Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

odstranění malware rvzr-a.akamaihd.net

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: odstranění malware rvzr-a.akamaihd.net

#16 Příspěvek od vyosek »

:arrow: Ja cas mel, ale kdyz jste editoval prispevke, tak se mi to nezobrazilo jako novy a tudiz jsem nemohl reagovat

:arrow: Udelejte novy log z FRST
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

valf
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 11 led 2014 18:28

Re: odstranění malware rvzr-a.akamaihd.net

#17 Příspěvek od valf »

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-01-2014 01
Ran by owner (administrator) on ZAKAZNIK on 15-01-2014 17:38:05
Running from C:\Documents and Settings\owner\Plocha
Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) ===================

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Motive Communications, Inc.) C:\Program Files\Common Files\Motive\McciCMService.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.exe
(Logitech Inc.) C:\WINDOWS\system32\LVCOMSX.EXE
(Logitech Inc.) C:\Program Files\Logitech\Video\LogiTray.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Motive Communications, Inc.) C:\Program Files\TO2SSM\McciTrayApp.exe
(MyHeritage) C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Logitech Inc.) C:\Program Files\Logitech\Video\FxSvr2.exe
(Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
() C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
() C:\Documents and Settings\owner\Data aplikací\Seznam.cz\bin\szndesktop.exe
(Václav Šimandl) C:\Program Files\Diar 5\diar.exe
(Rainy) C:\Program Files\Rainlendar\Rainlendar.exe
(Tošovský Jan) C:\Program Files\Noční obloha\vesmir.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Farbar) C:\Documents and Settings\owner\Plocha\FRST(1).exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDCPL] - C:\Windows\RTHDCPL.EXE [16116224 2007-01-30] (Realtek Semiconductor Corp.)
HKLM\...\Run: [SkyTel] - C:\Windows\SkyTel.EXE [2879488 2006-05-16] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Alcmtr] - C:\Windows\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.)
HKLM\...\Run: [LVCOMSX] - C:\WINDOWS\system32\LVCOMSX.EXE [221184 2005-07-19] (Logitech Inc.)
HKLM\...\Run: [LogitechVideoRepair] - C:\Program Files\Logitech\Video\ISStart.exe [458752 2005-06-08] (Logitech Inc.)
HKLM\...\Run: [LogitechVideoTray] - C:\Program Files\Logitech\Video\LogiTray.exe [217088 2005-06-08] (Logitech Inc.)
HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)
HKLM\...\Run: [TO2SSM_McciTrayApp] - C:\Program Files\TO2SSM\McciTrayApp.exe [1473536 2008-08-15] (Motive Communications, Inc.)
HKLM\...\Run: [Family Tree Builder Update] - C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe [2532864 2013-11-12] (MyHeritage)
HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k
HKLM\...\Run: [REGSHAVE] - C:\Program Files\REGSHAVE\REGSHAVE.EXE [53248 2002-02-04] (FUJI PHOTO FILM CO., LTD.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [TkBellExe] - C:\program files\real\realplayer\update\realsched.exe [295512 2013-06-19] (RealNetworks, Inc.)
HKLM\...\Run: [seznam-listicka-distribuce] - C:\Program Files\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM\...\Run: [Google Desktop Search] - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [1838592 2013-09-05] (Google)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2014-01-07] (AVAST Software)
HKLM\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 0
HKLM\...\Policies\Explorer: [NoResolveSearch] 1
HKCU\...\Run: [LogitechSoftwareUpdate] - C:\Program Files\Logitech\Video\ManifestEngine.exe [196608 2005-06-08] (Logitech Inc.)
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20587168 2013-11-18] (Skype Technologies S.A.)
HKCU\...\Run: [cz.seznam.software.autoupdate] - C:\Documents and Settings\owner\Data aplikací\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKCU\...\Run: [cz.seznam.software.szndesktop] - C:\Documents and Settings\owner\Data aplikací\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKCU\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 0
HKCU\...\Policies\Explorer: [NoInstrumentation] 1
HKU\Default User\...\RunOnce: [NeroHomeFirstStart] - C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe
AppInit_DLLs: C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [145408 2013-09-05] (Google)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Gamma Loader.lnk
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\AVerQuick.lnk
ShortcutTarget: AVerQuick.lnk -> C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe ()
Startup: C:\Documents and Settings\owner\Nabídka Start\Programy\Po spuštění\Diář.lnk
ShortcutTarget: Diář.lnk -> C:\Program Files\Diar 5\diar.exe (Václav Šimandl)
Startup: C:\Documents and Settings\owner\Nabídka Start\Programy\Po spuštění\Mozilla Firefox (2).lnk
ShortcutTarget: Mozilla Firefox (2).lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Startup: C:\Documents and Settings\owner\Nabídka Start\Programy\Po spuštění\Rainlendar.lnk
ShortcutTarget: Rainlendar.lnk -> C:\Program Files\Rainlendar\Rainlendar.exe (Rainy)
Startup: C:\Documents and Settings\owner\Nabídka Start\Programy\Po spuštění\Vesmír na dlani.lnk
ShortcutTarget: Vesmír na dlani.lnk -> C:\Program Files\Noční obloha\vesmir.exe (Tošovský Jan)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
HKCU\Software\Microsoft\Internet Explorer\Main,Prev Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
URLSearchHook: HKCU - (No Name) - {7757CBCC-0975-4b79-A519-90B142CA3A23} - No File
URLSearchHook: HKCU - MHURLSearchHook Class - {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Program Files\Family Toolbar\tbhelper.dll ()
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = http://search.myheritage.com?orig=ds&q={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = http://search.myheritage.com?orig=ds&q={searchTerms}
SearchScopes: HKCU - {D482BCAD-A777-451A-BB0C-46A0A8A9E5FD} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
BHO: Video Player - {19e6b0ed-4856-4cb2-8756-f72ecb172b34} - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta4\ie\VideoPlayerV3beta4.dll ()
BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO: Webexp Enhanced - {73d78f1b-734b-4529-88b2-d0b546c7e124} - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha801\ie\WebexpEnhancedV1alpha801.dll ()
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - &S-Rank - {B71B15CF-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam\Postak\SRank.dll (Seznam.cz a.s.)
Toolbar: HKLM - &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU - &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\Windows\System32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU - &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\Windows\system32\SHELL32.dll (Microsoft Corporation)
Toolbar: HKCU - &S-Rank - {B71B15CF-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam\Postak\SRank.dll (Seznam.cz a.s.)
Toolbar: HKCU - &Google - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
Toolbar: HKCU - No Name - {EFA17369-CDC0-4927-9AFC-BAAD1F96B2AE} - No File
DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204
DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} http://www.myheritage.cz/Genoogle/Compo ... eQuery.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF ProfilePath: C:\Documents and Settings\owner\Data aplikací\Mozilla\Firefox\Profiles\ihpvjar7.default-1369290633546
FF SearchEngineOrder.1: Google
FF Homepage: hxxp://www.seznam.cz/
FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @IObitBar.com/Plugin - C:\Program Files\IObitBar\toolbar\1.bin\NPi0Stub.dll No File
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.2.32 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.2 - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.2 - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.2 - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpchromebrowserrecordext;version=15.0.6.14 - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprphtml5videoshim;version=15.0.6.14 - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.2.32 - c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin: @real.com/RhapsodyPlayerEngine,version=1.1 - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF Plugin: @realnetworks.com/npdlplugin;version=1 - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll No File
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdivx32.dll (DivX,Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Computer, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Computer, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Computer, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Computer, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Computer, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpplugin.dll (RealPlayer)
FF Plugin ProgramFiles/Appdata: C:\Documents and Settings\owner\Data aplikací\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Documents and Settings\owner\Data aplikací\mozilla\plugins\npgtpo3dautoplugin.dll ()
FF SearchPlugin: C:\Documents and Settings\owner\Data aplikací\Mozilla\Firefox\Profiles\ihpvjar7.default-1369290633546\searchplugins\filmova-databaze-fdbcz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: AD Block - C:\Documents and Settings\owner\Data aplikací\Mozilla\Firefox\Profiles\ihpvjar7.default-1369290633546\Extensions\searchads@instair.net [2013-11-15]
FF Extension: Lišta Centrum.cz - C:\Documents and Settings\owner\Data aplikací\Mozilla\Firefox\Profiles\ihpvjar7.default-1369290633546\Extensions\toolbar@centrumholdings.com [2013-11-07]
FF Extension: Seznam lištička - C:\Documents and Settings\owner\Data aplikací\Mozilla\Firefox\Profiles\ihpvjar7.default-1369290633546\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2013-09-11]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-12-11]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2013-12-11]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{FD2FD708-1F6F-4B68-B141-C5778F0C19BB} [2013-12-11]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-12-11]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Firefox\Extensions: [i0ffxtbr@IObitBar.com] - C:\Program Files\IObitBar\toolbar\1.bin
FF HKLM\...\Firefox\Extensions: [{0153E448-190B-4987-BDE1-F256CADA672F}] - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: RealPlayer Browser Record Plugin - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012-09-26]
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-06-19]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-05-14]
FF HKLM\...\Firefox\Extensions: [{FCE04E1F-9378-4f39-96F6-5689A9159E45}] - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\Documents and Settings\All Users\Data aplikací\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ []
FF HKLM\...\Firefox\Extensions: [ext@bettersurfplus.com] - C:\Program Files\BetterSurf\BetterSurfPlus\ff
FF HKLM\...\Firefox\Extensions: [ext@WebexpEnhancedV1alpha801.net] - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha801\ff
FF Extension: Webexp Enhanced - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha801\ff [2013-12-20]
FF HKLM\...\Firefox\Extensions: [ext@VideoPlayerV3beta4.net] - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta4\ff
FF Extension: Video Player - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta4\ff [2014-01-10]

========================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-01-07] (AVAST Software)
S3 GoogleDesktopManager; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [1838592 2013-09-05] (Google)
S2 HidServ; C:\Windows\System32\svchost.exe [14336 2008-04-14] (Microsoft Corporation)
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2013-10-08] (Oracle Corporation)
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] ()
S2 SecureUpdateSvc; C:\Program Files\Secure Speed Dial\IE\SecureUpdate.exe [x]

==================== Drivers (Whitelisted) ====================

R1 AmdK8; C:\Windows\System32\DRIVERS\AmdK8.sys [43008 2006-06-18] (Advanced Micro Devices)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [67824 2014-01-07] (AVAST Software)
R1 AswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [54832 2014-01-07] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49944 2013-12-05] ()
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [775952 2014-01-07] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [410528 2014-01-07] (AVAST Software)
R1 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57672 2014-01-07] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [180248 2014-01-07] ()
R3 AVerBDA3x; C:\Windows\System32\DRIVERS\AVerBDA3x.sys [1171456 2006-12-14] (AVerMedia TECHNOLOGIES, Inc.)
S3 CCDECODE; C:\Windows\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
S3 gdrv; C:\WINDOWS\gdrv.sys [14656 2007-08-17] (Windows (R) Codename Longhorn DDK provider)
R0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] ()
R3 LVUSBSta; C:\Windows\System32\drivers\lvusbsta.sys [22016 2005-05-27] (Logitech Inc.)
R2 MASPINT; C:\Windows\System32\Drivers\MASPINT.sys [8096 2000-03-29] (MicroStaff Co.,Ltd.)
S3 MPE; C:\Windows\System32\DRIVERS\MPE.sys [15232 2008-04-13] (Microsoft Corporation)
S3 MREMP50; C:\Program Files\Common Files\Motive\MREMP50.sys [21248 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA))
S3 MRESP50; C:\Program Files\Common Files\Motive\MRESP50.sys [20096 2008-03-29] (Printing Communications Assoc., Inc. (PCAUSA))
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R0 nvata; C:\Windows\System32\DRIVERS\nvata.sys [105472 2006-10-18] (NVIDIA Corporation)
R3 NVENETFD; C:\Windows\System32\DRIVERS\NVENETFD.sys [58368 2006-11-27] (NVIDIA Corporation)
R3 nvnetbus; C:\Windows\System32\DRIVERS\nvnetbus.sys [19968 2006-11-27] (NVIDIA Corporation)
R2 PfFilter; C:\Program Files\IObit\Protected Folder\pffilter.sys [140848 2011-03-16] (IObit Information Technology)
R3 QCMerced; C:\Windows\System32\DRIVERS\LVCM.sys [1317152 2005-05-27] ()
R0 speedfan; C:\Windows\System32\speedfan.sys [5248 2006-09-24] (Windows (R) 2000 DDK provider)
S3 cpuz134; \??\C:\DOCUME~1\owner\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys [x]
S4 InCDFs; system32\drivers\InCDFs.sys [x]
S1 InCDPass; system32\drivers\InCDPass.sys [x]
S1 InCDRm; system32\drivers\InCDRm.sys [x]
S4 IntelIde; No ImagePath
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [x]
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [x]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [x]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [x]
U5 P3; C:\Windows\System32\Drivers\P3.sys [46592 2008-04-14] (Microsoft Corporation)
U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-15 17:37 - 2014-01-15 17:36 - 01220608 _____ (Farbar) C:\Documents and Settings\owner\Plocha\FRST(1).exe
2014-01-15 10:02 - 2014-01-15 10:02 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2914368$
2014-01-13 22:27 - 2014-01-13 22:30 - 00000000 ____D C:\AdwCleaner
2014-01-13 22:23 - 2014-01-13 22:23 - 00010581 _____ C:\JRT.txt
2014-01-13 22:16 - 2014-01-13 22:16 - 00000000 ____D C:\WINDOWS\ERUNT
2014-01-13 22:13 - 2014-01-13 22:13 - 00006366 _____ C:\sc-cleaner1.txt
2014-01-13 21:54 - 2014-01-13 21:54 - 00006366 _____ C:\sc-cleaner.txt
2014-01-13 21:48 - 2014-01-13 21:44 - 01236282 _____ C:\Documents and Settings\owner\Plocha\adwcleaner.exe
2014-01-13 21:47 - 2014-01-13 21:44 - 01037068 _____ (Thisisu) C:\Documents and Settings\owner\Plocha\JRT.exe
2014-01-13 21:46 - 2014-01-13 21:43 - 00406264 _____ (Bleeping Computer, LLC) C:\Documents and Settings\owner\Plocha\sc-cleaner.exe
2014-01-13 15:33 - 2014-01-13 15:33 - 00008113 _____ C:\Documents and Settings\owner\Plocha\Addition.zip
2014-01-13 10:40 - 2014-01-13 10:41 - 00050913 _____ C:\Documents and Settings\owner\Plocha\Addition.txt
2014-01-13 10:39 - 2014-01-15 17:38 - 00023970 _____ C:\Documents and Settings\owner\Plocha\FRST.txt
2014-01-13 10:38 - 2014-01-13 10:38 - 00000000 ____D C:\FRST
2014-01-13 10:37 - 2014-01-13 10:37 - 00015327 _____ C:\Documents and Settings\owner\Plocha\LM.bat
2014-01-13 10:37 - 2014-01-13 10:13 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\owner\Plocha\FRSTLauncher.exe
2014-01-13 10:28 - 2014-01-13 09:54 - 01219584 _____ (Farbar) C:\Documents and Settings\owner\Plocha\FRST.exe
2014-01-11 17:54 - 2014-01-11 17:57 - 00000000 ____D C:\rsit
2014-01-11 17:54 - 2014-01-11 17:54 - 00000000 ____D C:\Program Files\trend micro
2014-01-10 07:44 - 2014-01-10 07:44 - 00000000 ____D C:\Program Files\VideoPlayerV3
2014-01-07 09:17 - 2014-01-07 09:17 - 00000000 ____D C:\WINDOWS\system32\log
2014-01-07 08:11 - 2014-01-07 08:11 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Google+ Auto Backup
2014-01-06 20:23 - 2014-01-06 20:23 - 04558848 _____ (Google Inc.) C:\WINDOWS\system32\GPhotos.scr
2014-01-06 13:23 - 2014-01-15 11:08 - 00000278 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-823518204-1417001333-725345543-1003.job
2013-12-28 19:46 - 2013-12-28 19:46 - 00000000 ____D C:\Documents and Settings\NetworkService\Data aplikací\AVG
2013-12-27 19:46 - 2013-12-27 19:46 - 00000000 ____D C:\Documents and Settings\owner\Local Settings\Data aplikací\Avg2014
2013-12-27 19:23 - 2013-12-27 19:23 - 00000000 ____D C:\Documents and Settings\owner\Data aplikací\AVG
2013-12-27 19:19 - 2013-12-27 19:24 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AVG
2013-12-27 19:19 - 2013-12-27 19:19 - 00000000 __SHD C:\Documents and Settings\All Users\Data aplikací\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2013-12-20 18:37 - 2013-12-20 18:37 - 00000000 ____D C:\Program Files\WebexpEnhancedV1
2013-12-16 13:14 - 2013-12-16 13:14 - 00001915 _____ C:\Documents and Settings\All Users\Plocha\Google Earth.lnk
2013-12-16 13:14 - 2013-12-16 13:14 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Google Earth

==================== One Month Modified Files and Folders =======

2014-01-15 17:38 - 2014-01-13 10:39 - 00023970 _____ C:\Documents and Settings\owner\Plocha\FRST.txt
2014-01-15 17:38 - 2007-08-17 21:59 - 00000000 ____D C:\Documents and Settings\owner\Plocha
2014-01-15 17:36 - 2014-01-15 17:37 - 01220608 _____ (Farbar) C:\Documents and Settings\owner\Plocha\FRST(1).exe
2014-01-15 17:36 - 2010-02-09 21:28 - 00000000 ____D C:\Documents and Settings\owner\Dokumenty\Stažené soubory
2014-01-15 17:34 - 2009-06-14 18:21 - 00000466 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{E979B337-9A3F-438E-87C7-6198BD462FFC}.job
2014-01-15 17:31 - 2007-08-17 16:47 - 00000000 ____D C:\Documents and Settings\owner\Data aplikací\Skype
2014-01-15 15:54 - 2007-08-17 22:20 - 01295336 _____ C:\WINDOWS\WindowsUpdate.log
2014-01-15 15:48 - 2013-05-14 08:27 - 00000364 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2014-01-15 15:42 - 2012-03-29 15:55 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-01-15 15:10 - 2010-02-13 08:54 - 00000940 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-15 13:17 - 2007-08-17 21:59 - 00000000 ____D C:\Documents and Settings\owner
2014-01-15 12:19 - 2013-07-23 07:05 - 00031900 ____N C:\WINDOWS\SchedLgU.Txt
2014-01-15 11:08 - 2014-01-06 13:23 - 00000278 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-823518204-1417001333-725345543-1003.job
2014-01-15 11:08 - 2012-12-23 11:32 - 00000286 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-823518204-1417001333-725345543-1003.job
2014-01-15 11:08 - 2010-03-18 08:30 - 00000286 _____ C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-823518204-1417001333-725345543-1003.job
2014-01-15 10:24 - 2013-08-31 10:23 - 00000000 ____D C:\Documents and Settings\owner\Data aplikací\Seznam.cz
2014-01-15 10:17 - 2010-03-18 08:30 - 00000278 _____ C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-823518204-1417001333-725345543-1003.job
2014-01-15 10:16 - 2013-07-23 07:06 - 00000159 ____N C:\WINDOWS\wiadebug.log
2014-01-15 10:16 - 2013-07-23 07:06 - 00000049 ____N C:\WINDOWS\wiaservc.log
2014-01-15 10:16 - 2013-06-07 19:14 - 00000350 _____ C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job
2014-01-15 10:16 - 2013-06-03 12:50 - 00000350 _____ C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
2014-01-15 10:16 - 2010-02-13 08:54 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-15 10:16 - 2007-08-17 21:56 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2014-01-15 10:15 - 2007-08-17 21:59 - 00000272 ___SH C:\Documents and Settings\owner\ntuser.ini
2014-01-15 10:09 - 2013-08-19 16:25 - 00000000 ____D C:\WINDOWS\system32\MRT
2014-01-15 10:03 - 2007-08-19 18:14 - 83425928 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-01-15 10:02 - 2014-01-15 10:02 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2914368$
2014-01-13 22:30 - 2014-01-13 22:27 - 00000000 ____D C:\AdwCleaner
2014-01-13 22:30 - 2010-11-28 22:15 - 00000000 ____D C:\Documents and Settings\owner\Data aplikací\Uniblue
2014-01-13 22:30 - 2009-01-21 18:57 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\ICQ
2014-01-13 22:30 - 2007-08-17 23:50 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2014-01-13 22:30 - 2007-08-17 21:59 - 00000000 __RHD C:\Documents and Settings\owner\Data aplikací
2014-01-13 22:30 - 2007-08-17 21:59 - 00000000 ___HD C:\Documents and Settings\owner\Local Settings\Data aplikací
2014-01-13 22:23 - 2014-01-13 22:23 - 00010581 _____ C:\JRT.txt
2014-01-13 22:16 - 2014-01-13 22:16 - 00000000 ____D C:\WINDOWS\ERUNT
2014-01-13 22:13 - 2014-01-13 22:13 - 00006366 _____ C:\sc-cleaner1.txt
2014-01-13 21:54 - 2014-01-13 21:54 - 00006366 _____ C:\sc-cleaner.txt
2014-01-13 21:54 - 2011-06-23 20:47 - 00000730 _____ C:\Documents and Settings\All Users\Nabídka Start\Programy\Mozilla Firefox.lnk
2014-01-13 21:54 - 2010-11-16 22:27 - 00001813 _____ C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
2014-01-13 21:52 - 2007-08-17 21:59 - 00000000 ___RD C:\Documents and Settings\owner\Dokumenty
2014-01-13 21:44 - 2014-01-13 21:48 - 01236282 _____ C:\Documents and Settings\owner\Plocha\adwcleaner.exe
2014-01-13 21:44 - 2014-01-13 21:47 - 01037068 _____ (Thisisu) C:\Documents and Settings\owner\Plocha\JRT.exe
2014-01-13 21:43 - 2014-01-13 21:46 - 00406264 _____ (Bleeping Computer, LLC) C:\Documents and Settings\owner\Plocha\sc-cleaner.exe
2014-01-13 21:23 - 2007-08-17 17:13 - 00000000 ____D C:\Documents and Settings\owner\Dokumenty\AVerTV
2014-01-13 15:33 - 2014-01-13 15:33 - 00008113 _____ C:\Documents and Settings\owner\Plocha\Addition.zip
2014-01-13 10:41 - 2014-01-13 10:40 - 00050913 _____ C:\Documents and Settings\owner\Plocha\Addition.txt
2014-01-13 10:38 - 2014-01-13 10:38 - 00000000 ____D C:\FRST
2014-01-13 10:37 - 2014-01-13 10:37 - 00015327 _____ C:\Documents and Settings\owner\Plocha\LM.bat
2014-01-13 10:28 - 2007-08-28 18:51 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
2014-01-13 10:13 - 2014-01-13 10:37 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\owner\Plocha\FRSTLauncher.exe
2014-01-13 09:54 - 2014-01-13 10:28 - 01219584 _____ (Farbar) C:\Documents and Settings\owner\Plocha\FRST.exe
2014-01-11 17:57 - 2014-01-11 17:54 - 00000000 ____D C:\rsit
2014-01-11 17:54 - 2014-01-11 17:54 - 00000000 ____D C:\Program Files\trend micro
2014-01-11 08:21 - 2013-04-03 19:44 - 00002283 _____ C:\Documents and Settings\All Users\Plocha\Skype.lnk
2014-01-11 08:19 - 2007-08-17 16:47 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Skype
2014-01-11 07:55 - 2001-10-25 13:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2014-01-10 21:12 - 2007-08-17 18:15 - 00000000 ____D C:\Documents and Settings\owner\Local Settings\Data aplikací\Thunderbird
2014-01-10 07:44 - 2014-01-10 07:44 - 00000000 ____D C:\Program Files\VideoPlayerV3
2014-01-07 15:49 - 2013-05-14 08:27 - 00001733 _____ C:\Documents and Settings\All Users\Plocha\avast! Free Antivirus.lnk
2014-01-07 15:48 - 2013-05-14 08:27 - 00775952 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2014-01-07 15:48 - 2013-05-14 08:27 - 00410528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2014-01-07 15:48 - 2013-05-14 08:27 - 00180248 _____ C:\WINDOWS\system32\Drivers\aswVmm.sys
2014-01-07 15:48 - 2013-05-14 08:27 - 00067824 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2014-01-07 15:48 - 2013-05-14 08:27 - 00057672 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys
2014-01-07 15:48 - 2013-05-14 08:27 - 00054832 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
2014-01-07 15:48 - 2013-05-14 08:26 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2014-01-07 15:48 - 2007-11-26 08:55 - 00270240 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2014-01-07 13:28 - 2008-01-14 17:16 - 00000000 ____D C:\INSTALL
2014-01-07 09:17 - 2014-01-07 09:17 - 00000000 ____D C:\WINDOWS\system32\log
2014-01-07 09:14 - 2007-08-17 21:59 - 00000000 ___RD C:\Documents and Settings\owner\Nabídka Start\Programy\Po spuštění
2014-01-07 08:11 - 2014-01-07 08:11 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Google+ Auto Backup
2014-01-07 08:11 - 2007-08-28 17:10 - 00000000 ____D C:\Program Files\Google
2014-01-07 08:11 - 2007-08-17 23:50 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2014-01-06 23:25 - 2007-08-17 23:46 - 00000000 ____D C:\WINDOWS\Help
2014-01-06 20:23 - 2014-01-06 20:23 - 04558848 _____ (Google Inc.) C:\WINDOWS\system32\GPhotos.scr
2013-12-29 22:29 - 2013-03-27 21:01 - 00065536 _____ C:\WINDOWS\system32\config\TuneUp.evt
2013-12-29 08:12 - 2007-08-17 23:50 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2013-12-28 19:46 - 2013-12-28 19:46 - 00000000 ____D C:\Documents and Settings\NetworkService\Data aplikací\AVG
2013-12-28 19:46 - 2007-08-17 21:59 - 00000000 ____D C:\Documents and Settings\NetworkService\Data aplikací
2013-12-27 19:46 - 2013-12-27 19:46 - 00000000 ____D C:\Documents and Settings\owner\Local Settings\Data aplikací\Avg2014
2013-12-27 19:24 - 2013-12-27 19:19 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AVG
2013-12-27 19:23 - 2013-12-27 19:23 - 00000000 ____D C:\Documents and Settings\owner\Data aplikací\AVG
2013-12-27 19:19 - 2013-12-27 19:19 - 00000000 __SHD C:\Documents and Settings\All Users\Data aplikací\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2013-12-27 19:17 - 2010-12-06 18:46 - 00000862 _____ C:\Documents and Settings\All Users\Plocha\GOM Player.lnk
2013-12-27 19:17 - 2010-06-01 06:39 - 00000862 _____ C:\Documents and Settings\owner\Nabídka Start\GOM Player.lnk
2013-12-25 22:15 - 2010-11-16 22:27 - 00000838 _____ C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
2013-12-20 18:38 - 2013-03-07 12:18 - 00000664 _____ C:\WINDOWS\system32\d3d9caps.dat
2013-12-20 18:37 - 2013-12-20 18:37 - 00000000 ____D C:\Program Files\WebexpEnhancedV1
2013-12-20 12:02 - 2008-04-24 17:40 - 00000774 _____ C:\Documents and Settings\owner\Plocha\MyHeritage Family Tree Builder.lnk
2013-12-18 13:12 - 2013-05-14 05:54 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Google Drive
2013-12-16 13:14 - 2013-12-16 13:14 - 00001915 _____ C:\Documents and Settings\All Users\Plocha\Google Earth.lnk
2013-12-16 13:14 - 2013-12-16 13:14 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Google Earth

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe
[2002-09-20 17:05] - [2008-04-14 04:22] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1

C:\Windows\System32\winlogon.exe
[2002-09-20 17:05] - [2008-04-14 04:22] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea

C:\Windows\System32\svchost.exe
[2001-10-25 13:00] - [2008-04-14 04:22] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93

C:\Windows\System32\services.exe
[2001-10-25 13:00] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7

C:\Windows\System32\User32.dll
[2002-09-20 17:04] - [2008-04-14 04:22] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53

C:\Windows\System32\userinit.exe
[2002-09-20 17:05] - [2008-04-14 04:22] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239

C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys
[2001-10-25 13:00] - [2008-04-14 03:12] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1


==================== End Of Log ============================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: odstranění malware rvzr-a.akamaihd.net

#18 Příspěvek od vyosek »

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)
    HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k
    HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
    HKLM\...\Run: [TkBellExe] - C:\program files\real\realplayer\update\realsched.exe [295512 2013-06-19] (RealNetworks, Inc.)
    HKLM\...\Run: [seznam-listicka-distribuce] - C:\Program Files\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
    HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
    HKLM\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 0
    HKLM\...\Policies\Explorer: [NoResolveSearch] 1
    HKCU\...\Run: [LogitechSoftwareUpdate] - C:\Program Files\Logitech\Video\ManifestEngine.exe [196608 2005-06-08] (Logitech Inc.)
    HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20587168 2013-11-18] (Skype Technologies S.A.)
    HKCU\...\Run: [cz.seznam.software.autoupdate] - C:\Documents and Settings\owner\Data aplikací\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
    HKCU\...\Run: [cz.seznam.software.szndesktop] - C:\Documents and Settings\owner\Data aplikací\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
    HKCU\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 0
    HKCU\...\Policies\Explorer: [NoInstrumentation] 1
    HKU\Default User\...\RunOnce: [NeroHomeFirstStart] - C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe
    Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Gamma Loader.lnk
    Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\AVerQuick.lnk
    
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
    HKCU\Software\Microsoft\Internet Explorer\Main,Prev Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
    HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com
    HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
    URLSearchHook: HKCU - (No Name) - {7757CBCC-0975-4b79-A519-90B142CA3A23} - No File
    URLSearchHook: HKCU - MHURLSearchHook Class - {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Program Files\Family Toolbar\tbhelper.dll ()
    SearchScopes: HKLM - DefaultScope value is missing.
    SearchScopes: HKLM - {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = http://search.myheritage.com?orig=ds&q={searchTerms}
    SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    SearchScopes: HKCU - {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = http://search.myheritage.com?orig=ds&q={searchTerms}
    SearchScopes: HKCU - {D482BCAD-A777-451A-BB0C-46A0A8A9E5FD} URL = http://search.yahoo.com/search?fr=chr-g ... =685749&p={searchTerms}
    BHO: Video Player - {19e6b0ed-4856-4cb2-8756-f72ecb172b34} - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta4\ie\VideoPlayerV3beta4.dll ()
    BHO: Webexp Enhanced - {73d78f1b-734b-4529-88b2-d0b546c7e124} - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha801\ie\WebexpEnhancedV1alpha801.dll ()
    Toolbar: HKCU - No Name - {EFA17369-CDC0-4927-9AFC-BAAD1F96B2AE} - No File
    
    FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=
    FF Plugin: @IObitBar.com/Plugin - C:\Program Files\IObitBar\toolbar\1.bin\NPi0Stub.dll No File
    FF HKLM\...\Firefox\Extensions: [i0ffxtbr@IObitBar.com] - C:\Program Files\IObitBar\toolbar\1.bin
    FF HKLM\...\Firefox\Extensions: [ext@bettersurfplus.com] - C:\Program Files\BetterSurf\BetterSurfPlus\ff
    FF HKLM\...\Firefox\Extensions: [ext@WebexpEnhancedV1alpha801.net] - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha801\ff
    FF Extension: Webexp Enhanced - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha801\ff [2013-12-20]
    FF HKLM\...\Firefox\Extensions: [ext@VideoPlayerV3beta4.net] - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta4\ff
    FF Extension: Video Player - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta4\ff [2014-01-10]
    
    R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] ()
    S2 SecureUpdateSvc; C:\Program Files\Secure Speed Dial\IE\SecureUpdate.exe [x]
    S3 cpuz134; \??\C:\DOCUME~1\owner\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys [x]
    S4 InCDFs; system32\drivers\InCDFs.sys [x]
    S1 InCDPass; system32\drivers\InCDPass.sys [x]
    S1 InCDRm; system32\drivers\InCDRm.sys [x]
    S4 IntelIde; No ImagePath
    S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [x]
    S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [x]
    S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [x]
    S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [x]
    
    C:\Program Files\BetterSurf
    C:\Program Files\VideoPlayerV3
    2014-01-13 22:23 - 2014-01-13 22:23 - 00010581 _____ C:\JRT.txt
    2014-01-13 22:13 - 2014-01-13 22:13 - 00006366 _____ C:\sc-cleaner1.txt
    2014-01-13 21:54 - 2014-01-13 21:54 - 00006366 _____ C:\sc-cleaner.txt
    2014-01-13 21:48 - 2014-01-13 21:44 - 01236282 _____ C:\Documents and Settings\owner\Plocha\adwcleaner.exe
    2014-01-13 21:47 - 2014-01-13 21:44 - 01037068 _____ (Thisisu) C:\Documents and Settings\owner\Plocha\JRT.exe
    2014-01-13 21:46 - 2014-01-13 21:43 - 00406264 _____ (Bleeping Computer, LLC) C:\Documents and Settings\owner\Plocha\sc-cleaner.exe
    2014-01-13 15:33 - 2014-01-13 15:33 - 00008113 _____ C:\Documents and Settings\owner\Plocha\Addition.zip
    2014-01-13 10:40 - 2014-01-13 10:41 - 00050913 _____ C:\Documents and Settings\owner\Plocha\Addition.txt
    2014-01-13 10:39 - 2014-01-15 17:38 - 00023970 _____ C:\Documents and Settings\owner\Plocha\FRST.txt
    2014-01-13 10:37 - 2014-01-13 10:37 - 00015327 _____ C:\Documents and Settings\owner\Plocha\LM.bat
    2013-12-28 19:46 - 2013-12-28 19:46 - 00000000 ____D C:\Documents and Settings\NetworkService\Data aplikací\AVG
    2013-12-27 19:46 - 2013-12-27 19:46 - 00000000 ____D C:\Documents and Settings\owner\Local Settings\Data aplikací\Avg2014
    2013-12-27 19:23 - 2013-12-27 19:23 - 00000000 ____D C:\Documents and Settings\owner\Data aplikací\AVG
    2013-12-27 19:19 - 2013-12-27 19:24 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AVG
    2013-12-27 19:19 - 2013-12-27 19:19 - 00000000 __SHD C:\Documents and Settings\All Users\Data aplikací\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
    2013-12-20 18:37 - 2013-12-20 18:37 - 00000000 ____D C:\Program Files\WebexpEnhancedV1
    
    Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\WINDOWS\Tasks\AmiUpdXp.job => C:\Documents and Settings\owner\Data aplikací\SwvUpdater\Updater.exe <==== ATTENTION
    Task: C:\WINDOWS\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
    Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => C:\WINDOWS\TEMP\{8BD110E1-DF66-44BE-B7AA-8CBF2F202D83}.exe
    Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\WINDOWS\TEMP\{5AB13F25-67BF-4035-BABC-9FFB51B20D43}.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-823518204-1417001333-725345543-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
    Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-823518204-1417001333-725345543-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
    Task: C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-823518204-1417001333-725345543-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
    Task: C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-823518204-1417001333-725345543-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
    Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{E979B337-9A3F-438E-87C7-6198BD462FFC}.job => C:\WINDOWS\system32\msfeedssync.exe
    
    AlternateDataStreams: C:\Documents and Settings\All Users\Data aplikací\TEMP:73B1147D
    
    REG: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List" /v "5985:TCP" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List" /v "80:TCP" /f
    
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

valf
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 11 led 2014 18:28

Re: odstranění malware rvzr-a.akamaihd.net

#19 Příspěvek od valf »

Dobrý večer,
vypadá to, že jsem za vodou, zatím se všechny neřesti na PC ztratily, nerad bych to zakřik´, moc děkuju za pomoc.
Zdraví
valf






Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 15-01-2014 03
Ran by owner at 2014-01-16 13:03:07 Run:1
Running from C:\Documents and Settings\owner\Plocha
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)
HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [TkBellExe] - C:\program files\real\realplayer\update\realsched.exe [295512 2013-06-19] (RealNetworks, Inc.)
HKLM\...\Run: [seznam-listicka-distribuce] - C:\Program Files\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 0
HKLM\...\Policies\Explorer: [NoResolveSearch] 1
HKCU\...\Run: [LogitechSoftwareUpdate] - C:\Program Files\Logitech\Video\ManifestEngine.exe [196608 2005-06-08] (Logitech Inc.)
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20587168 2013-11-18] (Skype Technologies S.A.)
HKCU\...\Run: [cz.seznam.software.autoupdate] - C:\Documents and Settings\owner\Data aplikací\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKCU\...\Run: [cz.seznam.software.szndesktop] - C:\Documents and Settings\owner\Data aplikací\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKCU\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 0
HKCU\...\Policies\Explorer: [NoInstrumentation] 1
HKU\Default User\...\RunOnce: [NeroHomeFirstStart] - C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Gamma Loader.lnk
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\AVerQuick.lnk

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
HKCU\Software\Microsoft\Internet Explorer\Main,Prev Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
URLSearchHook: HKCU - (No Name) - {7757CBCC-0975-4b79-A519-90B142CA3A23} - No File
URLSearchHook: HKCU - MHURLSearchHook Class - {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Program Files\Family Toolbar\tbhelper.dll ()
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = http://search.myheritage.com?orig=ds&q={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = http://search.myheritage.com?orig=ds&q={searchTerms}
SearchScopes: HKCU - {D482BCAD-A777-451A-BB0C-46A0A8A9E5FD} URL = http://search.yahoo.com/search?fr=chr-g ... =685749&p={searchTerms}
BHO: Video Player - {19e6b0ed-4856-4cb2-8756-f72ecb172b34} - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta4\ie\VideoPlayerV3beta4.dll ()
BHO: Webexp Enhanced - {73d78f1b-734b-4529-88b2-d0b546c7e124} - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha801\ie\WebexpEnhancedV1alpha801.dll ()
Toolbar: HKCU - No Name - {EFA17369-CDC0-4927-9AFC-BAAD1F96B2AE} - No File

FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=
FF Plugin: @IObitBar.com/Plugin - C:\Program Files\IObitBar\toolbar\1.bin\NPi0Stub.dll No File
FF HKLM\...\Firefox\Extensions: [i0ffxtbr@IObitBar.com] - C:\Program Files\IObitBar\toolbar\1.bin
FF HKLM\...\Firefox\Extensions: [ext@bettersurfplus.com] - C:\Program Files\BetterSurf\BetterSurfPlus\ff
FF HKLM\...\Firefox\Extensions: [ext@WebexpEnhancedV1alpha801.net] - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha801\ff
FF Extension: Webexp Enhanced - C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha801\ff [2013-12-20]
FF HKLM\...\Firefox\Extensions: [ext@VideoPlayerV3beta4.net] - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta4\ff
FF Extension: Video Player - C:\Program Files\VideoPlayerV3\VideoPlayerV3beta4\ff [2014-01-10]

R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] ()
S2 SecureUpdateSvc; C:\Program Files\Secure Speed Dial\IE\SecureUpdate.exe [x]
S3 cpuz134; \??\C:\DOCUME~1\owner\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys [x]
S4 InCDFs; system32\drivers\InCDFs.sys [x]
S1 InCDPass; system32\drivers\InCDPass.sys [x]
S1 InCDRm; system32\drivers\InCDRm.sys [x]
S4 IntelIde; No ImagePath
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [x]
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [x]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [x]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [x]

C:\Program Files\BetterSurf
C:\Program Files\VideoPlayerV3
2014-01-13 22:23 - 2014-01-13 22:23 - 00010581 _____ C:\JRT.txt
2014-01-13 22:13 - 2014-01-13 22:13 - 00006366 _____ C:\sc-cleaner1.txt
2014-01-13 21:54 - 2014-01-13 21:54 - 00006366 _____ C:\sc-cleaner.txt
2014-01-13 21:48 - 2014-01-13 21:44 - 01236282 _____ C:\Documents and Settings\owner\Plocha\adwcleaner.exe
2014-01-13 21:47 - 2014-01-13 21:44 - 01037068 _____ (Thisisu) C:\Documents and Settings\owner\Plocha\JRT.exe
2014-01-13 21:46 - 2014-01-13 21:43 - 00406264 _____ (Bleeping Computer, LLC) C:\Documents and Settings\owner\Plocha\sc-cleaner.exe
2014-01-13 15:33 - 2014-01-13 15:33 - 00008113 _____ C:\Documents and Settings\owner\Plocha\Addition.zip
2014-01-13 10:40 - 2014-01-13 10:41 - 00050913 _____ C:\Documents and Settings\owner\Plocha\Addition.txt
2014-01-13 10:39 - 2014-01-15 17:38 - 00023970 _____ C:\Documents and Settings\owner\Plocha\FRST.txt
2014-01-13 10:37 - 2014-01-13 10:37 - 00015327 _____ C:\Documents and Settings\owner\Plocha\LM.bat
2013-12-28 19:46 - 2013-12-28 19:46 - 00000000 ____D C:\Documents and Settings\NetworkService\Data aplikací\AVG
2013-12-27 19:46 - 2013-12-27 19:46 - 00000000 ____D C:\Documents and Settings\owner\Local Settings\Data aplikací\Avg2014
2013-12-27 19:23 - 2013-12-27 19:23 - 00000000 ____D C:\Documents and Settings\owner\Data aplikací\AVG
2013-12-27 19:19 - 2013-12-27 19:24 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AVG
2013-12-27 19:19 - 2013-12-27 19:19 - 00000000 __SHD C:\Documents and Settings\All Users\Data aplikací\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2013-12-20 18:37 - 2013-12-20 18:37 - 00000000 ____D C:\Program Files\WebexpEnhancedV1

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\AmiUpdXp.job => C:\Documents and Settings\owner\Data aplikací\SwvUpdater\Updater.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => C:\WINDOWS\TEMP\{8BD110E1-DF66-44BE-B7AA-8CBF2F202D83}.exe
Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\WINDOWS\TEMP\{5AB13F25-67BF-4035-BABC-9FFB51B20D43}.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-823518204-1417001333-725345543-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-823518204-1417001333-725345543-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-823518204-1417001333-725345543-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-823518204-1417001333-725345543-1003.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{E979B337-9A3F-438E-87C7-6198BD462FFC}.job => C:\WINDOWS\system32\msfeedssync.exe

AlternateDataStreams: C:\Documents and Settings\All Users\Data aplikací\TEMP:73B1147D

REG: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List" /v "5985:TCP" /f
REG: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List" /v "80:TCP" /f

*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HP Software Update => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\TkBellExe => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\seznam-listicka-distribuce => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\LinkResolveIgnoreLinkInfo => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\LogitechSoftwareUpdate => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Skype => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.autoupdate => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.szndesktop => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\LinkResolveIgnoreLinkInfo => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoInstrumentation => Value deleted successfully.
HKU\Default User\Software\Microsoft\Windows\CurrentVersion\RunOnce\\NeroHomeFirstStart => Value deleted successfully.
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Gamma Loader.lnk => Moved successfully.
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\AVerQuick.lnk => Moved successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Prev Search Page => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{7757CBCC-0975-4b79-A519-90B142CA3A23} => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} => Value deleted successfully.
HKCR\CLSID\{1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BE28C22E-F666-424d-B5FD-125C4AFEE34E} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{BE28C22E-F666-424d-B5FD-125C4AFEE34E} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BE28C22E-F666-424d-B5FD-125C4AFEE34E} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{BE28C22E-F666-424d-B5FD-125C4AFEE34E} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D482BCAD-A777-451A-BB0C-46A0A8A9E5FD} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{D482BCAD-A777-451A-BB0C-46A0A8A9E5FD} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{19e6b0ed-4856-4cb2-8756-f72ecb172b34} => Key deleted successfully.
HKCR\CLSID\{19e6b0ed-4856-4cb2-8756-f72ecb172b34} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73d78f1b-734b-4529-88b2-d0b546c7e124} => Key deleted successfully.
HKCR\CLSID\{73d78f1b-734b-4529-88b2-d0b546c7e124} => Key deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EFA17369-CDC0-4927-9AFC-BAAD1F96B2AE} => Value deleted successfully.
HKCR\CLSID\{EFA17369-CDC0-4927-9AFC-BAAD1F96B2AE} => Key not found.
Firefox Keyword.URL deleted successfully.
HKLM\Software\MozillaPlugins\@IObitBar.com/Plugin => Key deleted successfully.
C:\Program Files\IObitBar\toolbar\1.bin\NPi0Stub.dll not found.
HKLM\Software\Mozilla\Firefox\Extensions\\i0ffxtbr@IObitBar.com => Value deleted successfully.
HKLM\Software\Mozilla\Firefox\Extensions\\ext@bettersurfplus.com => Value deleted successfully.
HKLM\Software\Mozilla\Firefox\Extensions\\ext@WebexpEnhancedV1alpha801.net => Value deleted successfully.
C:\Program Files\WebexpEnhancedV1\WebexpEnhancedV1alpha801\ff => Moved successfully.
HKLM\Software\Mozilla\Firefox\Extensions\\ext@VideoPlayerV3beta4.net => Value deleted successfully.
C:\Program Files\VideoPlayerV3\VideoPlayerV3beta4\ff => Moved successfully.
RealNetworks Downloader Resolver Service => Service deleted successfully.
SecureUpdateSvc => Service deleted successfully.
cpuz134 => Service deleted successfully.
InCDFs => Service deleted successfully.
InCDPass => Service deleted successfully.
InCDRm => Service deleted successfully.
IntelIde => Service deleted successfully.
MREMP50a64 => Service deleted successfully.
MREMPR5 => Service deleted successfully.
MRENDIS5 => Service deleted successfully.
MRESP50a64 => Service deleted successfully.
"C:\Program Files\BetterSurf" => File/Directory not found.
C:\Program Files\VideoPlayerV3 => Moved successfully.
C:\JRT.txt => Moved successfully.
C:\sc-cleaner1.txt => Moved successfully.
C:\sc-cleaner.txt => Moved successfully.
C:\Documents and Settings\owner\Plocha\adwcleaner.exe => Moved successfully.
C:\Documents and Settings\owner\Plocha\JRT.exe => Moved successfully.
C:\Documents and Settings\owner\Plocha\sc-cleaner.exe => Moved successfully.
C:\Documents and Settings\owner\Plocha\Addition.zip => Moved successfully.
C:\Documents and Settings\owner\Plocha\Addition.txt => Moved successfully.
C:\Documents and Settings\owner\Plocha\FRST.txt => Moved successfully.
C:\Documents and Settings\owner\Plocha\LM.bat => Moved successfully.
C:\Documents and Settings\NetworkService\Data aplikací\AVG => Moved successfully.
C:\Documents and Settings\owner\Local Settings\Data aplikací\Avg2014 => Moved successfully.
C:\Documents and Settings\owner\Data aplikací\AVG => Moved successfully.
C:\Documents and Settings\All Users\Data aplikací\AVG => Moved successfully.
C:\Documents and Settings\All Users\Data aplikací\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} => Moved successfully.
C:\Program Files\WebexpEnhancedV1 => Moved successfully.
C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\WINDOWS\Tasks\AmiUpdXp.job not found.
C:\WINDOWS\Tasks\avast! Emergency Update.job => Moved successfully.
C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => Moved successfully.
C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => Moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-823518204-1417001333-725345543-1003.job => Moved successfully.
C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-823518204-1417001333-725345543-1003.job => Moved successfully.
C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-823518204-1417001333-725345543-1003.job => Moved successfully.
C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-823518204-1417001333-725345543-1003.job => Moved successfully.
C:\WINDOWS\Tasks\User_Feed_Synchronization-{E979B337-9A3F-438E-87C7-6198BD462FFC}.job => Moved successfully.
C:\Documents and Settings\All Users\Data aplikací\TEMP => ":73B1147D" ADS removed successfully.

========= reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List" /v "5985:TCP" /f =========


Operace byla dokončena úspěšně.


========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List" /v "80:TCP" /f =========


Operace byla dokončena úspěšně.


========= End of Reg: =========



The system needs a manual reboot.

==== End of Fixlog ====

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: odstranění malware rvzr-a.akamaihd.net

#20 Příspěvek od vyosek »

Tak jeste uklidime :James008:

:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel èistiè
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

valf
Návštěvník
Návštěvník
Příspěvky: 11
Registrován: 11 led 2014 18:28

Re: odstranění malware rvzr-a.akamaihd.net

#21 Příspěvek od valf »

Dobrý den,
děkuju,hlavně za trpělivost, aby se i starý pes naučil novým kouskům,jinak mám hezké vzpomínky z poč.60-tých let na Šumavskou a místo mezi Monte Bu a Veveřím.
Zdraví
valf :)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: odstranění malware rvzr-a.akamaihd.net

#22 Příspěvek od vyosek »

Nemate zac, rad jsem pomohl :worship: Zase nekdy Obrázek

A na zaklade Pravidla o zamykani temat :lock:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zamčeno