Hlášení o detekci virů

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
ravelu
Návštěvník
Návštěvník
Příspěvky: 50
Registrován: 07 Led 2014 12:04

Hlášení o detekci virů

#1 Příspěvek od ravelu »

Dobrý den,prosím Vás o kontrolu PC.Začaly mi vyskakovat okna s hlášením o detekci nějakých virů/používám avast free/ a dvakrát se mi už seklo PC.Projel jsem PC dostupným soft.,ale vyskakují stále.Děkuji za pomoc.

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Hlášení o detekci virů

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Jakym dostupnym softem jste to projizdel??

:arrow: Jelikoz nevime o Vasem PC nic a z kristalove koule se spatne vesti, navic v Brne je ted pekna mlha, tak neni nic videt :?:

:arrow: Ale dosti legracek, kouknem na to :wink: Dejte log z RSIT http://forum.viry.cz/viewtopic.php?f=24&t=130784 - navod Vas povede...
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

ravelu
Návštěvník
Návštěvník
Příspěvky: 50
Registrován: 07 Led 2014 12:04

Re: Hlášení o detekci virů

#3 Příspěvek od ravelu »

Projížděl jsem to super antispyware,NPE/vše free/.Dávam log.

Logfile of random's system information tool 1.09 (written by random/random)
Run by pc at 2014-01-07 12:33:41
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 2 GB (6%) free of 40 GB
Total RAM: 3984 MB (69% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:34:11, on 7.1.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal

Running processes:
E:\štěstí.cz\stesti.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\pc.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: štěstí.cz - hlídání vzkazů.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - E:\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - E:\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SInstalátor (ssinstall) - PS Media s.r.o. - C:\Windows\SysWOW64\ssins.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VIA Karaoke digital mixer Service (VIAKaraokeService) - Unknown owner - C:\Windows\system32\viakaraokesrv.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9176 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"E:\Malwarebytes' Anti-Malware\mbamscheduler.exe"
"taskhost.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe"
C:\Windows\System32\svchost.exe -k HPZ12
"C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe"
C:\Windows\System32\svchost.exe -k HPZ12
"C:\Windows\system32\Dwm.exe"
C:\Windows\SysWOW64\ssins.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\viakaraokesrv.exe
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"E:\štěstí.cz\stesti.exe"
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_00000674
"C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\PANDORA.TV\PanService\KMPProcess.exe" KMPProcess
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"C:\Users\pc\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
taskeng.exe {BE094436-39B8-43AA-B40A-DEF53F33EB45}
C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\gwrsyf2z.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "www.seznam.cz"
prefs.js - "keyword.URL" - "http://search.yahoo.com/search?fr=green ... =198484&p="

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@VideoDownloadConverter_4z.com/Plugin]
"Description"=VideoDownloadConverter Plugin
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@VideoDownloadConverter_ScriptHelper.com/Plugin]
"Description"=VideoDownloadConverter_ScriptHelper Plugin
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.0]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled


C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\gwrsyf2z.default\extensions\
savingsslider@mybrowserbar.com
{58d2a791-6199-482f-a9aa-9b725ec61362}
{ea614400-e918-4741-9a97-7a972ff7c30b}

C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\gwrsyf2z.default\searchplugins\
conduit-search.xml
yahoo_ff.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-18 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-18 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2012-12-14 172144]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2012-12-14 399984]
"Persistence"=C:\Windows\system32\igfxpers.exe [2012-12-14 441968]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 7]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck]
C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2012-08-09 5263504]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kalendar]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorShield]
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdater]
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2013-12-20 6563096]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tsiVideo]
C:\Windows\SysWOW64\rundll32.exe [2009-07-14 44544]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Secunia PSI Tray.lnk]
C:\PROGRA~2\Secunia\PSI\psi_tray.exe []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2012-05-20 291648]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2013-12-17 684600]

C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
štěstí.cz - hlídání vzkazů.lnk - E:\štěstí.cz\stesti.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2012-12-14 442880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoInstrumentation"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-01-07 12:33:41 ----D---- C:\rsit
2014-01-07 10:04:56 ----A---- C:\Windows\ntbtlog.txt
2014-01-06 19:05:13 ----A---- C:\Windows\system32\SafeIPs64.dll
2014-01-06 19:05:11 ----A---- C:\Windows\SYSWOW64\SafeIPs.dll
2014-01-06 18:07:23 ----A---- C:\Windows\system32\drivers\mbam.sys
2014-01-05 18:09:04 ----A---- C:\Windows\SYSWOW64\xvidvfw.dll
2014-01-05 18:09:04 ----A---- C:\Windows\SYSWOW64\xvidcore.dll
2014-01-05 16:30:45 ----D---- C:\Users\pc\AppData\Roaming\DVDVideoSoft
2014-01-05 15:26:32 ----D---- C:\ProgramData\Movavi
2014-01-05 14:41:35 ----D---- C:\Users\pc\AppData\Roaming\FreeMoviesToDVD
2014-01-05 14:41:14 ----A---- C:\Windows\SYSWOW64\viscomdvdimg.dll
2014-01-05 14:41:14 ----A---- C:\Windows\SYSWOW64\VB6STKIT.DLL
2014-01-05 14:41:14 ----A---- C:\Windows\SYSWOW64\inetfr.DLL
2014-01-05 14:41:13 ----A---- C:\Windows\SYSWOW64\VB6FR.DLL
2014-01-05 14:41:13 ----A---- C:\Windows\SYSWOW64\MSCMCFR.DLL
2014-01-05 14:41:13 ----A---- C:\Windows\SYSWOW64\CMDLGFR.DLL
2014-01-05 14:40:44 ----D---- C:\Program Files (x86)\Free Videos To DVD
2014-01-04 19:16:16 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2014-01-04 19:16:16 ----D---- C:\Program Files\SUPERAntiSpyware
2014-01-03 17:38:30 ----D---- C:\ProgramData\AskPartnerNetwork
2014-01-02 15:56:40 ----D---- C:\ProgramData\Doctor Web
2013-12-23 13:25:07 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-12-23 12:31:04 ----D---- C:\Users\pc\AppData\Roaming\Apple Computer
2013-12-23 12:31:01 ----D---- C:\ProgramData\ProductData
2013-12-23 12:30:45 ----D---- C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2013-12-23 12:30:40 ----D---- C:\ProgramData\IObit
2013-12-23 12:29:19 ----D---- C:\Users\pc\AppData\Roaming\IObit
2013-12-15 19:27:17 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-12-15 19:27:17 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-12-15 19:27:17 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2013-12-15 19:27:17 ----A---- C:\Windows\system32\drivers\TsUsbGD.sys
2013-12-15 19:27:17 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2013-12-15 19:27:17 ----A---- C:\Windows\system32\drivers\rdpvideominiport.sys
2013-12-15 19:27:16 ----A---- C:\Windows\SYSWOW64\wksprtPS.dll
2013-12-15 19:27:16 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2013-12-15 19:27:16 ----A---- C:\Windows\SYSWOW64\rdpendp_winip.dll
2013-12-15 19:27:16 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2013-12-15 19:27:16 ----A---- C:\Windows\SYSWOW64\MsRdpWebAccess.dll
2013-12-15 19:27:16 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2013-12-15 19:27:16 ----A---- C:\Windows\system32\wksprtPS.dll
2013-12-15 19:27:16 ----A---- C:\Windows\system32\wksprt.exe
2013-12-15 19:27:16 ----A---- C:\Windows\system32\TSWbPrxy.exe
2013-12-15 19:27:16 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-12-15 19:27:16 ----A---- C:\Windows\system32\tsgqec.dll
2013-12-15 19:27:16 ----A---- C:\Windows\system32\rdpudd.dll
2013-12-15 19:27:16 ----A---- C:\Windows\system32\rdpendp_winip.dll
2013-12-15 19:27:16 ----A---- C:\Windows\system32\rdpcorets.dll
2013-12-15 19:27:16 ----A---- C:\Windows\system32\mstsc.exe
2013-12-15 19:27:16 ----A---- C:\Windows\system32\MsRdpWebAccess.dll
2013-12-15 19:27:16 ----A---- C:\Windows\system32\aaclient.dll
2013-12-15 19:27:15 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2013-12-15 19:27:15 ----A---- C:\Windows\system32\mstscax.dll
2013-12-15 18:59:33 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2013-12-15 18:59:33 ----A---- C:\Windows\system32\qdvd.dll
2013-12-12 14:28:45 ----A---- C:\Users\pc\AppData\Roaming\verzia.ini
2013-12-12 14:23:27 ----D---- C:\Program Files\Microsoft Synchronization Services
2013-12-12 14:23:27 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2013-12-12 14:23:18 ----D---- C:\Program Files (x86)\Microsoft Synchronization Services
2013-12-12 14:23:18 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2013-12-12 14:13:11 ----D---- C:\Program Files\CCleaner
2013-12-12 13:45:08 ----D---- C:\Users\pc\AppData\Roaming\Smart PC Solutions
2013-12-12 03:03:11 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2013-12-12 03:03:11 ----A---- C:\Windows\system32\wmploc.DLL
2013-12-12 03:03:10 ----A---- C:\Windows\SYSWOW64\wmp.dll
2013-12-12 03:03:10 ----A---- C:\Windows\system32\wmp.dll
2013-12-12 03:01:40 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-12-12 03:01:40 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-12-12 03:01:40 ----A---- C:\Windows\system32\jsproxy.dll
2013-12-12 03:01:40 ----A---- C:\Windows\system32\ieUnatt.exe
2013-12-12 03:01:40 ----A---- C:\Windows\system32\ieui.dll
2013-12-12 03:01:40 ----A---- C:\Windows\system32\iesetup.dll
2013-12-12 03:01:40 ----A---- C:\Windows\system32\iernonce.dll
2013-12-12 03:01:40 ----A---- C:\Windows\system32\ieetwproxystub.dll
2013-12-12 03:01:40 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2013-12-12 03:01:40 ----A---- C:\Windows\system32\ieetwcollector.exe
2013-12-12 03:01:40 ----A---- C:\Windows\system32\ie4uinit.exe
2013-12-12 03:01:39 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2013-12-12 03:01:39 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2013-12-12 03:01:39 ----A---- C:\Windows\system32\mshtml.dll
2013-12-12 03:01:39 ----A---- C:\Windows\system32\jscript9diag.dll
2013-12-12 03:01:39 ----A---- C:\Windows\system32\iertutil.dll
2013-12-12 03:01:39 ----A---- C:\Windows\system32\ieapfltr.dll
2013-12-12 03:01:38 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-12-12 03:01:38 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-12-12 03:01:38 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-12-12 03:01:38 ----A---- C:\Windows\system32\wininet.dll
2013-12-12 03:01:38 ----A---- C:\Windows\system32\urlmon.dll
2013-12-12 03:01:38 ----A---- C:\Windows\system32\ieframe.dll
2013-12-12 03:01:37 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-12-12 03:01:37 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-12-12 03:01:36 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-12-12 03:01:36 ----A---- C:\Windows\system32\jscript9.dll
2013-12-11 08:33:28 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2013-12-11 08:33:28 ----A---- C:\Windows\system32\msieftp.dll
2013-12-11 08:33:27 ----A---- C:\Windows\system32\win32k.sys
2013-12-11 08:33:23 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2013-12-11 08:33:23 ----A---- C:\Windows\system32\WMPhoto.dll
2013-12-11 08:33:19 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2013-12-11 08:33:19 ----A---- C:\Windows\system32\imagehlp.dll
2013-12-11 08:33:15 ----A---- C:\Windows\SYSWOW64\tzres.dll
2013-12-11 08:33:15 ----A---- C:\Windows\system32\tzres.dll
2013-12-11 08:33:12 ----A---- C:\Windows\system32\drivers\portcls.sys
2013-12-11 08:33:12 ----A---- C:\Windows\system32\drivers\drmk.sys
2013-12-11 08:33:11 ----A---- C:\Windows\SYSWOW64\wscript.exe
2013-12-11 08:33:11 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2013-12-11 08:33:11 ----A---- C:\Windows\SYSWOW64\cscript.exe
2013-12-11 08:33:11 ----A---- C:\Windows\system32\wscript.exe
2013-12-11 08:33:11 ----A---- C:\Windows\system32\scrrun.dll
2013-12-11 08:33:11 ----A---- C:\Windows\system32\cscript.exe
2013-12-10 20:12:04 ----A---- C:\Windows\system32\IEUDINIT.EXE
2013-12-10 20:09:06 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2013-12-10 20:09:06 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-10 20:09:01 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-12-10 20:09:01 ----A---- C:\Windows\SYSWOW64\msls31.dll
2013-12-10 20:09:01 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2013-12-10 20:09:01 ----A---- C:\Windows\system32\elshyph.dll
2013-12-10 20:09:00 ----A---- C:\Windows\SYSWOW64\wextract.exe
2013-12-10 20:09:00 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2013-12-10 20:09:00 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-12-10 20:09:00 ----A---- C:\Windows\SYSWOW64\url.dll
2013-12-10 20:09:00 ----A---- C:\Windows\SYSWOW64\msrating.dll
2013-12-10 20:09:00 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2013-12-10 20:09:00 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-12-10 20:09:00 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-12-10 20:09:00 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2013-12-10 20:09:00 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2013-12-10 20:09:00 ----A---- C:\Windows\SYSWOW64\inseng.dll
2013-12-10 20:09:00 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2013-12-10 20:09:00 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-12-10 20:09:00 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-12-10 20:09:00 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2013-12-10 20:09:00 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2013-12-10 20:09:00 ----A---- C:\Windows\SYSWOW64\icardie.dll
2013-12-10 20:09:00 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2013-12-10 20:09:00 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2013-12-10 20:08:59 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2013-12-10 20:08:59 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2013-12-10 20:08:59 ----A---- C:\Windows\SYSWOW64\occache.dll
2013-12-10 20:08:59 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2013-12-10 20:08:59 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2013-12-10 20:08:59 ----A---- C:\Windows\SYSWOW64\mshta.exe
2013-12-10 20:08:59 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2013-12-10 20:08:59 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2013-12-10 20:08:59 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-12-10 20:08:59 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2013-12-10 20:08:59 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-12-10 20:08:59 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-12-10 20:08:59 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2013-12-10 20:08:59 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2013-12-10 20:08:59 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2013-12-10 20:08:59 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-12-10 20:08:59 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-10 20:08:59 ----A---- C:\Windows\system32\msrating.dll
2013-12-10 20:08:59 ----A---- C:\Windows\system32\msls31.dll
2013-12-10 20:08:59 ----A---- C:\Windows\system32\mshtmler.dll
2013-12-10 20:08:59 ----A---- C:\Windows\system32\msfeedssync.exe
2013-12-10 20:08:59 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-12-10 20:08:59 ----A---- C:\Windows\system32\jsIntl.dll
2013-12-10 20:08:59 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-10 20:08:59 ----A---- C:\Windows\system32\iesysprep.dll
2013-12-10 20:08:59 ----A---- C:\Windows\system32\ieapfltr.dat
2013-12-10 20:08:59 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-12-10 20:08:59 ----A---- C:\Windows\system32\icardie.dll
2013-12-10 20:08:59 ----A---- C:\Windows\system32\dxtrans.dll
2013-12-10 20:08:59 ----A---- C:\Windows\system32\dxtmsft.dll
2013-12-10 20:08:58 ----A---- C:\Windows\system32\wextract.exe
2013-12-10 20:08:58 ----A---- C:\Windows\system32\webcheck.dll
2013-12-10 20:08:58 ----A---- C:\Windows\system32\vbscript.dll
2013-12-10 20:08:58 ----A---- C:\Windows\system32\url.dll
2013-12-10 20:08:58 ----A---- C:\Windows\system32\pngfilt.dll
2013-12-10 20:08:58 ----A---- C:\Windows\system32\occache.dll
2013-12-10 20:08:58 ----A---- C:\Windows\system32\mshtmlmedia.dll
2013-12-10 20:08:58 ----A---- C:\Windows\system32\mshtmled.dll
2013-12-10 20:08:58 ----A---- C:\Windows\system32\MshtmlDac.dll
2013-12-10 20:08:58 ----A---- C:\Windows\system32\mshta.exe
2013-12-10 20:08:58 ----A---- C:\Windows\system32\msfeeds.dll
2013-12-10 20:08:58 ----A---- C:\Windows\system32\licmgr10.dll
2013-12-10 20:08:58 ----A---- C:\Windows\system32\jscript.dll
2013-12-10 20:08:58 ----A---- C:\Windows\system32\inseng.dll
2013-12-10 20:08:58 ----A---- C:\Windows\system32\imgutil.dll
2013-12-10 20:08:58 ----A---- C:\Windows\system32\iexpress.exe
2013-12-10 20:08:58 ----A---- C:\Windows\system32\iepeers.dll
2013-12-10 20:08:58 ----A---- C:\Windows\system32\iedkcs32.dll
2013-12-10 11:37:52 ----SHD---- C:\AI_RecycleBin
2013-12-10 11:13:34 ----SHD---- C:\Windows\SYSWOW64\AI_RecycleBin
2013-12-10 11:13:20 ----DC---- C:\Windows\system32\DRVSTORE
2013-12-10 11:12:18 ----D---- C:\ProgramData\Soluto
2013-12-09 11:28:53 ----D---- C:\ProgramData\WEBREG
2013-12-09 11:28:45 ----D---- C:\Users\pc\AppData\Roaming\HP
2013-12-09 11:23:28 ----HD---- C:\Config.Msi
2013-12-09 11:23:28 ----D---- C:\Program Files (x86)\HP
2013-12-09 11:21:52 ----D---- C:\Program Files\HP
2013-12-09 11:19:41 ----D---- C:\ProgramData\HP
2013-12-09 11:19:33 ----A---- C:\Windows\system32\hpzids40.dll

======List of files/folders modified in the last 1 month======

2014-01-07 12:34:10 ----D---- C:\Program Files\trend micro
2014-01-07 12:33:52 ----D---- C:\Windows\Prefetch
2014-01-07 12:33:45 ----D---- C:\Windows\Temp
2014-01-07 11:06:30 ----SHD---- C:\System Volume Information
2014-01-07 10:47:55 ----D---- C:\Windows\System32
2014-01-07 10:47:55 ----D---- C:\Windows\inf
2014-01-07 10:47:55 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-01-07 10:45:28 ----A---- C:\Windows\SYSWOW64\log.txt
2014-01-07 10:42:35 ----D---- C:\Windows
2014-01-07 09:15:46 ----D---- C:\Windows\system32\config
2014-01-06 19:12:03 ----D---- C:\Windows\SoftwareDistribution
2014-01-06 19:09:53 ----RD---- C:\Documents
2014-01-06 19:05:11 ----D---- C:\Windows\SysWOW64
2014-01-06 18:13:14 ----HD---- C:\ProgramData
2014-01-06 18:13:14 ----D---- C:\Windows\system32\drivers
2014-01-05 19:02:56 ----SD---- C:\Users\pc\AppData\Roaming\Microsoft
2014-01-05 19:00:45 ----RD---- C:\Program Files (x86)
2014-01-05 18:58:32 ----D---- C:\Program Files (x86)\Common Files
2014-01-05 17:01:06 ----RSD---- C:\Windows\assembly
2014-01-04 19:34:40 ----SHD---- C:\Windows\Installer
2014-01-04 19:26:58 ----D---- C:\ProgramData\Norton
2014-01-04 19:16:32 ----D---- C:\Windows\system32\Tasks
2014-01-04 19:16:31 ----D---- C:\Windows\Tasks
2014-01-04 19:16:16 ----RD---- C:\Program Files
2014-01-04 13:00:27 ----D---- C:\Windows\winsxs
2014-01-04 11:45:03 ----D---- C:\Program Files (x86)\vso
2014-01-04 11:44:45 ----D---- C:\Users\pc\AppData\Roaming\Vso
2014-01-04 11:44:45 ----A---- C:\Users\pc\AppData\Roaming\inst.exe
2014-01-03 18:30:40 ----D---- C:\Windows\system32\catroot2
2014-01-03 17:59:46 ----D---- C:\Program Files (x86)\MSXML 4.0
2013-12-26 12:06:11 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2013-12-23 12:48:57 ----D---- C:\Windows\debug
2013-12-23 12:35:32 ----D---- C:\Windows\Panther
2013-12-17 13:57:33 ----D---- C:\Windows\system32\catroot
2013-12-16 13:29:02 ----D---- C:\Windows\rescache
2013-12-15 19:28:44 ----D---- C:\Windows\SYSWOW64\wbem
2013-12-15 19:28:44 ----D---- C:\Windows\SYSWOW64\en-US
2013-12-15 19:28:44 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-12-15 19:28:44 ----D---- C:\Windows\system32\wbem
2013-12-15 19:28:44 ----D---- C:\Windows\system32\en-US
2013-12-15 19:28:44 ----D---- C:\Windows\system32\DriverStore
2013-12-15 19:28:44 ----D---- C:\Windows\system32\drivers\en-US
2013-12-15 19:28:44 ----D---- C:\Windows\system32\cs-CZ
2013-12-15 19:28:44 ----D---- C:\Windows\PolicyDefinitions
2013-12-15 19:26:57 ----D---- C:\Program Files (x86)\Intel
2013-12-14 20:04:26 ----D---- C:\Windows\system32\MRT
2013-12-14 20:03:27 ----A---- C:\Windows\system32\MRT.exe
2013-12-13 17:57:33 ----RD---- C:\Users
2013-12-12 14:04:20 ----AD---- C:\ProgramData\TEMP
2013-12-12 03:18:49 ----D---- C:\Program Files\Windows Media Player
2013-12-12 03:18:49 ----D---- C:\Program Files (x86)\Windows Media Player
2013-12-12 03:18:48 ----D---- C:\Program Files\Internet Explorer
2013-12-12 03:18:48 ----D---- C:\Program Files (x86)\Internet Explorer
2013-12-11 15:09:44 ----D---- C:\Windows\system32\NDF
2013-12-11 12:08:30 ----D---- C:\Windows\Logs
2013-12-10 20:13:10 ----D---- C:\Windows\SYSWOW64\migration
2013-12-10 20:13:08 ----D---- C:\Windows\system32\migration
2013-12-10 19:24:30 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-12-10 18:06:03 ----D---- C:\Windows\Microsoft.NET
2013-12-09 12:20:18 ----D---- C:\Windows\twain_32
2013-12-09 12:19:36 ----RSD---- C:\Windows\Fonts
2013-12-09 11:40:38 ----D---- C:\Windows\pss
2013-12-09 11:28:27 ----A---- C:\Windows\win.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2012-05-20 19264]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 AppleCharger;AppleCharger; C:\Windows\system32\DRIVERS\AppleCharger.sys [2012-10-25 22680]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2013-12-17 131576]
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2013-11-25 28600]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2013-12-17 108440]
R3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athurx.sys [2012-10-18 1930240]
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver; C:\Windows\System32\Drivers\EtronHub3.sys [2012-08-07 65152]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver; C:\Windows\System32\Drivers\EtronXHCI.sys [2012-08-07 88832]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2012-12-14 5353888]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2012-06-19 342528]
R3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys [2012-05-20 357184]
R3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2012-05-20 789824]
R3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2012-07-19 110744]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2013-04-04 25928]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2012-07-02 62784]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2012-08-03 2206352]
S3 cpuz136;cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys []
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 145920]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2010-11-21 19968]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 43008]
S3 esgiguard;esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys []
S3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2013-10-29 82816]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM); C:\Windows\system32\DRIVERS\s1039bus.sys [2009-11-19 127600]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s1039mdfl.sys [2009-11-19 19568]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s1039mdm.sys [2009-11-19 161904]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s1039mgmt.sys [2009-11-19 141424]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS); C:\Windows\system32\DRIVERS\s1039nd5.sys [2009-11-19 34416]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s1039obex.sys [2009-11-19 137328]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM); C:\Windows\system32\DRIVERS\s1039unic.sys [2009-11-19 158320]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2013-10-10 144152]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-09-05 65640]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2013-11-25 440376]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2013-12-17 440376]
R2 AntiVirWebService;Avira Web Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [2013-12-17 1011768]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-04-20 635104]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-06-25 166720]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-17 277824]
R2 MBAMScheduler;MBAMScheduler; E:\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [2009-07-20 935208]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 PanService;PandoraService; C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe [2013-07-08 1922600]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ssinstall;SInstalátor; C:\Windows\SysWOW64\ssins.exe [2013-10-11 2324216]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-17 365376]
R2 VIAKaraokeService;VIA Karaoke digital mixer Service; C:\Windows\system32\viakaraokesrv.exe [2012-08-03 27792]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-01 116648]
S2 MBAMService;MBAMService; E:\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-10 257416]
S3 AppleChargerSrv;AppleChargerSrv; C:\Windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2012-12-14 277616]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-01 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2013-11-26 111616]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-26 65824]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-12-23 119408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-08-16 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Hlášení o detekci virů

#4 Příspěvek od vyosek »

Pisete, ze pouzivate Avast Free, ja v logu vidim Aviru :?:

Muzete prosim dat screen toho hlaseni o malware
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

ravelu
Návštěvník
Návštěvník
Příspěvky: 50
Registrován: 07 Led 2014 12:04

Re: Hlášení o detekci virů

#5 Příspěvek od ravelu »

Omlouvám se ,aviru.Správně.

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Hlášení o detekci virů

#6 Příspěvek od vyosek »

vyosek napsal: Muzete prosim dat screen toho hlaseni o malware
:???: :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

ravelu
Návštěvník
Návštěvník
Příspěvky: 50
Registrován: 07 Led 2014 12:04

Re: Hlášení o detekci virů

#7 Příspěvek od ravelu »

Snad je toto,co jste chtěl.
Přílohy
22.gif
22.gif (208.77 KiB) Zobrazeno 1051 x

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Hlášení o detekci virů

#8 Příspěvek od vyosek »

:arrow: Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
  • Ulozte nejlepe na plochu
  • Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
  • Probehne vytvoreni zalohy a nasledne prohledavani
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

ravelu
Návštěvník
Návštěvník
Příspěvky: 50
Registrován: 07 Led 2014 12:04

Re: Hlášení o detekci virů

#9 Příspěvek od ravelu »

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.9 (01.01.2014:1)
OS: Windows 7 Professional x64
Ran by pc on Łt 07.01.2014 at 14:12:29,50
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{CC99A798-FD3D-4AB4-969E-6071612524F9}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\ctoolbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\search settings
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC99A798-FD3D-4AB4-969E-6071612524F9}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\ctoolbar



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\Users\pc\AppData\Roaming\goforfiles"
Successfully deleted: [Folder] "C:\Users\pc\appdata\local\cool_mirage"
Successfully deleted: [Folder] "C:\Users\pc\appdata\local\swvupdater"
Successfully deleted: [Folder] "C:\Program Files (x86)\mypc backup"
Successfully deleted: [Folder] "C:\Program Files (x86)\Common Files\spigot"
Successfully deleted: [Folder] "C:\ai_recyclebin"
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"



~~~ FireFox

Successfully deleted: [File] C:\Users\pc\AppData\Roaming\mozilla\firefox\profiles\gwrsyf2z.default\user.js
Successfully deleted: [Folder] C:\Users\pc\AppData\Roaming\mozilla\firefox\profiles\gwrsyf2z.default\extensions\savingsslider@mybrowserbar.com
Emptied folder: C:\Users\pc\AppData\Roaming\mozilla\firefox\profiles\gwrsyf2z.default\minidumps [64 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Łt 07.01.2014 at 14:16:28,34
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

ravelu
Návštěvník
Návštěvník
Příspěvky: 50
Registrován: 07 Led 2014 12:04

Re: Hlášení o detekci virů

#10 Příspěvek od ravelu »

# AdwCleaner v3.016 - Report created 07/01/2014 at 14:20:45
# Updated 23/12/2013 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : pc - PC-PC
# Running from : C:\Users\pc\Desktop\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Users\pc\AppData\Local\Mobogenie
Folder Deleted : C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FTDownloader.com
Folder Deleted : C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj
Folder Deleted : C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
Folder Deleted : C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp
File Deleted : C:\Windows\System32\roboot64.exe
File Deleted : C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\gwrsyf2z.default\searchplugins\conduit-search.xml
File Deleted : C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\ighco7ac.default\user.js
File Deleted : C:\Windows\System32\Tasks\GoforFilesUpdate

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\hbcennhacfaagdopikcegfcobcadeocj
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pfndaklgolladniicklehhancnlgocpp
Key Deleted : HKCU\Software\Classes\pokki
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter.ScriptHelper
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@VideoDownloadConverter_4z.com/Plugin
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@VideoDownloadConverter_ScriptHelper.com/Plugin
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1F8EDE97-36D5-422A-B8F0-9406E2D87C60}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DCABB943-792E-44C4-9029-ECBEE6265AF9}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{FEB62B15-CC00-4736-AAEC-BA046C9DFF73}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8A4E8BCB-5598-4CAF-9DEC-4D452760E28D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A86782D8-7B41-452F-A217-1854F72DBA54}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2D6F0AC3-0C2E-4E07-8FDA-11268AB51211}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2D9083CE-8758-4704-BA57-3C891D7452BD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3D429207-4689-492D-A0E5-CDC5DFBB5005}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1F8EDE97-36D5-422A-B8F0-9406E2D87C60}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : HKCU\Software\GoforFiles
Key Deleted : HKCU\Software\WEDLMNGR
Key Deleted : HKCU\Software\AppDataLow\Software\VideoDownloadConverter_4z
Key Deleted : HKLM\Software\GoforFiles
Key Deleted : HKLM\Software\VideoDownloadConverter
Key Deleted : HKLM\Software\VideoDownloadConverter_4z

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16428


-\\ Mozilla Firefox v26.0 (cs)

[ File : C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\gwrsyf2z.default\prefs.js ]


[ File : C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\ighco7ac.default\prefs.js ]


-\\ Google Chrome v31.0.1650.63

[ File : C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R1].txt - [4547 octets] - [07/01/2014 14:20:23]
AdwCleaner[S1].txt - [4341 octets] - [07/01/2014 14:20:45]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [4401 octets] ##########

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Hlášení o detekci virů

#11 Příspěvek od vyosek »

Poprosim o log dle tohoto navodu http://forum.viry.cz/viewtopic.php?f=13&t=133100
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

ravelu
Návštěvník
Návštěvník
Příspěvky: 50
Registrován: 07 Led 2014 12:04

Re: Hlášení o detekci virů

#12 Příspěvek od ravelu »

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-01-2014
Ran by pc (administrator) on PC-PC on 07-01-2014 17:45:59
Running from C:\Users\pc\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) E:\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(Pandora.TV) C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe
(PS Media s.r.o.) C:\Windows\SysWOW64\ssins.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Zásobování a.s.) E:\štěstí.cz\stesti.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
(PandoraTV) C:\Program Files (x86)\PANDORA.TV\PanService\KMPProcess.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\pc\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ==================

HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-17] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Policies\Explorer: [NoInstrumentation] 0
Startup: C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\štěstí.cz - hlídání vzkazů.lnk
ShortcutTarget: štěstí.cz - hlídání vzkazů.lnk -> E:\štěstí.cz\stesti.exe (Zásobování a.s.)

==================== Internet (Whitelisted) ====================

SearchScopes: HKCU - {D9ADE083-3C5E-4436-A7CA-38DB45A6872A} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\gwrsyf2z.default
FF Homepage: www.seznam.cz
FF Keyword.URL: hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=198484&p=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\gwrsyf2z.default\searchplugins\yahoo_ff.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Start Page - C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\gwrsyf2z.default\Extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}
FF Extension: Seznam lištička - C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\gwrsyf2z.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}

Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/?clid=14875
CHR Extension: (Google Docs) - C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (Seznam Li\u0161ti\u010Dka - Email) - C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig\1.3.13_1
CHR Extension: (Seznam Li\u0161ti\u010Dka - Slovn\u00EDk) - C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd\1.2.13_1
CHR Extension: (YouTube) - C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Google Wallet) - C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0
CHR Extension: (Seznam Li\u0161ti\u010Dka - Rychl\u00E1 volba) - C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak\1.5.14_1
CHR Extension: (Gmail) - C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1

==================== Services (Whitelisted) =================

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [144152 2013-10-10] (SUPERAntiSpyware.com)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-25] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1011768 2013-12-17] (Avira Operations GmbH & Co. KG)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MBAMScheduler; E:\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; E:\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe [1922600 2013-07-08] (Pandora.TV)
R2 ssinstall; C:\Windows\SysWOW64\ssins.exe [2324216 2013-10-11] (PS Media s.r.o.)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27792 2012-08-03] (VIA Technologies, Inc.)

==================== Drivers (Whitelisted) ====================

R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22680 2012-10-25] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-25] (Avira Operations GmbH & Co. KG)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [110744 2012-07-19] (Qualcomm Atheros Co., Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S3 s1039bus; C:\Windows\System32\DRIVERS\s1039bus.sys [127600 2009-11-19] (MCCI Corporation)
S3 s1039mdfl; C:\Windows\System32\DRIVERS\s1039mdfl.sys [19568 2009-11-19] (MCCI Corporation)
S3 s1039mdm; C:\Windows\System32\DRIVERS\s1039mdm.sys [161904 2009-11-19] (MCCI Corporation)
S3 s1039mgmt; C:\Windows\System32\DRIVERS\s1039mgmt.sys [141424 2009-11-19] (MCCI Corporation)
S3 s1039nd5; C:\Windows\System32\DRIVERS\s1039nd5.sys [34416 2009-11-19] (MCCI Corporation)
S3 s1039obex; C:\Windows\System32\DRIVERS\s1039obex.sys [137328 2009-11-19] (MCCI Corporation)
S3 s1039unic; C:\Windows\System32\DRIVERS\s1039unic.sys [158320 2009-11-19] (MCCI Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [x]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
U5 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [42856 2010-11-21] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-07 17:45 - 2014-01-07 17:46 - 00011517 _____ C:\Users\pc\Desktop\FRST.txt
2014-01-07 17:45 - 2014-01-07 17:45 - 00000000 ____D C:\FRST
2014-01-07 17:43 - 2014-01-07 17:43 - 00112640 _____ (forum.viry.cz) C:\Users\pc\Desktop\FRSTLauncher.exe
2014-01-07 17:42 - 2014-01-07 17:42 - 01931762 _____ (Farbar) C:\Users\pc\Desktop\FRST64.exe
2014-01-07 14:20 - 2014-01-07 14:20 - 00000000 ____D C:\AdwCleaner
2014-01-07 12:33 - 2014-01-07 12:34 - 00000000 ____D C:\rsit
2014-01-07 10:42 - 2014-01-07 14:21 - 00000112 _____ C:\Windows\setupact.log
2014-01-07 10:42 - 2014-01-07 10:42 - 00000000 _____ C:\Windows\setuperr.log
2014-01-06 19:11 - 2014-01-07 16:32 - 00064475 _____ C:\Windows\WindowsUpdate.log
2014-01-06 19:05 - 2013-02-10 19:49 - 00540864 _____ (SafeIP) C:\Windows\system32\SafeIPs64.dll
2014-01-06 19:05 - 2013-02-10 19:49 - 00380608 _____ (SafeIP) C:\Windows\SysWOW64\SafeIPs.dll
2014-01-06 18:07 - 2014-01-06 18:07 - 00000624 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-06 18:07 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-05 18:09 - 2009-09-29 20:57 - 00758018 _____ C:\Windows\SysWOW64\xvidcore.dll
2014-01-05 18:09 - 2008-12-04 21:46 - 00180224 _____ C:\Windows\SysWOW64\xvidvfw.dll
2014-01-05 18:09 - 2008-10-08 10:16 - 00139264 _____ (http://www.xvid.org) C:\Windows\SysWOW64\xvid.ax
2014-01-05 16:30 - 2014-01-05 17:01 - 00000000 ____D C:\Users\pc\AppData\Roaming\DVDVideoSoft
2014-01-05 15:26 - 2014-01-05 15:26 - 00000000 ____D C:\Users\pc\AppData\Local\Movavi
2014-01-05 14:41 - 2014-01-05 18:19 - 00000000 ____D C:\Users\pc\AppData\Roaming\FreeMoviesToDVD
2014-01-05 14:41 - 2014-01-05 14:41 - 00001138 _____ C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free Videos To DVD.lnk
2014-01-05 14:41 - 2014-01-05 14:41 - 00001092 _____ C:\Users\pc\Desktop\Free Videos To DVD.lnk
2014-01-05 14:41 - 2009-01-23 21:21 - 00327680 _____ (Viscom Software www.viscomsoft.com) C:\Windows\SysWOW64\dvdauthor.ocx
2014-01-05 14:41 - 2009-01-23 21:21 - 00000401 _____ C:\Windows\SysWOW64\dvdauthor.lic
2014-01-05 14:41 - 2009-01-23 21:20 - 00233472 _____ (Viscom Software www.viscomsoft.com) C:\Windows\SysWOW64\viscomdvdimg.dll
2014-01-05 14:41 - 2009-01-23 21:08 - 00152848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\COMDLG32.OCX
2014-01-05 14:41 - 2009-01-23 21:08 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCMCFR.DLL
2014-01-05 14:41 - 2009-01-23 21:08 - 00119568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VB6FR.DLL
2014-01-05 14:41 - 2009-01-23 21:08 - 00115920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msinet.OCX
2014-01-05 14:41 - 2009-01-23 21:08 - 00101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VB6STKIT.DLL
2014-01-05 14:41 - 2009-01-23 21:08 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CMDLGFR.DLL
2014-01-05 14:41 - 2009-01-23 21:08 - 00015360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetfr.DLL
2014-01-05 14:40 - 2014-01-05 14:41 - 00000000 ____D C:\Program Files (x86)\Free Videos To DVD
2014-01-04 19:40 - 2014-01-04 19:40 - 00000897 _____ C:\Users\pc\Desktop\NPE – zástupce.lnk
2014-01-04 19:26 - 2014-01-06 18:04 - 00000000 ____D C:\Users\pc\AppData\Local\NPE
2014-01-04 19:16 - 2014-01-04 19:16 - 00001808 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Professional.lnk
2014-01-04 19:16 - 2014-01-04 19:16 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-12-31 11:18 - 2013-12-31 11:18 - 00028272 _____ C:\Users\pc\Desktop\IP Address Geolocation to Identify Website Visitor's Geographical Location.htm
2013-12-31 11:18 - 2013-12-31 11:18 - 00000000 ____D C:\Users\pc\Desktop\IP Address Geolocation to Identify Website Visitor's Geographical Location_files
2013-12-30 17:11 - 2014-01-06 19:10 - 00000000 ____D C:\Users\pc\AppData\Local\CrashDumps
2013-12-23 13:25 - 2013-12-23 13:25 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-23 13:08 - 2013-12-23 13:08 - 00000000 ____D C:\Windows\Tasks\ImCleanDisabled
2013-12-23 12:31 - 2013-12-23 12:31 - 00000000 ____D C:\Users\pc\AppData\Roaming\Apple Computer
2013-12-23 12:29 - 2013-12-23 12:38 - 00000000 ____D C:\Users\pc\AppData\Roaming\IObit
2013-12-17 14:21 - 2013-12-17 14:21 - 00005966 _____ C:\Users\pc\Desktop\Stoletý kalendář.htm
2013-12-17 14:21 - 2013-12-17 14:21 - 00000000 ____D C:\Users\pc\Desktop\Stoletý kalendář_files
2013-12-15 19:27 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2013-12-15 19:27 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2013-12-15 19:27 - 2012-08-23 15:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys
2013-12-15 19:27 - 2012-08-23 15:07 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2013-12-15 19:27 - 2012-08-23 14:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2013-12-15 19:27 - 2012-08-23 14:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2013-12-15 19:27 - 2012-08-23 14:41 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-12-15 19:27 - 2012-08-23 14:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-12-15 19:27 - 2012-08-23 14:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2013-12-15 19:27 - 2012-08-23 14:20 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2013-12-15 19:27 - 2012-08-23 14:18 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2013-12-15 19:27 - 2012-08-23 14:17 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2013-12-15 19:27 - 2012-08-23 14:06 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-12-15 19:27 - 2012-08-23 13:52 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2013-12-15 19:27 - 2012-08-23 12:20 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2013-12-15 19:27 - 2012-08-23 12:15 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2013-12-15 19:27 - 2012-08-23 12:14 - 00384000 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2013-12-15 19:27 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2013-12-15 19:27 - 2012-08-23 11:54 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2013-12-15 19:27 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2013-12-15 19:27 - 2012-08-23 11:39 - 01048064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2013-12-15 19:27 - 2012-08-23 11:22 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2013-12-15 19:27 - 2012-08-23 10:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2013-12-15 19:27 - 2012-08-23 09:19 - 04916224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2013-12-15 19:27 - 2012-08-23 09:13 - 05773824 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2013-12-15 18:59 - 2012-05-04 12:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2013-12-15 18:59 - 2012-05-04 10:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2013-12-12 14:28 - 2013-12-12 14:53 - 00000007 _____ C:\Users\pc\AppData\Roaming\verzia.ini
2013-12-12 14:24 - 2013-12-12 14:24 - 00000000 ____D C:\Users\pc\AppData\Local\iMemo
2013-12-12 14:23 - 2013-12-12 14:53 - 00000000 ____D C:\Users\pc\AppData\Local\Deployment
2013-12-12 14:23 - 2013-12-12 14:23 - 00000000 ____D C:\Users\pc\AppData\Local\Apps\2.0
2013-12-12 14:23 - 2013-12-12 14:23 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services
2013-12-12 14:23 - 2013-12-12 14:23 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2013-12-12 14:23 - 2013-12-12 14:23 - 00000000 ____D C:\Program Files (x86)\Microsoft Synchronization Services
2013-12-12 14:23 - 2013-12-12 14:23 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2013-12-12 14:13 - 2013-12-12 14:13 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-12-12 14:13 - 2013-12-12 14:13 - 00000000 ____D C:\Program Files\CCleaner
2013-12-12 13:45 - 2013-12-12 14:07 - 00000000 ____D C:\Users\pc\AppData\Roaming\Smart PC Solutions
2013-12-12 03:03 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-12 03:03 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-12 03:03 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-12 03:03 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-12 03:01 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-12 03:01 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-12 03:01 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-12 03:01 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-12 03:01 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-12 03:01 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-12 03:01 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-12 03:01 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-12 03:01 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-12 03:01 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-12 03:01 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-12 03:01 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-12 03:01 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-12 03:01 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-12 03:01 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-12 03:01 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-12 03:01 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-12 03:01 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-12 03:01 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-12 03:01 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-12 03:01 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-12 03:01 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-12 03:01 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-12 03:01 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-12 03:01 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-12 03:01 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-12 03:01 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-12 03:01 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-12 03:01 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-12 03:01 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-12 03:01 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-11 08:33 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-11 08:33 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-11 08:33 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-11 08:33 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-11 08:33 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-11 08:33 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-11 08:33 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-11 08:33 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-11 08:33 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-11 08:33 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-11 08:33 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-11 08:33 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-11 08:33 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-11 08:33 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-11 08:33 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-11 08:33 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-11 08:33 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-11 08:33 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-11 08:33 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-10 20:14 - 2013-12-10 20:14 - 00001393 _____ C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-12-10 20:14 - 2013-12-10 20:14 - 00000000 ____D C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-12-10 20:12 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2013-12-10 20:09 - 2013-12-10 20:09 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-10 20:09 - 2013-12-10 20:09 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-12-10 20:09 - 2013-12-10 20:09 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-12-10 20:09 - 2013-12-10 20:09 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-12-10 20:09 - 2013-12-10 20:09 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-12-10 20:09 - 2013-12-10 20:09 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-12-10 20:09 - 2013-12-10 20:09 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-12-10 20:09 - 2013-12-10 20:09 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-12-10 20:08 - 2013-12-10 20:08 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-12-10 20:08 - 2013-12-10 20:08 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-12-10 20:08 - 2013-12-10 20:08 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-12-10 20:08 - 2013-12-10 20:08 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-12-10 20:08 - 2013-12-10 20:08 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-12-10 20:08 - 2013-12-10 20:08 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-10 20:08 - 2013-12-10 20:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-12-10 20:08 - 2013-12-10 20:08 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-12-10 20:08 - 2013-12-10 20:08 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-12-10 20:08 - 2013-12-10 20:08 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-12-10 20:08 - 2013-12-10 20:08 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-12-10 20:08 - 2013-12-10 20:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-12-10 11:20 - 2013-12-10 11:20 - 00002050 _____ C:\Users\Public\Desktop\Foxit Reader.lnk
2013-12-10 11:19 - 2014-01-03 12:24 - 00003684 _____ C:\Windows\System32\Tasks\SolutoTask_e8559e51-fcd3-49cb-b1ef-45e01bcb9246
2013-12-09 11:28 - 2013-12-10 18:22 - 00003150 _____ C:\Windows\System32\Tasks\SidebarExecute
2013-12-09 11:28 - 2013-12-09 11:34 - 00000000 ____D C:\Users\pc\AppData\Roaming\HP
2013-12-09 11:28 - 2013-12-09 11:28 - 00000000 ____D C:\Users\pc\AppData\Local\HP
2013-12-09 11:23 - 2013-12-09 12:22 - 00000000 ____D C:\Program Files (x86)\HP
2013-12-09 11:21 - 2013-12-09 11:21 - 00000000 ____D C:\Program Files\HP
2013-12-09 11:19 - 2009-07-08 11:51 - 00642360 _____ (Hewlett-Packard) C:\Windows\system32\hpzids40.dll

==================== One Month Modified Files and Folders =======

2014-01-07 17:46 - 2014-01-07 17:45 - 00011517 _____ C:\Users\pc\Desktop\FRST.txt
2014-01-07 17:45 - 2014-01-07 17:45 - 00000000 ____D C:\FRST
2014-01-07 17:43 - 2014-01-07 17:43 - 00112640 _____ (forum.viry.cz) C:\Users\pc\Desktop\FRSTLauncher.exe
2014-01-07 17:42 - 2014-01-07 17:42 - 01931762 _____ (Farbar) C:\Users\pc\Desktop\FRST64.exe
2014-01-07 16:32 - 2014-01-06 19:11 - 00064475 _____ C:\Windows\WindowsUpdate.log
2014-01-07 14:29 - 2009-07-14 05:45 - 00021312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-07 14:29 - 2009-07-14 05:45 - 00021312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-07 14:26 - 2010-11-21 10:27 - 00666406 _____ C:\Windows\system32\perfh005.dat
2014-01-07 14:26 - 2010-11-21 10:27 - 00140102 _____ C:\Windows\system32\perfc005.dat
2014-01-07 14:26 - 2009-07-14 06:13 - 01577410 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-07 14:21 - 2014-01-07 10:42 - 00000112 _____ C:\Windows\setupact.log
2014-01-07 14:21 - 2013-08-18 06:51 - 00000000 _____ C:\Windows\SysWOW64\sinstall.log
2014-01-07 14:21 - 2009-07-14 06:08 - 00032626 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2014-01-07 14:21 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-07 14:20 - 2014-01-07 14:20 - 00000000 ____D C:\AdwCleaner
2014-01-07 12:34 - 2014-01-07 12:33 - 00000000 ____D C:\rsit
2014-01-07 12:34 - 2013-11-01 18:00 - 00000000 ____D C:\Program Files\trend micro
2014-01-07 10:42 - 2014-01-07 10:42 - 00000000 _____ C:\Windows\setuperr.log
2014-01-06 19:10 - 2013-12-30 17:11 - 00000000 ____D C:\Users\pc\AppData\Local\CrashDumps
2014-01-06 18:07 - 2014-01-06 18:07 - 00000624 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-06 18:04 - 2014-01-04 19:26 - 00000000 ____D C:\Users\pc\AppData\Local\NPE
2014-01-05 19:04 - 2013-08-15 17:51 - 00000000 ____D C:\Users\pc
2014-01-05 19:00 - 2013-12-01 11:47 - 00000000 ____D C:\Users\pc\AppData\Local\genienext
2014-01-05 18:19 - 2014-01-05 14:41 - 00000000 ____D C:\Users\pc\AppData\Roaming\FreeMoviesToDVD
2014-01-05 17:25 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2014-01-05 17:01 - 2014-01-05 16:30 - 00000000 ____D C:\Users\pc\AppData\Roaming\DVDVideoSoft
2014-01-05 15:26 - 2014-01-05 15:26 - 00000000 ____D C:\Users\pc\AppData\Local\Movavi
2014-01-05 14:41 - 2014-01-05 14:41 - 00001138 _____ C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free Videos To DVD.lnk
2014-01-05 14:41 - 2014-01-05 14:41 - 00001092 _____ C:\Users\pc\Desktop\Free Videos To DVD.lnk
2014-01-05 14:41 - 2014-01-05 14:40 - 00000000 ____D C:\Program Files (x86)\Free Videos To DVD
2014-01-04 19:40 - 2014-01-04 19:40 - 00000897 _____ C:\Users\pc\Desktop\NPE – zástupce.lnk
2014-01-04 19:38 - 2013-12-01 12:55 - 00000944 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-04 19:38 - 2013-12-01 12:55 - 00000940 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-04 19:37 - 2013-12-01 12:55 - 00003952 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-01-04 19:37 - 2013-12-01 12:55 - 00003700 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-01-04 19:36 - 2013-08-17 08:02 - 00002768 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-01-04 19:16 - 2014-01-04 19:16 - 00001808 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Professional.lnk
2014-01-04 19:16 - 2014-01-04 19:16 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2014-01-04 11:45 - 2013-10-21 09:44 - 00000000 ____D C:\Program Files (x86)\vso
2014-01-04 11:44 - 2013-10-21 09:44 - 00099384 _____ C:\Users\pc\AppData\Roaming\inst.exe
2014-01-04 11:44 - 2013-10-21 09:44 - 00082816 _____ (VSO Software) C:\Users\pc\AppData\Roaming\pcouffin.sys
2014-01-04 11:44 - 2013-10-21 09:44 - 00007859 _____ C:\Users\pc\AppData\Roaming\pcouffin.cat
2014-01-04 11:44 - 2013-10-21 09:44 - 00000033 _____ C:\Users\pc\AppData\Roaming\pcouffin.log
2014-01-04 11:44 - 2013-10-21 09:44 - 00000000 ____D C:\Users\pc\AppData\Roaming\Vso
2014-01-03 17:59 - 2013-08-28 15:27 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2014-01-03 13:32 - 2013-11-19 16:42 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-03 13:30 - 2013-08-16 13:29 - 00003854 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-01-03 12:24 - 2013-12-10 11:19 - 00003684 _____ C:\Windows\System32\Tasks\SolutoTask_e8559e51-fcd3-49cb-b1ef-45e01bcb9246
2013-12-31 11:18 - 2013-12-31 11:18 - 00028272 _____ C:\Users\pc\Desktop\IP Address Geolocation to Identify Website Visitor's Geographical Location.htm
2013-12-31 11:18 - 2013-12-31 11:18 - 00000000 ____D C:\Users\pc\Desktop\IP Address Geolocation to Identify Website Visitor's Geographical Location_files
2013-12-26 12:06 - 2013-08-15 13:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-12-23 19:08 - 2013-11-25 19:40 - 00000000 ___RD C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-12-23 13:25 - 2013-12-23 13:25 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-23 13:08 - 2013-12-23 13:08 - 00000000 ____D C:\Windows\Tasks\ImCleanDisabled
2013-12-23 12:38 - 2013-12-23 12:29 - 00000000 ____D C:\Users\pc\AppData\Roaming\IObit
2013-12-23 12:35 - 2013-08-15 18:45 - 00000000 ____D C:\Windows\Panther
2013-12-23 12:31 - 2013-12-23 12:31 - 00000000 ____D C:\Users\pc\AppData\Roaming\Apple Computer
2013-12-17 14:21 - 2013-12-17 14:21 - 00005966 _____ C:\Users\pc\Desktop\Stoletý kalendář.htm
2013-12-17 14:21 - 2013-12-17 14:21 - 00000000 ____D C:\Users\pc\Desktop\Stoletý kalendář_files
2013-12-17 13:57 - 2013-10-29 07:46 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-12-17 13:57 - 2013-10-28 20:09 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-12-17 13:57 - 2013-10-28 20:09 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-12-16 13:29 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-15 19:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-12-15 19:26 - 2013-08-15 18:00 - 00000000 ____D C:\Program Files (x86)\Intel
2013-12-14 20:04 - 2013-08-23 06:38 - 00000000 ____D C:\Windows\system32\MRT
2013-12-14 20:03 - 2013-08-23 06:38 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-12 14:53 - 2013-12-12 14:28 - 00000007 _____ C:\Users\pc\AppData\Roaming\verzia.ini
2013-12-12 14:53 - 2013-12-12 14:23 - 00000000 ____D C:\Users\pc\AppData\Local\Deployment
2013-12-12 14:24 - 2013-12-12 14:24 - 00000000 ____D C:\Users\pc\AppData\Local\iMemo
2013-12-12 14:23 - 2013-12-12 14:23 - 00000000 ____D C:\Users\pc\AppData\Local\Apps\2.0
2013-12-12 14:23 - 2013-12-12 14:23 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services
2013-12-12 14:23 - 2013-12-12 14:23 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2013-12-12 14:23 - 2013-12-12 14:23 - 00000000 ____D C:\Program Files (x86)\Microsoft Synchronization Services
2013-12-12 14:23 - 2013-12-12 14:23 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2013-12-12 14:23 - 2013-10-16 14:35 - 00108816 _____ C:\Users\pc\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-12 14:13 - 2013-12-12 14:13 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-12-12 14:13 - 2013-12-12 14:13 - 00000000 ____D C:\Program Files\CCleaner
2013-12-12 14:07 - 2013-12-12 13:45 - 00000000 ____D C:\Users\pc\AppData\Roaming\Smart PC Solutions
2013-12-12 14:05 - 2009-07-14 05:45 - 00419160 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-11 15:09 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF
2013-12-10 20:14 - 2013-12-10 20:14 - 00001393 _____ C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-12-10 20:14 - 2013-12-10 20:14 - 00000000 ____D C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-12-10 20:09 - 2013-12-10 20:09 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-10 20:09 - 2013-12-10 20:09 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-12-10 20:09 - 2013-12-10 20:09 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-12-10 20:09 - 2013-12-10 20:09 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-12-10 20:09 - 2013-12-10 20:09 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-12-10 20:09 - 2013-12-10 20:09 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-12-10 20:09 - 2013-12-10 20:09 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-12-10 20:09 - 2013-12-10 20:09 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-12-10 20:09 - 2013-12-10 20:09 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-12-10 20:08 - 2013-12-10 20:08 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-12-10 20:08 - 2013-12-10 20:08 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-12-10 20:08 - 2013-12-10 20:08 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-12-10 20:08 - 2013-12-10 20:08 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-12-10 20:08 - 2013-12-10 20:08 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-12-10 20:08 - 2013-12-10 20:08 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-10 20:08 - 2013-12-10 20:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-12-10 20:08 - 2013-12-10 20:08 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-12-10 20:08 - 2013-12-10 20:08 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-12-10 20:08 - 2013-12-10 20:08 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-12-10 20:08 - 2013-12-10 20:08 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-12-10 20:08 - 2013-12-10 20:08 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-12-10 20:08 - 2013-12-10 20:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-12-10 19:24 - 2013-08-16 13:29 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-10 19:24 - 2013-08-16 13:29 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-10 18:22 - 2013-12-09 11:28 - 00003150 _____ C:\Windows\System32\Tasks\SidebarExecute
2013-12-10 18:21 - 2013-08-28 07:11 - 00004312 _____ C:\Windows\System32\Tasks\Ad-Aware Antivirus Scheduled Scan
2013-12-10 11:20 - 2013-12-10 11:20 - 00002050 _____ C:\Users\Public\Desktop\Foxit Reader.lnk
2013-12-09 12:22 - 2013-12-09 11:23 - 00000000 ____D C:\Program Files (x86)\HP
2013-12-09 11:40 - 2013-10-20 17:38 - 00000000 ____D C:\Windows\pss
2013-12-09 11:34 - 2013-12-09 11:28 - 00000000 ____D C:\Users\pc\AppData\Roaming\HP
2013-12-09 11:28 - 2013-12-09 11:28 - 00000000 ____D C:\Users\pc\AppData\Local\HP
2013-12-09 11:28 - 2009-07-14 03:34 - 00000513 _____ C:\Windows\win.ini
2013-12-09 11:21 - 2013-12-09 11:21 - 00000000 ____D C:\Program Files\HP

Some content of TEMP:
====================
C:\Users\pc\AppData\Local\Temp\avgnt.exe
C:\Users\pc\AppData\Local\Temp\Quarantine.exe
C:\Users\pc\AppData\Local\Temp\SpOrder.dll


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-12-30 00:59




===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: () (Fixed) (Total:38.96 GB) (Free:2.17 GB) NTFS
Drive d: (Hry) (Fixed) (Total:126.96 GB) (Free:122.48 GB) NTFS
Drive e: (Záloha) (Fixed) (Total:132.07 GB) (Free:60.52 GB) NTFS

Available physical RAM: 2802.55 MB
Total physical RAM: 3983.69 MB
Percentage of memory in use: 29%

==================== MBR and Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: AFEE1298)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=39 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=127 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=132 GB) - (Type=07 NTFS)

==================== Scheduled Tasks (whitelisted) ==================

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\pc\Desktop" je 4 MB.


***** Startup Programs *****

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 7
C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck
C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kalendar
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar
C:\Windows\SysWOW64\rundll32.exe C:\Users\pc\AppData\Local\Temp\\tsiVi532.dll,startme [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorShield
Re�im ECHO je vypnut.

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdater
Re�im ECHO je vypnut.

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware
Re�im ECHO je vypnut.

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tsiVideo
Re�im ECHO je vypnut.

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk
C:\PROGRA~2\Secunia\PSI\psi_tray.exe [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Secunia PSI Tray.lnk



***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Hlášení o detekci virů

#13 Příspěvek od vyosek »

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKCU\...\Policies\Explorer: [NoInstrumentation] 0
    
    SearchScopes: HKCU - {D9ADE083-3C5E-4436-A7CA-38DB45A6872A} URL = http://search.yahoo.com/search?fr=chr-g ... =198484&p={searchTerms}
    
    FF Keyword.URL: hxxp://search.yahoo.com/search?fr=green ... =198484&p=
    
    R2 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe [1922600 2013-07-08] (Pandora.TV)
    S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
    
    2013-12-23 12:29 - 2013-12-23 12:38 - 00000000 ____D C:\Users\pc\AppData\Roaming\IObit
    C:\Program Files (x86)\PANDORA.TV
    C:\Program Files\Enigma Software Group
    C:\Users\pc\AppData\Local\Temp\avgnt.exe
    C:\Users\pc\AppData\Local\Temp\Quarantine.exe
    C:\Users\pc\AppData\Local\Temp\SpOrder.dll
    
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 7" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorShield" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdater" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware" /f
    
    CMD: shutdown /r /f /t 2
    
    End
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

ravelu
Návštěvník
Návštěvník
Příspěvky: 50
Registrován: 07 Led 2014 12:04

Re: Hlášení o detekci virů

#14 Příspěvek od ravelu »

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 05-01-2014
Ran by pc at 2014-01-07 18:28:15 Run:1
Running from C:\Users\pc\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
HKCU\...\Policies\Explorer: [NoInstrumentation] 0

SearchScopes: HKCU - {D9ADE083-3C5E-4436-A7CA-38DB45A6872A} URL = http://search.yahoo.com/search?fr=chr-g ... =198484&p={searchTerms}

FF Keyword.URL: hxxp://search.yahoo.com/search?fr=green ... =198484&p=

R2 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe [1922600 2013-07-08] (Pandora.TV)
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x]

2013-12-23 12:29 - 2013-12-23 12:38 - 00000000 ____D C:\Users\pc\AppData\Roaming\IObit
C:\Program Files (x86)\PANDORA.TV
C:\Program Files\Enigma Software Group
C:\Users\pc\AppData\Local\Temp\avgnt.exe
C:\Users\pc\AppData\Local\Temp\Quarantine.exe
C:\Users\pc\AppData\Local\Temp\SpOrder.dll

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 7" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorShield" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdater" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware" /f

CMD: shutdown /r /f /t 2

End
*****************

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoInstrumentation => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D9ADE083-3C5E-4436-A7CA-38DB45A6872A} => Key deleted successfully.
HKCR\CLSID\{D9ADE083-3C5E-4436-A7CA-38DB45A6872A} => Key not found.
Firefox Keyword.URL deleted successfully.
PanService => Service deleted successfully.
esgiguard => Service deleted successfully.
C:\Users\pc\AppData\Roaming\IObit => Moved successfully.
C:\Program Files (x86)\PANDORA.TV => Moved successfully.
"C:\Program Files\Enigma Software Group" => File/Directory not found.
C:\Users\pc\AppData\Local\Temp\avgnt.exe => Moved successfully.
C:\Users\pc\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\pc\AppData\Local\Temp\SpOrder.dll => Moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.

========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 7" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorShield" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdater" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= shutdown /r /f /t 2 =========


========= End of CMD: =========



The system needs a manual reboot.

==== End of Fixlog ====

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Hlášení o detekci virů

#15 Příspěvek od vyosek »

Jak se chova PC??
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět