odstranění malware rvzr-a.akamaihd.net

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: odstranění malware rvzr-a.akamaihd.net

#16 Příspěvek od vyosek »

:arrow: Ja cas mel, ale kdyz jste editoval prispevke, tak se mi to nezobrazilo jako novy a tudiz jsem nemohl reagovat

:arrow: Udelejte novy log z FRST
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

valf
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 11 Led 2014 18:28

Re: odstranění malware rvzr-a.akamaihd.net

#17 Příspěvek od valf »

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-01-2014 01
Ran by owner (administrator) on ZAKAZNIK on 15-01-2014 17:38:05
Running from C:\Documents and Settings\owner\Plocha
Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) ===================

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Motive Communications, Inc.) C:\Program Files\Common Files\Motive\McciCMService.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.exe
(Logitech Inc.) C:\WINDOWS\system32\LVCOMSX.EXE
(Logitech Inc.) C:\Program Files\Logitech\Video\LogiTray.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Motive Communications, Inc.) C:\Program Files\TO2SSM\McciTrayApp.exe
(MyHeritage) C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Logitech Inc.) C:\Program Files\Logitech\Video\FxSvr2.exe
(Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
() C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
() C:\Documents and Settings\owner\Data aplikací\Seznam.cz\bin\szndesktop.exe
(Václav Šimandl) C:\Program Files\Diar 5\diar.exe
(Rainy) C:\Program Files\Rainlendar\Rainlendar.exe
(Tošovský Jan) C:\Program Files\Noční obloha\vesmir.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Farbar) C:\Documents and Settings\owner\Plocha\FRST(1).exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDCPL] - C:\Windows\RTHDCPL.EXE [16116224 2007-01-30] (Realtek Semiconductor Corp.)
HKLM\...\Run: [SkyTel] - C:\Windows\SkyTel.EXE [2879488 2006-05-16] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Alcmtr] - C:\Windows\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.)
HKLM\...\Run: [LVCOMSX] - C:\WINDOWS\system32\LVCOMSX.EXE [221184 2005-07-19] (Logitech Inc.)
HKLM\...\Run: [LogitechVideoRepair] - C:\Program Files\Logitech\Video\ISStart.exe [458752 2005-06-08] (Logitech Inc.)
HKLM\...\Run: [LogitechVideoTray] - C:\Program Files\Logitech\Video\LogiTray.exe [217088 2005-06-08] (Logitech Inc.)
HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)
HKLM\...\Run: [TO2SSM_McciTrayApp] - C:\Program Files\TO2SSM\McciTrayApp.exe [1473536 2008-08-15] (Motive Communications, Inc.)
HKLM\...\Run: [Family Tree Builder Update] - C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe [2532864 2013-11-12] (MyHeritage)
HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k
HKLM\...\Run: [REGSHAVE] - C:\Program Files\REGSHAVE\REGSHAVE.EXE [53248 2002-02-04] (FUJI PHOTO FILM CO., LTD.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [TkBellExe] - C:\program files\real\realplayer\update\realsched.exe [295512 2013-06-19] (RealNetworks, Inc.)
HKLM\...\Run: [seznam-listicka-distribuce] - C:\Program Files\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM\...\Run: [Google Desktop Search] - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [1838592 2013-09-05] (Google)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2014-01-07] (AVAST Software)
HKLM\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 0
HKLM\...\Policies\Explorer: [NoResolveSearch] 1
HKCU\...\Run: [LogitechSoftwareUpdate] - C:\Program Files\Logitech\Video\ManifestEngine.exe [196608 2005-06-08] (Logitech Inc.)
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20587168 2013-11-18] (Skype Technologies S.A.)
HKCU\...\Run: [cz.seznam.software.autoupdate] - C:\Documents and Settings\owner\Data aplikací\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKCU\...\Run: [cz.seznam.software.szndesktop] - C:\Documents and Settings\owner\Data aplikací\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKCU\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 0
HKCU\...\Policies\Explorer: [NoInstrumentation] 1
HKU\Default User\...\RunOnce: [NeroHomeFirstStart] - C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe
AppInit_DLLs: C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [145408 2013-09-05] (Google)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Gamma Loader.lnk
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\AVerQuick.lnk
ShortcutTarget: AVerQuick.lnk -> C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe ()
Startup: C:\Documents and Settings\owner\Nabídka Start\Programy\Po spuštění\Diář.lnk
ShortcutTarget: Diář.lnk -> C:\Program Files\Diar 5\diar.exe (Václav Šimandl)
Startup: C:\Documents and Settings\owner\Nabídka Start\Programy\Po spuštění\Mozilla Firefox (2).lnk
ShortcutTarget: Mozilla Firefox (2).lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Startup: C:\Documents and Settings\owner\Nabídka Start\Programy\Po spuštění\Rainlendar.lnk
ShortcutTarget: Rainlendar.lnk -> C:\Program Files\Rainlendar\Rainlendar.exe (Rainy)
Startup: C:\Documents and Settings\owner\Nabídka Start\Programy\Po spuštění\Vesmír na dlani.lnk
ShortcutTarget: Vesmír na dlani.lnk -> C:\Program Files\Noční obloha\vesmir.exe (Tošovský Jan)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
HKCU\Software\Microsoft\Internet Explorer\Main,Prev Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
URLSearchHook: HKCU - (No Name) - {7757CBCC-0975-4b79-A519-90B142CA3A23} - No File
URLSearchHook: HKCU - MHURLSearchHook Class - {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Program Files\Family Toolbar\tbhelper.dll ()
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = http://search.myheritage.com?orig=ds&q={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = http://search.myheritage.com?orig=ds&q={searchTerms}
SearchScopes: HKCU - {D482BCAD-A777-451A-BB0C-46A0A8A9E5FD} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
BHO: Video Player - {19e6b0ed-4856-4cb2-8756-f72ecb172b34} - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta4\ie\VideoPlayerV3beta4.dll ()
BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO: Webexp Enhanced - {73d78f1b-734b-4529-88b2-d0b546c7e124} - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha801\ie\WebexpEnhancedV1alpha801.dll ()
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - &S-Rank - {B71B15CF-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam\Postak\SRank.dll (Seznam.cz a.s.)
Toolbar: HKLM - &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU - &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\System32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU - &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\Windows\system32\SHELL32.dll (Microsoft Corporation)
Toolbar: HKCU - &S-Rank - {B71B15CF-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam\Postak\SRank.dll (Seznam.cz a.s.)
Toolbar: HKCU - &Google - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
Toolbar: HKCU - No Name - {EFA17369-CDC0-4927-9AFC-BAAD1F96B2AE} - No File
DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204
DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} http://www.myheritage.cz/Genoogle/Compo ... eQuery.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF ProfilePath: C:\Documents and Settings\owner\Data aplikací\Mozilla\Firefox\Profiles\ihpvjar7.default-1369290633546
FF SearchEngineOrder.1: Google
FF Homepage: hxxp://www.seznam.cz/
FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @IObitBar.com/Plugin - C:\Program Files\IObitBar\toolbar\1.bin\NPi0Stub.dll No File
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.2.32 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.2 - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.2 - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.2 - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpchromebrowserrecordext;version=15.0.6.14 - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprphtml5videoshim;version=15.0.6.14 - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.2.32 - c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin: @real.com/RhapsodyPlayerEngine,version=1.1 - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF Plugin: @realnetworks.com/npdlplugin;version=1 - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll No File
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdivx32.dll (DivX,Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Computer, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Computer, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Computer, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Computer, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Computer, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpplugin.dll (RealPlayer)
FF Plugin ProgramFiles/Appdata: C:\Documents and Settings\owner\Data aplikací\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Documents and Settings\owner\Data aplikací\mozilla\plugins\npgtpo3dautoplugin.dll ()
FF SearchPlugin: C:\Documents and Settings\owner\Data aplikací\Mozilla\Firefox\Profiles\ihpvjar7.default-1369290633546\searchplugins\filmova-databaze-fdbcz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: AD Block - C:\Documents and Settings\owner\Data aplikací\Mozilla\Firefox\Profiles\ihpvjar7.default-1369290633546\Extensions\searchads@instair.net [2013-11-15]
FF Extension: Lišta Centrum.cz - C:\Documents and Settings\owner\Data aplikací\Mozilla\Firefox\Profiles\ihpvjar7.default-1369290633546\Extensions\toolbar@centrumholdings.com [2013-11-07]
FF Extension: Seznam lištička - C:\Documents and Settings\owner\Data aplikací\Mozilla\Firefox\Profiles\ihpvjar7.default-1369290633546\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2013-09-11]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-12-11]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2013-12-11]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{FD2FD708-1F6F-4B68-B141-C5778F0C19BB} [2013-12-11]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-12-11]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Firefox\Extensions: [i0ffxtbr@IObitBar.com] - C:\Program Files\IObitBar\toolbar\1.bin
FF HKLM\...\Firefox\Extensions: [{0153E448-190B-4987-BDE1-F256CADA672F}] - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: RealPlayer Browser Record Plugin - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012-09-26]
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-06-19]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-05-14]
FF HKLM\...\Firefox\Extensions: [{FCE04E1F-9378-4f39-96F6-5689A9159E45}] - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ []
FF HKLM\...\Firefox\Extensions: [ext@bettersurfplus.com] - C:\Program Files\BetterSurf\BetterSurfPlus\ff
FF HKLM\...\Firefox\Extensions: [ext@WebexpEnhancedV1alpha801.net] - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha801\ff
FF Extension: Webexp Enhanced - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha801\ff [2013-12-20]
FF HKLM\...\Firefox\Extensions: [ext@VideoPlayerV3beta4.net] - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta4\ff
FF Extension: Video Player - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta4\ff [2014-01-10]

========================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-01-07] (AVAST Software)
S3 GoogleDesktopManager; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [1838592 2013-09-05] (Google)
S2 HidServ; C:\Windows\System32\svchost.exe [14336 2008-04-14] (Microsoft Corporation)
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2013-10-08] (Oracle Corporation)
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] ()
S2 SecureUpdateSvc; C:\Program Files\Secure Speed Dial\IE\SecureUpdate.exe [x]

==================== Drivers (Whitelisted) ====================

R1 AmdK8; C:\Windows\System32\DRIVERS\AmdK8.sys [43008 2006-06-18] (Advanced Micro Devices)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [67824 2014-01-07] (AVAST Software)
R1 AswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [54832 2014-01-07] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49944 2013-12-05] ()
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [775952 2014-01-07] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [410528 2014-01-07] (AVAST Software)
R1 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57672 2014-01-07] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [180248 2014-01-07] ()
R3 AVerBDA3x; C:\Windows\System32\DRIVERS\AVerBDA3x.sys [1171456 2006-12-14] (AVerMedia TECHNOLOGIES, Inc.)
S3 CCDECODE; C:\Windows\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
S3 gdrv; C:\WINDOWS\gdrv.sys [14656 2007-08-17] (Windows (R) Codename Longhorn DDK provider)
R0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] ()
R3 LVUSBSta; C:\Windows\System32\drivers\lvusbsta.sys [22016 2005-05-27] (Logitech Inc.)
R2 MASPINT; C:\Windows\System32\Drivers\MASPINT.sys [8096 2000-03-29] (MicroStaff Co.,Ltd.)
S3 MPE; C:\Windows\System32\DRIVERS\MPE.sys [15232 2008-04-13] (Microsoft Corporation)
S3 MREMP50; C:\Program Files\Common Files\Motive\MREMP50.sys [21248 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA))
S3 MRESP50; C:\Program Files\Common Files\Motive\MRESP50.sys [20096 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA))
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R0 nvata; C:\Windows\System32\DRIVERS\nvata.sys [105472 2006-10-18] (NVIDIA Corporation)
R3 NVENETFD; C:\Windows\System32\DRIVERS\NVENETFD.sys [58368 2006-11-27] (NVIDIA Corporation)
R3 nvnetbus; C:\Windows\System32\DRIVERS\nvnetbus.sys [19968 2006-11-27] (NVIDIA Corporation)
R2 PfFilter; C:\Program Files\IObit\Protected Folder\pffilter.sys [140848 2011-03-16] (IObit Information Technology)
R3 QCMerced; C:\Windows\System32\DRIVERS\LVCM.sys [1317152 2005-05-27] ()
R0 speedfan; C:\Windows\System32\speedfan.sys [5248 2006-09-24] (Windows (R) 2000 DDK provider)
S3 cpuz134; \??\C:\DOCUME~1\owner\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys [x]
S4 InCDFs; system32\drivers\InCDFs.sys [x]
S1 InCDPass; system32\drivers\InCDPass.sys [x]
S1 InCDRm; system32\drivers\InCDRm.sys [x]
S4 IntelIde; No ImagePath
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [x]
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [x]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [x]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [x]
U5 P3; C:\Windows\System32\Drivers\P3.sys [46592 2008-04-14] (Microsoft Corporation)
U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-15 17:37 - 2014-01-15 17:36 - 01220608 _____ (Farbar) C:\Documents and Settings\owner\Plocha\FRST(1).exe
2014-01-15 10:02 - 2014-01-15 10:02 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2914368$
2014-01-13 22:27 - 2014-01-13 22:30 - 00000000 ____D C:\AdwCleaner
2014-01-13 22:23 - 2014-01-13 22:23 - 00010581 _____ C:\JRT.txt
2014-01-13 22:16 - 2014-01-13 22:16 - 00000000 ____D C:\WINDOWS\ERUNT
2014-01-13 22:13 - 2014-01-13 22:13 - 00006366 _____ C:\sc-cleaner1.txt
2014-01-13 21:54 - 2014-01-13 21:54 - 00006366 _____ C:\sc-cleaner.txt
2014-01-13 21:48 - 2014-01-13 21:44 - 01236282 _____ C:\Documents and Settings\owner\Plocha\adwcleaner.exe
2014-01-13 21:47 - 2014-01-13 21:44 - 01037068 _____ (Thisisu) C:\Documents and Settings\owner\Plocha\JRT.exe
2014-01-13 21:46 - 2014-01-13 21:43 - 00406264 _____ (Bleeping Computer, LLC) C:\Documents and Settings\owner\Plocha\sc-cleaner.exe
2014-01-13 15:33 - 2014-01-13 15:33 - 00008113 _____ C:\Documents and Settings\owner\Plocha\Addition.zip
2014-01-13 10:40 - 2014-01-13 10:41 - 00050913 _____ C:\Documents and Settings\owner\Plocha\Addition.txt
2014-01-13 10:39 - 2014-01-15 17:38 - 00023970 _____ C:\Documents and Settings\owner\Plocha\FRST.txt
2014-01-13 10:38 - 2014-01-13 10:38 - 00000000 ____D C:\FRST
2014-01-13 10:37 - 2014-01-13 10:37 - 00015327 _____ C:\Documents and Settings\owner\Plocha\LM.bat
2014-01-13 10:37 - 2014-01-13 10:13 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\owner\Plocha\FRSTLauncher.exe
2014-01-13 10:28 - 2014-01-13 09:54 - 01219584 _____ (Farbar) C:\Documents and Settings\owner\Plocha\FRST.exe
2014-01-11 17:54 - 2014-01-11 17:57 - 00000000 ____D C:\rsit
2014-01-11 17:54 - 2014-01-11 17:54 - 00000000 ____D C:\Program Files\trend micro
2014-01-10 07:44 - 2014-01-10 07:44 - 00000000 ____D C:\Program Files\VideoPlayerV3
2014-01-07 09:17 - 2014-01-07 09:17 - 00000000 ____D C:\WINDOWS\system32\log
2014-01-07 08:11 - 2014-01-07 08:11 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Google+ Auto Backup
2014-01-06 20:23 - 2014-01-06 20:23 - 04558848 _____ (Google Inc.) C:\WINDOWS\system32\GPhotos.scr
2014-01-06 13:23 - 2014-01-15 11:08 - 00000278 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-823518204-1417001333-725345543-1003.job
2013-12-28 19:46 - 2013-12-28 19:46 - 00000000 ____D C:\Documents and Settings\NetworkService\Data aplikací\AVG
2013-12-27 19:46 - 2013-12-27 19:46 - 00000000 ____D C:\Documents and Settings\owner\Local Settings\Data aplikací\Avg2014
2013-12-27 19:23 - 2013-12-27 19:23 - 00000000 ____D C:\Documents and Settings\owner\Data aplikací\AVG
2013-12-27 19:19 - 2013-12-27 19:24 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AVG
2013-12-27 19:19 - 2013-12-27 19:19 - 00000000 __SHD C:\Documents and Settings\All Users\Data aplikací\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2013-12-20 18:37 - 2013-12-20 18:37 - 00000000 ____D C:\Program Files\WebexpEnhancedV1
2013-12-16 13:14 - 2013-12-16 13:14 - 00001915 _____ C:\Documents and Settings\All Users\Plocha\Google Earth.lnk
2013-12-16 13:14 - 2013-12-16 13:14 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Google Earth

==================== One Month Modified Files and Folders =======

2014-01-15 17:38 - 2014-01-13 10:39 - 00023970 _____ C:\Documents and Settings\owner\Plocha\FRST.txt
2014-01-15 17:38 - 2007-08-17 21:59 - 00000000 ____D C:\Documents and Settings\owner\Plocha
2014-01-15 17:36 - 2014-01-15 17:37 - 01220608 _____ (Farbar) C:\Documents and Settings\owner\Plocha\FRST(1).exe
2014-01-15 17:36 - 2010-02-09 21:28 - 00000000 ____D C:\Documents and Settings\owner\Dokumenty\Stažené soubory
2014-01-15 17:34 - 2009-06-14 18:21 - 00000466 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{E979B337-9A3F-438E-87C7-6198BD462FFC}.job
2014-01-15 17:31 - 2007-08-17 16:47 - 00000000 ____D C:\Documents and Settings\owner\Data aplikací\Skype
2014-01-15 15:54 - 2007-08-17 22:20 - 01295336 _____ C:\WINDOWS\WindowsUpdate.log
2014-01-15 15:48 - 2013-05-14 08:27 - 00000364 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2014-01-15 15:42 - 2012-03-29 15:55 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-01-15 15:10 - 2010-02-13 08:54 - 00000940 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-15 13:17 - 2007-08-17 21:59 - 00000000 ____D C:\Documents and Settings\owner
2014-01-15 12:19 - 2013-07-23 07:05 - 00031900 ____N C:\WINDOWS\SchedLgU.Txt
2014-01-15 11:08 - 2014-01-06 13:23 - 00000278 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-823518204-1417001333-725345543-1003.job
2014-01-15 11:08 - 2012-12-23 11:32 - 00000286 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-823518204-1417001333-725345543-1003.job
2014-01-15 11:08 - 2010-03-18 08:30 - 00000286 _____ C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-823518204-1417001333-725345543-1003.job
2014-01-15 10:24 - 2013-08-31 10:23 - 00000000 ____D C:\Documents and Settings\owner\Data aplikací\Seznam.cz
2014-01-15 10:17 - 2010-03-18 08:30 - 00000278 _____ C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-823518204-1417001333-725345543-1003.job
2014-01-15 10:16 - 2013-07-23 07:06 - 00000159 ____N C:\WINDOWS\wiadebug.log
2014-01-15 10:16 - 2013-07-23 07:06 - 00000049 ____N C:\WINDOWS\wiaservc.log
2014-01-15 10:16 - 2013-06-07 19:14 - 00000350 _____ C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job
2014-01-15 10:16 - 2013-06-03 12:50 - 00000350 _____ C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
2014-01-15 10:16 - 2010-02-13 08:54 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-15 10:16 - 2007-08-17 21:56 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2014-01-15 10:15 - 2007-08-17 21:59 - 00000272 ___SH C:\Documents and Settings\owner\ntuser.ini
2014-01-15 10:09 - 2013-08-19 16:25 - 00000000 ____D C:\WINDOWS\system32\MRT
2014-01-15 10:03 - 2007-08-19 18:14 - 83425928 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-01-15 10:02 - 2014-01-15 10:02 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2914368$
2014-01-13 22:30 - 2014-01-13 22:27 - 00000000 ____D C:\AdwCleaner
2014-01-13 22:30 - 2010-11-28 22:15 - 00000000 ____D C:\Documents and Settings\owner\Data aplikací\Uniblue
2014-01-13 22:30 - 2009-01-21 18:57 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\ICQ
2014-01-13 22:30 - 2007-08-17 23:50 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2014-01-13 22:30 - 2007-08-17 21:59 - 00000000 __RHD C:\Documents and Settings\owner\Data aplikací
2014-01-13 22:30 - 2007-08-17 21:59 - 00000000 ___HD C:\Documents and Settings\owner\Local Settings\Data aplikací
2014-01-13 22:23 - 2014-01-13 22:23 - 00010581 _____ C:\JRT.txt
2014-01-13 22:16 - 2014-01-13 22:16 - 00000000 ____D C:\WINDOWS\ERUNT
2014-01-13 22:13 - 2014-01-13 22:13 - 00006366 _____ C:\sc-cleaner1.txt
2014-01-13 21:54 - 2014-01-13 21:54 - 00006366 _____ C:\sc-cleaner.txt
2014-01-13 21:54 - 2011-06-23 20:47 - 00000730 _____ C:\Documents and Settings\All Users\Nabídka Start\Programy\Mozilla Firefox.lnk
2014-01-13 21:54 - 2010-11-16 22:27 - 00001813 _____ C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
2014-01-13 21:52 - 2007-08-17 21:59 - 00000000 ___RD C:\Documents and Settings\owner\Dokumenty
2014-01-13 21:44 - 2014-01-13 21:48 - 01236282 _____ C:\Documents and Settings\owner\Plocha\adwcleaner.exe
2014-01-13 21:44 - 2014-01-13 21:47 - 01037068 _____ (Thisisu) C:\Documents and Settings\owner\Plocha\JRT.exe
2014-01-13 21:43 - 2014-01-13 21:46 - 00406264 _____ (Bleeping Computer, LLC) C:\Documents and Settings\owner\Plocha\sc-cleaner.exe
2014-01-13 21:23 - 2007-08-17 17:13 - 00000000 ____D C:\Documents and Settings\owner\Dokumenty\AVerTV
2014-01-13 15:33 - 2014-01-13 15:33 - 00008113 _____ C:\Documents and Settings\owner\Plocha\Addition.zip
2014-01-13 10:41 - 2014-01-13 10:40 - 00050913 _____ C:\Documents and Settings\owner\Plocha\Addition.txt
2014-01-13 10:38 - 2014-01-13 10:38 - 00000000 ____D C:\FRST
2014-01-13 10:37 - 2014-01-13 10:37 - 00015327 _____ C:\Documents and Settings\owner\Plocha\LM.bat
2014-01-13 10:28 - 2007-08-28 18:51 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
2014-01-13 10:13 - 2014-01-13 10:37 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\owner\Plocha\FRSTLauncher.exe
2014-01-13 09:54 - 2014-01-13 10:28 - 01219584 _____ (Farbar) C:\Documents and Settings\owner\Plocha\FRST.exe
2014-01-11 17:57 - 2014-01-11 17:54 - 00000000 ____D C:\rsit
2014-01-11 17:54 - 2014-01-11 17:54 - 00000000 ____D C:\Program Files\trend micro
2014-01-11 08:21 - 2013-04-03 19:44 - 00002283 _____ C:\Documents and Settings\All Users\Plocha\Skype.lnk
2014-01-11 08:19 - 2007-08-17 16:47 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Skype
2014-01-11 07:55 - 2001-10-25 13:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2014-01-10 21:12 - 2007-08-17 18:15 - 00000000 ____D C:\Documents and Settings\owner\Local Settings\Data aplikací\Thunderbird
2014-01-10 07:44 - 2014-01-10 07:44 - 00000000 ____D C:\Program Files\VideoPlayerV3
2014-01-07 15:49 - 2013-05-14 08:27 - 00001733 _____ C:\Documents and Settings\All Users\Plocha\avast! Free Antivirus.lnk
2014-01-07 15:48 - 2013-05-14 08:27 - 00775952 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2014-01-07 15:48 - 2013-05-14 08:27 - 00410528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2014-01-07 15:48 - 2013-05-14 08:27 - 00180248 _____ C:\WINDOWS\system32\Drivers\aswVmm.sys
2014-01-07 15:48 - 2013-05-14 08:27 - 00067824 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2014-01-07 15:48 - 2013-05-14 08:27 - 00057672 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys
2014-01-07 15:48 - 2013-05-14 08:27 - 00054832 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
2014-01-07 15:48 - 2013-05-14 08:26 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2014-01-07 15:48 - 2007-11-26 08:55 - 00270240 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2014-01-07 13:28 - 2008-01-14 17:16 - 00000000 ____D C:\INSTALL
2014-01-07 09:17 - 2014-01-07 09:17 - 00000000 ____D C:\WINDOWS\system32\log
2014-01-07 09:14 - 2007-08-17 21:59 - 00000000 ___RD C:\Documents and Settings\owner\Nabídka Start\Programy\Po spuštění
2014-01-07 08:11 - 2014-01-07 08:11 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Google+ Auto Backup
2014-01-07 08:11 - 2007-08-28 17:10 - 00000000 ____D C:\Program Files\Google
2014-01-07 08:11 - 2007-08-17 23:50 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2014-01-06 23:25 - 2007-08-17 23:46 - 00000000 ____D C:\WINDOWS\Help
2014-01-06 20:23 - 2014-01-06 20:23 - 04558848 _____ (Google Inc.) C:\WINDOWS\system32\GPhotos.scr
2013-12-29 22:29 - 2013-03-27 21:01 - 00065536 _____ C:\WINDOWS\system32\config\TuneUp.evt
2013-12-29 08:12 - 2007-08-17 23:50 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2013-12-28 19:46 - 2013-12-28 19:46 - 00000000 ____D C:\Documents and Settings\NetworkService\Data aplikací\AVG
2013-12-28 19:46 - 2007-08-17 21:59 - 00000000 ____D C:\Documents and Settings\NetworkService\Data aplikací
2013-12-27 19:46 - 2013-12-27 19:46 - 00000000 ____D C:\Documents and Settings\owner\Local Settings\Data aplikací\Avg2014
2013-12-27 19:24 - 2013-12-27 19:19 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AVG
2013-12-27 19:23 - 2013-12-27 19:23 - 00000000 ____D C:\Documents and Settings\owner\Data aplikací\AVG
2013-12-27 19:19 - 2013-12-27 19:19 - 00000000 __SHD C:\Documents and Settings\All Users\Data aplikací\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2013-12-27 19:17 - 2010-12-06 18:46 - 00000862 _____ C:\Documents and Settings\All Users\Plocha\GOM Player.lnk
2013-12-27 19:17 - 2010-06-01 06:39 - 00000862 _____ C:\Documents and Settings\owner\Nabídka Start\GOM Player.lnk
2013-12-25 22:15 - 2010-11-16 22:27 - 00000838 _____ C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
2013-12-20 18:38 - 2013-03-07 12:18 - 00000664 _____ C:\WINDOWS\system32\d3d9caps.dat
2013-12-20 18:37 - 2013-12-20 18:37 - 00000000 ____D C:\Program Files\WebexpEnhancedV1
2013-12-20 12:02 - 2008-04-24 17:40 - 00000774 _____ C:\Documents and Settings\owner\Plocha\MyHeritage Family Tree Builder.lnk
2013-12-18 13:12 - 2013-05-14 05:54 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Google Drive
2013-12-16 13:14 - 2013-12-16 13:14 - 00001915 _____ C:\Documents and Settings\All Users\Plocha\Google Earth.lnk
2013-12-16 13:14 - 2013-12-16 13:14 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Google Earth

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe
[2002-09-20 17:05] - [2008-04-14 04:22] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1

C:\Windows\System32\winlogon.exe
[2002-09-20 17:05] - [2008-04-14 04:22] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea

C:\Windows\System32\svchost.exe
[2001-10-25 13:00] - [2008-04-14 04:22] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93

C:\Windows\System32\services.exe
[2001-10-25 13:00] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7

C:\Windows\System32\User32.dll
[2002-09-20 17:04] - [2008-04-14 04:22] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53

C:\Windows\System32\userinit.exe
[2002-09-20 17:05] - [2008-04-14 04:22] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239

C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys
[2001-10-25 13:00] - [2008-04-14 03:12] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1


==================== End Of Log ============================

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: odstranění malware rvzr-a.akamaihd.net

#18 Příspěvek od vyosek »

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)
    HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k
    HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
    HKLM\...\Run: [TkBellExe] - C:\program files\real\realplayer\update\realsched.exe [295512 2013-06-19] (RealNetworks, Inc.)
    HKLM\...\Run: [seznam-listicka-distribuce] - C:\Program Files\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
    HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
    HKLM\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 0
    HKLM\...\Policies\Explorer: [NoResolveSearch] 1
    HKCU\...\Run: [LogitechSoftwareUpdate] - C:\Program Files\Logitech\Video\ManifestEngine.exe [196608 2005-06-08] (Logitech Inc.)
    HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20587168 2013-11-18] (Skype Technologies S.A.)
    HKCU\...\Run: [cz.seznam.software.autoupdate] - C:\Documents and Settings\owner\Data aplikací\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
    HKCU\...\Run: [cz.seznam.software.szndesktop] - C:\Documents and Settings\owner\Data aplikací\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
    HKCU\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 0
    HKCU\...\Policies\Explorer: [NoInstrumentation] 1
    HKU\Default User\...\RunOnce: [NeroHomeFirstStart] - C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe
    Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Gamma Loader.lnk
    Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\AVerQuick.lnk
    
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
    HKCU\Software\Microsoft\Internet Explorer\Main,Prev Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
    HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com
    HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
    URLSearchHook: HKCU - (No Name) - {7757CBCC-0975-4b79-A519-90B142CA3A23} - No File
    URLSearchHook: HKCU - MHURLSearchHook Class - {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Program Files\Family Toolbar\tbhelper.dll ()
    SearchScopes: HKLM - DefaultScope value is missing.
    SearchScopes: HKLM - {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = http://search.myheritage.com?orig=ds&q={searchTerms}
    SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    SearchScopes: HKCU - {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = http://search.myheritage.com?orig=ds&q={searchTerms}
    SearchScopes: HKCU - {D482BCAD-A777-451A-BB0C-46A0A8A9E5FD} URL = http://search.yahoo.com/search?fr=chr-g ... =685749&p={searchTerms}
    BHO: Video Player - {19e6b0ed-4856-4cb2-8756-f72ecb172b34} - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta4\ie\VideoPlayerV3beta4.dll ()
    BHO: Webexp Enhanced - {73d78f1b-734b-4529-88b2-d0b546c7e124} - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha801\ie\WebexpEnhancedV1alpha801.dll ()
    Toolbar: HKCU - No Name - {EFA17369-CDC0-4927-9AFC-BAAD1F96B2AE} - No File
    
    FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=
    FF Plugin: @IObitBar.com/Plugin - C:\Program Files\IObitBar\toolbar\1.bin\NPi0Stub.dll No File
    FF HKLM\...\Firefox\Extensions: [i0ffxtbr@IObitBar.com] - C:\Program Files\IObitBar\toolbar\1.bin
    FF HKLM\...\Firefox\Extensions: [ext@bettersurfplus.com] - C:\Program Files\BetterSurf\BetterSurfPlus\ff
    FF HKLM\...\Firefox\Extensions: [ext@WebexpEnhancedV1alpha801.net] - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha801\ff
    FF Extension: Webexp Enhanced - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha801\ff [2013-12-20]
    FF HKLM\...\Firefox\Extensions: [ext@VideoPlayerV3beta4.net] - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta4\ff
    FF Extension: Video Player - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta4\ff [2014-01-10]
    
    R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] ()
    S2 SecureUpdateSvc; C:\Program Files\Secure Speed Dial\IE\SecureUpdate.exe [x]
    S3 cpuz134; \??\C:\DOCUME~1\owner\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys [x]
    S4 InCDFs; system32\drivers\InCDFs.sys [x]
    S1 InCDPass; system32\drivers\InCDPass.sys [x]
    S1 InCDRm; system32\drivers\InCDRm.sys [x]
    S4 IntelIde; No ImagePath
    S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [x]
    S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [x]
    S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [x]
    S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [x]
    
    C:\Program Files\BetterSurf
    C:\Program Files\VideoPlayerV3
    2014-01-13 22:23 - 2014-01-13 22:23 - 00010581 _____ C:\JRT.txt
    2014-01-13 22:13 - 2014-01-13 22:13 - 00006366 _____ C:\sc-cleaner1.txt
    2014-01-13 21:54 - 2014-01-13 21:54 - 00006366 _____ C:\sc-cleaner.txt
    2014-01-13 21:48 - 2014-01-13 21:44 - 01236282 _____ C:\Documents and Settings\owner\Plocha\adwcleaner.exe
    2014-01-13 21:47 - 2014-01-13 21:44 - 01037068 _____ (Thisisu) C:\Documents and Settings\owner\Plocha\JRT.exe
    2014-01-13 21:46 - 2014-01-13 21:43 - 00406264 _____ (Bleeping Computer, LLC) C:\Documents and Settings\owner\Plocha\sc-cleaner.exe
    2014-01-13 15:33 - 2014-01-13 15:33 - 00008113 _____ C:\Documents and Settings\owner\Plocha\Addition.zip
    2014-01-13 10:40 - 2014-01-13 10:41 - 00050913 _____ C:\Documents and Settings\owner\Plocha\Addition.txt
    2014-01-13 10:39 - 2014-01-15 17:38 - 00023970 _____ C:\Documents and Settings\owner\Plocha\FRST.txt
    2014-01-13 10:37 - 2014-01-13 10:37 - 00015327 _____ C:\Documents and Settings\owner\Plocha\LM.bat
    2013-12-28 19:46 - 2013-12-28 19:46 - 00000000 ____D C:\Documents and Settings\NetworkService\Data aplikací\AVG
    2013-12-27 19:46 - 2013-12-27 19:46 - 00000000 ____D C:\Documents and Settings\owner\Local Settings\Data aplikací\Avg2014
    2013-12-27 19:23 - 2013-12-27 19:23 - 00000000 ____D C:\Documents and Settings\owner\Data aplikací\AVG
    2013-12-27 19:19 - 2013-12-27 19:24 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AVG
    2013-12-27 19:19 - 2013-12-27 19:19 - 00000000 __SHD C:\Documents and Settings\All Users\Data aplikací\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
    2013-12-20 18:37 - 2013-12-20 18:37 - 00000000 ____D C:\Program Files\WebexpEnhancedV1
    
    Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\WINDOWS\Tasks\AmiUpdXp.job => C:\Documents and Settings\owner\Data aplikací\SwvUpdater\Updater.exe <==== ATTENTION
    Task: C:\WINDOWS\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
    Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => C:\WINDOWS\TEMP\{8BD110E1-DF66-44BE-B7AA-8CBF2F202D83}.exe
    Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\WINDOWS\TEMP\{5AB13F25-67BF-4035-BABC-9FFB51B20D43}.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-823518204-1417001333-725345543-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
    Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-823518204-1417001333-725345543-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
    Task: C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-823518204-1417001333-725345543-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
    Task: C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-823518204-1417001333-725345543-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
    Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{E979B337-9A3F-438E-87C7-6198BD462FFC}.job => C:\WINDOWS\system32\msfeedssync.exe
    
    AlternateDataStreams: C:\Documents and Settings\All Users\Data aplikací\TEMP:73B1147D
    
    REG: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List" /v "5985:TCP" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List" /v "80:TCP" /f
    
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

valf
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 11 Led 2014 18:28

Re: odstranění malware rvzr-a.akamaihd.net

#19 Příspěvek od valf »

Dobrý večer,
vypadá to, že jsem za vodou, zatím se všechny neřesti na PC ztratily, nerad bych to zakřik´, moc děkuju za pomoc.
Zdraví
valf






Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 15-01-2014 03
Ran by owner at 2014-01-16 13:03:07 Run:1
Running from C:\Documents and Settings\owner\Plocha
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)
HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [TkBellExe] - C:\program files\real\realplayer\update\realsched.exe [295512 2013-06-19] (RealNetworks, Inc.)
HKLM\...\Run: [seznam-listicka-distribuce] - C:\Program Files\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 0
HKLM\...\Policies\Explorer: [NoResolveSearch] 1
HKCU\...\Run: [LogitechSoftwareUpdate] - C:\Program Files\Logitech\Video\ManifestEngine.exe [196608 2005-06-08] (Logitech Inc.)
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20587168 2013-11-18] (Skype Technologies S.A.)
HKCU\...\Run: [cz.seznam.software.autoupdate] - C:\Documents and Settings\owner\Data aplikací\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKCU\...\Run: [cz.seznam.software.szndesktop] - C:\Documents and Settings\owner\Data aplikací\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKCU\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 0
HKCU\...\Policies\Explorer: [NoInstrumentation] 1
HKU\Default User\...\RunOnce: [NeroHomeFirstStart] - C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Gamma Loader.lnk
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\AVerQuick.lnk

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
HKCU\Software\Microsoft\Internet Explorer\Main,Prev Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
URLSearchHook: HKCU - (No Name) - {7757CBCC-0975-4b79-A519-90B142CA3A23} - No File
URLSearchHook: HKCU - MHURLSearchHook Class - {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Program Files\Family Toolbar\tbhelper.dll ()
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = http://search.myheritage.com?orig=ds&q={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = http://search.myheritage.com?orig=ds&q={searchTerms}
SearchScopes: HKCU - {D482BCAD-A777-451A-BB0C-46A0A8A9E5FD} URL = http://search.yahoo.com/search?fr=chr-g ... =685749&p={searchTerms}
BHO: Video Player - {19e6b0ed-4856-4cb2-8756-f72ecb172b34} - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta4\ie\VideoPlayerV3beta4.dll ()
BHO: Webexp Enhanced - {73d78f1b-734b-4529-88b2-d0b546c7e124} - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha801\ie\WebexpEnhancedV1alpha801.dll ()
Toolbar: HKCU - No Name - {EFA17369-CDC0-4927-9AFC-BAAD1F96B2AE} - No File

FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=
FF Plugin: @IObitBar.com/Plugin - C:\Program Files\IObitBar\toolbar\1.bin\NPi0Stub.dll No File
FF HKLM\...\Firefox\Extensions: [i0ffxtbr@IObitBar.com] - C:\Program Files\IObitBar\toolbar\1.bin
FF HKLM\...\Firefox\Extensions: [ext@bettersurfplus.com] - C:\Program Files\BetterSurf\BetterSurfPlus\ff
FF HKLM\...\Firefox\Extensions: [ext@WebexpEnhancedV1alpha801.net] - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha801\ff
FF Extension: Webexp Enhanced - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha801\ff [2013-12-20]
FF HKLM\...\Firefox\Extensions: [ext@VideoPlayerV3beta4.net] - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta4\ff
FF Extension: Video Player - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta4\ff [2014-01-10]

R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] ()
S2 SecureUpdateSvc; C:\Program Files\Secure Speed Dial\IE\SecureUpdate.exe [x]
S3 cpuz134; \??\C:\DOCUME~1\owner\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys [x]
S4 InCDFs; system32\drivers\InCDFs.sys [x]
S1 InCDPass; system32\drivers\InCDPass.sys [x]
S1 InCDRm; system32\drivers\InCDRm.sys [x]
S4 IntelIde; No ImagePath
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [x]
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [x]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [x]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [x]

C:\Program Files\BetterSurf
C:\Program Files\VideoPlayerV3
2014-01-13 22:23 - 2014-01-13 22:23 - 00010581 _____ C:\JRT.txt
2014-01-13 22:13 - 2014-01-13 22:13 - 00006366 _____ C:\sc-cleaner1.txt
2014-01-13 21:54 - 2014-01-13 21:54 - 00006366 _____ C:\sc-cleaner.txt
2014-01-13 21:48 - 2014-01-13 21:44 - 01236282 _____ C:\Documents and Settings\owner\Plocha\adwcleaner.exe
2014-01-13 21:47 - 2014-01-13 21:44 - 01037068 _____ (Thisisu) C:\Documents and Settings\owner\Plocha\JRT.exe
2014-01-13 21:46 - 2014-01-13 21:43 - 00406264 _____ (Bleeping Computer, LLC) C:\Documents and Settings\owner\Plocha\sc-cleaner.exe
2014-01-13 15:33 - 2014-01-13 15:33 - 00008113 _____ C:\Documents and Settings\owner\Plocha\Addition.zip
2014-01-13 10:40 - 2014-01-13 10:41 - 00050913 _____ C:\Documents and Settings\owner\Plocha\Addition.txt
2014-01-13 10:39 - 2014-01-15 17:38 - 00023970 _____ C:\Documents and Settings\owner\Plocha\FRST.txt
2014-01-13 10:37 - 2014-01-13 10:37 - 00015327 _____ C:\Documents and Settings\owner\Plocha\LM.bat
2013-12-28 19:46 - 2013-12-28 19:46 - 00000000 ____D C:\Documents and Settings\NetworkService\Data aplikací\AVG
2013-12-27 19:46 - 2013-12-27 19:46 - 00000000 ____D C:\Documents and Settings\owner\Local Settings\Data aplikací\Avg2014
2013-12-27 19:23 - 2013-12-27 19:23 - 00000000 ____D C:\Documents and Settings\owner\Data aplikací\AVG
2013-12-27 19:19 - 2013-12-27 19:24 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AVG
2013-12-27 19:19 - 2013-12-27 19:19 - 00000000 __SHD C:\Documents and Settings\All Users\Data aplikací\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2013-12-20 18:37 - 2013-12-20 18:37 - 00000000 ____D C:\Program Files\WebexpEnhancedV1

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\AmiUpdXp.job => C:\Documents and Settings\owner\Data aplikací\SwvUpdater\Updater.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => C:\WINDOWS\TEMP\{8BD110E1-DF66-44BE-B7AA-8CBF2F202D83}.exe
Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\WINDOWS\TEMP\{5AB13F25-67BF-4035-BABC-9FFB51B20D43}.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-823518204-1417001333-725345543-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-823518204-1417001333-725345543-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-823518204-1417001333-725345543-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-823518204-1417001333-725345543-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{E979B337-9A3F-438E-87C7-6198BD462FFC}.job => C:\WINDOWS\system32\msfeedssync.exe

AlternateDataStreams: C:\Documents and Settings\All Users\Data aplikací\TEMP:73B1147D

REG: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List" /v "5985:TCP" /f
REG: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List" /v "80:TCP" /f

*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HP Software Update => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\TkBellExe => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\seznam-listicka-distribuce => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\LinkResolveIgnoreLinkInfo => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\LogitechSoftwareUpdate => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Skype => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.autoupdate => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.szndesktop => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\LinkResolveIgnoreLinkInfo => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoInstrumentation => Value deleted successfully.
HKU\Default User\Software\Microsoft\Windows\CurrentVersion\RunOnce\\NeroHomeFirstStart => Value deleted successfully.
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Gamma Loader.lnk => Moved successfully.
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\AVerQuick.lnk => Moved successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Prev Search Page => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{7757CBCC-0975-4b79-A519-90B142CA3A23} => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} => Value deleted successfully.
HKCR\CLSID\{1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BE28C22E-F666-424d-B5FD-125C4AFEE34E} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{BE28C22E-F666-424d-B5FD-125C4AFEE34E} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BE28C22E-F666-424d-B5FD-125C4AFEE34E} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{BE28C22E-F666-424d-B5FD-125C4AFEE34E} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D482BCAD-A777-451A-BB0C-46A0A8A9E5FD} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{D482BCAD-A777-451A-BB0C-46A0A8A9E5FD} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{19e6b0ed-4856-4cb2-8756-f72ecb172b34} => Key deleted successfully.
HKCR\CLSID\{19e6b0ed-4856-4cb2-8756-f72ecb172b34} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73d78f1b-734b-4529-88b2-d0b546c7e124} => Key deleted successfully.
HKCR\CLSID\{73d78f1b-734b-4529-88b2-d0b546c7e124} => Key deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EFA17369-CDC0-4927-9AFC-BAAD1F96B2AE} => Value deleted successfully.
HKCR\CLSID\{EFA17369-CDC0-4927-9AFC-BAAD1F96B2AE} => Key not found.
Firefox Keyword.URL deleted successfully.
HKLM\Software\MozillaPlugins\@IObitBar.com/Plugin => Key deleted successfully.
C:\Program Files\IObitBar\toolbar\1.bin\NPi0Stub.dll not found.
HKLM\Software\Mozilla\Firefox\Extensions\\i0ffxtbr@IObitBar.com => Value deleted successfully.
HKLM\Software\Mozilla\Firefox\Extensions\\ext@bettersurfplus.com => Value deleted successfully.
HKLM\Software\Mozilla\Firefox\Extensions\\ext@WebexpEnhancedV1alpha801.net => Value deleted successfully.
C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha801\ff => Moved successfully.
HKLM\Software\Mozilla\Firefox\Extensions\\ext@VideoPlayerV3beta4.net => Value deleted successfully.
C:\Program Files\VideoPlayerV3\VideoPlayerV3beta4\ff => Moved successfully.
RealNetworks Downloader Resolver Service => Service deleted successfully.
SecureUpdateSvc => Service deleted successfully.
cpuz134 => Service deleted successfully.
InCDFs => Service deleted successfully.
InCDPass => Service deleted successfully.
InCDRm => Service deleted successfully.
IntelIde => Service deleted successfully.
MREMP50a64 => Service deleted successfully.
MREMPR5 => Service deleted successfully.
MRENDIS5 => Service deleted successfully.
MRESP50a64 => Service deleted successfully.
"C:\Program Files\BetterSurf" => File/Directory not found.
C:\Program Files\VideoPlayerV3 => Moved successfully.
C:\JRT.txt => Moved successfully.
C:\sc-cleaner1.txt => Moved successfully.
C:\sc-cleaner.txt => Moved successfully.
C:\Documents and Settings\owner\Plocha\adwcleaner.exe => Moved successfully.
C:\Documents and Settings\owner\Plocha\JRT.exe => Moved successfully.
C:\Documents and Settings\owner\Plocha\sc-cleaner.exe => Moved successfully.
C:\Documents and Settings\owner\Plocha\Addition.zip => Moved successfully.
C:\Documents and Settings\owner\Plocha\Addition.txt => Moved successfully.
C:\Documents and Settings\owner\Plocha\FRST.txt => Moved successfully.
C:\Documents and Settings\owner\Plocha\LM.bat => Moved successfully.
C:\Documents and Settings\NetworkService\Data aplikací\AVG => Moved successfully.
C:\Documents and Settings\owner\Local Settings\Data aplikací\Avg2014 => Moved successfully.
C:\Documents and Settings\owner\Data aplikací\AVG => Moved successfully.
C:\Documents and Settings\All Users\Data aplikací\AVG => Moved successfully.
C:\Documents and Settings\All Users\Data aplikací\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} => Moved successfully.
C:\Program Files\WebexpEnhancedV1 => Moved successfully.
C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\WINDOWS\Tasks\AmiUpdXp.job not found.
C:\WINDOWS\Tasks\avast! Emergency Update.job => Moved successfully.
C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => Moved successfully.
C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => Moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-823518204-1417001333-725345543-1003.job => Moved successfully.
C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-823518204-1417001333-725345543-1003.job => Moved successfully.
C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-823518204-1417001333-725345543-1003.job => Moved successfully.
C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-823518204-1417001333-725345543-1003.job => Moved successfully.
C:\WINDOWS\Tasks\User_Feed_Synchronization-{E979B337-9A3F-438E-87C7-6198BD462FFC}.job => Moved successfully.
C:\Documents and Settings\All Users\Data aplikací\TEMP => ":73B1147D" ADS removed successfully.

========= reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List" /v "5985:TCP" /f =========


Operace byla dokončena úspěšně.


========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List" /v "80:TCP" /f =========


Operace byla dokončena úspěšně.


========= End of Reg: =========



The system needs a manual reboot.

==== End of Fixlog ====

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: odstranění malware rvzr-a.akamaihd.net

#20 Příspěvek od vyosek »

Tak jeste uklidime :James008:

:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel èistiè
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

valf
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 11 Led 2014 18:28

Re: odstranění malware rvzr-a.akamaihd.net

#21 Příspěvek od valf »

Dobrý den,
děkuju,hlavně za trpělivost, aby se i starý pes naučil novým kouskům,jinak mám hezké vzpomínky z poč.60-tých let na Šumavskou a místo mezi Monte Bu a Veveřím.
Zdraví
valf :)

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: odstranění malware rvzr-a.akamaihd.net

#22 Příspěvek od vyosek »

Nemate zac, rad jsem pomohl :worship: Zase nekdy Obrázek

A na zaklade Pravidla o zamykani temat :lock:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zamčeno