Ahoj, v poslednom case je notas dost spomaleny. Taktiez uz mam dlhsie nerieseny problem s nahodne vygenerovanymi prihlasovacimi uctami pri zapnuti windowsu (momentalne su 3 ucty navyse, nahodne zhluky pismen). Po odstraneni s admin. pravami sa onedlho objavia znovu. Antivirus eset nikdy nic podozrive nenasiel. RSIT je dolu:
Logfile of random's system information tool 1.10 (written by random/random)
Run by Turbo at 2017-01-18 07:51:12
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 13 GB (5%) free of 260 GB
Total RAM: 3063 MB (63% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:55:08, on 18. 1. 2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18538)
Boot mode: Normal
Running processes:
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\windows\system32\taskhost.exe
C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe
C:\Program Files\Lenovo\VeriFace\PManage.exe
C:\Program Files\Lenovo\Energy Management\utility.exe
C:\Program Files\Lenovo\Energy Management\Energy Management.exe
C:\Program Files\Lenovo\YouCam\YCMMirage.exe
C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\Users\Turbo\Downloads\RSIT.exe
C:\Program Files\trend micro\Turbo.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe
O4 - HKLM\..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [OnekeyStudio] C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe
O4 - HKLM\..\Run: [VeriFaceManager] C:\Program Files\Lenovo\VeriFace\PManage.exe
O4 - HKLM\..\Run: [EnergyUtility] C:\Program Files\Lenovo\Energy Management\utility.exe
O4 - HKLM\..\Run: [Energy Management] C:\Program Files\Lenovo\Energy Management\Energy Management.exe
O4 - HKLM\..\Run: [YouCam Mirage] "C:\Program Files\Lenovo\YouCam\YCMMirage.exe"
O4 - HKLM\..\Run: [YouCam Tray] "C:\Program Files\Lenovo\YouCam\YouCam.exe" /s
O4 - HKCU\..\Run: [Google Update] C:\Users\Turbo\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe
O4 - HKUS\S-1-5-21-3825014317-2607772001-1910489964-1018\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3825014317-2607772001-1910489964-1018\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\RunOnce: [WLStart] "C:\Program Files\Windows Live\Installer\wlstart.exe" /nosearch /nohomepage (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [WLStart] "C:\Program Files\Windows Live\Installer\wlstart.exe" /nosearch /nohomepage (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Lenovo\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\Lenovo\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDow ... rtScan.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: ܟ
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: Dragon Age: Prameny - aktualizace obsahu (DAUpdaterSvc) - BioWare - C:\Program Files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: IGRS - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe
O23 - Service: Lenovo ReadyComm AppSvc - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\AppSvc.exe
O23 - Service: Lenovo ReadyComm ConnSvc - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Wondershare Application Framework Service (WsAppService) - Wondershare - C:\Program Files\Wondershare\WAF\2.3.2.219\WsAppService.exe
O23 - Service: Wondershare Driver Install Service (WsDrvInst) - Wondershare - C:\Program Files\Wondershare\dr.fone toolkit for Android\Library\DriverInstaller\DriverInstall.exe
--
End of file - 7782 bytes
======Scheduled tasks folder======
C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-3825014317-2607772001-1910489964-1003Core1cf8f9c4007da6e.job - C:\Users\Turbo\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-3825014317-2607772001-1910489964-1003UA1ceebb13ad1ecd7.job - C:\Users\Turbo\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-3825014317-2607772001-1910489964-1003UA1cfeaab72ee63d.job - C:\Users\Turbo\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Turbo\AppData\Roaming\Mozilla\Firefox\Profiles\dku322xp.default
prefs.js - "browser.search.suggest.enabled" - false
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.facebook.com/"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.15"
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 22.0.0.209 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF32_22_0_0_209.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\windows\system32\Adobe\Director\np32dsw_1217157.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@cambridgesoft.com/Chem3D,version=12.0]
"Description"=CambridgeSoft Chem3D Plugin 12.0
"Path"=C:\Program Files\CambridgeSoft\ChemOffice2010\Chem3D\npChem3DPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@cambridgesoft.com/ChemDraw,version=12.0]
"Description"=CambridgeSoft ChemDraw Plugin 12.0
"Path"=C:\Program Files\CambridgeSoft\ChemOffice2010\ChemDraw\npcdp32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.55.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.55.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nokia.com/EnablerPlugin]
"Description"=Nokia Suite Enabler Plugin
"Path"=C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\components\
nsILegitCheckPlugin.xpt
nsIQTScriptablePlugin.xpt
C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
npLegitCheckPlugin.dll
NPOFF12.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-04-14 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-04-14 171944]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe [2009-11-16 487992]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2009-11-24 501640]
"OnekeyStudio"=C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [2009-12-19 665504]
"VeriFaceManager"=C:\Program Files\Lenovo\VeriFace\PManage.exe [2010-02-06 3122528]
"EnergyUtility"=C:\Program Files\Lenovo\Energy Management\utility.exe [2009-12-17 4114368]
"Energy Management"=C:\Program Files\Lenovo\Energy Management\Energy Management.exe [2009-12-17 6223808]
"YouCam Mirage"=C:\Program Files\Lenovo\YouCam\YCMMirage.exe [2011-01-11 136488]
"YouCam Tray"=C:\Program Files\Lenovo\YouCam\YouCam.exe [2011-01-11 228448]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Turbo\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe [2016-12-17 601752]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19 1160408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\Turbo\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-30 144200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvBackend]
C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe []
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="Üź"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=28
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.clmp3enc"=C:\PROGRA~1\Lenovo\Power2Go\CLMP3Enc.ACM
"msacm.siren"=sirenacm.dll
"vidc.XVID"=xvidvfw.dll
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"vidc.VP60"=C:\windows\system32\vp6vfw.dll
"vidc.VP61"=C:\windows\system32\vp6vfw.dll
"vidc.tscc"=tsccvid.dll
"VIDC.IV41"=IR41_32.AX
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2017-01-17 22:56:12 ----D---- C:\Program Files\Mozilla Firefox
2017-01-15 11:40:57 ----D---- C:\wxProdOp
2017-01-11 06:38:17 ----A---- C:\windows\system32\wdigest.dll
2017-01-11 06:38:17 ----A---- C:\windows\system32\TSpkg.dll
2017-01-11 06:38:17 ----A---- C:\windows\system32\sspisrv.dll
2017-01-11 06:38:17 ----A---- C:\windows\system32\sspicli.dll
2017-01-11 06:38:17 ----A---- C:\windows\system32\schannel.dll
2017-01-11 06:38:17 ----A---- C:\windows\system32\secur32.dll
2017-01-11 06:38:17 ----A---- C:\windows\system32\rpchttp.dll
2017-01-11 06:38:17 ----A---- C:\windows\system32\rpcrt4.dll
2017-01-11 06:38:17 ----A---- C:\windows\system32\ncrypt.dll
2017-01-11 06:38:17 ----A---- C:\windows\system32\msv1_0.dll
2017-01-11 06:38:17 ----A---- C:\windows\system32\msobjs.dll
2017-01-11 06:38:17 ----A---- C:\windows\system32\msaudite.dll
2017-01-11 06:38:17 ----A---- C:\windows\system32\lsass.exe
2017-01-11 06:38:17 ----A---- C:\windows\system32\lsasrv.dll
2017-01-11 06:38:17 ----A---- C:\windows\system32\kerberos.dll
2017-01-11 06:38:17 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2017-01-11 06:38:17 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2017-01-11 06:38:17 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2017-01-11 06:38:17 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2017-01-11 06:38:17 ----A---- C:\windows\system32\drivers\ksecdd.sys
2017-01-11 06:38:17 ----A---- C:\windows\system32\cryptbase.dll
2017-01-11 06:38:17 ----A---- C:\windows\system32\credssp.dll
2017-01-11 06:38:17 ----A---- C:\windows\system32\bcrypt.dll
2017-01-11 06:38:17 ----A---- C:\windows\system32\auditpol.exe
2017-01-11 06:38:17 ----A---- C:\windows\system32\adtschema.dll
2017-01-06 10:13:55 ----A---- C:\windows\system32\WinUSBCoInstaller2.dll
2017-01-06 10:13:55 ----A---- C:\windows\system32\drivers\wsadb.sys
2017-01-06 10:12:21 ----D---- C:\ProgramData\wsr
2017-01-06 10:02:03 ----D---- C:\Users\Turbo\AppData\Roaming\Wondershare
2017-01-06 10:01:51 ----D---- C:\Program Files\Wondershare
2017-01-06 10:01:50 ----D---- C:\ProgramData\Wondershare
======List of files/folders modified in the last 1 month======
2017-01-18 07:52:00 ----D---- C:\windows\temp
2017-01-18 07:51:24 ----D---- C:\Program Files\trend micro
2017-01-18 07:51:08 ----D---- C:\windows\Prefetch
2017-01-18 07:43:39 ----A---- C:\windows\wdict32.INI
2017-01-18 07:43:07 ----D---- C:\Windows
2017-01-18 07:33:34 ----D---- C:\ProgramData\VeriFace
2017-01-18 07:32:53 ----D---- C:\windows\system32\config
2017-01-18 07:31:23 ----A---- C:\windows\system32\log.txt
2017-01-18 07:31:16 ----D---- C:\ProgramData\NVIDIA
2017-01-18 07:31:05 ----D---- C:\Program Files\Mozilla Maintenance Service
2017-01-17 22:56:37 ----RD---- C:\Program Files
2017-01-17 08:26:02 ----SHD---- C:\System Volume Information
2017-01-15 11:41:05 ----RSD---- C:\windows\Fonts
2017-01-11 20:37:32 ----SHD---- C:\windows\Installer
2017-01-11 20:36:13 ----D---- C:\windows\System32
2017-01-11 20:35:30 ----D---- C:\windows\system32\Tasks
2017-01-11 17:54:17 ----D---- C:\windows\rescache
2017-01-11 17:16:59 ----D---- C:\windows\inf
2017-01-11 17:16:58 ----D---- C:\windows\debug
2017-01-11 16:49:55 ----D---- C:\windows\winsxs
2017-01-11 07:08:44 ----D---- C:\windows\system32\en-US
2017-01-11 07:08:43 ----D---- C:\windows\system32\drivers
2017-01-11 06:40:38 ----D---- C:\windows\system32\MRT
2017-01-11 06:40:28 ----AC---- C:\windows\system32\MRT.exe
2017-01-11 06:31:13 ----D---- C:\windows\system32\catroot2
2017-01-08 13:25:51 ----A---- C:\windows\system32\PerfStringBackup.INI
2017-01-08 10:09:15 ----D---- C:\Users\Turbo\AppData\Roaming\Skype
2017-01-08 09:08:52 ----D---- C:\ProgramData\Skype
2017-01-08 09:08:46 ----RD---- C:\Program Files\Skype
2017-01-06 10:37:51 ----D---- C:\ProgramData
2017-01-06 10:15:23 ----D---- C:\windows\system32\DriverStore
2017-01-04 14:12:57 ----D---- C:\Users\Turbo\AppData\Roaming\vlc
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\windows\system32\DRIVERS\epfwwfp.sys [2016-12-01 71304]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2009-12-17 433176]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\windows\System32\drivers\sfhlp02.sys [2004-10-28 6656]
R0 sptd;sptd; C:\windows\System32\Drivers\sptd.sys [2010-10-07 436792]
R1 eamonm;eamonm; C:\windows\system32\DRIVERS\eamonm.sys [2016-12-01 206472]
R1 ehdrv;ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [2016-12-01 156288]
R1 epfw;epfw; C:\windows\system32\DRIVERS\epfw.sys [2016-12-01 162952]
R1 EpfwLWF;ESET Personal Firewall; C:\windows\system32\DRIVERS\EpfwLWF.sys [2016-12-01 52872]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 lirsgt;lirsgt; C:\windows\system32\DRIVERS\lirsgt.sys [2010-06-16 18048]
R2 SVKP;SVKP; \??\C:\windows\system32\SVKP.sys [2014-03-01 2368]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\windows\system32\DRIVERS\AcpiVpc.sys [2010-01-20 23136]
R3 BCM43XX;Broadcom 802.11 - ovládač sieťového adaptéru; C:\windows\system32\DRIVERS\bcmwl6.sys [2009-11-05 2494968]
R3 clwvd;CyberLink WebCam Virtual Driver; C:\windows\system32\DRIVERS\clwvd.sys [2011-01-11 27632]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\CHDRT32.sys [2009-11-24 507392]
R3 ETD;ELAN PS/2 Port Input Device; C:\windows\system32\DRIVERS\ETD.sys [2009-11-26 119296]
R3 HECI;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECI.sys [2009-09-17 41088]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\windows\system32\drivers\nvhda32v.sys [2012-12-19 154040]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt86win7.sys [2011-06-10 394856]
R3 usbsmi;Lenovo EasyCamera; C:\windows\system32\DRIVERS\SMIksdrv.sys [2009-10-26 171776]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 14336]
R3 wdmirror;wdmirror; C:\windows\system32\DRIVERS\WDMirror.sys [2009-07-16 11792]
S0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\windows\System32\drivers\sfdrv01.sys [2004-11-25 46080]
S0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:\windows\System32\drivers\sfsync02.sys [2004-11-29 19648]
S2 atksgt;atksgt; C:\windows\system32\DRIVERS\atksgt.sys [2010-06-16 271360]
S2 Parvdm;Parvdm; C:\windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 androidusb;Google Device Driver; C:\windows\System32\Drivers\wsadb.sys [2017-01-06 34704]
S3 AVerPola;AVerMedia USB Polaris Series Capture Service; C:\windows\system32\DRIVERS\AVerPola.sys [2009-08-05 314752]
S3 AVPolCIR;AVerMedia USB Polaris Series Custom IR Service; C:\windows\system32\DRIVERS\AVPolCIR.sys [2009-08-05 32896]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 Bridge0;Bridge0; C:\windows\system32\drivers\WDBridge.sys [2009-07-28 63240]
S3 BthEnum;Bluetooth Request Block Driver; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 btusbflt;Bluetooth USB Filter; C:\windows\system32\drivers\btusbflt.sys [2010-07-04 45736]
S3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2010-07-04 86056]
S3 btwavdt;Bluetooth AVDT Service; C:\windows\system32\DRIVERS\btwavdt.sys [2010-07-04 108072]
S3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2010-07-04 29472]
S3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2010-07-04 18472]
S3 fssfltr;FssFltr; C:\windows\system32\DRIVERS\fssfltr.sys [2010-09-22 39272]
S3 gHidPnp;USB Device Enhanced Function Driver; C:\windows\System32\Drivers\gHidPnp.Sys []
S3 gMouUsb;USB Mouse Device Drv; C:\windows\system32\DRIVERS\gMouUsb.sys []
S3 hamachi;Hamachi Network Interface; C:\windows\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2009-06-10 4756480]
S3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\k57nd60x.sys [2009-07-13 229888]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\windows\system32\drivers\ccdcmb.sys [2013-01-23 18560]
S3 nmwcdc;Nokia USB Communication Driver; C:\windows\system32\drivers\ccdcmbo.sys [2013-01-23 23168]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\windows\system32\DRIVERS\pccsmcfd.sys [2012-10-17 19072]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUStor.sys [2009-12-11 182304]
S3 sisagp;SIS AGP Bus Filter; C:\windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TrueSight;TrueSight; \??\ []
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
S3 upperdev;upperdev; C:\windows\system32\DRIVERS\usbser_lowerflt.sys [2013-01-23 8192]
S3 usb_rndisx;USB RNDIS Adapter; C:\windows\system32\DRIVERS\usb8023x.sys [2013-02-12 15872]
S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2013-08-29 28160]
S3 UsbserFilt;UsbserFilt; C:\windows\system32\DRIVERS\usbser_lowerfltj.sys [2013-01-23 8192]
S3 viaagp;VIA AGP Bus Filter; C:\windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WimFltr;WimFltr; C:\windows\system32\DRIVERS\wimfltr.sys [2008-08-06 128104]
S4 ekbdflt;ekbdflt; C:\windows\system32\DRIVERS\ekbdflt.sys [2016-12-01 122496]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-12-19 82640]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service; C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-11 30312]
R2 btwdins;Bluetooth Service; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [2010-06-13 628000]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2016-12-01 2167696]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-12-23 13336]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-12-09 268824]
R2 nvsvc;NVIDIA Display Driver Service; C:\windows\system32\nvvsvc.exe [2013-08-30 662816]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-09-05 1364256]
R2 ReadyComm.DirectRouter;ReadyComm.DirectRouter; C:\windows\System32\IgrsSvcs.exe [2009-07-14 20992]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-12-10 238944]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-12-10 86880]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-08-29 414496]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-12-09 2320920]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2016-11-29 105144]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2016-09-20 324224]
S3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu; C:\Program Files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-09-22 1493352]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2016-11-12 102912]
S3 IGRS;IGRS; C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe [2009-07-14 38152]
S3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc; C:\Program Files\Lenovo\ReadyComm\AppSvc.exe [2009-08-14 509192]
S3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc; C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe [2009-09-22 579400]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2017-01-17 146888]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2009-09-26 149336]
S3 PS_MDP;ReadyComm Presentation Space Helper Service; C:\windows\System32\IgrsSvcs.exe [2009-07-14 20992]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2010-06-17 1343400]
S4 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2016-11-29 45752]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2010-12-10 44384]
S4 NetMsmqActivator;@C:\windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2016-11-29 135848]
S4 NetPipeActivator;@C:\windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2016-11-29 135848]
S4 NetTcpActivator;@C:\windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2016-11-29 135848]
-----------------EOF-----------------

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Preventivka (pravdepodobne virus)
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Preventivka (pravdepodobne virus)
ahoj,
v logu nic podozrive nevidim, preventivne prescanuj s ADWCleanerom
v logu nic podozrive nevidim, preventivne prescanuj s ADWCleanerom
FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: Preventivka (pravdepodobne virus)
# AdwCleaner v6.042 - *Logfile created 18/01/2017 *at 20:10:15
# *Updated on 06/01/2017 by Malwarebytes
# *Database : 2017-01-17.2 [*Server]
# *Operating System : Windows 7 Home Premium Service Pack 1 (X86)
# *Username : Turbo - TURBO-PC
# *Running from : C:\Users\Turbo\Downloads\adwcleaner_6.042.exe
# *Mode: Scan
# *Support : https://www.malwarebytes.com/support
***** [ *Services ] *****
*No malicious services found.
***** [ *Folders ] *****
*Folder Found: C:\ProgramData\ICQ\ICQNewTab
*Folder Found: C:\ProgramData\Application Data\ICQ\ICQNewTab
*Folder Found: C:\Users\Turbo\AppData\Roaming\Mozilla\Firefox\Profiles\dku322xp.default\CT2790392
***** [ *Files ] *****
*File Found: C:\Users\Turbo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Free Youtube Downloader.lnk
*File Found: C:\windows\Reimage.ini
***** [ DLL ] *****
*No malicious DLLs found.
***** [ WMI ] *****
*No malicious keys found.
***** [ *Shortcuts ] *****
*No infected shortcut found.
***** [ *Scheduled tasks ] *****
*No malicious task found.
***** [ *Registry ] *****
*Key Found: HKLM\SOFTWARE\Classes\Applications\iMeshSetup-r1444-n-bf.exe
*Key Found: HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine
*Key Found: HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine.1
*Key Found: HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
*Key Found: HKLM\SOFTWARE\Classes\CLSID\{6BC38BF4-E84D-46E1-920B-42D31AEA617E}
*Key Found: HKLM\SOFTWARE\Classes\CLSID\{98ED0D10-F1FC-4113-A095-9BD7F96040C9}
*Key Found: HKLM\SOFTWARE\Classes\CLSID\{B162A975-6C7C-4202-9167-306028913A3D}
*Key Found: HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
*Key Found: HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
*Key Found: HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
*Key Found: HKLM\SOFTWARE\Classes\TypeLib\{81CA8FCD-1420-4A07-B47D-B30F3DDA79E1}
*Key Found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}
*Key Found: HKU\.DEFAULT\Software\AskPartnerNetwork
*Key Found: HKU\S-1-5-21-3825014317-2607772001-1910489964-1003\Software\APN PIP
*Key Found: HKU\S-1-5-21-3825014317-2607772001-1910489964-1003\Software\Reimage
*Key Found: HKU\S-1-5-21-3825014317-2607772001-1910489964-1003\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief.
*Key Found: HKU\S-1-5-21-3825014317-2607772001-1910489964-1003\Software\Mail.Ru
*Key Found: HKU\S-1-5-21-3825014317-2607772001-1910489964-1003\Software\AppDataLow\Software\Mail.Ru
*Key Found: HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3825014317-2607772001-1910489964-1003\Software\ICQ\ICQToolbar
*Key Found: HKU\S-1-5-18\Software\AskPartnerNetwork
*Key Found: HKCU\Software\APN PIP
*Key Found: HKCU\Software\Reimage
*Key Found: HKCU\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief.
*Key Found: HKCU\Software\Mail.Ru
*Key Found: HKCU\Software\AppDataLow\Software\Mail.Ru
*Key Found: HKLM\SOFTWARE\Reimage
*Key Found: HKLM\SOFTWARE\Trymedia Systems
*Key Found: HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL
***** [ *Web browsers ] *****
*No malicious Firefox based browser items found.
*No malicious Chromium based browser items found.
*************************
C:\AdwCleaner\AdwCleaner[R3].txt - [1138 *Bytes] - [18/11/2014 21:14:47]
C:\AdwCleaner\AdwCleaner[S1].txt - [3483 *Bytes] - [18/01/2017 20:10:15]
C:\AdwCleaner\AdwCleaner[S3].txt - [1206 *Bytes] - [18/11/2014 21:19:34]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [3631 *Bytes] ##########
# *Updated on 06/01/2017 by Malwarebytes
# *Database : 2017-01-17.2 [*Server]
# *Operating System : Windows 7 Home Premium Service Pack 1 (X86)
# *Username : Turbo - TURBO-PC
# *Running from : C:\Users\Turbo\Downloads\adwcleaner_6.042.exe
# *Mode: Scan
# *Support : https://www.malwarebytes.com/support
***** [ *Services ] *****
*No malicious services found.
***** [ *Folders ] *****
*Folder Found: C:\ProgramData\ICQ\ICQNewTab
*Folder Found: C:\ProgramData\Application Data\ICQ\ICQNewTab
*Folder Found: C:\Users\Turbo\AppData\Roaming\Mozilla\Firefox\Profiles\dku322xp.default\CT2790392
***** [ *Files ] *****
*File Found: C:\Users\Turbo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Free Youtube Downloader.lnk
*File Found: C:\windows\Reimage.ini
***** [ DLL ] *****
*No malicious DLLs found.
***** [ WMI ] *****
*No malicious keys found.
***** [ *Shortcuts ] *****
*No infected shortcut found.
***** [ *Scheduled tasks ] *****
*No malicious task found.
***** [ *Registry ] *****
*Key Found: HKLM\SOFTWARE\Classes\Applications\iMeshSetup-r1444-n-bf.exe
*Key Found: HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine
*Key Found: HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine.1
*Key Found: HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
*Key Found: HKLM\SOFTWARE\Classes\CLSID\{6BC38BF4-E84D-46E1-920B-42D31AEA617E}
*Key Found: HKLM\SOFTWARE\Classes\CLSID\{98ED0D10-F1FC-4113-A095-9BD7F96040C9}
*Key Found: HKLM\SOFTWARE\Classes\CLSID\{B162A975-6C7C-4202-9167-306028913A3D}
*Key Found: HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
*Key Found: HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
*Key Found: HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
*Key Found: HKLM\SOFTWARE\Classes\TypeLib\{81CA8FCD-1420-4A07-B47D-B30F3DDA79E1}
*Key Found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}
*Key Found: HKU\.DEFAULT\Software\AskPartnerNetwork
*Key Found: HKU\S-1-5-21-3825014317-2607772001-1910489964-1003\Software\APN PIP
*Key Found: HKU\S-1-5-21-3825014317-2607772001-1910489964-1003\Software\Reimage
*Key Found: HKU\S-1-5-21-3825014317-2607772001-1910489964-1003\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief.
*Key Found: HKU\S-1-5-21-3825014317-2607772001-1910489964-1003\Software\Mail.Ru
*Key Found: HKU\S-1-5-21-3825014317-2607772001-1910489964-1003\Software\AppDataLow\Software\Mail.Ru
*Key Found: HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3825014317-2607772001-1910489964-1003\Software\ICQ\ICQToolbar
*Key Found: HKU\S-1-5-18\Software\AskPartnerNetwork
*Key Found: HKCU\Software\APN PIP
*Key Found: HKCU\Software\Reimage
*Key Found: HKCU\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief.
*Key Found: HKCU\Software\Mail.Ru
*Key Found: HKCU\Software\AppDataLow\Software\Mail.Ru
*Key Found: HKLM\SOFTWARE\Reimage
*Key Found: HKLM\SOFTWARE\Trymedia Systems
*Key Found: HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL
***** [ *Web browsers ] *****
*No malicious Firefox based browser items found.
*No malicious Chromium based browser items found.
*************************
C:\AdwCleaner\AdwCleaner[R3].txt - [1138 *Bytes] - [18/11/2014 21:14:47]
C:\AdwCleaner\AdwCleaner[S1].txt - [3483 *Bytes] - [18/01/2017 20:10:15]
C:\AdwCleaner\AdwCleaner[S3].txt - [1206 *Bytes] - [18/11/2014 21:19:34]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [3631 *Bytes] ##########
Re: Preventivka (pravdepodobne virus)
vycisti registre CCleanerom a napis, ci su este nejake problemy ?
FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: Preventivka (pravdepodobne virus)
Po vycisteni AdwCleanerom je to lepsie. CCleaner pouzivam viackrat do tyzdna (najdlhsie kontroluje Edge, ktory nepouzivam). Avsak to neriesi moj problem "s viacerymi uzivatelskymi uctami", posledny (treti) pribudol pred par mesiacmi.
Re: Preventivka (pravdepodobne virus)
toto nebude virovy problem
ucty zmaz ako administrator, ak sa objavia skus na forum.zive.cz
ucty zmaz ako administrator, ak sa objavia skus na forum.zive.cz
FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/