Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Avast hlásí útok adware.

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
DJFil
Návštěvník
Návštěvník
Příspěvky: 122
Registrován: 12 říj 2006 21:01

Re: Avast hlásí útok adware.

#16 Příspěvek od DJFil »

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-01-2015
Ran by Filip at 2015-01-01 23:42:40
Running from C:\Users\Filip\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

777 ShowSoft v3 (HKLM-x32\...\{9352B83B-D6E4-4EB1-9908-B79592A3782B}_is1) (Version: 3.4.2 - 777-Systems N.V.)
777 ShowSoft v3 (HKLM-x32\...\AirShowsoft) (Version: 3.3.5 - UNKNOWN)
777 ShowSoft v3 (x32 Version: 3.3.5 - UNKNOWN) Hidden
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 15.0.0.356 - Adobe Systems Incorporated)
Adobe Flash Media Live Encoder 3.2 (HKLM-x32\...\{0659E943-DDF4-44FC-9FEE-A13B09F8BB08}) (Version: 3.2.0 - Adobe Systems Incorporated)
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.246 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.246 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
AirLive X.USB (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 7.0 - OvisLink)
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{0A1FAC46-B899-421D-B1A2-470896DC45DB}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{E68DD413-B834-4923-8181-0A03B7555187}) (Version: - Microsoft)
Avast Free Antivirus (HKLM-x32\...\avast) (Version: 10.0.2208 - AVAST Software)
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.68.1077 - AB Team, d.o.o.)
CameraHelperMsi (x32 Version: 13.51.815.0 - Logitech) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.01 - Piriform)
CPUID CPU-Z 1.62 (HKLM\...\CPUID CPU-Z_is1) (Version: - )
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.47.1.0335 - Disc Soft Ltd)
DesetiPrsty5 5.3 (HKLM-x32\...\DesetiPrsty5) (Version: - )
DuckTales Remastered (HKLM-x32\...\RHVja1RhbGVzUmVtYXN0ZXJlZA==_is1) (Version: 1 - )
erLT (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
FIFA 13 (HKLM-x32\...\{A29E18C2-7AB1-4b6b-848C-5D5E2C85F0C0}) (Version: 1.5.0.0 - Electronic Arts)
FIFA 14 1.2 (HKLM-x32\...\FIFA 14_is1) (Version: - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.95 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
IHF Handball Challenge 14 (HKLM-x32\...\IHF Handball Challenge 14_is1) (Version: - )
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.18.10.3215 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.66956 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation)
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: - )
iSpy (HKLM-x32\...\{88964344-7E39-457C-BBA3-CA5188538884}) (Version: 6.2.5 - iSpy)
Java 7 Update 21 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217017FF}) (Version: 7.0.210 - Oracle)
JavaFX 2.1.0 (HKLM-x32\...\{1111706F-666A-4037-7777-210328764D10}) (Version: 2.1.0 - Oracle Corporation)
jetAudio Basic (HKLM-x32\...\{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}) (Version: 8.1.0 - COWON)
Live-Strip.com Sendertool (HKLM-x32\...\{D911FE2B-44E3-420F-8157-30D93F4A5DE7}) (Version: 2.1.8 - CAM-CONTENT S.L.)
LiveStripSplitter (HKLM-x32\...\{7C8AACCD-584F-45D5-953C-4B808A4D344E}) (Version: 1.0.3 - CAM-CONTENT S.L.)
Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.51 - Logitech Inc.)
Marvell Miniport Driver (HKLM-x32\...\Marvell Miniport Driver) (Version: 11.45.4.3 - Marvell)
MediaCoder 0.8.28.5582 (HKLM-x32\...\MediaCoder) (Version: 0.8.28.5582 - Mediatronic)
MediaCoder x64 0.8.28.5582 (HKLM\...\MediaCoder x64) (Version: 0.8.28.5582 - Mediatronic)
Microsoft .NET Framework 4.5.1 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Windows Media Video 9 VCM (HKLM-x32\...\WMV9_VCM) (Version: - )
Mozilla Firefox 34.0.5 (x86 cs) (HKLM-x32\...\Mozilla Firefox 34.0.5 (x86 cs)) (Version: 34.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MXGP (HKLM-x32\...\{DDF4F25B-99A9-49EC-A6FF-ECCC92ED1181}) (Version: 6.0 - Black Box)
NVIDIA PhysX (HKLM-x32\...\{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}) (Version: 9.10.0513 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
Rayman Legends (HKLM-x32\...\UmF5bWFuTGVnZW5kcw==_is1) (Version: 1 - )
Rayman Legends CZ (HKLM\...\{AFEC7CAB-BA90-4388-91C8-A8CB2F81205D}) (Version: 1.0 - Majkumi)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.72.410.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6959 - Realtek Semiconductor Corp.)
Skype™ 6.22 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.22.107 - Skype Technologies S.A.)
SplitCam (HKLM-x32\...\SplitCam) (Version: 6.9.4.1 - SplitCam Co)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Uplay (HKLM-x32\...\Uplay) (Version: 3.0 - Ubisoft)
VISIT-X Video Splitter 9.0.1.3 (HKLM-x32\...\VISIT-X Video Splitter_is1) (Version: 9.0.1.3 - Visit-X B.V.)
VX-Software 9 v.9.1.5.6 (HKLM-x32\...\{54DDB1B0-5E5B-4637-99DD-7A364CE6A75B}}_is1) (Version: - )
VX-Tool Uploader 1.0.0.0 (HKLM-x32\...\VX-Tool Uploader) (Version: 1.0.0.0 - VISIT-X)
Windows Media Encoder 9 Series (HKLM-x32\...\Windows Media Encoder 9) (Version: - )
WinRAR 4.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-3985477195-3131831738-4107921213-1000_Classes\CLSID\{083f5ae0-2b0a-11dd-bd0b-0800200c9a66}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)

==================== Restore Points =========================

10-12-2014 13:15:52 Nainstalováno rozhraní DirectX
11-12-2014 17:33:07 Nainstalováno: FIFA 13 CZ dabing
12-12-2014 15:01:25 Windows Update
17-12-2014 19:55:08 Nainstalováno rozhraní DirectX
17-12-2014 19:57:35 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
17-12-2014 19:58:13 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005
18-12-2014 13:53:33 Windows Update
21-12-2014 19:50:47 Windows Update
26-12-2014 10:02:50 Nainstalováno rozhraní DirectX
26-12-2014 11:14:42 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
26-12-2014 11:16:03 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005
26-12-2014 11:18:29 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030
26-12-2014 21:27:24 Nainstalováno rozhraní DirectX
26-12-2014 21:44:24 Nainstalováno: Rayman Legends CZ
30-12-2014 21:53:51 zoek.exe restore point
30-12-2014 23:11:53 Restore Point Created by FRST

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2014-12-30 23:12 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {0DFB9901-3BA2-4C5B-8EE9-BB6925C0A558} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-12-12] (Piriform Ltd)
Task: {0F1037B2-C66E-463E-9B3D-F78B68550141} - System32\Tasks\{40FA150C-6BF4-4870-9034-70DB27C41389} => Firefox.exe http://ui.skype.com/ui/0/6.10.0.104/cs/ ... rogressBar
Task: {101938C8-FECD-4897-8317-F6BAB322099E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-27] (Google Inc.)
Task: {292FDD47-3ED7-4504-B6F0-720602FB173D} - System32\Tasks\{DD2E631E-76E7-4C2D-B804-D124A93273B6} => Chrome.exe http://ui.skype.com/ui/0/6.0.0.126/cs/a ... rogressBar
Task: {29EF8D87-A81B-47E5-AF62-B757FEE4F120} - System32\Tasks\{D7188A75-E3F9-46DC-8379-E3F3FBAC4E82} => Firefox.exe http://ui.skype.com/ui/0/6.10.0.104/cs/ ... rogressBar
Task: {2A7292B1-C455-44BC-87C2-F2044B84C969} - \DoctorPC_Start No Task File <==== ATTENTION
Task: {2FD03142-AE14-49E9-82DB-7BD6EDB026E4} - System32\Tasks\{F6B698F4-5CB3-4EEF-B083-DF9E3936DCD4} => Firefox.exe http://ui.skype.com/ui/0/6.10.0.104/cs/ ... rogressBar
Task: {38F96307-7DCB-4C06-A094-1239D59B61D8} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-10] (Adobe Systems Incorporated)
Task: {47AC4DC4-C93A-4CC2-9F21-4699D43D63F5} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-11-11] (AVAST Software)
Task: {52986818-FC10-410F-AF83-356976D85136} - \DoctorPC_Popup No Task File <==== ATTENTION
Task: {54B869F3-8022-43F7-88BD-544533135162} - System32\Tasks\{0C2305A5-0527-4E42-9DE8-16C8F32DD428} => Firefox.exe http://ui.skype.com/ui/0/6.16.0.105/cs/ ... rogressBar
Task: {600B24DF-3F52-474C-A296-808F1805F22B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-27] (Google Inc.)
Task: {6768E172-29BF-4456-8342-8C45D3E24E0A} - System32\Tasks\avastBCLRestartS-1-5-21-3985477195-3131831738-4107921213-1000 => Firefox.exe
Task: {6CA4D97D-2CCF-4D6A-847B-9CC3B9CF0237} - System32\Tasks\{944C02FD-DE92-4AE3-9AB9-8CF8E6C22D29} => C:\Program Files (x86)\SplitCam\SplitCam.exe [2014-09-15] (SplitCam Co.)
Task: {719D46EF-DA6E-4D76-8FBE-F116407AEE65} - System32\Tasks\{405C4407-774F-4C41-8D9B-99BB71A03D58} => pcalua.exe -a "C:\Users\Filip\Downloads\setup (1).exe" -d C:\Users\Filip\Downloads
Task: {8DF844E5-0E95-4914-B4A6-35B51A3CB837} - System32\Tasks\{AD87651E-A937-4CA2-A2A9-15A980D62BAA} => Chrome.exe http://ui.skype.com/ui/0/6.3.0.105/cs/a ... rogressBar
Task: {A944AD2E-D2C5-42CD-832D-C5ADECBD4466} - System32\Tasks\{5DFCE99A-DACA-42D5-B104-7E7A82B9A945} => C:\Program Files (x86)\SplitCam\SplitCam.exe [2014-09-15] (SplitCam Co.)
Task: {DBF4FE20-D146-49AE-888C-E4B13FDF92D6} - System32\Tasks\{064EADBF-7BE4-4860-A83D-37C2FBEC2BEA} => Firefox.exe http://ui.skype.com/ui/0/6.16.0.105/cs/ ... rogressBar
Task: {E165CF1C-BB8B-4BCF-AC48-3E0DF5AFEA1E} - System32\Tasks\{0B942AEE-69D9-4DED-BD07-41823DC75BBF} => Chrome.exe http://ui.skype.com/ui/0/6.0.0.126/cs/a ... rogressBar
Task: {ED7B347B-C8A0-442F-8D21-80DDC040E5F6} - System32\Tasks\{4EDDDE55-D69E-434F-ACEB-A7155332FD13} => pcalua.exe -a C:\Windows\system32\pcwrun.exe -c "C:\Program Files (x86)\SplitCam\SplitCam.exe"
Task: {F66239FA-AD6B-4009-A13B-2AC736B1CD5A} - System32\Tasks\{84151FB7-2691-4CB6-8B12-8B88B9C525D8} => Firefox.exe http://ui.skype.com/ui/0/5.9.0.115/cs/g ... Error=1618
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2012-05-25 21:44 - 2011-05-28 21:05 - 00164864 _____ () C:\Program Files\WinRAR\rarext.dll
2014-12-17 16:48 - 2014-12-17 16:48 - 00012520 _____ () C:\Users\Filip\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.7.3.gadget\CoreTempReader.dll
2014-12-17 16:48 - 2014-12-17 16:48 - 00015080 _____ () C:\Users\Filip\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.7.3.gadget\GetCoreTempInfoNET.dll
2014-12-17 16:48 - 2014-12-17 16:48 - 00014056 _____ () C:\Users\Filip\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.7.3.gadget\SystemInfo.dll
2012-09-13 00:38 - 2012-09-13 00:38 - 00264040 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
2014-11-11 17:53 - 2014-11-11 17:53 - 00388208 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxDDU.dll
2014-11-11 17:53 - 2014-11-11 17:53 - 05851328 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxRT.dll
2014-11-11 17:53 - 2014-11-11 17:53 - 04495336 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\x86\VBoxRT-x86.dll
2015-01-01 23:14 - 2015-01-01 23:14 - 02909696 _____ () C:\Program Files\AVAST Software\Avast\defs\15010101\algo.dll
2014-11-11 17:53 - 2014-11-11 17:53 - 38562088 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2012-09-13 00:38 - 2012-09-13 00:38 - 02144104 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtCore4.dll
2012-09-13 00:38 - 2012-09-13 00:38 - 07955304 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtGui4.dll
2012-09-13 00:38 - 2012-09-13 00:38 - 00341352 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtXml4.dll
2012-09-13 00:38 - 2012-09-13 00:38 - 00028008 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QGif4.dll
2012-09-13 00:38 - 2012-09-13 00:38 - 00127336 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QJpeg4.dll
2012-09-13 00:39 - 2012-09-13 00:39 - 00336232 _____ () C:\Program Files (x86)\Common Files\logishrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll
2014-09-15 06:17 - 2014-09-15 06:17 - 00114304 _____ () C:\Program Files (x86)\SplitCam\splitcam_hd_driver_ProxyPlugin.ax
2014-12-09 15:30 - 2014-12-09 15:30 - 03758192 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)


========================= Accounts: ==========================

Administrator (S-1-5-21-3985477195-3131831738-4107921213-500 - Administrator - Disabled)
Filip (S-1-5-21-3985477195-3131831738-4107921213-1000 - Administrator - Enabled) => C:\Users\Filip
Guest (S-1-5-21-3985477195-3131831738-4107921213-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3985477195-3131831738-4107921213-1200 - Limited - Enabled)

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (01/01/2015 00:36:38 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Generování kontextu aktivace pro C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest1 se nezdařilo. Chyba v souboru manifestu nebo zásad C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest2 na řádku C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest3.
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Součást 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

Error: (12/31/2014 00:01:39 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Generování kontextu aktivace pro C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest1 se nezdařilo. Chyba v souboru manifestu nebo zásad C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest2 na řádku C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest3.
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Součást 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

Error: (12/30/2014 11:11:53 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Chyba služby Stínová kopie svazků: Při dotazu na rozhraní IVssWriterCallback došlo k neočekávané chybě. hr = 0x80070005, Přístup byl odepřen.
.
To je často způsobeno nesprávným nastavením zabezpečení v modulu pro zápis nebo žadateli.


Operace:
Shromažďování dat modulu pro zápis

Kontext:
ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
Název modulu pro zápis: System Writer
ID instance modulu pro zápis: {80033fb3-e4ef-44a5-bd80-c67e2f6bad6f}

Error: (12/29/2014 11:19:33 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Generování kontextu aktivace pro C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest1 se nezdařilo. Chyba v souboru manifestu nebo zásad C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest2 na řádku C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest3.
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Součást 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

Error: (12/29/2014 01:36:31 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: iexplore.exe, verze: 11.0.9600.17496, časové razítko: 0x546fdf97
Název chybujícího modulu: ntdll.dll, verze: 6.1.7601.18247, časové razítko: 0x521eaf24
Kód výjimky: 0xc0000005
Posun chyby: 0x0000000000053290
ID chybujícího procesu: 0x11c8
Čas spuštění chybující aplikace: 0xiexplore.exe0
Cesta k chybující aplikaci: iexplore.exe1
Cesta k chybujícímu modulu: iexplore.exe2
ID zprávy: iexplore.exe3

Error: (12/28/2014 08:53:42 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Generování kontextu aktivace pro C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest1 se nezdařilo. Chyba v souboru manifestu nebo zásad C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest2 na řádku C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest3.
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Součást 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

Error: (12/28/2014 07:19:12 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: iexplore.exe, verze: 11.0.9600.17496, časové razítko: 0x546fdf97
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x0000000000000000
ID chybujícího procesu: 0xd48
Čas spuštění chybující aplikace: 0xiexplore.exe0
Cesta k chybující aplikaci: iexplore.exe1
Cesta k chybujícímu modulu: iexplore.exe2
ID zprávy: iexplore.exe3

Error: (12/26/2014 03:30:56 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: iexplore.exe, verze: 11.0.9600.17496, časové razítko: 0x546fdf97
Název chybujícího modulu: ntdll.dll, verze: 6.1.7601.18247, časové razítko: 0x521eaf24
Kód výjimky: 0xc0000374
Posun chyby: 0x00000000000c4102
ID chybujícího procesu: 0x1760
Čas spuštění chybující aplikace: 0xiexplore.exe0
Cesta k chybující aplikaci: iexplore.exe1
Cesta k chybujícímu modulu: iexplore.exe2
ID zprávy: iexplore.exe3

Error: (12/26/2014 01:37:25 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: LiveStrip.exe, verze: 0.0.0.0, časové razítko: 0x506285fe
Název chybujícího modulu: Adobe AIR.dll, verze: 15.0.0.356, časové razítko: 0x544f1d44
Kód výjimky: 0xc0000005
Posun chyby: 0x010544fc
ID chybujícího procesu: 0x16a0
Čas spuštění chybující aplikace: 0xLiveStrip.exe0
Cesta k chybující aplikaci: LiveStrip.exe1
Cesta k chybujícímu modulu: LiveStrip.exe2
ID zprávy: LiveStrip.exe3

Error: (12/25/2014 09:18:00 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 34.0.5.5443, časové razítko: 0x5475dd5d
Název chybujícího modulu: mozalloc.dll, verze: 34.0.5.5443, časové razítko: 0x5475d664
Kód výjimky: 0x80000003
Posun chyby: 0x00001425
ID chybujícího procesu: 0x13d4
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3


System errors:
=============
Error: (01/01/2015 11:38:15 PM) (Source: NetBT) (EventID: 4321) (User: )
Description: Název WORKGROUP :1d nelze zaregistrovat v rozhraní s IP adresou 192.168.0.12.
Počítač s IP adresou 192.168.0.13 nepovolil získání názvu
tímto počítačem.

Error: (01/01/2015 11:33:04 PM) (Source: NetBT) (EventID: 4321) (User: )
Description: Název WORKGROUP :1d nelze zaregistrovat v rozhraní s IP adresou 192.168.0.12.
Počítač s IP adresou 192.168.0.13 nepovolil získání názvu
tímto počítačem.

Error: (01/01/2015 11:33:05 PM) (Source: BROWSER) (EventID: 8009) (User: )
Description: Prohledávač se nemůže povýšit na hlavní prohledávač. Za hlavní prohledávač
se aktuálně považuje počítač FILI-PC.

Error: (01/01/2015 11:27:54 PM) (Source: NetBT) (EventID: 4321) (User: )
Description: Název WORKGROUP :1d nelze zaregistrovat v rozhraní s IP adresou 192.168.0.12.
Počítač s IP adresou 192.168.0.13 nepovolil získání názvu
tímto počítačem.

Error: (01/01/2015 11:22:44 PM) (Source: NetBT) (EventID: 4321) (User: )
Description: Název WORKGROUP :1d nelze zaregistrovat v rozhraní s IP adresou 192.168.0.12.
Počítač s IP adresou 192.168.0.13 nepovolil získání názvu
tímto počítačem.

Error: (01/01/2015 11:17:33 PM) (Source: NetBT) (EventID: 4321) (User: )
Description: Název WORKGROUP :1d nelze zaregistrovat v rozhraní s IP adresou 192.168.0.12.
Počítač s IP adresou 192.168.0.13 nepovolil získání názvu
tímto počítačem.

Error: (01/01/2015 11:12:23 PM) (Source: NetBT) (EventID: 4321) (User: )
Description: Název WORKGROUP :1d nelze zaregistrovat v rozhraní s IP adresou 192.168.0.12.
Počítač s IP adresou 192.168.0.13 nepovolil získání názvu
tímto počítačem.

Error: (01/01/2015 09:25:57 AM) (Source: BROWSER) (EventID: 8032) (User: )
Description: Službě Browser se při přenosu \Device\NetBT_Tcpip_{B1D1B5F0-A855-4160-81F8-301BCC86544E} příliš často nezdařilo načíst záložní seznam.
Záložní prohledávač bude ukončen.

Error: (12/31/2014 07:25:10 PM) (Source: Disk) (EventID: 7) (User: )
Description: Zařízení \Device\Harddisk0\DR0 má chybný blok.

Error: (12/31/2014 07:25:07 PM) (Source: Disk) (EventID: 7) (User: )
Description: Zařízení \Device\Harddisk0\DR0 má chybný blok.


Microsoft Office Sessions:
=========================

CodeIntegrity Errors:
===================================
Date: 2012-05-28 23:32:00.392
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Filip\AppData\Local\Temp\EverestDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2012-05-28 23:32:00.375
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Filip\AppData\Local\Temp\EverestDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2012-05-28 23:32:00.342
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64 because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2012-05-28 23:32:00.326
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64 because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2012-05-28 23:31:27.682
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Filip\AppData\Local\Temp\EverestDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2012-05-28 23:31:27.664
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Filip\AppData\Local\Temp\EverestDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2012-05-28 23:31:27.613
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64 because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2012-05-28 23:31:27.596
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64 because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2012-05-28 23:29:19.741
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Filip\AppData\Local\Temp\EverestDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2012-05-28 23:29:19.724
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Filip\AppData\Local\Temp\EverestDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Processor: Intel(R) Pentium(R) CPU G3420 @ 3.20GHz
Percentage of memory in use: 44%
Total physical RAM: 3958.03 MB
Available physical RAM: 2185.53 MB
Total Pagefile: 7914.23 MB
Available Pagefile: 6049.32 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: (ACER) (Fixed) (Total:465.76 GB) (Free:241.97 GB) NTFS ==>[Drive with boot components (obtained from BCD)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 7D826B35)
Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Avast hlásí útok adware.

#17 Příspěvek od vyosek »

:arrow: Kdyz hlaska vyskoci, tak prosim foto a na mail

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    CloseProcesses:
    CreateRestorePoint:
    
    HKU\S-1-5-21-3985477195-3131831738-4107921213-1000\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2015-01-01] (Google Inc.)
    
    2014-12-26 21:43 - 2014-12-26 21:43 - 00000000 ____D () C:\Users\Filip\AppData\Roaming\Majkumi
    2014-12-26 21:27 - 2014-12-26 21:27 - 00000945 _____ () C:\Users\Filip\Desktop\Uplay.lnk
    2015-01-01 23:42 - 2015-01-01 23:42 - 00012891 _____ () C:\Users\Filip\Desktop\FRST.txt
    2015-01-01 23:41 - 2015-01-01 23:41 - 00029696 _____ () C:\Users\Filip\AppData\Local\MSGBOX.EXE
    2015-01-01 23:41 - 2015-01-01 23:41 - 00015327 _____ () C:\Users\Filip\Desktop\LM.bat42015-01-01 23:40 - 2015-01-01 23:40 - 00112640 _____ (forum.viry.cz) C:\Users\Filip\Desktop\FRSTLauncher.exe
    
    2015-01-01 12:38 - 2015-01-01 23:11 - 00000946 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2015-01-01 12:38 - 2015-01-01 16:43 - 00000950 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    
    Hosts:
    EmptyTemp:
    Reboot:
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět