 - 2013-12-02 20:09 - 01959184 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2013-12-02 20:08 - 2013-12-02 20:09 - 00112640 _____ C:\Users\user\Desktop\FRSTLauncher.exe
2013-12-02 20:08 - 2013-12-02 20:08 - 00112640 _____ C:\Users\user\Downloads\FRSTLauncher.exe
2013-12-02 20:08 - 2013-12-02 20:07 - 01959184 _____ (Farbar) C:\Users\user\Downloads\FRST64.exe
2013-12-02 20:05 - 2013-05-10 13:14 - 00000000 ____D C:\Users\user\AppData\Local\PokerStars
2013-12-02 19:57 - 2011-01-08 13:40 - 00000000 ____D C:\Users\user\AppData\Roaming\Skype
2013-12-02 19:17 - 2011-11-08 09:26 - 00000932 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-02 17:47 - 2009-07-14 05:45 - 00010240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-02 17:47 - 2009-07-14 05:45 - 00010240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-02 17:43 - 2012-10-16 19:38 - 00000924 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1241329632-66754793-2357093618-1002UA.job
2013-12-02 17:39 - 2011-11-08 09:26 - 00000928 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-02 17:39 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-02 17:39 - 2009-07-14 05:51 - 00077478 _____ C:\Windows\setupact.log
2013-12-02 04:39 - 2013-12-01 18:21 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-02 04:39 - 2010-12-22 17:53 - 00000000 ___RD C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-12-02 04:39 - 2010-10-15 20:14 - 00000000 ____D C:\ProgramData\P4G
2013-12-02 04:39 - 2009-07-14 08:44 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-12-02 04:39 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
2013-12-02 00:25 - 2010-10-15 19:16 - 01456965 _____ C:\Windows\WindowsUpdate.log
2013-12-01 21:31 - 2013-12-01 21:29 - 00000000 ____D C:\AdwCleaner
2013-12-01 21:19 - 2013-12-01 21:19 - 00000000 ____D C:\Windows\ERUNT
2013-12-01 21:17 - 2013-12-01 21:17 - 01110034 _____ C:\Users\user\Downloads\adwcleaner.exe
2013-12-01 21:17 - 2013-12-01 21:17 - 01034531 _____ (Thisisu) C:\Users\user\Downloads\JRT.exe
2013-12-01 20:43 - 2012-10-16 19:38 - 00000902 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1241329632-66754793-2357093618-1002Core.job
2013-12-01 19:23 - 2013-12-01 19:23 - 00000000 ____D C:\ProgramData\HitmanPro
2013-12-01 18:50 - 2013-12-01 18:50 - 00000000 ____D C:\FRST
2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Roaming\ESET
2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Local\ESET
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\ProgramData\ESET
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\Program Files\ESET
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\Users\user\AppData\Roaming\Malwarebytes
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-28 09:51 - 2013-04-18 22:50 - 00000000 ____D C:\Users\user\AppData\Local\Eraser 6
2013-11-27 19:32 - 2009-08-03 21:00 - 00626776 _____ C:\Windows\system32\perfh005.dat
2013-11-27 19:32 - 2009-08-03 21:00 - 00125050 _____ C:\Windows\system32\perfc005.dat
2013-11-27 19:32 - 2009-07-14 06:13 - 01484558 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-27 00:09 - 2011-11-17 12:10 - 00000000 ____D C:\Users\user\AppData\Roaming\SoftGrid Client
2013-11-24 22:41 - 2013-11-24 22:41 - 105952601 _____ C:\Windows\SysWOW64\驧笌¡
2013-11-20 18:45 - 2013-11-20 18:45 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud(1).pps
2013-11-19 23:07 - 2013-11-19 23:07 - 105275480 _____ C:\Windows\SysWOW64\[䅏¡
2013-11-19 20:01 - 2013-11-19 20:00 - 00000000 ____D C:\Users\user\Desktop\DCIM30
2013-11-19 17:05 - 2012-09-26 15:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-18 23:46 - 2013-11-18 23:46 - 105004989 _____ C:\Windows\SysWOW64\᷒齍‹
2013-11-18 20:39 - 2013-11-18 20:38 - 19696439 _____ C:\Users\user\Downloads\dentalne materialy.zip
2013-11-18 20:38 - 2013-11-18 20:38 - 05671495 _____ C:\Users\user\Downloads\dentalnie materialy zivice a plasty.rar
2013-11-18 20:38 - 2013-11-18 20:38 - 05092838 _____ C:\Users\user\Downloads\Dentalne materialy.rar
2013-11-18 20:37 - 2013-11-18 20:37 - 05165110 _____ C:\Users\user\Downloads\Nový priečinok.rar
2013-11-18 20:36 - 2013-11-18 20:36 - 06878569 _____ C:\Users\user\Downloads\dentelne_materialy.rar
2013-11-17 23:37 - 2011-10-28 20:27 - 00675328 ___SH C:\Users\user\Thumbs.db
2013-11-17 22:47 - 2013-11-17 22:47 - 104760117 _____ C:\Windows\SysWOW64\束Ⓠ£
2013-11-17 17:10 - 2013-11-17 17:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-14 23:52 - 2013-11-14 23:52 - 00000000 ____D C:\Users\user\Desktop\kluc_A
2013-11-14 23:43 - 2013-11-14 22:28 - 00000000 ____D C:\Users\user\Desktop\histology_2year
2013-11-14 21:57 - 2013-11-14 21:57 - 104278918 _____ C:\Windows\SysWOW64\죠䡽ª
2013-11-12 22:04 - 2013-11-12 22:04 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud.pps
2013-11-11 22:25 - 2013-11-11 22:22 - 19341362 _____ C:\Users\user\Downloads\3(1).rar
2013-11-11 22:25 - 2013-11-11 22:22 - 17717501 _____ C:\Users\user\Downloads\1.rar
2013-11-11 22:25 - 2013-11-11 22:22 - 14875731 _____ C:\Users\user\Downloads\2.rar
2013-11-11 21:56 - 2013-11-11 21:56 - 19341362 _____ C:\Users\user\Downloads\3.rar
2013-11-11 19:07 - 2013-11-11 19:07 - 00000000 ____D C:\Users\user\Desktop\DCIM20
2013-11-11 17:55 - 2013-11-11 17:55 - 103792856 _____ C:\Windows\SysWOW64\ᨡ锓”
2013-11-10 23:00 - 2013-11-10 23:00 - 103551423 _____ C:\Windows\SysWOW64\⑴篷“
2013-11-10 22:21 - 2013-11-10 22:21 - 00000000 ____D C:\Users\user\Downloads\dent_mat_otazky
2013-11-10 22:20 - 2013-11-10 22:20 - 04042707 _____ C:\Users\user\Downloads\dent_Mat.zip
2013-11-06 11:18 - 2013-11-06 11:18 - 102722523 _____ C:\Windows\SysWOW64\䖩ఄ«
2013-11-05 18:19 - 2013-11-05 18:19 - 105048247 _____ C:\Windows\SysWOW64\榠︚N
2013-11-04 21:03 - 2013-11-04 21:03 - 104964650 _____ C:\Windows\SysWOW64\㣮ᵞF

Files to move or delete:
====================
C:\Users\user\SkypeSetup.exe


Some content of TEMP:
====================
C:\Users\user\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-27 21:19

==================== End Of Log ============================

este raz Vam velmi pekne dakujem

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: virus policia SR

#8 Příspěvek od vyosek »

:arrow: Mate tam ESET a Aviru, jeden z nich musi pryc

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKCU\...\Run: [Facebook Update] - C:\Users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-10-16] (Facebook Inc.)
    HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18678376 2013-04-19] (Skype Technologies S.A.)
    MountPoints2: {ba6b132a-0f92-11e0-acb6-1c4bd61be8be} - F:\.autorun\autorun.exe
    HKLM-x32\...\Run: [RemoteControl9] - C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe [87336 2009-07-06] (CyberLink Corp.)
    HKLM-x32\...\Run: [UpdateLBPShortCut] - C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
    HKLM-x32\...\Run: [UpdateP2GoShortCut] - C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
    HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
    HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
    Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
    Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Photosmart 5510 series.lnk
    
    SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL =
    SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
    BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
    BHO-x32: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
    Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
    Toolbar: HKLM-x32 - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
    Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
    Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
    
    R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-10-23] (APN LLC.)
    U3 tmlwf;
    U3 tmwfp; 
    
    2013-12-01 19:23 - 2013-12-01 19:23 - 00000000 ____D C:\ProgramData\HitmanPro
    C:\Program Files (x86)\AskPartnerNetwork
    2013-12-02 20:09 - 2013-12-02 20:09 - 00015327 _____ C:\Users\user\Desktop\LM.bat
    2013-12-02 20:09 - 2013-12-02 20:08 - 00029696 _____ C:\Users\user\AppData\Local\MSGBOX.EXE
    2013-12-02 20:08 - 2013-12-02 20:09 - 00112640 _____ C:\Users\user\Desktop\FRSTLauncher.exe
    2013-12-02 20:08 - 2013-12-02 20:08 - 00112640 _____ C:\Users\user\Downloads\FRSTLauncher.exe
    2013-12-02 20:08 - 2013-12-02 20:07 - 01959184 _____ (Farbar) C:\Users\user\Downloads\FRST64.exe
    C:\Users\user\AppData\Local\Temp\Quarantine.exe
    C:\Users\user\SkypeSetup.exe
    
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer" /f
    
    Hosts:
    CMD: shutdown /r /f /t 2
    
    End
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

likes
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 01 pro 2013 18:42

Re: virus policia SR

#9 Příspěvek od likes »

Dakujem :)
nech sa paci log :)
Inak nemam NOD len Aviru, neviem ako sa tam dostala ani v spustenych ho nemam ani v prog. liste
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 03-12-2013 02
Ran by user at 2013-12-04 10:46:40 Run:1
Running from C:\Users\user\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
HKCU\...\Run: [Facebook Update] - C:\Users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-10-16] (Facebook Inc.)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18678376 2013-04-19] (Skype Technologies S.A.)
MountPoints2: {ba6b132a-0f92-11e0-acb6-1c4bd61be8be} - F:\.autorun\autorun.exe
HKLM-x32\...\Run: [RemoteControl9] - C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe [87336 2009-07-06] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateLBPShortCut] - C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] - C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Photosmart 5510 series.lnk

SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL =
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
BHO-x32: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
Toolbar: HKLM-x32 - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File

R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-10-23] (APN LLC.)
U3 tmlwf;
U3 tmwfp;

2013-12-01 19:23 - 2013-12-01 19:23 - 00000000 ____D C:\ProgramData\HitmanPro
C:\Program Files (x86)\AskPartnerNetwork
2013-12-02 20:09 - 2013-12-02 20:09 - 00015327 _____ C:\Users\user\Desktop\LM.bat
2013-12-02 20:09 - 2013-12-02 20:08 - 00029696 _____ C:\Users\user\AppData\Local\MSGBOX.EXE
2013-12-02 20:08 - 2013-12-02 20:09 - 00112640 _____ C:\Users\user\Desktop\FRSTLauncher.exe
2013-12-02 20:08 - 2013-12-02 20:08 - 00112640 _____ C:\Users\user\Downloads\FRSTLauncher.exe
2013-12-02 20:08 - 2013-12-02 20:07 - 01959184 _____ (Farbar) C:\Users\user\Downloads\FRST64.exe
C:\Users\user\AppData\Local\Temp\Quarantine.exe
C:\Users\user\SkypeSetup.exe

REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer" /f

Hosts:
CMD: shutdown /r /f /t 2

End
*****************

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Facebook Update => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Skype => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ba6b132a-0f92-11e0-acb6-1c4bd61be8be} => Key deleted successfully.
HKCR\CLSID\{ba6b132a-0f92-11e0-acb6-1c4bd61be8be} => Key not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\RemoteControl9 => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\UpdateLBPShortCut => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\UpdateP2GoShortCut => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk => Moved successfully.
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Photosmart 5510 series.lnk => Moved successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => Key deleted successfully.
HKCR\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully.
HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7} => Key deleted successfully.
HKCR\CLSID\{41564952-412D-5637-00A7-7A786E7484D7} => Key deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{41564952-412D-5637-00A7-7A786E7484D7} => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{41564952-412D-5637-00A7-7A786E7484D7} => Value deleted successfully.
HKCR\CLSID\{41564952-412D-5637-00A7-7A786E7484D7} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{41564952-412D-5637-00A7-7A786E7484D7} => Value deleted successfully.
HKCR\Wow6432Node\CLSID\{41564952-412D-5637-00A7-7A786E7484D7} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Value deleted successfully.
HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Key not found.
HKCR\PROTOCOLS\Filter\text/xml => Key deleted successfully.
HKCR\CLSID\{807553E5-5146-11D5-A672-00B0D022E945} => Key not found.
APNMCP => Service deleted successfully.
tmlwf => Service deleted successfully.
tmwfp => Service deleted successfully.
C:\ProgramData\HitmanPro => Moved successfully.
C:\Program Files (x86)\AskPartnerNetwork => Moved successfully.
"C:\Users\user\Desktop\LM.bat" => File/Directory not found.
C:\Users\user\AppData\Local\MSGBOX.EXE => Moved successfully.
"C:\Users\user\Desktop\FRSTLauncher.exe" => File/Directory not found.
"C:\Users\user\Downloads\FRSTLauncher.exe" => File/Directory not found.
C:\Users\user\Downloads\FRST64.exe => Moved successfully.
C:\Users\user\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\user\SkypeSetup.exe => Moved successfully.

========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========

"C:\Windows\System32\Drivers\etc\hosts" => Could not move.
Could not reset Hosts.

========= shutdown /r /f /t 2 =========


========= End of CMD: =========



The system needs a manual reboot.

==== End of Fixlog ====

Dakujem Vam velmi pekne :)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: virus policia SR

#10 Příspěvek od vyosek »

Tak jeste jeden fixlist, postup stejny

Kód: Vybrat vše

Start
U3 a82suxqo; C:\Windows\System32\Drivers\a82suxqo.sys [0 ] (Microsoft Corporation)
U3 tmlwf;
U3 tmwfp;

2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Roaming\ESET
2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Local\ESET
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\ProgramData\ESET
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\Program Files\ESET
End
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

likes
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 01 pro 2013 18:42

Re: virus policia SR

#11 Příspěvek od likes »

Dakujem spravil som to :) nech sa paci log :
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 03-12-2013 02
Ran by user at 2013-12-05 13:02:57 Run:2
Running from C:\Users\user\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
U3 a82suxqo; C:\Windows\System32\Drivers\a82suxqo.sys [0 ] (Microsoft Corporation)
U3 tmlwf;
U3 tmwfp;

2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Roaming\ESET
2013-12-01 18:48 - 2013-12-01 18:48 - 00000000 ____D C:\Users\user\AppData\Local\ESET
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\ProgramData\ESET
2013-12-01 18:43 - 2013-12-01 18:43 - 00000000 ____D C:\Program Files\ESET
End
*****************

a82suxqo => Service not found.
tmlwf => Service deleted successfully.
tmwfp => Service deleted successfully.
C:\Users\user\AppData\Roaming\ESET => Moved successfully.
C:\Users\user\AppData\Local\ESET => Moved successfully.
C:\ProgramData\ESET => Moved successfully.
C:\Program Files\ESET => Moved successfully.

==== End of Fixlog ====

Vieme sa prosim Vas este raz pozriet nejak, ci je uplne vonku ten virus? dakujem velmi pekne :)
toto je najnovsi log v terajsom aktualnom stave, neviem ci pomoze :
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-12-2013 02
Ran by user (administrator) on USER-NB on 05-12-2013 13:05:13
Running from C:\Users\user\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(ATK) C:\Program Files\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
(ATK) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(The Eraser Project) C:\Program Files\Eraser\Eraser.exe
(syncables, LLC) C:\Program Files (x86)\syncables\syncables desktop\syncables.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Sun Microsystems, Inc.) C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Boingo Wireless, Inc.) C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
() C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(asus) C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Farbar) C:\Users\user\Desktop\FRST64(1).exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [649608 2010-04-13] (ELAN Microelectronic Corp.)
HKLM\...\Run: [ASUS WebStorage] - C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe
HKLM\...\Run: [Setwallpaper] - c:\programdata\SetWallpaper.cmd
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [Eraser] - C:\Program Files\Eraser\Eraser.exe [980920 2012-05-22] (The Eraser Project)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [Syncables] - C:\Program Files (x86)\syncables\syncables desktop\syncables.exe [370480 2010-04-05] (syncables, LLC)
HKLM-x32\...\Run: [Boingo Wi-Fi] - C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk [2429 2010-10-15] ()
HKLM-x32\...\Run: [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [7350912 2010-02-04] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-01-05] (ASUS)
HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1597440 2010-07-02] ()
HKLM-x32\...\Run: [SessionLogon] - C:\ExpressGateUtil\SessionLogon.exe
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-04] (Avira Operations GmbH & Co. KG)
HKU\UpdatusUser\...\Run: [swg] - "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
AppInit_DLLs: C:\Windows\System32\nvinitx.dll [239720 2011-05-21] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [200808 2011-05-21] (NVIDIA Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\m6guis4w.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_149.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.11.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.11.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8051.1204 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\user\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\atlas-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\azet-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\dunaj-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slovnik-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\zoznam-sk.xml

==================== Services (Whitelisted) =================

S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2013-01-10] (Adobe Systems)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [66872 2011-03-26] ()
R3 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2010-04-06] ()

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-08-11] (Avira Operations GmbH & Co. KG)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-12-24] ()
U3 a3995hj6; C:\Windows\System32\Drivers\a3995hj6.sys [0 ] (Microsoft Corporation)
U4 a82suxqo;
U4 APNMCP;
U4 tmlwf;
U4 tmwfp;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-12-05 13:05 - 2013-12-05 13:05 - 00012477 _____ C:\Users\user\Desktop\FRST.txt
2013-12-05 13:01 - 2013-12-05 13:01 - 00000000 ____D C:\Users\user\Desktop\topographical anatomy of H+N for dentistry students
2013-12-05 13:00 - 2013-12-05 13:00 - 105576360 _____ C:\Windows\SysWOW64\⋽ЩŸ
2013-12-04 10:15 - 2013-12-04 10:10 - 01959614 _____ (Farbar) C:\Users\user\Desktop\FRST64(1).exe
2013-12-04 10:10 - 2013-12-04 10:10 - 01959614 _____ (Farbar) C:\Users\user\Downloads\FRST64(1).exe
2013-12-03 19:49 - 2013-12-03 19:49 - 09273864 _____ C:\Users\user\Downloads\Dentálne materiály 7.11.2013, cast.rar
2013-12-01 21:29 - 2013-12-01 21:31 - 00000000 ____D C:\AdwCleaner
2013-12-01 21:19 - 2013-12-01 21:19 - 00000000 ____D C:\Windows\ERUNT
2013-12-01 21:17 - 2013-12-01 21:17 - 01110034 _____ C:\Users\user\Downloads\adwcleaner.exe
2013-12-01 21:17 - 2013-12-01 21:17 - 01034531 _____ (Thisisu) C:\Users\user\Downloads\JRT.exe
2013-12-01 18:50 - 2013-12-04 10:46 - 00000000 ____D C:\FRST
2013-12-01 18:21 - 2013-12-02 04:39 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\Users\user\AppData\Roaming\Malwarebytes
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-24 22:41 - 2013-11-24 22:41 - 105952601 _____ C:\Windows\SysWOW64\驧笌¡
2013-11-20 18:45 - 2013-11-20 18:45 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud(1).pps
2013-11-19 23:07 - 2013-11-19 23:07 - 105275480 _____ C:\Windows\SysWOW64\[䅏¡
2013-11-19 20:00 - 2013-11-19 20:01 - 00000000 ____D C:\Users\user\Desktop\DCIM30
2013-11-18 23:46 - 2013-11-18 23:46 - 105004989 _____ C:\Windows\SysWOW64\᷒齍‹
2013-11-18 20:38 - 2013-11-18 20:39 - 19696439 _____ C:\Users\user\Downloads\dentalne materialy.zip
2013-11-18 20:38 - 2013-11-18 20:38 - 05671495 _____ C:\Users\user\Downloads\dentalnie materialy zivice a plasty.rar
2013-11-18 20:38 - 2013-11-18 20:38 - 05092838 _____ C:\Users\user\Downloads\Dentalne materialy.rar
2013-11-18 20:37 - 2013-11-18 20:37 - 05165110 _____ C:\Users\user\Downloads\Nový priečinok.rar
2013-11-18 20:36 - 2013-11-18 20:36 - 06878569 _____ C:\Users\user\Downloads\dentelne_materialy.rar
2013-11-17 22:47 - 2013-11-17 22:47 - 104760117 _____ C:\Windows\SysWOW64\束Ⓠ£
2013-11-17 17:10 - 2013-11-17 17:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-14 23:52 - 2013-11-14 23:52 - 00000000 ____D C:\Users\user\Desktop\kluc_A
2013-11-14 22:28 - 2013-11-14 23:43 - 00000000 ____D C:\Users\user\Desktop\histology_2year
2013-11-14 21:57 - 2013-11-14 21:57 - 104278918 _____ C:\Windows\SysWOW64\죠䡽ª
2013-11-12 22:04 - 2013-11-12 22:04 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud.pps
2013-11-11 22:22 - 2013-11-11 22:25 - 19341362 _____ C:\Users\user\Downloads\3(1).rar
2013-11-11 22:22 - 2013-11-11 22:25 - 17717501 _____ C:\Users\user\Downloads\1.rar
2013-11-11 22:22 - 2013-11-11 22:25 - 14875731 _____ C:\Users\user\Downloads\2.rar
2013-11-11 21:56 - 2013-11-11 21:56 - 19341362 _____ C:\Users\user\Downloads\3.rar
2013-11-11 19:07 - 2013-11-11 19:07 - 00000000 ____D C:\Users\user\Desktop\DCIM20
2013-11-11 17:55 - 2013-11-11 17:55 - 103792856 _____ C:\Windows\SysWOW64\ᨡ锓”
2013-11-10 23:00 - 2013-11-10 23:00 - 103551423 _____ C:\Windows\SysWOW64\⑴篷“
2013-11-10 22:21 - 2013-11-10 22:21 - 00000000 ____D C:\Users\user\Downloads\dent_mat_otazky
2013-11-10 22:20 - 2013-11-10 22:20 - 04042707 _____ C:\Users\user\Downloads\dent_Mat.zip
2013-11-06 11:18 - 2013-11-06 11:18 - 102722523 _____ C:\Windows\SysWOW64\䖩ఄ«
2013-11-05 18:19 - 2013-11-05 18:19 - 105048247 _____ C:\Windows\SysWOW64\榠︚N

==================== One Month Modified Files and Folders =======

2013-12-05 13:05 - 2013-12-05 13:05 - 00012477 _____ C:\Users\user\Desktop\FRST.txt
2013-12-05 13:05 - 2009-07-14 05:45 - 00010240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-05 13:05 - 2009-07-14 05:45 - 00010240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-05 13:01 - 2013-12-05 13:01 - 00000000 ____D C:\Users\user\Desktop\topographical anatomy of H+N for dentistry students
2013-12-05 13:00 - 2013-12-05 13:00 - 105576360 _____ C:\Windows\SysWOW64\⋽ЩŸ
2013-12-05 12:56 - 2011-11-08 09:26 - 00000928 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-05 12:56 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-05 12:56 - 2009-07-14 05:51 - 00077926 _____ C:\Windows\setupact.log
2013-12-05 08:32 - 2010-10-15 19:16 - 01699707 _____ C:\Windows\WindowsUpdate.log
2013-12-05 08:17 - 2011-11-08 09:26 - 00000932 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-04 23:43 - 2012-10-16 19:38 - 00000924 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1241329632-66754793-2357093618-1002UA.job
2013-12-04 22:42 - 2011-01-08 13:40 - 00000000 ____D C:\Users\user\AppData\Roaming\Skype
2013-12-04 20:43 - 2012-10-16 19:38 - 00000902 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1241329632-66754793-2357093618-1002Core.job
2013-12-04 10:46 - 2013-12-01 18:50 - 00000000 ____D C:\FRST
2013-12-04 10:46 - 2010-12-22 17:53 - 00000000 ___RD C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-12-04 10:10 - 2013-12-04 10:15 - 01959614 _____ (Farbar) C:\Users\user\Desktop\FRST64(1).exe
2013-12-04 10:10 - 2013-12-04 10:10 - 01959614 _____ (Farbar) C:\Users\user\Downloads\FRST64(1).exe
2013-12-04 00:52 - 2011-11-17 12:10 - 00000000 ____D C:\Users\user\AppData\Roaming\SoftGrid Client
2013-12-03 19:49 - 2013-12-03 19:49 - 09273864 _____ C:\Users\user\Downloads\Dentálne materiály 7.11.2013, cast.rar
2013-12-03 19:03 - 2012-12-13 19:48 - 00000000 ____D C:\Advanced Tram Simulator 0.57b
2013-12-03 18:59 - 2009-08-03 21:00 - 00626776 _____ C:\Windows\system32\perfh005.dat
2013-12-03 18:59 - 2009-08-03 21:00 - 00125050 _____ C:\Windows\system32\perfc005.dat
2013-12-03 18:59 - 2009-07-14 06:13 - 01484558 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-02 20:05 - 2013-05-10 13:14 - 00000000 ____D C:\Users\user\AppData\Local\PokerStars
2013-12-02 04:39 - 2013-12-01 18:21 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-02 04:39 - 2010-10-15 20:14 - 00000000 ____D C:\ProgramData\P4G
2013-12-02 04:39 - 2009-07-14 08:44 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-12-02 04:39 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
2013-12-01 21:31 - 2013-12-01 21:29 - 00000000 ____D C:\AdwCleaner
2013-12-01 21:19 - 2013-12-01 21:19 - 00000000 ____D C:\Windows\ERUNT
2013-12-01 21:17 - 2013-12-01 21:17 - 01110034 _____ C:\Users\user\Downloads\adwcleaner.exe
2013-12-01 21:17 - 2013-12-01 21:17 - 01034531 _____ (Thisisu) C:\Users\user\Downloads\JRT.exe
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\Users\user\AppData\Roaming\Malwarebytes
2013-12-01 18:21 - 2013-12-01 18:21 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-28 09:51 - 2013-04-18 22:50 - 00000000 ____D C:\Users\user\AppData\Local\Eraser 6
2013-11-24 22:41 - 2013-11-24 22:41 - 105952601 _____ C:\Windows\SysWOW64\驧笌¡
2013-11-20 18:45 - 2013-11-20 18:45 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud(1).pps
2013-11-19 23:07 - 2013-11-19 23:07 - 105275480 _____ C:\Windows\SysWOW64\[䅏¡
2013-11-19 20:01 - 2013-11-19 20:00 - 00000000 ____D C:\Users\user\Desktop\DCIM30
2013-11-19 17:05 - 2012-09-26 15:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-18 23:46 - 2013-11-18 23:46 - 105004989 _____ C:\Windows\SysWOW64\᷒齍‹
2013-11-18 20:39 - 2013-11-18 20:38 - 19696439 _____ C:\Users\user\Downloads\dentalne materialy.zip
2013-11-18 20:38 - 2013-11-18 20:38 - 05671495 _____ C:\Users\user\Downloads\dentalnie materialy zivice a plasty.rar
2013-11-18 20:38 - 2013-11-18 20:38 - 05092838 _____ C:\Users\user\Downloads\Dentalne materialy.rar
2013-11-18 20:37 - 2013-11-18 20:37 - 05165110 _____ C:\Users\user\Downloads\Nový priečinok.rar
2013-11-18 20:36 - 2013-11-18 20:36 - 06878569 _____ C:\Users\user\Downloads\dentelne_materialy.rar
2013-11-17 23:37 - 2011-10-28 20:27 - 00675328 ___SH C:\Users\user\Thumbs.db
2013-11-17 22:47 - 2013-11-17 22:47 - 104760117 _____ C:\Windows\SysWOW64\束Ⓠ£
2013-11-17 17:10 - 2013-11-17 17:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-14 23:52 - 2013-11-14 23:52 - 00000000 ____D C:\Users\user\Desktop\kluc_A
2013-11-14 23:43 - 2013-11-14 22:28 - 00000000 ____D C:\Users\user\Desktop\histology_2year
2013-11-14 21:57 - 2013-11-14 21:57 - 104278918 _____ C:\Windows\SysWOW64\죠䡽ª
2013-11-12 22:04 - 2013-11-12 22:04 - 00101376 _____ C:\Users\user\Downloads\G-Senses II a III-2013-14 for stud.pps
2013-11-11 22:25 - 2013-11-11 22:22 - 19341362 _____ C:\Users\user\Downloads\3(1).rar
2013-11-11 22:25 - 2013-11-11 22:22 - 17717501 _____ C:\Users\user\Downloads\1.rar
2013-11-11 22:25 - 2013-11-11 22:22 - 14875731 _____ C:\Users\user\Downloads\2.rar
2013-11-11 21:56 - 2013-11-11 21:56 - 19341362 _____ C:\Users\user\Downloads\3.rar
2013-11-11 19:07 - 2013-11-11 19:07 - 00000000 ____D C:\Users\user\Desktop\DCIM20
2013-11-11 17:55 - 2013-11-11 17:55 - 103792856 _____ C:\Windows\SysWOW64\ᨡ锓”
2013-11-10 23:00 - 2013-11-10 23:00 - 103551423 _____ C:\Windows\SysWOW64\⑴篷“
2013-11-10 22:21 - 2013-11-10 22:21 - 00000000 ____D C:\Users\user\Downloads\dent_mat_otazky
2013-11-10 22:20 - 2013-11-10 22:20 - 04042707 _____ C:\Users\user\Downloads\dent_Mat.zip
2013-11-06 11:18 - 2013-11-06 11:18 - 102722523 _____ C:\Windows\SysWOW64\䖩ఄ«
2013-11-05 18:19 - 2013-11-05 18:19 - 105048247 _____ C:\Windows\SysWOW64\榠︚N

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-27 21:19

==================== End Of Log ============================
Dakujem Velmi pekne

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: virus policia SR

#12 Příspěvek od vyosek »

Log vypada OK, jak se chova PC??
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

likes
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 01 pro 2013 18:42

Re: virus policia SR

#13 Příspěvek od likes »

uplne normalne :) a este je aj trocha rychlejsi ako pred tým :)
Dakujem Vam velmi pekne :)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: virus policia SR

#14 Příspěvek od vyosek »

Tak jeste uklidime :James008:

:arrow: T-Cleaner http://vyosek.tym.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět