Re: Zdravím a prosím o kontrolu. Předem díky
Napsal: 28 lis 2012 20:15
Navíc nejde ani vypnout ve správci úloh
Pomáháme v boji s počítačovou havěti!
https://forum.viry.cz:443/
Kód: Vybrat vše
:otl
MOD - [2012.11.28 15:57:40 | 001,024,024 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\windows._cacheinvalidation.pyd
MOD - [2012.11.28 15:57:40 | 000,792,576 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\wx._gdi_.pyd
MOD - [2012.11.28 15:57:40 | 000,571,392 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\pysqlite2._sqlite.pyd
MOD - [2012.11.28 15:57:40 | 000,263,168 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\win32com.shell.shell.pyd
MOD - [2012.11.28 15:57:40 | 000,096,256 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\win32api.pyd
MOD - [2012.11.28 15:57:40 | 000,086,016 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\_elementtree.pyd
MOD - [2012.11.28 15:57:40 | 000,070,656 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\wx._html2.pyd
MOD - [2012.11.28 15:57:40 | 000,040,448 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\_socket.pyd
MOD - [2012.11.28 15:57:40 | 000,023,040 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\win32ts.pyd
MOD - [2012.11.28 15:57:40 | 000,011,776 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\win32crypt.pyd
MOD - [2012.11.28 15:57:39 | 001,169,408 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\wx._core_.pyd
MOD - [2012.11.28 15:57:39 | 000,807,424 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\wx._windows_.pyd
MOD - [2012.11.28 15:57:39 | 000,731,136 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\wx._misc_.pyd
MOD - [2012.11.28 15:57:39 | 000,645,120 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\_ssl.pyd
MOD - [2012.11.28 15:57:39 | 000,354,304 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\pythoncom26.dll
MOD - [2012.11.28 15:57:39 | 000,311,808 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\_hashlib.pyd
MOD - [2012.11.28 15:57:39 | 000,121,856 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\wx._wizard.pyd
MOD - [2012.11.28 15:57:39 | 000,111,104 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\win32file.pyd
MOD - [2012.11.28 15:57:39 | 000,110,592 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\win32security.pyd
MOD - [2012.11.28 15:57:39 | 000,110,592 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\pywintypes26.dll
MOD - [2012.11.28 15:57:39 | 000,073,728 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\_ctypes.pyd
MOD - [2012.11.28 15:57:39 | 000,039,424 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\win32inet.pyd
MOD - [2012.11.28 15:57:39 | 000,036,352 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\win32process.pyd
MOD - [2012.11.28 15:57:39 | 000,022,528 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\win32pdh.pyd
MOD - [2012.11.28 15:57:39 | 000,017,920 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\win32profile.pyd
MOD - [2012.11.28 15:57:38 | 001,056,256 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\wx._controls_.pyd
MOD - [2012.11.28 15:57:38 | 000,585,728 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\unicodedata.pyd
MOD - [2012.11.28 15:57:38 | 000,153,088 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\pyexpat.pyd
MOD - [2012.11.28 15:57:38 | 000,017,920 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\win32event.pyd
MOD - [2012.11.28 15:57:38 | 000,011,776 | ---- | M] () -- C:\Users\noname\AppData\Local\Temp\_MEI10842\select.pyd
SRV - File not found [Auto | Stopped] -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\avp.exe -- (AVP)
SRV - [2012.10.06 17:01:48 | 003,084,176 | ---- | M] (Emsisoft GmbH) [Auto | Running] -- C:\Program Files\Emsisoft Anti-Malware\a2service.exe -- (a2AntiMalware)
DRV - [2011.05.19 13:10:34 | 000,017,904 | ---- | M] (Emsi Software GmbH) [Kernel | System | Running] -- C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys -- (A2DDA)
DRV - [2010.05.05 08:40:32 | 000,011,776 | ---- | M] (Emsi Software GmbH) [Kernel | System | Running] -- C:\Program Files\Emsisoft Anti-Malware\a2util32.sys -- (a2util)
DRV - [2009.11.02 20:27:16 | 000,019,984 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\klmouflt.sys -- (klmouflt)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-639110540-3213493223-2817070946-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-639110540-3213493223-2817070946-1000\..\SearchScopes\{B6F86392-1B41-46F9-907E-23D00B97D55D}: "URL" = http://www.google.cz/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
IE - HKU\S-1-5-21-639110540-3213493223-2817070946-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
CHR - homepage: http://www.ask.com/?l=dis&o=14597cr
CHR - homepage: http://www.ask.com/?l=dis&o=14597cr
O4 - HKLM..\Run: [emsisoft anti-malware] c:\program files\emsisoft anti-malware\a2guard.exe (Emsisoft GmbH)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
[2011.07.23 11:08:39 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\AVG10
[2012.10.31 15:52:14 | 000,000,000 | ---D | M] -- C:\Users\noname\AppData\Roaming\Ad-Aware Antivirus
[2011.02.09 14:37:03 | 000,000,000 | ---D | M] -- C:\Users\noname\AppData\Roaming\AVG10
[2012.09.25 13:31:51 | 000,000,000 | ---D | M] -- C:\Users\noname\AppData\Roaming\ESET
[24 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[26 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[2 C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\*.tmp files -> C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\*.tmp -> ]
[3 C:\Windows\System32\spool\PRINTERS\*.tmp files -> C:\Windows\System32\spool\PRINTERS\*.tmp -> ]
[2012.06.26 15:03:16 | 000,106,960 | ---- | M] () -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\FirmwareUpdate\AgentInstaller.exe
[2012.06.26 15:03:16 | 000,101,328 | ---- | M] () -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\FirmwareUpdate\AgentUpdate.exe
[2012.07.02 16:12:50 | 000,183,736 | ---- | M] () -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\FirmwareUpdate\BinaryLoaderMgr.exe
[2012.07.02 16:12:50 | 000,021,432 | ---- | M] () -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\FirmwareUpdate\KiesPDLR.exe
[2012.07.02 16:12:52 | 003,742,648 | ---- | M] (Freeware) -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\MediaModules\MyFreeCodecPack.exe
[2012.07.02 16:12:54 | 000,449,976 | ---- | M] (ml) -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\Updater\Kies.Update.exe
[2012.08.07 06:25:02 | 000,960,440 | ---- | M] (Samsung) -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\Kies.exe
[2012.08.07 06:25:04 | 000,278,968 | ---- | M] () -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\KiesDriverInstaller.exe
[2012.07.30 06:17:50 | 000,320,512 | ---- | M] (Samsung) -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\KiesLogger.exe
[2012.08.07 06:25:02 | 003,524,536 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\KiesTrayAgent.exe
[2012.08.07 06:11:30 | 000,182,784 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\DeviceModules\ConnectionManager.exe
[2012.08.07 06:17:30 | 000,322,048 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\DeviceModules\DeviceDataService.exe
[2012.08.07 06:12:24 | 000,717,312 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\DeviceModules\DeviceManager.exe
[2012.08.07 06:25:06 | 000,067,512 | ---- | M] (Samsung) -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\DeviceModules\Kies_Tutorial.exe
[2012.07.30 06:17:10 | 000,057,344 | ---- | M] () -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\DeviceModules\RegisterCOM.exe
[2012.08.03 07:42:04 | 000,106,960 | ---- | M] () -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\FirmwareUpdate\AgentInstaller.exe
[2012.08.03 07:42:04 | 000,101,328 | ---- | M] () -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\FirmwareUpdate\AgentUpdate.exe
[2012.08.07 06:25:10 | 000,183,736 | ---- | M] () -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\FirmwareUpdate\BinaryLoaderMgr.exe
[2012.08.07 06:25:12 | 000,021,432 | ---- | M] () -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\FirmwareUpdate\KiesPDLR.exe
[2012.08.07 06:25:12 | 003,742,648 | ---- | M] (Freeware) -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\MediaModules\MyFreeCodecPack.exe
[2012.07.30 06:16:18 | 000,172,032 | ---- | M] (Musiccity Co.Ltd.) -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\System32\muzapp.exe
[2012.08.07 06:25:14 | 000,593,848 | ---- | M] (ml) -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\Updater\Kies.Update.exe
[2012.07.02 16:12:54 | 000,449,976 | ---- | M] (ml) -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Temp\Kies.Update.exe
[2012.08.07 06:25:14 | 000,593,848 | ---- | M] (ml) -- C:\Users\noname\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.Update.exe
[2012.11.28 15:57:31 | 000,000,936 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012.11.28 16:33:04 | 000,000,940 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2012.11.25 09:51:12 | 000,000,914 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-639110540-3213493223-2817070946-1000Core.job
[2012.11.28 16:15:11 | 000,000,966 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-639110540-3213493223-2817070946-1000UA.job
[2012.11.26 15:01:32 | 000,000,324 | ---- | M] () -- C:\Windows\Tasks\HPCeeScheduleFornoname.job
@Alternate Data Stream - 6248 bytes -> C:\Windows\PLA\System\System Diagnostics.xml:0v1ieca3Feahez0jAwxjjk5uRh
@Alternate Data Stream - 150 bytes -> C:\ProgramData\TEMP:CB0AACC9
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:0E08FC17
:files
C:\Program Files\Emsisoft Anti-Malware
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp
:commands
[RESETHOSTS]
[EMPTYTEMP]
[EMPTYFLASH]
[EMPTYJAVA]