Stránka 2 z 2

Re: Facebook VIR - prosim o kontrolu logu

Napsal: 25 črc 2011 10:45
od Caroprd111
S přebytečnými antiviry si zatím nelamte hlavu, ty odstraníme až po odvirování. :)

Znovu spusťte OTL a do spodního bílého okna vložte následující skript. Poté klikněte na Opravit, PC se restartuje, výsledný log vložte sem.

Kód: Vybrat vše

:commands
[RESETHOSTS]
[EMPTYTEMP]
[EMPTYFLASH]
[CLEARALLRESTOREPOINTS]

:OTL
SRV - File not found [Auto | Stopped] -- -- (AVGIDSAgent)
SRV - File not found [Auto | Stopped] -- -- (avgfws9)
SRV - File not found [Auto | Stopped] -- -- (avg9wd)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - File not found
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 172.16.32.250 153.19.250.100 0.0.0.0 208.67.222.222
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - File not found
[2011.07.24 16:57:37 | 000,000,000 | -H-D | C] -- C:\Windows\update.tray-12-0-lnk
[2011.07.24 16:57:37 | 000,000,000 | -H-D | C] -- C:\Windows\update.tray-12-0
[2011.07.21 12:33:12 | 004,636,907 | ---- | C] () -- C:\Windows\geoiplist
[2011.07.21 12:33:11 | 000,904,792 | ---- | C] () -- C:\Windows\geoiplist.rar
[2011.07.21 12:32:48 | 000,246,272 | ---- | C] () -- C:\Windows\unrar.exe

Re: Facebook VIR - prosim o kontrolu logu

Napsal: 25 črc 2011 11:31
od dovemonkey
provedeno :) .....výsledný log >>>


All processes killed
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: oem
->Temp folder emptied: 521860 bytes
->Temporary Internet Files folder emptied: 36729093 bytes
->Google Chrome cache emptied: 19183113 bytes
->Flash cache emptied: 896 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 4429 bytes
RecycleBin emptied: 446 bytes

Total Files Cleaned = 54,00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: oem
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0,00 mb


========== OTL ==========
Error: No service named AVGIDSAgent was found to stop!
Service\Driver key AVGIDSAgent not found.
Error: No service named avgfws9 was found to stop!
Service\Driver key avgfws9 not found.
Error: No service named avg9wd was found to stop!
Service\Driver key avg9wd not found.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ not found.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\linkscanner\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1}\ not found.
File {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - File not found not found.
C:\Windows\update.tray-12-0-lnk folder moved successfully.
C:\Windows\update.tray-12-0 folder moved successfully.
C:\Windows\geoiplist moved successfully.
C:\Windows\geoiplist.rar moved successfully.
C:\Windows\unrar.exe moved successfully.

OTL by OldTimer - Version 3.2.26.1 log created on 07252011_122603

Files\Folders moved on Reboot...
C:\Users\oem\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
C:\Users\oem\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S48OH3PM\afr[2].htm moved successfully.
File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Re: Facebook VIR - prosim o kontrolu logu

Napsal: 25 črc 2011 11:40
od Caroprd111
Obrázek Stáhněte MBAM http://www.viry.cz/forum/viewtopic.php?f=29&t=67229
  • Podle návodu v odkazu nainstalujte, poté dejte úplný sken.
  • Nic nemažte :!: MBAM má občas falešné detekce a mohl by smazat např. systémové soubory.
  • Log vložte sem.

Re: Facebook VIR - prosim o kontrolu logu

Napsal: 25 črc 2011 11:50
od dovemonkey
PC jsem projel MBAMem již v noci tady je log co to našlo...právě dělám další test...log hned vložím.....


Malwarebytes' Anti-Malware 1.51.1.1800
http://www.malwarebytes.org

Verze databáze: 7266

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

25.7.2011 1:17:21
mbam-log-2011-07-25 (01-17-21).txt

Typ: Úplná kontrola (C:\|D:\|)
Kontrolované objekty: 245625
Uplynulý čas: 54 minut, 2 sekund

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 1
Infikované soubory: 24

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
c:\Windows\rpcminer (Trojan.BCMiner) -> Quarantined and deleted successfully.

Infikované soubory:
c:\Qoobox\quarantine\C\Windows\l1rezerv.exe.vir (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\Windows\services32.exe.vir (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\Windows\sysdriver32.exe.vir (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\Windows\sysdriver32_.exe.vir (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\Windows\update.1\svchost.exe.vir (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\Windows\update.tray-12-0\svchost.exe.vir (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\Windows\update.tray-2-0\svchost.exe.vir (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Windows\update.tray-12-0-lnk\svchost.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Windows\update.tray-2-0-lnk\svchost.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
d:\filmy\facebook-pic00005267.exe (Trojan.Yimfoca) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\bitcoinmineropencl.cl (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\bitcoinminercuda_10.cubin (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\bitcoinminercuda_11.cubin (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\bitcoinminercuda_20.cubin (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\cudart32_32_16.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\curllib.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\libeay32.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\libsasl.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\openldap.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\rpcminer-4way.exe (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\rpcminer-cpu.exe (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\rpcminer-cuda.exe (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\rpcminer-opencl.exe (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\Windows\rpcminer\ssleay32.dll (Trojan.BCMiner) -> Quarantined and deleted successfully.

Re: Facebook VIR - prosim o kontrolu logu

Napsal: 25 črc 2011 11:55
od Caroprd111
Ok, neměl byste spouštět další programy bez doporučení rádce!

Re: Facebook VIR - prosim o kontrolu logu

Napsal: 25 črc 2011 13:01
od dovemonkey
JJ beru na vědomí.....tady je log. Děkuji


Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Verze databáze: 7268

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

25.7.2011 13:32:16
mbam-log-2011-07-25 (13-32-15).txt

Typ: Úplná kontrola (C:\|D:\|)
Kontrolované objekty: 246564
Uplynulý čas: 46 minut, 1 sekund

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 0

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)

Re: Facebook VIR - prosim o kontrolu logu

Napsal: 25 črc 2011 13:03
od Caroprd111
Jak se chová PC?

Re: Facebook VIR - prosim o kontrolu logu

Napsal: 25 črc 2011 13:08
od dovemonkey
Zdá se, že v pohodě :) ....

Re: Facebook VIR - prosim o kontrolu logu

Napsal: 25 črc 2011 13:17
od Caroprd111
Poprosím Vás o nový log z RSIT.

Re: Facebook VIR - prosim o kontrolu logu

Napsal: 25 črc 2011 13:27
od dovemonkey
tady je :)....


Logfile of random's system information tool 1.09 (written by random/random)
Run by oem at 2011-07-25 14:24:39
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 30 GB (60%) free of 50 GB
Total RAM: 1014 MB (30% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:24:59, on 25.7.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\oem\Desktop\RSIT.exe
C:\Program Files\trend micro\oem.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: C:\Windows\System32\avgrsstx.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

--
End of file - 3636 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-367092564-4290927158-3838574436-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-367092564-4290927158-3838574436-1000UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-07-04 820864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-07-04 820864]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2009-11-24 323640]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-09-23 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-09-23 173592]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-09-23 150552]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2011-07-06 449584]
"Malwarebytes' Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2011-07-06 1047656]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-07-04 3493720]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\oem\AppData\Local\Google\Update\GoogleUpdate.exe [2011-07-19 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
c:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2005-02-17 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & DestroyY\TeaTimer.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2011-07-24 3037696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\System32\avgrsstx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-09-23 218112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2011-07-25 203776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2011-07-25 14:24:39 ----D---- C:\rsit
2011-07-25 12:26:03 ----D---- C:\_OTL
2011-07-25 11:10:32 ----A---- C:\Windows\system32\wininet.dll
2011-07-25 11:10:32 ----A---- C:\Windows\system32\urlmon.dll
2011-07-25 11:10:32 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2011-07-25 11:10:32 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2011-07-25 11:10:32 ----A---- C:\Windows\system32\msrating.dll
2011-07-25 11:10:32 ----A---- C:\Windows\system32\msls31.dll
2011-07-25 11:10:32 ----A---- C:\Windows\system32\mshtmler.dll
2011-07-25 11:10:32 ----A---- C:\Windows\system32\msfeedssync.exe
2011-07-25 11:10:32 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-07-25 11:10:32 ----A---- C:\Windows\system32\jsproxy.dll
2011-07-25 11:10:32 ----A---- C:\Windows\system32\ieui.dll
2011-07-25 11:10:32 ----A---- C:\Windows\system32\iesysprep.dll
2011-07-25 11:10:32 ----A---- C:\Windows\system32\iertutil.dll
2011-07-25 11:10:32 ----A---- C:\Windows\system32\ieakeng.dll
2011-07-25 11:10:32 ----A---- C:\Windows\system32\IEAdvpack.dll
2011-07-25 11:10:31 ----A---- C:\Windows\system32\ieframe.dll
2011-07-25 11:10:31 ----A---- C:\Windows\system32\dxtrans.dll
2011-07-25 11:10:31 ----A---- C:\Windows\system32\dxtmsft.dll
2011-07-25 11:10:30 ----A---- C:\Windows\system32\iernonce.dll
2011-07-25 11:10:30 ----A---- C:\Windows\system32\ieapfltr.dll
2011-07-25 11:10:30 ----A---- C:\Windows\system32\ieapfltr.dat
2011-07-25 11:10:30 ----A---- C:\Windows\system32\ie4uinit.exe
2011-07-25 11:10:30 ----A---- C:\Windows\system32\icardie.dll
2011-07-25 11:10:29 ----A---- C:\Windows\system32\wextract.exe
2011-07-25 11:10:29 ----A---- C:\Windows\system32\webcheck.dll
2011-07-25 11:10:29 ----A---- C:\Windows\system32\url.dll
2011-07-25 11:10:29 ----A---- C:\Windows\system32\mshtmled.dll
2011-07-25 11:10:29 ----A---- C:\Windows\system32\licmgr10.dll
2011-07-25 11:10:29 ----A---- C:\Windows\system32\inseng.dll
2011-07-25 11:10:29 ----A---- C:\Windows\system32\iesetup.dll
2011-07-25 11:10:29 ----A---- C:\Windows\system32\iedkcs32.dll
2011-07-25 11:10:28 ----A---- C:\Windows\system32\vbscript.dll
2011-07-25 11:10:28 ----A---- C:\Windows\system32\pngfilt.dll
2011-07-25 11:10:28 ----A---- C:\Windows\system32\occache.dll
2011-07-25 11:10:28 ----A---- C:\Windows\system32\mshtml.dll
2011-07-25 11:10:28 ----A---- C:\Windows\system32\mshta.exe
2011-07-25 11:10:28 ----A---- C:\Windows\system32\msfeeds.dll
2011-07-25 11:10:28 ----A---- C:\Windows\system32\jscript9.dll
2011-07-25 11:10:28 ----A---- C:\Windows\system32\jscript.dll
2011-07-25 11:10:28 ----A---- C:\Windows\system32\imgutil.dll
2011-07-25 11:10:28 ----A---- C:\Windows\system32\iexpress.exe
2011-07-25 11:10:28 ----A---- C:\Windows\system32\ieUnatt.exe
2011-07-25 11:10:28 ----A---- C:\Windows\system32\iepeers.dll
2011-07-25 11:10:28 ----A---- C:\Windows\system32\ieakui.dll
2011-07-25 11:10:28 ----A---- C:\Windows\system32\ieaksie.dll
2011-07-25 11:10:28 ----A---- C:\Windows\system32\admparse.dll
2011-07-25 10:55:06 ----D---- C:\Windows\system32\SPReview
2011-07-25 10:54:17 ----D---- C:\Windows\system32\EventProviders
2011-07-25 02:02:31 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-07-25 02:02:30 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-07-25 02:02:28 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-07-25 02:02:25 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-07-25 02:02:24 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-07-25 02:02:20 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-07-25 02:01:32 ----A---- C:\Windows\system32\aswBoot.exe
2011-07-25 02:01:32 ----A---- C:\Windows\avastSS.scr
2011-07-25 02:01:19 ----D---- C:\ProgramData\AVAST Software
2011-07-25 02:01:19 ----D---- C:\Program Files\AVAST Software
2011-07-25 00:20:29 ----D---- C:\Users\oem\AppData\Roaming\Malwarebytes
2011-07-25 00:20:15 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2011-07-25 00:20:13 ----D---- C:\ProgramData\Malwarebytes
2011-07-25 00:20:10 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-07-25 00:20:10 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-07-25 00:10:47 ----D---- C:\Program Files\Spybot - Search & DestroyY
2011-07-24 21:26:10 ----SHD---- C:\$RECYCLE.BIN
2011-07-24 19:26:57 ----D---- C:\Windows\ERDNT
2011-07-24 19:16:56 ----D---- C:\Qoobox
2011-07-24 17:47:25 ----D---- C:\Program Files\trend micro
2011-07-24 17:18:43 ----HD---- C:\Windows\PIF
2011-07-24 17:16:26 ----D---- C:\Users\oem\AppData\Roaming\Spyware Terminator
2011-07-24 17:16:26 ----A---- C:\Windows\system32\drivers\sp_rsdrv2.sys
2011-07-24 17:16:22 ----D---- C:\ProgramData\Spyware Terminator
2011-07-24 17:16:22 ----D---- C:\Program Files\Spyware Terminator
2011-07-24 17:00:39 ----D---- C:\Program Files\Spybot - Search & DestroyS
2011-07-24 16:53:20 ----D---- C:\$AVG
2011-07-24 16:24:30 ----D---- C:\Program Files\SDHelper (Spybot - Search & Destroy)
2011-07-24 16:24:30 ----D---- C:\Program Files\Misc. Support Library (Spybot - Search & Destroy)
2011-07-24 16:24:29 ----D---- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2011-07-24 16:24:29 ----D---- C:\Program Files\File Scanner Library (Spybot - Search & Destroy)
2011-07-24 16:21:53 ----D---- C:\ProgramData\Spybot - Search & Destroy
2011-07-24 16:21:51 ----D---- C:\Program Files\Spybot - Search & Destroy
2011-07-24 15:56:04 ----D---- C:\Program Files\CCleaner
2011-07-21 12:32:50 ----D---- C:\Windows\ufa
2011-07-21 12:32:49 ----D---- C:\Windows\phoenix
2011-07-21 12:29:35 ----D---- C:\Windows\av_ico
2011-07-21 12:28:17 ----HD---- C:\Windows\update.tray-2-0-lnk
2011-07-21 12:28:17 ----HD---- C:\Windows\update.tray-2-0
2011-07-20 12:09:25 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2011-07-20 12:09:09 ----D---- C:\Program Files\DAEMON Tools Lite
2011-07-20 12:08:44 ----D---- C:\Users\oem\AppData\Roaming\DAEMON Tools Lite
2011-07-20 12:08:44 ----D---- C:\ProgramData\DAEMON Tools Lite
2011-07-14 15:35:32 ----D---- C:\Users\oem\AppData\Roaming\WinRAR
2011-07-14 15:35:26 ----D---- C:\Program Files\WinRAR
2011-07-13 09:28:24 ----A---- C:\Windows\system32\drivers\bthport.sys
2011-07-13 09:28:23 ----A---- C:\Windows\system32\fsquirt.exe
2011-07-13 09:28:23 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2011-07-13 09:28:15 ----A---- C:\Windows\system32\winsrv.dll
2011-07-13 09:28:15 ----A---- C:\Windows\system32\kernel32.dll
2011-07-13 09:28:15 ----A---- C:\Windows\system32\conhost.exe
2011-07-13 09:28:02 ----A---- C:\Windows\system32\KernelBase.dll
2011-07-13 09:28:00 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-13 09:27:59 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-13 09:27:59 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-13 09:27:59 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-07-13 09:27:59 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-13 09:27:59 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-07-13 09:27:59 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-07-13 09:27:59 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-07-13 09:27:58 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-07-13 09:27:58 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-07-13 09:27:58 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-07-13 09:27:58 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-07-13 09:27:58 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-07-13 09:27:58 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-07-13 09:27:58 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-07-13 09:27:58 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-07-13 09:27:58 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-07-13 09:27:58 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-07-13 09:27:58 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-07-13 09:27:57 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-07-13 09:27:57 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-13 09:27:57 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-07-13 09:27:57 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-13 09:27:57 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-07-13 09:27:57 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-07-13 09:27:57 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-07-13 09:27:57 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-07-13 09:27:57 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-07-13 09:27:45 ----A---- C:\Windows\system32\win32k.sys
2011-07-04 20:58:03 ----D---- C:\UP2011
2011-07-04 20:57:43 ----D---- C:\Program Files\Common Files\InstallShield
2011-06-29 22:35:29 ----A---- C:\Windows\system32\tquery.dll
2011-06-29 22:35:28 ----A---- C:\Windows\system32\mssrch.dll
2011-06-29 22:35:26 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2011-06-29 22:35:26 ----A---- C:\Windows\system32\SearchIndexer.exe
2011-06-29 22:35:25 ----A---- C:\Windows\system32\mssvp.dll
2011-06-29 22:35:25 ----A---- C:\Windows\system32\mssphtb.dll
2011-06-29 22:35:25 ----A---- C:\Windows\system32\mssph.dll
2011-06-29 22:35:24 ----A---- C:\Windows\system32\SearchFilterHost.exe
2011-06-29 22:35:22 ----A---- C:\Windows\system32\msscntrs.dll
2011-06-29 22:34:21 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-06-29 22:34:20 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2011-06-29 22:34:20 ----A---- C:\Windows\system32\drivers\afd.sys
2011-06-29 22:33:22 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-06-29 22:33:22 ----A---- C:\Windows\system32\cfgmgr32.dll
2011-06-29 22:32:46 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-06-29 22:32:46 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-06-29 22:32:46 ----A---- C:\Windows\system32\drivers\srv.sys
2011-06-29 22:31:13 ----A---- C:\Windows\system32\oleaut32.dll
2011-06-29 22:31:10 ----A---- C:\Windows\system32\inetcomm.dll
2011-06-29 22:31:07 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-06-29 22:31:07 ----A---- C:\Windows\system32\d3d10_1.dll
2011-06-29 22:28:56 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-06-29 22:28:55 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-06-29 22:28:54 ----A---- C:\Windows\system32\drivers\mrxsmb.sys

======List of files/folders modified in the last 1 month======

2011-07-25 14:24:55 ----D---- C:\Windows\Prefetch
2011-07-25 14:24:50 ----D---- C:\Windows\Temp
2011-07-25 14:03:04 ----D---- C:\Windows\system32\config
2011-07-25 13:53:02 ----D---- C:\Windows\system32\catroot2
2011-07-25 13:53:02 ----D---- C:\Windows\system32\catroot
2011-07-25 13:31:29 ----D---- C:\Windows\Microsoft.NET
2011-07-25 13:28:57 ----RSD---- C:\Windows\assembly
2011-07-25 12:33:21 ----D---- C:\Windows\System32
2011-07-25 12:33:21 ----D---- C:\Windows\inf
2011-07-25 12:33:21 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-25 12:26:50 ----D---- C:\Windows
2011-07-25 12:26:08 ----D---- C:\Windows\system32\drivers\etc
2011-07-25 12:15:30 ----D---- C:\Windows\winsxs
2011-07-25 11:55:23 ----D---- C:\Windows\system32\migration
2011-07-25 11:55:23 ----D---- C:\Windows\system32\cs-CZ
2011-07-25 11:55:23 ----D---- C:\Windows\PolicyDefinitions
2011-07-25 11:55:23 ----D---- C:\Program Files\Internet Explorer
2011-07-25 11:55:22 ----D---- C:\Windows\system32\en-US
2011-07-25 11:52:12 ----D---- C:\Windows\system32\DriverStore
2011-07-25 11:22:18 ----D---- C:\Program Files\Windows Sidebar
2011-07-25 11:22:18 ----D---- C:\Program Files\Windows Portable Devices
2011-07-25 11:22:18 ----D---- C:\Program Files\Windows Media Player
2011-07-25 11:22:18 ----D---- C:\Program Files\Windows Mail
2011-07-25 11:22:18 ----D---- C:\Program Files\DVD Maker
2011-07-25 11:22:17 ----D---- C:\Program Files\Windows Photo Viewer
2011-07-25 11:22:17 ----D---- C:\Program Files\Windows Journal
2011-07-25 11:22:15 ----D---- C:\Windows\servicing
2011-07-25 11:22:15 ----D---- C:\Windows\ehome
2011-07-25 11:22:15 ----D---- C:\Program Files\Windows Defender
2011-07-25 11:22:09 ----D---- C:\Windows\system32\sysprep
2011-07-25 11:22:09 ----D---- C:\Windows\system32\oobe
2011-07-25 11:22:09 ----D---- C:\Windows\system32\da-DK
2011-07-25 11:22:05 ----D---- C:\Windows\system32\Setup
2011-07-25 11:22:05 ----D---- C:\Windows\system32\cs
2011-07-25 11:22:05 ----D---- C:\Windows\system32\AdvancedInstallers
2011-07-25 11:22:02 ----D---- C:\Windows\system32\sppui
2011-07-25 11:22:02 ----D---- C:\Windows\system32\manifeststore
2011-07-25 11:22:02 ----D---- C:\Windows\system32\es-ES
2011-07-25 11:22:01 ----D---- C:\Windows\system32\drivers\cs-CZ
2011-07-25 11:22:01 ----AD---- C:\Windows\system32\drivers
2011-07-25 11:22:00 ----D---- C:\Windows\system32\wbem
2011-07-25 11:21:59 ----D---- C:\Windows\system32\migwiz
2011-07-25 11:21:59 ----D---- C:\Windows\system32\Dism
2011-07-25 11:21:29 ----RSD---- C:\Windows\Fonts
2011-07-25 11:21:28 ----D---- C:\Windows\AppPatch
2011-07-25 11:21:14 ----D---- C:\Windows\system32\Boot
2011-07-25 11:11:48 ----D---- C:\Windows\Logs
2011-07-25 11:04:53 ----A---- C:\Windows\system32\msclmd.dll
2011-07-25 10:55:03 ----SHD---- C:\System Volume Information
2011-07-25 10:54:09 ----SHD---- C:\Windows\Installer
2011-07-25 10:54:09 ----D---- C:\Config.Msi
2011-07-25 10:54:08 ----D---- C:\Program Files\Microsoft Office
2011-07-25 02:09:11 ----D---- C:\Windows\system32\Tasks
2011-07-25 02:01:19 ----RD---- C:\Program Files
2011-07-25 02:01:19 ----D---- C:\ProgramData
2011-07-25 01:34:38 ----D---- C:\Windows\debug
2011-07-25 01:18:54 ----D---- C:\Windows\Tasks
2011-07-24 21:19:47 ----A---- C:\Windows\system.ini
2011-07-24 21:09:42 ----D---- C:\Program Files\Common Files
2011-07-24 19:28:12 ----SHDC---- C:\Windows\$NtUninstallKB27084$
2011-07-24 16:41:22 ----SD---- C:\Users\oem\AppData\Roaming\Microsoft
2011-07-13 17:26:10 ----D---- C:\Users\oem\AppData\Roaming\vlc
2011-07-13 14:35:22 ----A---- C:\Windows\system32\MRT.exe
2011-07-13 14:34:55 ----D---- C:\ProgramData\Microsoft Help
2011-07-05 17:08:14 ----D---- C:\Windows\system32\NDF
2011-07-04 21:01:57 ----HD---- C:\Program Files\InstallShield Installation Information
2011-07-01 10:12:22 ----D---- C:\ProgramData\Adobe
2011-06-29 23:33:47 ----D---- C:\Program Files\Common Files\microsoft shared

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 BTHidEnum;Bluetooth HID Enumerator; C:\Windows\System32\Drivers\vbtenum.sys [2007-03-05 20880]
R0 BTHidMgr;Bluetooth HID Manager Service; C:\Windows\System32\Drivers\BTHidMgr.sys [2007-03-05 35600]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-07-04 25432]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-07-04 441176]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-07-04 309848]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-07-04 43608]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-07-20 218688]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-11-16 108792]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-07-04 19544]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-07-04 54104]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-11-16 116520]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2009-11-16 95896]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2006-11-16 32256]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2006-11-16 43520]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2006-11-16 37376]
R3 BCM43XX;Broadcom 802.11 – ovladač síťového adaptéru; C:\Windows\system32\DRIVERS\bcmwl6.sys [2009-07-14 1131008]
R3 BlueletAudio;Bluetooth Audio Service; C:\Windows\system32\DRIVERS\blueletaudio.sys [2007-05-11 34704]
R3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\Windows\system32\DRIVERS\BlueletSCOAudio.sys [2007-03-05 27792]
R3 BT;Bluetooth PAN Network Adapter; C:\Windows\system32\DRIVERS\btnetdrv.sys [2007-03-05 18320]
R3 HBtnKey;HBtnKey; C:\Windows\system32\DRIVERS\cpqbttn.sys [2009-04-20 9344]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2009-04-29 15872]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-09-23 4808192]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2011-07-06 22712]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\Windows\System32\Drivers\RootMdm.sys [2009-07-14 8192]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-14 139776]
R3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 84992]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2009-07-14 1068032]
R3 VComm;Virtual Serial port driver; C:\Windows\system32\DRIVERS\VComm.sys [2007-03-05 34448]
R3 VcommMgr;Bluetooth VComm Manager Service; C:\Windows\System32\Drivers\VcommMgr.sys [2007-03-05 44304]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 14336]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 .1394ohci;.1394ohci; \* []
S3 .HDAudBus;.HDAudBus; \* []
S3 .usbhub;.usbhub; \* []
S3 AF15BDA;AF9015 BDA Device; C:\Windows\system32\DRIVERS\AF15BDA.sys [2011-01-13 483200]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\Windows\System32\Drivers\btcusb.sys [2007-05-09 36496]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 393728]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-07-04 42184]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-11-30 1343400]

-----------------EOF-----------------

Re: Facebook VIR - prosim o kontrolu logu

Napsal: 25 črc 2011 19:30
od Caroprd111
Obrázek Odinstalujte ComboFix přes:
Start >> Spustit, zkopírujte do okénka:

ComboFix /Uninstall

stiskněte Enter



Obrázek Stáhněte T-Cleaner http://sweb.cz/Marinus/T-Cleaner.exe
  • Spusťte, pro potvrzení volby mačkejte klávesu A, Enter
  • Po použití program vymažte. Pozor, antiviry ho mohou falešně označit za vir.

Obrázek Stáhněte TFC http://oldtimer.geekstogo.com/TFC.exe
  • Spusťte.
  • Klikněte na "Start". Potvrďte hlášku kliknutím na "Ok" (Bude následovat restart)

Obrázek Stáhněte OTC http://oldtimer.geekstogo.com/OTC.exe
  • Spusťte.
  • Klikněte na "CleanUp!". Potvrďte hlášky kliknutím na "Yes" (Bude následovat restart)


Obrázek Stáhněte Ccleaner http://viry.cz/forum/viewtopic.php?t=7478
Obrázek Záložka Čistič
  • Dejte analyzovat, po dokončení dejte Spustit Ccleaner.

    Obrázek Záložka Registry
  • Klikněte na Hledej problémy, po dokončení klikněte na Opravit problémy, zálohu dělat nemusíte, potom dejte Opravit všechny problémy.
Obrázek OK Obrázek Zavřít

Re: Facebook VIR - prosim o kontrolu logu

Napsal: 25 črc 2011 21:02
od dovemonkey
Krom Uninstall Combofixu (nešlo to), provedeno vše :).....ještě něco ?? .....jinak mockrát děkuji za pomoc a ochotu :)

Re: Facebook VIR - prosim o kontrolu logu

Napsal: 25 črc 2011 21:05
od Caroprd111
Je to vše. :) Nemáte zač. :)