Stránka 2 z 3

Re: Mám zavirovaný počítač, prosím o pomoc

Napsal: 09 srp 2014 12:05
od Duinhil
Zkontroloval jsem Avastem a skoro žádný vir :) Jenom mi to našlo známý vir sources.inf který nejde samozřejmě odstranit. (Omlouvám se za těch 50 virů)

Re: Mám zavirovaný počítač, prosím o pomoc

Napsal: 09 srp 2014 12:17
od Duinhil
To co jste mi napsal jsem už provedl. Chci ještě upozornit že jsem teď si dělal pořádek na ploše a smazal jsem pár nepotřebných souborů. Když jsem to smazal tak se mi přestal točit kolečku u kurzoru jako by se něco načítalo (předtím se mi točilo v kuse)

A dnes mi už po 4 vyjelo
RunDLL
"There was a program strating
C:\PROGRA~1\COMMON~1\System\SysMenu.dll

The specified module could not be found.

Re: Mám zavirovaný počítač, prosím o pomoc

Napsal: 09 srp 2014 17:28
od Rudy
Ještě poprosím o log ComboFix:
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware.

Re: Mám zavirovaný počítač, prosím o pomoc

Napsal: 09 srp 2014 20:02
od Duinhil
Stránku nelze otevřít :/

Re: Mám zavirovaný počítač, prosím o pomoc

Napsal: 09 srp 2014 20:31
od motji
Vypněte antivir, momentálně má Avast s combofixem trošku problém :D

Re: Mám zavirovaný počítač, prosím o pomoc

Napsal: 17 srp 2014 22:55
od Duinhil
Promiňte že tak pozdě byl jsem na dovolený





ComboFix 14-08-15.01 - ERIK . 08. 2014 15:02:21.1.4 - x64
Microsoft Windows 8 Enterprise 6.2.9200.0.1250.420.1033.18.8173.6385 [GMT 2:00]
Spuštěný z: c:\users\ERIK\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: avast! Antivirus *Enabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\BlockAndSurf-soft
c:\program files (x86)\BlockAndSurf-soft\171.crx
c:\program files (x86)\BlockAndSurf-soft\171.dat
c:\program files (x86)\BlockAndSurf-soft\171.xpi
c:\program files (x86)\BlockAndSurf-soft\a.db
c:\program files (x86)\BlockAndSurf-soft\b.db
c:\program files (x86)\BlockAndSurf-soft\BlockAndSurfdg171.bin
c:\program files (x86)\BlockAndSurf-soft\BlockAndSurfdg171.dll
c:\program files (x86)\BlockAndSurf-soft\BlockAndSurfdg171.ini
c:\program files (x86)\BlockAndSurf-soft\Sqlite3.dll
c:\program files (x86)\CostMin
c:\program files (x86)\CostMin\U.dat
c:\program files (x86)\CostMin\U.tlb
c:\program files (x86)\MyPC Backup
c:\program files (x86)\MyPC Backup\aff.conf
c:\program files (x86)\MyPC Backup\AlphaVSS.51.x86.dll
c:\program files (x86)\MyPC Backup\AlphaVSS.52.x64.dll
c:\program files (x86)\MyPC Backup\AlphaVSS.52.x86.dll
c:\program files (x86)\MyPC Backup\AlphaVSS.60.x64.dll
c:\program files (x86)\MyPC Backup\AlphaVSS.60.x86.dll
c:\program files (x86)\MyPC Backup\AlphaVSS.Common.dll
c:\program files (x86)\MyPC Backup\AWSSDK.dll
c:\program files (x86)\MyPC Backup\BackupStack.exe
c:\program files (x86)\MyPC Backup\Config\api.ts2
c:\program files (x86)\MyPC Backup\Configuration Updater.exe
c:\program files (x86)\MyPC Backup\Crypto32.dll
c:\program files (x86)\MyPC Backup\Crypto64.dll
c:\program files (x86)\MyPC Backup\Database\mpcb_backup_conf.db
c:\program files (x86)\MyPC Backup\Database\mpcb_backup_id.db
c:\program files (x86)\MyPC Backup\Database\mpcb_file_cache.db
c:\program files (x86)\MyPC Backup\Database\mpcb_queues.db
c:\program files (x86)\MyPC Backup\Database\mpcb_settings.db
c:\program files (x86)\MyPC Backup\Database\mpcb_sig_cache.db
c:\program files (x86)\MyPC Backup\Database\mpcb_version_queue.db
c:\program files (x86)\MyPC Backup\de_DE.mo
c:\program files (x86)\MyPC Backup\diffstack.dll
c:\program files (x86)\MyPC Backup\es_ES.mo
c:\program files (x86)\MyPC Backup\fr_FR.mo
c:\program files (x86)\MyPC Backup\GetText.dll
c:\program files (x86)\MyPC Backup\it_IT.mo
c:\program files (x86)\MyPC Backup\log\APPLICATION.log
c:\program files (x86)\MyPC Backup\log\AUTH.log
c:\program files (x86)\MyPC Backup\log\BACKOFF.log
c:\program files (x86)\MyPC Backup\log\BACKUP.log
c:\program files (x86)\MyPC Backup\log\BACKUP_COMPLETE.log
c:\program files (x86)\MyPC Backup\log\CLIENT.log
c:\program files (x86)\MyPC Backup\log\EXTERNAL_DRIVE.log
c:\program files (x86)\MyPC Backup\log\GRID_RECOVERY.log
c:\program files (x86)\MyPC Backup\log\GRID_RECOVERY_INIT.log
c:\program files (x86)\MyPC Backup\log\LICENCE.log
c:\program files (x86)\MyPC Backup\log\NETWORK_SHARES.log
c:\program files (x86)\MyPC Backup\log\REMOTING.log
c:\program files (x86)\MyPC Backup\log\REQUEST.log
c:\program files (x86)\MyPC Backup\log\SERVICE.log
c:\program files (x86)\MyPC Backup\log\SHELL.log
c:\program files (x86)\MyPC Backup\log\UPDATER.log
c:\program files (x86)\MyPC Backup\log\UTC_MIGRATION.log
c:\program files (x86)\MyPC Backup\log\WAIT_HANDLES.log
c:\program files (x86)\MyPC Backup\LogicNP.EZShellExtensions.dll
c:\program files (x86)\MyPC Backup\MPCBClient.dll
c:\program files (x86)\MyPC Backup\MPCBContextMenu.dll
c:\program files (x86)\MyPC Backup\MPCBIconOverlays.dll
c:\program files (x86)\MyPC Backup\MyPC Backup.exe
c:\program files (x86)\MyPC Backup\mypcbackup.ico
c:\program files (x86)\MyPC Backup\ObjectListView.dll
c:\program files (x86)\MyPC Backup\pt_PT.mo
c:\program files (x86)\MyPC Backup\RegisterExtensionDotNet20_x64.exe
c:\program files (x86)\MyPC Backup\RegisterExtensionDotNet20_x86.exe
c:\program files (x86)\MyPC Backup\Resources\keycache\_00d31b12-7f0e-40ad-8537-33392cdf8a03_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_00d31b12-7f0e-40ad-8537-33392cdf8a03_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_044cd395-ed69-4f35-b88a-acd261d7610b_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_044cd395-ed69-4f35-b88a-acd261d7610b_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_044f11e6-67c7-4b63-9868-2c6cdf368d78_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_044f11e6-67c7-4b63-9868-2c6cdf368d78_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_1a3b7959-8cab-436e-a38f-e4d2d398efb5_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_1a3b7959-8cab-436e-a38f-e4d2d398efb5_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_275e7c6c-4e0d-498c-a1ca-93a9813ce7f5_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_275e7c6c-4e0d-498c-a1ca-93a9813ce7f5_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_27f85087-cd02-47d9-a351-8243a6a18563_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_27f85087-cd02-47d9-a351-8243a6a18563_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_2bd55eea-bef2-4a31-bcae-93453589634f_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_2bd55eea-bef2-4a31-bcae-93453589634f_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_3229e601-937e-422a-a24b-09fe44c09a33_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_3229e601-937e-422a-a24b-09fe44c09a33_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_3a150413-cde8-4902-8dbd-426f42cc29a2_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_3a150413-cde8-4902-8dbd-426f42cc29a2_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_3bc95fac-ca56-49c3-bfb1-b0d699b78a11_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_3bc95fac-ca56-49c3-bfb1-b0d699b78a11_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_416bd435-9cbf-4875-99a4-dcb109b84b56_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_416bd435-9cbf-4875-99a4-dcb109b84b56_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_45a61454-84a5-4e6d-8497-ad4042be0a2d_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_45a61454-84a5-4e6d-8497-ad4042be0a2d_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_52d8d3b1-fc02-4392-bad6-e4f8bfa00d66_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_52d8d3b1-fc02-4392-bad6-e4f8bfa00d66_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_568de197-b3f0-4dca-9faa-eaf4c6f366d1_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_568de197-b3f0-4dca-9faa-eaf4c6f366d1_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_56e8f451-597e-4052-93c0-e4bc63a80fe7_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_56e8f451-597e-4052-93c0-e4bc63a80fe7_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_5cf35bbb-45ef-48fb-8680-b0d7e6a77870_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_5cf35bbb-45ef-48fb-8680-b0d7e6a77870_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_62c69f97-c0c9-4b25-aa3e-7640a7d8f95f_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_62c69f97-c0c9-4b25-aa3e-7640a7d8f95f_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_63b54707-7ccf-41f7-8498-22206d16ea67_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_63b54707-7ccf-41f7-8498-22206d16ea67_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_66d09aae-d31e-4b10-81c7-288c74bad90c_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_66d09aae-d31e-4b10-81c7-288c74bad90c_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_6770c614-4745-4804-b5ab-1bc3cc948339_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_6770c614-4745-4804-b5ab-1bc3cc948339_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_71cf9807-4ef2-4019-a5a9-84b23d46f3b2_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_71cf9807-4ef2-4019-a5a9-84b23d46f3b2_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_77e6b83f-7a45-44e8-99d7-64943b0972f8_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_77e6b83f-7a45-44e8-99d7-64943b0972f8_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_79062d06-ad1b-476d-a608-ba0b18ed18bc_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_79062d06-ad1b-476d-a608-ba0b18ed18bc_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_801d2858-0c7f-4457-933b-ae83c88a2c75_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_801d2858-0c7f-4457-933b-ae83c88a2c75_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_8bb9c72a-e36b-41db-9190-0f803c844f2b_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_8bb9c72a-e36b-41db-9190-0f803c844f2b_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_8c3f78d8-2fcb-417c-bf79-b2892437152a_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_8c3f78d8-2fcb-417c-bf79-b2892437152a_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_8d11b528-bfa9-41cd-9bd1-2c0ebb4a9310_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_8d11b528-bfa9-41cd-9bd1-2c0ebb4a9310_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_8eb4fe56-12c4-4ec8-ad74-d748ee37aca4_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_8eb4fe56-12c4-4ec8-ad74-d748ee37aca4_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_9528ecd1-97d2-47d4-86b8-5beedebd98c4_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_9528ecd1-97d2-47d4-86b8-5beedebd98c4_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_9743d62e-5324-437c-998c-ae476c53e6b9_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_9743d62e-5324-437c-998c-ae476c53e6b9_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_a02b45e7-d5cf-401c-931f-12d63884726a_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_a02b45e7-d5cf-401c-931f-12d63884726a_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_a2ada733-31e0-4b15-a8d7-47f80775db46_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_a2ada733-31e0-4b15-a8d7-47f80775db46_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_a9feaedd-b228-4f34-9cfd-1c8c6e0e7104_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_a9feaedd-b228-4f34-9cfd-1c8c6e0e7104_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_aba289b5-a7cd-4eb1-b30a-56e3c9707480_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_aba289b5-a7cd-4eb1-b30a-56e3c9707480_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_b5587489-fe30-42d0-bc3d-9b3aed6d8aa0_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_b5587489-fe30-42d0-bc3d-9b3aed6d8aa0_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_bdbc0f1a-fd1b-4e49-b101-93fcec486f4e_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_bdbc0f1a-fd1b-4e49-b101-93fcec486f4e_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_c35d5d7b-3c71-4266-ab28-71d0e6f2e87c_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_c35d5d7b-3c71-4266-ab28-71d0e6f2e87c_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_c5f7d6f9-f2c1-40e7-838b-192bf9e4b242_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_c5f7d6f9-f2c1-40e7-838b-192bf9e4b242_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_d6cbc30d-a798-454a-856d-82389c7a0980_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_d6cbc30d-a798-454a-856d-82389c7a0980_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_d861f6af-8811-4322-bd52-6d02edc79386_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_d861f6af-8811-4322-bd52-6d02edc79386_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_dbad659e-a42a-47cf-952d-5c70427ce360_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_dbad659e-a42a-47cf-952d-5c70427ce360_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_dbdff6e3-1be0-4811-85fa-472248ab5b86_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_dbdff6e3-1be0-4811-85fa-472248ab5b86_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\Resources\keycache\_dda15aba-6a4b-47bb-aa43-70cabc9e55fa_backupKeyCache.block
c:\program files (x86)\MyPC Backup\Resources\keycache\_dda15aba-6a4b-47bb-aa43-70cabc9e55fa_backupKeyCache.tree
c:\program files (x86)\MyPC Backup\RestartExplorer.exe
c:\program files (x86)\MyPC Backup\Service Start.exe
c:\program files (x86)\MyPC Backup\Shared Stack.dll
c:\program files (x86)\MyPC Backup\Signup Wizard.exe
c:\program files (x86)\MyPC Backup\syncicon.ico
c:\program files (x86)\MyPC Backup\syncing.ico
c:\program files (x86)\MyPC Backup\tick.ico
c:\program files (x86)\MyPC Backup\uninst.exe
c:\program files (x86)\MyPC Backup\UnRegisterExtensions.exe
c:\program files (x86)\MyPC Backup\Updater.exe
c:\program files (x86)\MyPC Backup\x64\System.Data.SQLite.dll
c:\program files (x86)\MyPC Backup\x86\System.Data.SQLite.dll
c:\program files (x86)\ShopperPro
c:\program files (x86)\ShopperPro\config.json
c:\program files (x86)\ShopperPro\database1_0_0.json
c:\program files (x86)\ShopperPro\FireFox\content\overlay.js
c:\program files (x86)\ShopperPro\FireFox\content\overlay.xul
c:\program files (x86)\ShopperPro\FireFox\content\shopperpro_128.png
c:\program files (x86)\ShopperPro\FireFox\chrome.manifest
c:\program files (x86)\ShopperPro\FireFox\install.rdf
c:\program files (x86)\ShopperPro\JSDriver\1.35.1.155\config.json
c:\program files (x86)\ShopperPro\JSDriver\1.35.1.155\database1_0_0.json
c:\program files (x86)\ShopperPro\JSDriver\1.35.1.155\jsdrv.exe
c:\program files (x86)\ShopperPro\JSDriver\1.35.1.155\jsdrv.sys
c:\program files (x86)\ShopperPro\JSDriver\1.37.0.193\config.json
c:\program files (x86)\ShopperPro\JSDriver\1.37.0.193\database1_0_0.json
c:\program files (x86)\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe
c:\program files (x86)\ShopperPro\JSDriver\1.37.0.193\jsdrv.sys
c:\program files (x86)\ShopperPro\JSDriver\1.37.1.189\config.json
c:\program files (x86)\ShopperPro\JSDriver\1.37.1.189\database1_0_0.json
c:\program files (x86)\ShopperPro\JSDriver\1.37.1.189\jsdrv.exe
c:\program files (x86)\ShopperPro\JSDriver\1.37.1.189\jsdrv.sys
c:\program files (x86)\ShopperPro\JSDriver\jsdrv.exe
c:\program files (x86)\ShopperPro\JSDriver\jsdrv.sys
c:\program files (x86)\ShopperPro\JSDriver\JSEngine.dll
c:\program files (x86)\ShopperPro\JSDriver\jsinst.exe
c:\program files (x86)\ShopperPro\JSDriver\jslsp.dll
c:\program files (x86)\ShopperPro\JSDriver\JSxmldb.dll
c:\program files (x86)\ShopperPro\JSDriver\sporder.dll
c:\program files (x86)\ShopperPro\manifest.json
c:\program files (x86)\ShopperPro\ShopperPro.crx
c:\program files (x86)\ShopperPro\ShopperPro.zip
c:\program files (x86)\ShopperPro\ShopperPro64.dll
c:\programdata\641461883ccda8f7
c:\programdata\641461883ccda8f7\{2F5F003B-C71B-72E3-42B4-DE51AB079EB2}
c:\programdata\CostMin
c:\programdata\CostMin\gV.dat
c:\users\ERIK\AppData\Local\Microsoft\Windows\Temporary Internet Files\{6A0569A8-1D6F-4C81-B6AD-3CFE323E5605}.xps
c:\users\ERIK\AppData\Local\Microsoft\Windows\Temporary Internet Files\{CBBBA99F-CAFF-489B-8455-DF1C77F84EAC}.xps
c:\users\ERIK\AppData\Local\MSGBOX.EXE
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_BackupStack
-------\Legacy_SPDRIVER_1.37.0.193
-------\Legacy_BackupStack
-------\Legacy_SPDRIVER_1.37.0.193
-------\Service_BackupStack
-------\Service_SPDRIVER_1.37.0.193
-------\Service_BackupStack
-------\Service_SPDRIVER_1.37.0.193
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-07-17 do 2014-08-17 )))))))))))))))))))))))))))))))
.
.
2014-08-17 13:09 . 2014-08-17 13:09 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-08-14 10:05 . 2014-08-14 10:05 17536 ----a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2014-08-13 17:57 . 2014-08-13 17:57 262312 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10244.bin
2014-08-13 13:18 . 2014-07-15 22:51 71168 ----a-w- c:\windows\system32\drivers\hdaudbus.sys
2014-08-13 13:16 . 2014-06-10 22:44 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-08-13 13:16 . 2014-06-10 22:43 35480 ----a-w- c:\windows\SysWow64\TsWpfWrp.exe
2014-08-09 10:11 . 2014-08-09 10:10 28184 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2014-08-09 10:11 . 2014-08-09 10:11 43152 ----a-w- c:\windows\avastSS.scr
2014-08-09 10:10 . 2014-08-09 10:10 448400 ----a-w- c:\windows\system32\drivers\aswNdisFlt.sys
2014-08-09 09:21 . 2014-08-17 13:12 122584 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-08-09 09:21 . 2014-08-09 09:21 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2014-08-09 09:21 . 2014-08-09 09:21 -------- d-----w- c:\programdata\Malwarebytes
2014-08-09 09:21 . 2014-05-12 05:26 64216 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-08-09 09:21 . 2014-05-12 05:26 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-08-09 09:21 . 2014-05-12 05:25 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-08-09 09:18 . 2014-08-09 09:18 -------- d-----w- c:\users\ERIK\AppData\Local\TuneUp Software
2014-08-08 19:26 . 2014-08-17 13:09 -------- d-----w- c:\users\ERIK\AppData\Local\Temp
2014-08-08 17:05 . 2014-08-08 17:05 -------- d-----w- c:\users\ERIK\AppData\Local\Adobe
2014-08-08 16:50 . 2014-08-08 19:25 -------- d-----w- C:\FRST
2014-08-08 14:45 . 2014-08-09 09:55 -------- d-----w- c:\program files (x86)\trend micro
2014-08-08 14:45 . 2014-08-08 14:45 -------- d-----w- C:\rsit
2014-08-06 17:51 . 2014-08-06 17:51 -------- d-----w- c:\users\ERIK\New folder
2014-08-06 13:35 . 2014-08-06 13:35 -------- d-----w- c:\programdata\Steam
2014-07-30 17:36 . 2014-07-30 17:37 -------- d-----w- c:\program files (x86)\Europa Universalis IV
2014-07-30 17:15 . 2014-07-30 17:15 -------- d-----w- c:\program files (x86)\Origin Games
2014-07-29 10:06 . 2014-07-29 10:06 -------- d-----w- c:\windows\system32\appmgmt
2014-07-28 17:54 . 2014-07-28 17:56 -------- d-----w- c:\program files (x86)\Cossacks - Back To War
2014-07-28 17:53 . 2002-09-12 14:14 4296704 ----a-r- c:\windows\una2setup.exe
2014-07-28 17:30 . 2014-07-28 17:30 -------- d-----w- c:\program files (x86)\American Conquest - Fight Back
2014-07-28 10:43 . 2014-07-28 10:43 53248 ----a-w- c:\windows\SysWow64\unrar.dll
2014-07-28 10:43 . 2002-04-22 07:15 4284416 ----a-r- c:\windows\uncsetup.exe
2014-07-28 10:36 . 2014-08-17 13:06 -------- d-----w- c:\programdata\IePluginServices
2014-07-28 10:35 . 2014-08-17 13:06 -------- d-----w- c:\programdata\WindowsMangerProtect
2014-07-28 10:34 . 2014-07-28 10:34 -------- d-----w- c:\users\ERIK\AppData\Local\MaxiGet Download Manager
2014-07-27 20:47 . 2014-07-27 20:47 -------- d-----w- c:\program files (x86)\GSC Game World
2014-07-22 15:30 . 2014-07-22 15:30 -------- d-----w- c:\program files (x86)\Seznam.cz
2014-07-22 15:29 . 2014-08-14 10:03 -------- d-----w- c:\users\ERIK\AppData\Roaming\Seznam.cz
2014-07-22 15:04 . 2014-07-22 15:04 -------- d-----w- c:\users\ERIK\AppData\Roaming\Civitas3
2014-07-22 15:02 . 2014-07-28 15:02 -------- d-----w- c:\programdata\McAfee Security Scan
2014-07-22 15:02 . 2014-07-22 15:02 -------- d-----w- c:\programdata\McAfee
2014-07-21 16:39 . 2014-07-21 16:39 -------- d-----w- c:\users\ERIK\AppData\Roaming\HeroesAndGeneralsDesktop
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-08-13 13:26 . 2013-12-10 21:34 99218768 ----a-w- c:\windows\system32\MRT.exe
2014-08-09 10:11 . 2014-06-04 17:11 427360 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-08-09 10:11 . 2014-06-04 17:11 92008 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-08-09 10:11 . 2014-06-04 17:11 224896 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-08-09 10:11 . 2014-06-04 17:11 79184 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-08-09 10:11 . 2014-06-04 17:11 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-08-09 10:11 . 2014-06-04 17:11 29208 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-08-09 10:11 . 2014-06-04 17:11 1041168 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-08-09 10:11 . 2014-06-04 17:11 307344 ----a-w- c:\windows\system32\aswBoot.exe
2014-08-09 10:11 . 2014-06-04 17:11 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-08-02 00:15 . 2013-12-10 22:00 704480 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-08-02 00:15 . 2013-12-10 22:00 105440 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-07-16 08:24 . 2013-12-26 21:01 40760 ----a-w- c:\windows\system32\TURegOpt.exe
2014-07-16 08:24 . 2014-01-08 22:24 43320 ----a-w- c:\windows\system32\uxtuneup.dll
2014-07-16 08:24 . 2013-12-26 21:01 29496 ----a-w- c:\windows\system32\authuitu.dll
2014-07-16 08:24 . 2013-12-26 21:01 25400 ----a-w- c:\windows\SysWow64\authuitu.dll
2014-07-16 08:24 . 2014-01-08 22:24 36152 ----a-w- c:\windows\SysWow64\uxtuneup.dll
2014-07-12 13:11 . 2014-03-05 17:31 76152 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2014-07-12 13:11 . 2014-03-05 17:33 297088 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2014-07-12 13:11 . 2014-03-05 17:31 297088 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2014-07-12 13:08 . 2014-03-05 17:31 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2014-06-30 22:42 . 2014-07-09 21:04 394240 ----a-w- c:\windows\system32\devinv.dll
2014-06-30 22:42 . 2014-07-09 21:04 87552 ----a-w- c:\windows\system32\aepic.dll
2014-06-17 23:27 . 2014-07-09 21:05 1440256 ----a-w- c:\windows\SysWow64\osk.exe
2014-06-17 23:24 . 2014-07-09 21:05 1557504 ----a-w- c:\windows\system32\osk.exe
2014-06-06 14:06 . 2014-07-09 21:04 596480 ----a-w- c:\windows\system32\qedit.dll
2014-06-06 10:17 . 2014-07-09 21:04 497152 ----a-w- c:\windows\SysWow64\qedit.dll
2014-06-02 22:33 . 2014-07-09 21:05 265216 ----a-w- c:\windows\system32\InkEd.dll
2014-05-29 23:31 . 2014-07-09 21:05 452608 ----a-w- c:\windows\SysWow64\SHCore.dll
2014-05-29 23:03 . 2014-07-09 21:05 588288 ----a-w- c:\windows\system32\SHCore.dll
2014-05-29 23:02 . 2014-07-09 21:05 439808 ----a-w- c:\windows\system32\lsm.dll
2014-05-29 23:02 . 2014-07-09 21:05 1281536 ----a-w- c:\windows\system32\lsasrv.dll
2014-05-29 22:24 . 2014-07-09 21:04 576512 ----a-w- c:\windows\system32\drivers\afd.sys
2014-05-29 19:40 . 2014-05-29 19:40 283064 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2014-05-26 16:54 . 2014-04-24 17:19 78336 ----a-w- c:\windows\SysWow64\rp.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-11-14 20586656]
"hmemms"="c:\users\ERIK\MSOCache32\patch\files\hmemmsi.exe" [2014-03-25 84480]
"Steam"="c:\program files (x86)\Steam\Steam.exe" [2014-08-13 1937600]
"AVG-Secure-Search-Update_0414c"="c:\program files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe" [2014-04-24 2725912]
"DAEMON Tools Lite"="d:\hry\DAEMON Tools Lite\DTLite.exe" [2014-03-04 3696912]
"EADM"="c:\program files (x86)\Origin\Origin.exe" [2014-07-25 3595608]
"cz.seznam.software.autoupdate"="c:\users\ERIK\AppData\Roaming\Seznam.cz\szninstall.exe" [2013-05-16 1062472]
"cz.seznam.software.szndesktop"="c:\users\ERIK\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" [2013-04-12 92664]
"uTorrent"="c:\users\ERIK\AppData\Roaming\uTorrent\uTorrent.exe" [2014-07-28 1270864]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"V0700Mon.exe"="c:\windows\V0700Mon.exe" [2011-08-22 28672]
"vProt"="c:\program files (x86)\AVG SafeGuard toolbar\vprot.exe" [2014-05-07 2561560]
"Gameiki"="d:\hry\Gameiki Mod Installer\Gameiki Mod Installer.exe" [2014-02-23 358912]
"BlueStacks Agent"="c:\program files (x86)\BlueStacks\HD-Agent.exe" [2014-03-13 819984]
"Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2014-03-21 2691480]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-08-09 4085896]
"seznam-listicka-distribuce"="c:\program files (x86)\Seznam.cz\distribution\szninstall.exe" [2013-05-16 1062472]
.
c:\users\ERIK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE /tsr [2013-6-25 228552]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R0 prohlp01;StarForce Protection Helper Driver v1;c:\windows\System32\drivers\prohlp01.sys;c:\windows\SYSNATIVE\drivers\prohlp01.sys [x]
R1 {f9d2f209-1697-4837-85f2-d88e4c9f7c81}Gw64;{f9d2f209-1697-4837-85f2-d88e4c9f7c81}Gw64;c:\windows\system32\drivers\{f9d2f209-1697-4837-85f2-d88e4c9f7c81}Gw64.sys;c:\windows\SYSNATIVE\drivers\{f9d2f209-1697-4837-85f2-d88e4c9f7c81}Gw64.sys [x]
R1 prodrv05;StarForce Protection Environment Driver v5;c:\windows\System32\drivers\prodrv05.sys;c:\windows\SYSNATIVE\drivers\prodrv05.sys [x]
R2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.3.132.0\BBSvc.exe;c:\program files (x86)\Microsoft\BingBar\7.3.132.0\BBSvc.exe [x]
R2 BstHdAndroidSvc;BlueStacks Android Service;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]
R2 IePluginServices;IePlugin Services;c:\programdata\IePluginServices\PluginService.exe;c:\programdata\IePluginServices\PluginService.exe [x]
R2 Update wisen wizard;Update wisen wizard;c:\program files (x86)\wisen wizard\updatewisenwizard.exe;c:\program files (x86)\wisen wizard\updatewisenwizard.exe [x]
R2 Util wisen wizard;Util wisen wizard;c:\program files (x86)\wisen wizard\bin\utilwisenwizard.exe;c:\program files (x86)\wisen wizard\bin\utilwisenwizard.exe [x]
R2 WindowsMangerProtect;WindowsMangerProtect Service;c:\programdata\WindowsMangerProtect\ProtectWindowsManager.exe;c:\programdata\WindowsMangerProtect\ProtectWindowsManager.exe [x]
R3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.exe;c:\program files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.exe [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
R3 SPBIUpdd;ShopperPro UpdateD;c:\program files\Common Files\ShopperPro\spbiw.sys;c:\program files\Common Files\ShopperPro\spbiw.sys [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 ssudserd;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudserd.sys;c:\windows\SYSNATIVE\DRIVERS\ssudserd.sys [x]
R3 vmicheartbeat;Hyper-V Heartbeat Service;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x]
S0 aswNdisFlt;Avast! Firewall Driver;c:\windows\system32\DRIVERS\aswNdisFlt.sys;c:\windows\SYSNATIVE\DRIVERS\aswNdisFlt.sys [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys;c:\windows\SYSNATIVE\drivers\aswKbd.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\System32\drivers\dtsoftbus01.sys;c:\windows\SYSNATIVE\drivers\dtsoftbus01.sys [x]
S2 APNMCP;Ask Update Service;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe;c:\program files\AVAST Software\Avast\afwServ.exe [x]
S2 BstHdDrv;BlueStacks Hypervisor;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [x]
S2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe [x]
S2 BstHdUpdaterSvc;BlueStacks Updater Service;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe;c:\program files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [x]
S2 vToolbarUpdater18.1.5;vToolbarUpdater18.1.5;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.5\ToolbarUpdater.exe;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.5\ToolbarUpdater.exe [x]
S3 AU8168;AU 8168 NT Driver;c:\windows\system32\DRIVERS\au630x64.sys;c:\windows\SYSNATIVE\DRIVERS\au630x64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys;c:\program files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [x]
S3 V0700Vid;Creative Live! Cam Chat HD Driver;c:\windows\system32\DRIVERS\V0700Vid.sys;c:\windows\SYSNATIVE\DRIVERS\V0700Vid.sys [x]
S3 WSDScan;WSD Scan Support;c:\windows\system32\DRIVERS\WSDScan.sys;c:\windows\SYSNATIVE\DRIVERS\WSDScan.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-08-15 14:21 1104200 ----a-w- c:\program files (x86)\Google\Chrome\Application\36.0.1985.143\Installer\chrmstp.exe
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{A6EADE66-0000-0000-484E-7E8A45000000}]
2013-09-05 14:04 215416 ----a-w- c:\program files (x86)\Adobe\Reader 11.0\Esl\AiodLite.dll
.
Obsah adresáře 'Naplánované úlohy'
.
2014-08-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-22 15:02]
.
2014-08-17 c:\windows\Tasks\AVG-Secure-Search-Update_0414c_rel.job
- c:\program files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe [2014-04-24 19:15]
.
2014-08-17 c:\windows\Tasks\AVG-Secure-Search-Update_0414c_rmv.job
- c:\program files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe [2014-04-24 19:15]
.
2014-08-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-11 17:58]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1]
@="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}"
[HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}]
2014-03-20 09:24 667808 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2]
@="{853B7E05-C47D-4985-909A-D0DC5C6D7303}"
[HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}]
2014-03-20 09:24 667808 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3]
@="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}"
[HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}]
2014-03-20 09:24 667808 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-08-09 10:11 634872 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 164016 ----a-w- c:\users\ERIK\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 164016 ----a-w- c:\users\ERIK\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 164016 ----a-w- c:\users\ERIK\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 164016 ----a-w- c:\users\ERIK\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2013-10-01 7199448]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
uInternet Settings,ProxyServer = http=127.0.0.1:14326;https=127.0.0.1:14326
TCP: DhcpNameServer = 192.168.3.20 192.168.0.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.5\ViProtocol.dll
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{D24B1533-0F9F-16A6-085C-C003477D15EF} - (no file)
Wow6432Node-HKCU-Run-SPDriver - c:\program files (x86)\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe
Wow6432Node-HKLM-Run-SPDriver - c:\program files (x86)\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe
c:\users\ERIK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk - c:\program files (x86)\MyPC Backup\MyPC Backup.exe
c:\users\ERIK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Unify3DWebPlayerUpdate.lnk - c:\users\ERIK\AppData\Local\Unify3D\WebPlayer\Unify3DWebPlayerUpdate.exe
AddRemove-6606702C-EC7C-2EBB-5BEA-1518D256F019 - c:\program files (x86)\BlockAndSurf-soft\Uninstall.exe
AddRemove-BattlEye A2 Free - d:\hry\Bohemia InteractiveBattlEye\UnInstallBE.exe
AddRemove-iWebar - c:\program files (x86)\iWebar\Uninstall.exe
AddRemove-ShopperPro - c:\program files (x86)\ShopperPro\SPremove.exe
AddRemove-WindowsMangerProtect - c:\programdata\WindowsMangerProtect\ProtectWindowsManager.exe
AddRemove-{2F5F003B-C71B-72E3-42B4-DE51AB079EB2} - c:\programdata\CostMin\gV.exe
AddRemove-{5F189DF5-2D05-472B-9091-84D9848AE48B}{be0fb33b} - c:\progra~2\SUPPOR~1\SUPPOR~1.DLL
AddRemove-DesktopWeatherAlerts - c:\users\ERIK\AppData\Local\WeatherAlerts\DesktopWeatherAlertsuninstall.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\BlueStacks]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Malwarebytes Anti-Malware\mbam.exe
c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.5\loggingserver.exe
c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
c:\program files (x86)\Steam\bin\steamwebhelper.exe
c:\program files (x86)\Common Files\Steam\SteamService.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
.
**************************************************************************
.
Celkový čas: 2014-08-17 15:18:31 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-08-17 13:18
.
Před spuštěním: 10 511 650 816 bytes free
Po spuštění: 10 410 131 456 bytes free
.
- - End Of File - - 186FE3832BD5965D77CB837BA2DCB1B1
A36C5E4F47E84449FF07ED3517B43A31

Re: Mám zavirovaný počítač, prosím o pomoc

Napsal: 18 srp 2014 10:52
od Rudy
Ještě dočistíme. Přesuňte ComboFix na plochu. Otevřte poznámkový blok a zkopírujte do něj:

KillAll::
File::
c:\windows\una2setup.exe
c:\users\ERIK\MSOCache32\patch\files\hmemmsi.exe
c:\windows\SYSNATIVE\drivers\{f9d2f209-1697-4837-85f2-d88e4c9f7c81}Gw64.sys
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\AVG-Secure-Search-Update_0414c_rel.job
c:\windows\Tasks\AVG-Secure-Search-Update_0414c_rmv.job

Folder::
c:\programdata\McAfee Security Scan

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hmemms"=-

Driver::
f9d2f209-1697-4837-85f2-d88e4c9f7c81}Gw64;{f9d2f209-1697-4837-85f2-d88e4c9f7c81}Gw64
BBSvc
BBUpdate

RegLock::
[HKEY_LOCAL_MACHINE\SOFTWARE\BlueStacks]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

Reboot::
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek

Re: Mám zavirovaný počítač, prosím o pomoc

Napsal: 20 srp 2014 11:05
od Duinhil
Hotovo

Re: Mám zavirovaný počítač, prosím o pomoc

Napsal: 20 srp 2014 11:24
od Duinhil
ComboFix 14-08-19.01 - ERIK . 08. 2014 12:08:21.2.4 - x64
Microsoft Windows 8 Enterprise 6.2.9200.0.1250.420.1033.18.8173.6425 [GMT 2:00]
Spuštěný z: c:\users\ERIK\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\ERIK\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: avast! Antivirus *Enabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\users\ERIK\MSOCache32\patch\files\hmemmsi.exe"
"c:\windows\system32\drivers\{f9d2f209-1697-4837-85f2-d88e4c9f7c81}Gw64.sys"
"c:\windows\Tasks\AVG-Secure-Search-Update_0414c_rel.job"
"c:\windows\Tasks\AVG-Secure-Search-Update_0414c_rmv.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\una2setup.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\McAfee Security Scan
c:\programdata\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
c:\programdata\McAfee Security Scan\Extensions\RegFireFoxAddon.exe
c:\programdata\McAfee Security Scan\ftstate.ini
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-07-20 do 2014-08-20 )))))))))))))))))))))))))))))))
.
.
2014-08-20 10:15 . 2014-08-20 10:15 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-08-20 10:15 . 2014-08-20 10:15 -------- d-----w- c:\users\HomeGroupUser$\AppData\Local\temp
2014-08-20 10:15 . 2014-08-20 10:15 -------- d-----w- c:\users\Guest\AppData\Local\temp
2014-08-20 10:15 . 2014-08-20 10:15 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-08-20 10:15 . 2014-08-20 10:15 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2014-08-19 11:40 . 2014-08-19 11:40 122584 ----a-w- c:\windows\system32\drivers\48230029.sys
2014-08-18 16:25 . 2014-08-18 16:25 -------- d-----w- c:\program files (x86)\Tremulous
2014-08-18 16:23 . 2014-08-18 16:23 -------- d-----w- c:\program files (x86)\Smart Driver Updater
2014-08-18 16:23 . 2014-08-18 16:23 -------- d-----w- c:\users\ERIK\AppData\Roaming\Smart Driver Updater
2014-08-18 16:23 . 2014-08-18 16:23 -------- d-----w- c:\users\ERIK\AppData\Roaming\Opera Software
2014-08-18 16:23 . 2014-08-18 16:23 -------- d-----w- c:\users\ERIK\AppData\Local\Opera Software
2014-08-18 16:23 . 2014-08-19 16:23 -------- d-----w- c:\program files (x86)\Opera
2014-08-14 10:05 . 2014-08-14 10:05 17536 ----a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin
2014-08-13 17:57 . 2014-08-13 17:57 262312 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10244.bin
2014-08-13 13:18 . 2014-07-15 22:51 71168 ----a-w- c:\windows\system32\drivers\hdaudbus.sys
2014-08-13 13:16 . 2014-06-10 22:44 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-08-13 13:16 . 2014-06-10 22:43 35480 ----a-w- c:\windows\SysWow64\TsWpfWrp.exe
2014-08-09 10:11 . 2014-08-09 10:10 28184 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2014-08-09 10:11 . 2014-08-09 10:11 43152 ----a-w- c:\windows\avastSS.scr
2014-08-09 10:10 . 2014-08-09 10:10 448400 ----a-w- c:\windows\system32\drivers\aswNdisFlt.sys
2014-08-09 09:21 . 2014-08-20 09:38 122584 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-08-09 09:21 . 2014-08-09 09:21 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2014-08-09 09:21 . 2014-08-09 09:21 -------- d-----w- c:\programdata\Malwarebytes
2014-08-09 09:21 . 2014-05-12 05:26 64216 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-08-09 09:21 . 2014-05-12 05:26 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-08-09 09:21 . 2014-05-12 05:25 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-08-09 09:18 . 2014-08-09 09:18 -------- d-----w- c:\users\ERIK\AppData\Local\TuneUp Software
2014-08-08 19:26 . 2014-08-20 10:18 -------- d-----w- c:\users\ERIK\AppData\Local\Temp
2014-08-08 17:05 . 2014-08-08 17:05 -------- d-----w- c:\users\ERIK\AppData\Local\Adobe
2014-08-08 16:50 . 2014-08-08 19:25 -------- d-----w- C:\FRST
2014-08-08 14:45 . 2014-08-09 09:55 -------- d-----w- c:\program files (x86)\trend micro
2014-08-08 14:45 . 2014-08-08 14:45 -------- d-----w- C:\rsit
2014-08-06 17:51 . 2014-08-06 17:51 -------- d-----w- c:\users\ERIK\New folder
2014-08-06 13:35 . 2014-08-06 13:35 -------- d-----w- c:\programdata\Steam
2014-07-30 17:36 . 2014-07-30 17:37 -------- d-----w- c:\program files (x86)\Europa Universalis IV
2014-07-30 17:15 . 2014-07-30 17:15 -------- d-----w- c:\program files (x86)\Origin Games
2014-07-29 10:06 . 2014-07-29 10:06 -------- d-----w- c:\windows\system32\appmgmt
2014-07-28 17:54 . 2014-07-28 17:56 -------- d-----w- c:\program files (x86)\Cossacks - Back To War
2014-07-28 17:53 . 2002-09-12 14:14 4296704 ----a-r- c:\windows\una2setup.exe
2014-07-28 17:30 . 2014-07-28 17:30 -------- d-----w- c:\program files (x86)\American Conquest - Fight Back
2014-07-28 10:43 . 2014-07-28 10:43 53248 ----a-w- c:\windows\SysWow64\unrar.dll
2014-07-28 10:43 . 2002-04-22 07:15 4284416 ----a-r- c:\windows\uncsetup.exe
2014-07-28 10:36 . 2014-08-17 13:06 -------- d-----w- c:\programdata\IePluginServices
2014-07-28 10:35 . 2014-08-17 13:06 -------- d-----w- c:\programdata\WindowsMangerProtect
2014-07-28 10:34 . 2014-07-28 10:34 -------- d-----w- c:\users\ERIK\AppData\Local\MaxiGet Download Manager
2014-07-27 20:47 . 2014-07-27 20:47 -------- d-----w- c:\program files (x86)\GSC Game World
2014-07-22 15:30 . 2014-07-22 15:30 -------- d-----w- c:\program files (x86)\Seznam.cz
2014-07-22 15:29 . 2014-08-14 10:03 -------- d-----w- c:\users\ERIK\AppData\Roaming\Seznam.cz
2014-07-22 15:04 . 2014-07-22 15:04 -------- d-----w- c:\users\ERIK\AppData\Roaming\Civitas3
2014-07-22 15:02 . 2014-07-22 15:02 -------- d-----w- c:\programdata\McAfee
2014-07-21 16:39 . 2014-07-21 16:39 -------- d-----w- c:\users\ERIK\AppData\Roaming\HeroesAndGeneralsDesktop
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-08-13 13:26 . 2013-12-10 21:34 99218768 ----a-w- c:\windows\system32\MRT.exe
2014-08-09 10:11 . 2014-06-04 17:11 427360 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-08-09 10:11 . 2014-06-04 17:11 92008 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-08-09 10:11 . 2014-06-04 17:11 224896 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-08-09 10:11 . 2014-06-04 17:11 79184 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-08-09 10:11 . 2014-06-04 17:11 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-08-09 10:11 . 2014-06-04 17:11 29208 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-08-09 10:11 . 2014-06-04 17:11 1041168 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-08-09 10:11 . 2014-06-04 17:11 307344 ----a-w- c:\windows\system32\aswBoot.exe
2014-08-09 10:11 . 2014-06-04 17:11 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-08-02 00:15 . 2013-12-10 22:00 704480 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-08-02 00:15 . 2013-12-10 22:00 105440 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-07-16 08:24 . 2013-12-26 21:01 40760 ----a-w- c:\windows\system32\TURegOpt.exe
2014-07-16 08:24 . 2014-01-08 22:24 43320 ----a-w- c:\windows\system32\uxtuneup.dll
2014-07-16 08:24 . 2013-12-26 21:01 29496 ----a-w- c:\windows\system32\authuitu.dll
2014-07-16 08:24 . 2013-12-26 21:01 25400 ----a-w- c:\windows\SysWow64\authuitu.dll
2014-07-16 08:24 . 2014-01-08 22:24 36152 ----a-w- c:\windows\SysWow64\uxtuneup.dll
2014-07-12 13:11 . 2014-03-05 17:31 76152 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2014-07-12 13:11 . 2014-03-05 17:33 297088 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2014-07-12 13:11 . 2014-03-05 17:31 297088 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2014-07-12 13:08 . 2014-03-05 17:31 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2014-06-30 22:42 . 2014-07-09 21:04 394240 ----a-w- c:\windows\system32\devinv.dll
2014-06-30 22:42 . 2014-07-09 21:04 87552 ----a-w- c:\windows\system32\aepic.dll
2014-06-17 23:27 . 2014-07-09 21:05 1440256 ----a-w- c:\windows\SysWow64\osk.exe
2014-06-17 23:24 . 2014-07-09 21:05 1557504 ----a-w- c:\windows\system32\osk.exe
2014-06-06 14:06 . 2014-07-09 21:04 596480 ----a-w- c:\windows\system32\qedit.dll
2014-06-06 10:17 . 2014-07-09 21:04 497152 ----a-w- c:\windows\SysWow64\qedit.dll
2014-06-02 22:33 . 2014-07-09 21:05 265216 ----a-w- c:\windows\system32\InkEd.dll
2014-05-29 23:31 . 2014-07-09 21:05 452608 ----a-w- c:\windows\SysWow64\SHCore.dll
2014-05-29 23:03 . 2014-07-09 21:05 588288 ----a-w- c:\windows\system32\SHCore.dll
2014-05-29 23:02 . 2014-07-09 21:05 439808 ----a-w- c:\windows\system32\lsm.dll
2014-05-29 23:02 . 2014-07-09 21:05 1281536 ----a-w- c:\windows\system32\lsasrv.dll
2014-05-29 22:24 . 2014-07-09 21:04 576512 ----a-w- c:\windows\system32\drivers\afd.sys
2014-05-29 19:40 . 2014-05-29 19:40 283064 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-11-14 20586656]
"Steam"="c:\program files (x86)\Steam\Steam.exe" [2014-08-13 1937600]
"AVG-Secure-Search-Update_0414c"="c:\program files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe" [2014-04-24 2725912]
"DAEMON Tools Lite"="d:\hry\DAEMON Tools Lite\DTLite.exe" [2014-03-04 3696912]
"EADM"="c:\program files (x86)\Origin\Origin.exe" [2014-07-25 3595608]
"cz.seznam.software.autoupdate"="c:\users\ERIK\AppData\Roaming\Seznam.cz\szninstall.exe" [2013-05-16 1062472]
"cz.seznam.software.szndesktop"="c:\users\ERIK\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" [2013-04-12 92664]
"uTorrent"="c:\users\ERIK\AppData\Roaming\uTorrent\uTorrent.exe" [2014-07-28 1270864]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"V0700Mon.exe"="c:\windows\V0700Mon.exe" [2011-08-22 28672]
"vProt"="c:\program files (x86)\AVG SafeGuard toolbar\vprot.exe" [2014-05-07 2561560]
"Gameiki"="d:\hry\Gameiki Mod Installer\Gameiki Mod Installer.exe" [2014-02-23 358912]
"BlueStacks Agent"="c:\program files (x86)\BlueStacks\HD-Agent.exe" [2014-03-13 819984]
"Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2014-03-21 2691480]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-08-09 4085896]
"seznam-listicka-distribuce"="c:\program files (x86)\Seznam.cz\distribution\szninstall.exe" [2013-05-16 1062472]
.
c:\users\ERIK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE /tsr [2013-6-25 228552]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R0 prohlp01;StarForce Protection Helper Driver v1;c:\windows\System32\drivers\prohlp01.sys;c:\windows\SYSNATIVE\drivers\prohlp01.sys [x]
R1 {f9d2f209-1697-4837-85f2-d88e4c9f7c81}Gw64;{f9d2f209-1697-4837-85f2-d88e4c9f7c81}Gw64;c:\windows\system32\drivers\{f9d2f209-1697-4837-85f2-d88e4c9f7c81}Gw64.sys;c:\windows\SYSNATIVE\drivers\{f9d2f209-1697-4837-85f2-d88e4c9f7c81}Gw64.sys [x]
R1 prodrv05;StarForce Protection Environment Driver v5;c:\windows\System32\drivers\prodrv05.sys;c:\windows\SYSNATIVE\drivers\prodrv05.sys [x]
R2 BstHdAndroidSvc;BlueStacks Android Service;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
R3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
R3 SPBIUpdd;ShopperPro UpdateD;c:\program files\Common Files\ShopperPro\spbiw.sys;c:\program files\Common Files\ShopperPro\spbiw.sys [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 ssudserd;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudserd.sys;c:\windows\SYSNATIVE\DRIVERS\ssudserd.sys [x]
R3 vmicheartbeat;Hyper-V Heartbeat Service;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x]
S0 aswNdisFlt;Avast! Firewall Driver;c:\windows\system32\DRIVERS\aswNdisFlt.sys;c:\windows\SYSNATIVE\DRIVERS\aswNdisFlt.sys [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys;c:\windows\SYSNATIVE\drivers\aswKbd.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\System32\drivers\dtsoftbus01.sys;c:\windows\SYSNATIVE\drivers\dtsoftbus01.sys [x]
S2 APNMCP;Ask Update Service;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe;c:\program files\AVAST Software\Avast\afwServ.exe [x]
S2 BstHdDrv;BlueStacks Hypervisor;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [x]
S2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe [x]
S2 BstHdUpdaterSvc;BlueStacks Updater Service;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe;c:\program files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [x]
S2 vToolbarUpdater18.1.5;vToolbarUpdater18.1.5;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.5\ToolbarUpdater.exe;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.5\ToolbarUpdater.exe [x]
S3 AU8168;AU 8168 NT Driver;c:\windows\system32\DRIVERS\au630x64.sys;c:\windows\SYSNATIVE\DRIVERS\au630x64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys;c:\program files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [x]
S3 V0700Vid;Creative Live! Cam Chat HD Driver;c:\windows\system32\DRIVERS\V0700Vid.sys;c:\windows\SYSNATIVE\DRIVERS\V0700Vid.sys [x]
S3 WSDScan;WSD Scan Support;c:\windows\system32\DRIVERS\WSDScan.sys;c:\windows\SYSNATIVE\DRIVERS\WSDScan.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-08-15 14:21 1104200 ----a-w- c:\program files (x86)\Google\Chrome\Application\36.0.1985.143\Installer\chrmstp.exe
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{A6EADE66-0000-0000-484E-7E8A45000000}]
2013-09-05 14:04 215416 ----a-w- c:\program files (x86)\Adobe\Reader 11.0\Esl\AiodLite.dll
.
Obsah adresáře 'Naplánované úlohy'
.
2014-08-19 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-22 15:02]
.
2014-08-20 c:\windows\Tasks\AVG-Secure-Search-Update_0414c_rel.job
- c:\program files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe [2014-04-24 19:15]
.
2014-08-20 c:\windows\Tasks\AVG-Secure-Search-Update_0414c_rmv.job
- c:\program files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe [2014-04-24 19:15]
.
2014-08-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-11 17:58]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1]
@="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}"
[HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}]
2014-03-20 09:24 667808 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2]
@="{853B7E05-C47D-4985-909A-D0DC5C6D7303}"
[HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}]
2014-03-20 09:24 667808 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3]
@="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}"
[HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}]
2014-03-20 09:24 667808 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-08-09 10:11 634872 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 164016 ----a-w- c:\users\ERIK\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 164016 ----a-w- c:\users\ERIK\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 164016 ----a-w- c:\users\ERIK\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-11 02:09 164016 ----a-w- c:\users\ERIK\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2013-10-01 7199448]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
uInternet Settings,ProxyServer = http=127.0.0.1:14326;https=127.0.0.1:14326
TCP: DhcpNameServer = 192.168.3.20 192.168.0.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.5\ViProtocol.dll
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\BlueStacks]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.5\loggingserver.exe
c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
.
**************************************************************************
.
Celkový čas: 2014-08-20 12:23:16 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-08-20 10:23
ComboFix2.txt 2014-08-17 13:18
.
Před spuštěním: 12 474 568 704 bytes free
Po spuštění: 12 270 219 264 bytes free
.
- - End Of File - - E6BC03C6D0ED4B5037A5775FF7DA8D2A
A36C5E4F47E84449FF07ED3517B43A31

Re: Mám zavirovaný počítač, prosím o pomoc

Napsal: 20 srp 2014 12:46
od Rudy
Nastala nějaká změna?

Re: Mám zavirovaný počítač, prosím o pomoc

Napsal: 30 srp 2014 12:36
od Duinhil
Ano, Avast nic nenašel, vše je rychlejší mnohokrát vám děkuji. Ale mám tu ještě jeden problém a to je modrá smrt a někdy se mi bezdůvodně vypíná počítač.

Re: Mám zavirovaný počítač, prosím o pomoc

Napsal: 30 srp 2014 16:50
od Rudy
Otevřte adresář c:\windows\minidump, jeho obsah zabalte do raru a přiložte k vašemu příštímu postu.

Re: Mám zavirovaný počítač, prosím o pomoc

Napsal: 04 zář 2014 15:35
od Duinhil
Nechce mi to dovolit... K tomu mi začala blbnout Nvidia a myš se mi seká třeba i na 2 sec zamrzne

Re: Mám zavirovaný počítač, prosím o pomoc

Napsal: 04 zář 2014 17:15
od Rudy
Soubor/soubory někam zkopírujte a zablte pak ty kopie a pošlete.

Re: Mám zavirovaný počítač, prosím o pomoc

Napsal: 04 zář 2014 18:33
od Duinhil
Tady to je