Stránka 1 z 1

mám vir z FB :-(

Napsal: 31 črc 2011 21:31
od Betel
Zdravím prosím o radu asi mám ten vir (snazil jsem se aktualizovat flash player)
Výpis z toho programku : Logfile of random's system information tool 1.09 (written by random/random)
Run by Betelgueze at 2011-07-31 22:19:19
Microsoft Windows 7 Ultimate
System drive C: has 17 GB (28%) free of 60 GB
Total RAM: 3067 MB (36% free)


=========Mozilla firefox=========

ProfilePath - C:\Users\Betelgueze\AppData\Roaming\Mozilla\Firefox\Profiles\dq4xeuvz.default

prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}:2.5.6.0, {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.0, DTToolbar@toolbarnet.com:1.1.3.0244, {32a1fd71-835e-4b11-8e54-886fda0b4c89}:1.1, {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.7, {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906, QipCounter@qip.ru:1.0, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.16"
prefs.js - "keyword.URL" - "http://search.qip.ru/search?from=FF&query="

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=12.0.1.599]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprjplug;version=12.0.1.599]
"Description"=RealJukebox Netscape Plugin
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.599]
"Description"=RealPlayer(tm) HTML5VideoShim Plug-In
"Path"=C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.599]
"Description"=12.0.1.599
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0]
"Description"=
"Path"=c:\Program Files\Sony\Media Go\npmediago.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{AB2CE124-6272-4b12-94A9-7303C7397BD1}
{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nppl3260.xpt
nsIQTScriptablePlugin.xpt
nsjsrealplayerplugin.xpt

C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll
nppdf32.dll
nppl3260.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
nprjplug.dll
nprpjplug.dll
QuickTimePlugin.class

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\Betelgueze\AppData\Roaming\Mozilla\Firefox\Profiles\dq4xeuvz.default\extensions\
DTToolbar@toolbarnet.com
engine@conduit.com
plugin2@gameplaylabs.com
QipCounter@qip.ru
{32a1fd71-835e-4b11-8e54-886fda0b4c89}
{800b5000-a755-47e1-992b-48a1c1357f07}
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}

C:\Users\Betelgueze\AppData\Roaming\Mozilla\Firefox\Profiles\dq4xeuvz.default\searchplugins\
daemon-search.xml
icqplugin-1.xml
icqplugin-2.xml
icqplugin-3.xml
icqplugin-4.xml
icqplugin-5.xml
icqplugin-6.xml
icqplugin-7.xml
icqplugin.gif
icqplugin.src
icqplugin.xml
qip-search.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6B5863A0-C43F-4C0A-982B-CC0E9125783F}]
QipLI Class - C:\Users\Betelgueze\AppData\Roaming\Microsoft\Internet Explorer\qstatsrv.dll [2010-10-25 48080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Users\Betelgueze\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2010-11-01 149968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-05-04 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
BS Player Toolbar - C:\Program Files\BS_Player\tbBS_P.dll [2009-12-31 2349080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - BS Player Toolbar - C:\Program Files\BS_Player\tbBS_P.dll [2009-12-31 2349080]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2010-11-07 281768]
"TkBellExe"=C:\Program Files\Real\RealPlayer\Update\realsched.exe [2010-10-31 274608]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-06-08 37296]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-03-17 421888]
"BVRPLiveUpdate"=C:\Program Files\Avanquest update\Engine\LUKernel.exe [2009-11-17 386304]
"AdobeAAMUpdater-1.0"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
"SwitchBoard"=C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS5ServiceManager"=C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-04-08 254696]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"Sony Ericsson PC Companion"=C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe [2010-11-16 422912]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-12-03 14944136]
"BlazeServoTool"=C:\Program Files\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe [2010-03-06 286720]
"QIP Internet Guardian"=C:\Users\Betelgueze\AppData\Roaming\QipGuard\QipGuard.exe [2010-12-13 187776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"msacm.lhacm"=lhacm.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2011-07-31 22:16:56 ----D---- C:\Program Files\trend micro
2011-07-31 22:16:52 ----D---- C:\rsit
2011-07-19 12:50:41 ----D---- C:\Program Files\QipGuard
2011-07-19 12:49:46 ----D---- C:\Program Files\QIP 2010
2011-07-08 19:38:30 ----D---- C:\ProgramData\Solidshield
2011-07-08 19:25:17 ----A---- C:\Windows\system32\XAudio2_4.dll
2011-07-08 19:25:17 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-07-08 19:25:17 ----A---- C:\Windows\system32\xactengine3_4.dll
2011-07-08 19:25:17 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2011-07-08 19:25:17 ----A---- C:\Windows\system32\D3DX9_41.dll
2011-07-08 19:25:17 ----A---- C:\Windows\system32\d3dx10_41.dll
2011-07-08 19:25:17 ----A---- C:\Windows\system32\d3dx10_40.dll
2011-07-08 19:25:17 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2011-07-08 19:25:17 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2011-07-08 19:25:16 ----A---- C:\Windows\system32\D3DX9_40.dll
2011-07-08 19:25:15 ----A---- C:\Windows\system32\XAudio2_3.dll
2011-07-08 19:25:15 ----A---- C:\Windows\system32\XAudio2_2.dll
2011-07-08 19:25:15 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2011-07-08 19:25:15 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2011-07-08 19:25:15 ----A---- C:\Windows\system32\xactengine3_3.dll
2011-07-08 19:25:15 ----A---- C:\Windows\system32\xactengine3_2.dll
2011-07-08 19:25:15 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2011-07-08 19:25:15 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-07-08 19:25:15 ----A---- C:\Windows\system32\d3dx10_39.dll
2011-07-08 19:25:15 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2011-07-08 19:25:14 ----A---- C:\Windows\system32\XAudio2_1.dll
2011-07-08 19:25:14 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2011-07-08 19:25:14 ----A---- C:\Windows\system32\xactengine3_1.dll
2011-07-08 19:25:14 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2011-07-08 19:25:14 ----A---- C:\Windows\system32\d3dx10_38.dll
2011-07-08 19:25:14 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2011-07-08 19:25:13 ----A---- C:\Windows\system32\XAudio2_0.dll
2011-07-08 19:25:13 ----A---- C:\Windows\system32\xactengine3_0.dll
2011-07-08 19:25:13 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2011-07-08 19:25:13 ----A---- C:\Windows\system32\D3DX9_38.dll
2011-07-08 19:25:13 ----A---- C:\Windows\system32\D3DX9_37.dll
2011-07-08 19:25:13 ----A---- C:\Windows\system32\d3dx10_37.dll
2011-07-08 19:25:13 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2011-07-08 19:25:12 ----A---- C:\Windows\system32\xactengine2_10.dll
2011-07-08 19:25:12 ----A---- C:\Windows\system32\d3dx10_36.dll
2011-07-08 19:25:12 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2011-07-08 19:25:11 ----A---- C:\Windows\system32\xactengine2_9.dll
2011-07-08 19:25:11 ----A---- C:\Windows\system32\d3dx9_36.dll
2011-07-08 19:25:11 ----A---- C:\Windows\system32\d3dx9_35.dll
2011-07-08 19:25:11 ----A---- C:\Windows\system32\d3dx10_35.dll
2011-07-08 19:25:11 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2011-07-08 19:25:10 ----A---- C:\Windows\system32\xactengine2_8.dll
2011-07-08 19:25:10 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2011-07-08 19:25:10 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-07-08 19:25:09 ----A---- C:\Windows\system32\xinput1_3.dll
2011-07-08 19:25:09 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-07-08 19:25:09 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-07-08 19:25:09 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-07-08 19:25:09 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-07-08 19:25:09 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-07-08 19:25:08 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-07-08 19:25:07 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-07-08 19:25:07 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-07-08 19:25:07 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-07-08 19:25:07 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-07-08 19:25:07 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-07-08 19:25:07 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-07-08 19:25:07 ----A---- C:\Windows\system32\d3dx10.dll
2011-07-08 19:25:06 ----A---- C:\Windows\system32\xinput1_2.dll
2011-07-08 19:25:06 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-07-08 19:25:05 ----A---- C:\Windows\system32\xinput1_1.dll
2011-07-08 19:25:05 ----A---- C:\Windows\system32\xactengine2_2.dll
2011-07-08 19:25:05 ----A---- C:\Windows\system32\xactengine2_1.dll
2011-07-08 19:24:57 ----A---- C:\Windows\system32\xactengine2_0.dll
2011-07-08 19:24:57 ----A---- C:\Windows\system32\x3daudio1_0.dll
2011-07-08 19:24:57 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-07-08 19:24:57 ----A---- C:\Windows\system32\d3dx9_29.dll
2011-07-08 19:24:57 ----A---- C:\Windows\system32\d3dx9_28.dll
2011-07-08 19:24:56 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-07-08 19:24:56 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-07-08 19:24:56 ----A---- C:\Windows\system32\d3dx9_25.dll
2011-07-08 19:24:55 ----A---- C:\Windows\system32\d3dx9_24.dll
2011-07-08 16:01:23 ----D---- C:\Program Files\Common Files\Java
2011-07-08 16:01:11 ----A---- C:\Windows\system32\javaws.exe
2011-07-08 16:01:11 ----A---- C:\Windows\system32\javaw.exe
2011-07-08 16:01:11 ----A---- C:\Windows\system32\java.exe

======List of files/folders modified in the last 1 month======

2011-07-31 22:19:34 ----D---- C:\Windows\Temp
2011-07-31 22:17:07 ----D---- C:\Windows\Prefetch
2011-07-31 22:16:56 ----RD---- C:\Program Files
2011-07-31 19:11:55 ----D---- C:\Users\Betelgueze\AppData\Roaming\uTorrent
2011-07-30 23:53:38 ----SHD---- C:\System Volume Information
2011-07-28 11:15:37 ----D---- C:\Windows\system32\config
2011-07-24 22:07:58 ----D---- C:\Users\Betelgueze\AppData\Roaming\Skype
2011-07-24 22:03:19 ----D---- C:\Users\Betelgueze\AppData\Roaming\skypePM
2011-07-20 20:33:07 ----D---- C:\Windows\system32\wdi
2011-07-19 13:56:43 ----D---- C:\Users\Betelgueze\AppData\Roaming\ICQ
2011-07-19 12:50:41 ----D---- C:\Users\Betelgueze\AppData\Roaming\QipGuard
2011-07-19 12:49:41 ----D---- C:\Program Files\QIP Infium
2011-07-08 19:38:30 ----HD---- C:\ProgramData
2011-07-08 19:25:18 ----D---- C:\Windows\System32
2011-07-08 19:25:05 ----RSD---- C:\Windows\assembly
2011-07-08 19:24:59 ----D---- C:\Windows\Microsoft.NET
2011-07-08 19:24:26 ----SHD---- C:\Windows\Installer
2011-07-08 19:24:26 ----D---- C:\Windows\Logs
2011-07-08 19:24:26 ----D---- C:\Config.Msi
2011-07-08 19:24:15 ----D---- C:\Windows\winsxs
2011-07-08 19:18:37 ----HD---- C:\Program Files\InstallShield Installation Information
2011-07-08 16:01:23 ----D---- C:\Program Files\Common Files
2011-07-08 16:01:08 ----D---- C:\Program Files\Java
2011-07-02 00:52:08 ----D---- C:\Windows\inf
2011-07-02 00:52:08 ----A---- C:\Windows\system32\PerfStringBackup.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 giveio;giveio; C:\Windows\system32\giveio.sys [1996-04-03 5248]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 speedfan;speedfan; C:\Windows\system32\speedfan.sys [2006-09-24 5248]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-11-05 691696]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2011-06-29 138192]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2011-06-29 66616]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-08-18 4994560]
R3 BCM43XX;Broadcom 802.11 – ovladač síťového adaptéru; C:\Windows\system32\DRIVERS\bcmwl6.sys [2009-07-14 1131008]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 14336]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 AF15BDA;AF9015 BDA Device; C:\Windows\system32\DRIVERS\AF15BDA.sys [2009-06-03 483200]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 aw8bc998;aw8bc998; C:\Windows\system32\drivers\aw8bc998.sys []
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 392704]
S3 IT9135BDA;IT9135 BDA Devices; C:\Windows\System32\Drivers\IT9135BDA.sys [2011-05-26 94336]
S3 KMWDFILTERx86;HIDServiceDesc; C:\Windows\system32\DRIVERS\KMWDFILTER.sys [2009-04-29 25088]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM); C:\Windows\system32\DRIVERS\s1018bus.sys [2009-03-25 86824]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s1018mdfl.sys [2009-03-25 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s1018mdm.sys [2009-03-25 114728]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s1018mgmt.sys [2009-03-25 106208]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS); C:\Windows\system32\DRIVERS\s1018nd5.sys [2009-03-25 26024]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s1018obex.sys [2009-03-25 104744]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM); C:\Windows\system32\DRIVERS\s1018unic.sys [2009-03-25 109864]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-08-18 176128]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2011-06-29 269480]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2011-04-29 136360]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 QipGuard;QipGuard; C:\Program Files\QipGuard\QipGuard.exe [2010-12-13 187776]
R3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2010-10-26 155344]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-10-16 1343400]

-----------------EOF-----------------

Re: mám vir z FB :-(

Napsal: 31 črc 2011 21:40
od Rudy
V logu není FB virus vidět. Udělejte kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.

Re: mám vir z FB :-(

Napsal: 01 srp 2011 09:05
od Betel
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Verze databáze: 7341

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

1.8.2011 9:59:18
mbam-log-2011-08-01 (09-59-01).txt

Typ: Úplná kontrola (C:\|D:\|E:\|F:\|)
Kontrolované objekty: 374354
Uplynulý čas: 1 hodin, 47 minut, 52 sekund

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 4

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
c:\Users\betelgueze\AppData\Roaming\QIP\Profiles\231576736@qip.ru\rcvdfiles\mr.tiger_219755483\windows loader v1.9-daz\windows loader.exe (PUP.HackTool.Windowsloader) -> No action taken.
c:\Users\betelgueze\AppData\Roaming\QIP\Profiles\231576736@qip.ru\rcvdfiles\wojczek_195035793\22on2nw011\activators\software -2(best!!)\removewat.exe (HackTool.Wpakill) -> No action taken.
d:\Martin\Instal\aktivatory\activators\software -2(best!!)\removewat.exe (HackTool.Wpakill) -> No action taken.
c:\Users\betelgueze\AppData\Local\Temp\opravny_zapocet_vysledky.pdf (Trojan.Agent) -> No action taken.

Koukam ale tyto věci by snad neměly být chybné :turned:

Re: mám vir z FB :-(

Napsal: 01 srp 2011 11:01
od vyosek
Zdravim a pekny den preji :)

Omlouvam se kolegovi za vstup :oops:

Myslite ze crack samotnych windows je v poradku = neni havet? A co legislativni stranka, autorsky zakon :?:

Re: mám vir z FB :-(

Napsal: 01 srp 2011 11:19
od Betel
ano omlouvám se

Re: mám vir z FB :-(

Napsal: 01 srp 2011 11:24
od Betel
popravdě se ovšem ani nevěděl co to je. nemám s tím moc zkušeností a instal i opravy doposud mi dělali kluci. . . pokusím se napravit co nejrychleji svoje (jejich) chyby a našetřím si na origoš.

Re: mám vir z FB :-(

Napsal: 01 srp 2011 14:25
od vyosek
Z me strany tedy vse, pravidla hovori jasne o podpore nelegalni SW...

Necham na kolegovi, jelikoz je to jeho thread, ci udela vyjimku nebo nikoliv...

Re: mám vir z FB :-(

Napsal: 01 srp 2011 17:35
od Rudy
Pravidla hovoří jasně. Vyjímku neudělám ani já.

Re: mám vir z FB :-(

Napsal: 02 srp 2011 10:09
od Betel
cry cry tak lock a delete díky za snahu . . .

Re: mám vir z FB :-(

Napsal: 02 srp 2011 10:32
od vyosek
I za kolegu, neni zac :wink:

:lock: