Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

trojsky kun z fake KMP player - zhoršuje se to

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
nereide
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 151
Registrován: 16 kvě 2010 17:19

trojsky kun z fake KMP player - zhoršuje se to

#1 Příspěvek od nereide »

Dobrý den, mám problém s tím, že jsem si stáhla update oblíbeného přehrávače KMP player, od té doby na mě všude vyskakují reklamy (adware), neustále mě to přesměrovává na dalesearch - tohle pokud se bude zhoršovat, mi znemožní řešení problému zde...atd., tuším, že to dělá bordel i jinde, objevil se mi tady program, co tady nemá co dělat atd. Poprosila bych o pomoc a zároveň o tip, jestli někde není bezpečný zdroj KMP playeru nebo ho už musím odepsat :( Po vyřešení samozřejmě přispěju na dobro fóra, jako vždy. Moc děkuji! Jo a DaWinci je regulérní program, ten je v pořádku.

Logfile of random's system information tool 1.09 (written by random/random)
Run by uzivatel at 2013-10-02 09:01:14
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 36 GB (23%) free of 153 GB
Total RAM: 953 MB (36% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:01:20, on 2.10.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files\DawinciKlientM21\DWKatCli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
c:\Documents and Settings\uzivatel\Dokumenty\Stažené soubory\RSIT.exe
C:\Program Files\trend micro\uzivatel.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dalesearch.com/?babsrc=HP_ss ... 0&tsp=5018
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 1530185827
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: CiSvc - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - c:\Program Files\Skype\Updater\Updater.exe

--
End of file - 5278 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\avast! Emergency Update.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\uzivatel\Data aplikací\Mozilla\Firefox\Profiles\winhhlow.default-1371402308171

prefs.js - "browser.search.useDBForOrder" - "false"
prefs.js - "browser.startup.homepage" - "http://www.centrum.cz/"

"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.7.700.224 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@xstandard.com/XStandard]
"Description"=
"Path"=C:\Program Files\XStandard\Bin\NPXStandard.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


C:\Program Files\Mozilla Firefox\plugins\
nppdf32.dll

C:\Documents and Settings\uzivatel\Data aplikací\Mozilla\Firefox\Profiles\winhhlow.default-1371402308171\extensions\
WebSiteRecommendation@weliketheweb.com

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-04-04 462752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-08-30 201784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-04-04 171424]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-08-30 201784]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2013-08-30 4858968]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-03-12 253816]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]
C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe [2006-07-17 53248]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
c:\Program Files\Skype\Phone\Skype.exe [2012-07-13 17420464]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [2009-09-04 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2008-06-11 212992]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2008-05-19 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2011-09-04 113024]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit"
"C:\WINDOWS\system32\igfxsrvc.exe"="C:\WINDOWS\system32\igfxsrvc.exe:*:Enabled:igfxsrvc Module"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\tlntsvr.exe"="C:\WINDOWS\system32\tlntsvr.exe:*:Disabled:telnet"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\PANDORA.TV\PanService\KMPProcess.exe"="C:\Program Files\PANDORA.TV\PanService\KMPProcess.exe:*:Enabled:KMPProcess"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======List of files/folders created in the last 1 month======

2013-10-01 21:14:20 ----D---- C:\Program Files\Mozilla Firefox
2013-09-29 01:03:40 ----D---- C:\Program Files\SimilarSites
2013-09-29 01:03:30 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\SimilarSites
2013-09-27 20:37:06 ----D---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2013-09-27 20:31:49 ----D---- C:\Program Files\Optimizer Pro
2013-09-27 20:30:18 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\Babylon
2013-09-27 20:30:18 ----D---- C:\Documents and Settings\All Users\Data aplikací\Babylon

======List of files/folders modified in the last 1 month======

2013-10-02 09:01:17 ----D---- C:\Program Files\trend micro
2013-10-02 08:57:05 ----D---- C:\Program Files\The KMPlayer
2013-10-02 08:55:11 ----D---- C:\WINDOWS\temp
2013-10-02 07:52:32 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-10-02 07:52:31 ----RD---- C:\Program Files
2013-09-28 01:47:36 ----D---- C:\WINDOWS\system32\CatRoot2
2013-09-22 19:00:50 ----SD---- C:\WINDOWS\Tasks
2013-09-22 19:00:47 ----D---- C:\WINDOWS

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [2013-08-30 49376]
R0 aswVmm;aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [2013-08-30 177864]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2013-08-30 49760]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2013-08-30 770344]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2013-08-30 369584]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2013-08-30 56080]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2013-08-30 29816]
R2 aswMonFlt;aswMonFlt; \??\C:\WINDOWS\system32\drivers\aswMonFlt.sys []
R2 Ethpdrv;Ethernet Packet Driver; C:\WINDOWS\system32\DRIVERS\ethpdrv.sys [2005-09-08 9728]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2008-03-19 175104]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2008-06-11 6021184]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-06-13 4754944]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 AR5416;Atheros AR5008 Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\athw.sys [2009-09-30 1585728]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service; C:\WINDOWS\system32\drivers\IntcHdmi.sys [2007-05-05 105984]
S3 ipw_bus;IPWireless; C:\WINDOWS\system32\DRIVERS\ipw_bus.sys [2005-09-27 58320]
S3 ipw_mdfl;Wireless Broadband Modem Filter; C:\WINDOWS\system32\DRIVERS\ipw_mdfl.sys [2005-09-27 8272]
S3 ipw_mdm;Wireless Broadband Modem (WDM); C:\WINDOWS\system32\DRIVERS\ipw_mdm.sys [2005-09-27 95440]
S3 MREMP50;MREMP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS []
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 MRESP50;MRESP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS []
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []
S3 TrueSight;TrueSight; \??\c:\windows\system32\drivers\TrueSight.sys []
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-05-19 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-05-19 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-08-30 46808]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2013-04-04 181664]
S2 SkypeUpdate;Skype Updater; c:\Program Files\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-10 257416]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-10-01 118680]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]

-----------------EOF-----------------

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: trojsky kun z fake KMP player - zhoršuje se to

#2 Příspěvek od stell »

Zdravim
Pouzi tento moj navod na delta search, logy ADWcleaner, a junkware removat tool , OTL>>vkladaj sem.
A nastav aj domovsku stranku, tak ako je v navode.
A nakoniec sprav sken z programom malwarebytes, najdene daj zmazat, alog vloz tiez sem, a potom uvidime,,
http://www.viruskasino.com/2013/07/delta-search.html
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

nereide
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 151
Registrován: 16 kvě 2010 17:19

Re: trojsky kun z fake KMP player - zhoršuje se to

#3 Příspěvek od nereide »

Děkuji! Vkládám logy. Bohužel problém nevyřešen, reklamy se pořád objevují (jinak domovskou stránku jsem řešila hned, to není problém, problémem bylo přesměrovávání - ale to se teď už neobjevuje, aspoň tohle se vyřešilo). Jediný rozdíl je, že tam chvíli vydrží původní reklama a pak naskočí ta jejich.

ADW
# AdwCleaner v3.006 - Report created 02/10/2013 at 09:41:46
# Updated 01/10/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : uzivatel - NTBACER
# Running from : C:\Documents and Settings\uzivatel\Plocha\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Documents and Settings\All Users\Data aplikací\Babylon
Folder Deleted : C:\Documents and Settings\All Users\Data aplikací\ICQ\ICQToolbar
Folder Deleted : C:\Program Files\optimizer pro
Folder Deleted : C:\Program Files\SimilarSites
Folder Deleted : C:\Documents and Settings\uzivatel\Data aplikací\Babylon
Folder Deleted : C:\Documents and Settings\uzivatel\Data aplikací\SimilarSites

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla
Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ICQ Service.exe
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5D723752-5899-47E8-99B4-62C824EF9E13}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\Ask.com
Key Deleted : HKCU\Software\AskToolbar
Key Deleted : HKCU\Software\ICQ\ICQToolbar
Key Deleted : HKCU\Software\PIP
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\AppDataLow\AskToolbarInfo
Key Deleted : HKLM\Software\ICQ\ICQToolbar
Key Deleted : HKLM\Software\PIP

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]

-\\ Mozilla Firefox v24.0 (cs)

[ File : C:\Documents and Settings\uzivatel\Data aplikací\Mozilla\Firefox\Profiles\winhhlow.default-1371402308171\prefs.js ]

Line Deleted : user_pref("browser.newtab.url", "hxxp://www.dalesearch.com/?babsrc=NT_ss&mntrId ... 0&tsp=5018");

*************************

AdwCleaner[R0].txt - [3613 octets] - [02/10/2013 09:31:54]
AdwCleaner[S0].txt - [3444 octets] - [02/10/2013 09:41:46]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3504 octets] ##########


ADW2 (2. pokus)
# AdwCleaner v3.006 - Report created 02/10/2013 at 10:16:03
# Updated 01/10/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : uzivatel - NTBACER
# Running from : C:\Documents and Settings\uzivatel\Plocha\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702


-\\ Mozilla Firefox v24.0 (cs)

[ File : C:\Documents and Settings\uzivatel\Data aplikací\Mozilla\Firefox\Profiles\winhhlow.default-1371402308171\prefs.js ]


*************************

AdwCleaner[R0].txt - [3613 octets] - [02/10/2013 09:31:54]
AdwCleaner[R1].txt - [938 octets] - [02/10/2013 09:46:14]
AdwCleaner[R2].txt - [997 octets] - [02/10/2013 10:15:03]
AdwCleaner[S0].txt - [3584 octets] - [02/10/2013 09:41:46]
AdwCleaner[S1].txt - [919 octets] - [02/10/2013 10:16:03]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [978 octets] ##########
----------------------------------------------------------------------------------------------

JRT

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.3 (09.27.2013:1)
OS: Microsoft Windows XP x86
Ran by uzivatel on st 02.10.2013 at 9:48:36,09
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] "hkey_current_user\software\microsoft\internet explorer\low rights\elevationpolicy\{a5aa24ea-11b8-4113-95ae-9ed71deaf12a}"



~~~ Files



~~~ Folders





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on st 02.10.2013 at 9:53:07,40
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


a nakonec OTL log

All processes killed
========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
< %windir%\*.tmp ipconfig /flushdns /c >
C:\Documents and Settings\uzivatel\Plocha\cmd.bat deleted successfully.
C:\Documents and Settings\uzivatel\Plocha\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Evicka

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: uzivatel
->Temp folder emptied: 55287595 bytes
->Temporary Internet Files folder emptied: 328492 bytes
->Java cache emptied: 27524 bytes
->FireFox cache emptied: 4386327 bytes
->Flash cache emptied: 506 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 23566456 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 80,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 10022013_095351

Files\Folders moved on Reboot...
File\Folder C:\WINDOWS\temp\_avast_\Webshlock.txt not found!

PendingFileRenameOperations files...

Registry entries deleted on Reboot...



MALWARE nic nenašel... log nevím kam se mi uložil, pokud byl, v C/programfiles/malware není :(

Chová se to ale lépe a už to není tak agresivní.

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: trojsky kun z fake KMP player - zhoršuje se to

#4 Příspěvek od stell »

Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

nereide
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 151
Registrován: 16 kvě 2010 17:19

Re: trojsky kun z fake KMP player - zhoršuje se to

#5 Příspěvek od nereide »

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-09-2013 01
Ran by uzivatel (administrator) on NTBACER on 02-10-2013 10:43:50
Running from C:\Documents and Settings\uzivatel\Dokumenty\Stažené soubory
Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastUI.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Ghisler Software GmbH) C:\totalcmd\TOTALCMD.EXE
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-30] (AVAST Software)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
Winlogon\Notify\!SASWinLogon: C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
HKU\Default User\...\RunOnce: [nltide_2] - regsvr32 /s /n /i:U shell32
SSODL: UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - No File

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x960FABE79583CA01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = cs
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
ShellExecuteHooks: - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No File [ ]
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [113024 2011-09-04] (SuperAdBlocker.com)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37

FireFox:
========
FF ProfilePath: C:\Documents and Settings\uzivatel\Data aplikací\Mozilla\Firefox\Profiles\winhhlow.default-1371402308171
FF Homepage: hxxp://www.centrum.cz/
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @xstandard.com/XStandard - C:\Program Files\XStandard\Bin\NPXStandard.dll (Belus Technology Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: No Name - C:\Documents and Settings\uzivatel\Data aplikací\Mozilla\Firefox\Profiles\winhhlow.default-1371402308171\Extensions\WebSiteRecommendation@weliketheweb.com
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF

========================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 CiSvc; %SystemRoot%\system32\cisvc.exe [x]
R2 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf"

==================== Drivers (Whitelisted) ====================

S3 AR5416; C:\Windows\System32\DRIVERS\athw.sys [1585728 2009-09-30] (Atheros Communications, Inc.)
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [29816 2013-08-30] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [66336 2013-08-30] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [49760 2013-08-30] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49376 2013-08-30] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [770344 2013-08-30] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [369584 2013-08-30] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [56080 2013-08-30] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [177864 2013-08-30] ()
R3 b57w2k; C:\Windows\System32\DRIVERS\b57xp32.sys [175104 2008-03-19] (Broadcom Corporation)
R2 Ethpdrv; C:\Windows\System32\DRIVERS\ethpdrv.sys [9728 2005-09-08] (Gemfor s.r.o.)
S3 ipw_bus; C:\Windows\System32\DRIVERS\ipw_bus.sys [58320 2005-09-27] (MCCI)
S3 ipw_mdfl; C:\Windows\System32\DRIVERS\ipw_mdfl.sys [8272 2005-09-27] (MCCI)
S3 ipw_mdm; C:\Windows\System32\DRIVERS\ipw_mdm.sys [95440 2005-09-27] (MCCI)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
U3 TrueSight; c:\windows\system32\drivers\TrueSight.sys [111872 2012-01-03] ()
S4 IntelIde; No ImagePath
S3 MREMP50; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS [x]
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [x]
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [x]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [x]
S3 MRESP50; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [x]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [x]
U1 WS2IFSL;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-10-02 10:43 - 2013-10-02 10:43 - 00000000 ____D C:\FRST
2013-10-02 10:19 - 2013-10-02 10:19 - 00001057 _____ C:\Documents and Settings\uzivatel\Plocha\adw2.txt
2013-10-02 09:53 - 2013-10-02 09:53 - 00000753 _____ C:\Documents and Settings\uzivatel\Plocha\JRT.txt
2013-10-02 09:53 - 2013-10-02 09:53 - 00000000 ____D C:\_OTL
2013-10-02 09:48 - 2013-10-02 09:48 - 00000000 ____D C:\WINDOWS\ERUNT
2013-10-02 09:46 - 2013-10-02 09:46 - 00003584 _____ C:\Documents and Settings\uzivatel\Plocha\AdwCleaner[S0].txt
2013-10-02 09:31 - 2013-10-02 10:16 - 00000000 ____D C:\AdwCleaner
2013-10-02 09:31 - 2013-10-02 09:31 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\uzivatel\Plocha\OTL.exe
2013-10-02 09:31 - 2013-10-02 09:31 - 00000933 _____ C:\Documents and Settings\uzivatel\Plocha\navod.txt
2013-10-02 09:30 - 2013-10-02 09:30 - 01030305 _____ (Thisisu) C:\Documents and Settings\uzivatel\Plocha\JRT.exe
2013-10-02 09:29 - 2013-10-02 09:29 - 01045226 _____ C:\Documents and Settings\uzivatel\Plocha\adwcleaner.exe
2013-10-01 21:14 - 2013-10-02 07:52 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-09-30 23:48 - 2013-09-30 23:48 - 04906636 _____ C:\Documents and Settings\uzivatel\Dokumenty\magda.rar
2013-09-30 20:13 - 2013-09-30 23:47 - 00000000 ____D C:\Documents and Settings\uzivatel\Dokumenty\magda
2013-09-29 01:03 - 2013-09-29 01:03 - 00000000 ____D C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\Google
2013-09-29 00:44 - 2013-09-29 00:50 - 00000000 ____D C:\Documents and Settings\uzivatel\Dokumenty\pro vulkan
2013-09-23 23:50 - 2013-09-24 00:11 - 00000000 ____D C:\Documents and Settings\uzivatel\Dokumenty\dvorce

==================== One Month Modified Files and Folders =======

2013-10-02 10:43 - 2013-10-02 10:43 - 00000000 ____D C:\FRST
2013-10-02 10:43 - 2010-03-14 14:26 - 00000000 ____D C:\Documents and Settings\uzivatel\Dokumenty\Stažené soubory
2013-10-02 10:19 - 2013-10-02 10:19 - 00001057 _____ C:\Documents and Settings\uzivatel\Plocha\adw2.txt
2013-10-02 10:19 - 2009-12-23 01:59 - 00000000 ____D C:\Documents and Settings\uzivatel\Plocha
2013-10-02 10:17 - 2009-12-23 02:48 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-10-02 10:17 - 2009-12-23 02:48 - 00000049 _____ C:\WINDOWS\wiaservc.log
2013-10-02 10:17 - 2009-12-23 01:54 - 01117247 _____ C:\WINDOWS\WindowsUpdate.log
2013-10-02 10:16 - 2013-10-02 09:31 - 00000000 ____D C:\AdwCleaner
2013-10-02 10:16 - 2009-12-23 01:59 - 00000272 ___SH C:\Documents and Settings\uzivatel\ntuser.ini
2013-10-02 10:16 - 2009-12-23 01:59 - 00000000 ____D C:\Documents and Settings\uzivatel
2013-10-02 10:00 - 2012-01-02 18:09 - 00000784 _____ C:\Documents and Settings\All Users\Plocha\Malwarebytes Anti-Malware.lnk
2013-10-02 10:00 - 2010-01-16 12:51 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-10-02 10:00 - 2010-01-16 12:51 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Malwarebytes' Anti-Malware
2013-10-02 10:00 - 2009-12-23 02:44 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2013-10-02 09:53 - 2013-10-02 09:53 - 00000753 _____ C:\Documents and Settings\uzivatel\Plocha\JRT.txt
2013-10-02 09:53 - 2013-10-02 09:53 - 00000000 ____D C:\_OTL
2013-10-02 09:48 - 2013-10-02 09:48 - 00000000 ____D C:\WINDOWS\ERUNT
2013-10-02 09:46 - 2013-10-02 09:46 - 00003584 _____ C:\Documents and Settings\uzivatel\Plocha\AdwCleaner[S0].txt
2013-10-02 09:41 - 2010-05-30 09:26 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\ICQ
2013-10-02 09:41 - 2009-12-23 02:44 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2013-10-02 09:41 - 2009-12-23 01:59 - 00000000 __RHD C:\Documents and Settings\uzivatel\Data aplikací
2013-10-02 09:31 - 2013-10-02 09:31 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\uzivatel\Plocha\OTL.exe
2013-10-02 09:31 - 2013-10-02 09:31 - 00000933 _____ C:\Documents and Settings\uzivatel\Plocha\navod.txt
2013-10-02 09:30 - 2013-10-02 09:30 - 01030305 _____ (Thisisu) C:\Documents and Settings\uzivatel\Plocha\JRT.exe
2013-10-02 09:29 - 2013-10-02 09:29 - 01045226 _____ C:\Documents and Settings\uzivatel\Plocha\adwcleaner.exe
2013-10-02 09:01 - 2010-05-16 18:24 - 00000000 ____D C:\Program Files\trend micro
2013-10-02 08:57 - 2010-01-09 18:55 - 00000000 ____D C:\Program Files\The KMPlayer
2013-10-02 08:57 - 2009-12-23 01:59 - 00000000 ___RD C:\Documents and Settings\uzivatel\Nabídka Start\Programy
2013-10-02 08:44 - 2013-08-25 19:52 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\Vysledky
2013-10-02 07:52 - 2013-10-01 21:14 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-10-02 07:52 - 2012-04-25 21:52 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-10-02 00:01 - 2013-06-22 18:43 - 00000000 ____D C:\Documents and Settings\uzivatel\Dokumenty\recepty
2013-10-01 20:15 - 2001-10-25 18:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2013-09-30 23:54 - 2010-05-23 20:11 - 00138117 ____H C:\treeinfo.wc
2013-09-30 23:54 - 2009-12-23 01:59 - 00000000 ___RD C:\Documents and Settings\uzivatel\Dokumenty
2013-09-30 23:48 - 2013-09-30 23:48 - 04906636 _____ C:\Documents and Settings\uzivatel\Dokumenty\magda.rar
2013-09-30 23:47 - 2013-09-30 20:13 - 00000000 ____D C:\Documents and Settings\uzivatel\Dokumenty\magda
2013-09-29 01:03 - 2013-09-29 01:03 - 00000000 ____D C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\Google
2013-09-29 01:03 - 2009-12-23 01:59 - 00000000 ___HD C:\Documents and Settings\uzivatel\Local Settings\Data aplikací
2013-09-29 00:50 - 2013-09-29 00:44 - 00000000 ____D C:\Documents and Settings\uzivatel\Dokumenty\pro vulkan
2013-09-28 01:25 - 2009-12-23 02:44 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2013-09-28 01:21 - 2010-01-09 18:35 - 00123392 _____ C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-09-24 23:13 - 2010-04-05 23:42 - 00000000 ____D C:\Documents and Settings\uzivatel\Dokumenty\www
2013-09-24 22:45 - 2010-04-05 21:04 - 00002539 _____ C:\Documents and Settings\uzivatel\Plocha\Microsoft Office FrontPage 2003.lnk
2013-09-24 22:36 - 2010-01-15 18:29 - 00000000 ____D C:\Documents and Settings\uzivatel\Dokumenty\works
2013-09-24 00:12 - 2009-12-23 01:59 - 00000000 ___RD C:\Documents and Settings\uzivatel\Dokumenty\Obrázky
2013-09-24 00:11 - 2013-09-23 23:50 - 00000000 ____D C:\Documents and Settings\uzivatel\Dokumenty\dvorce
2013-09-22 19:00 - 2012-07-09 08:06 - 00000316 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2013-09-22 19:00 - 2009-12-23 01:55 - 00002507 _____ C:\WINDOWS\system32\CONFIG.NT
2013-09-17 21:03 - 2009-12-23 08:12 - 00002517 _____ C:\Documents and Settings\uzivatel\Plocha\Microsoft Office Excel 2003.lnk
2013-09-17 18:29 - 2010-05-25 13:44 - 00000000 ____D C:\Documents and Settings\uzivatel\Dokumenty\rodiny
2013-09-08 13:00 - 2010-12-05 21:29 - 00000000 ____D C:\Documents and Settings\uzivatel\Dokumenty\chov dostihy dle zemi
2013-09-04 22:00 - 2010-01-15 18:35 - 00000000 ____D C:\Documents and Settings\uzivatel\Dokumenty\ROCENKY

Files to move or delete:
====================
C:\Documents and Settings\uzivatel\hpothb07.dat


Some content of TEMP:
====================
C:\Documents and Settings\uzivatel\Local Settings\temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe
[2008-04-14 08:52] - [2008-04-14 08:52] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1

C:\Windows\System32\winlogon.exe
[2008-04-14 08:52] - [2008-04-14 08:52] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea

C:\Windows\System32\svchost.exe
[2008-04-14 08:52] - [2008-04-14 08:52] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93

C:\Windows\System32\services.exe
[2008-04-14 08:52] - [2009-02-09 13:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7

C:\Windows\System32\User32.dll
[2008-04-14 08:52] - [2008-04-14 08:52] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53

C:\Windows\System32\userinit.exe
[2008-04-14 08:52] - [2008-04-14 08:52] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239

C:\Windows\System32\Drivers\volsnap.sys
[2008-04-14 07:42] - [2008-04-14 07:42] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1


==================== End Of Log ============================

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: trojsky kun z fake KMP player - zhoršuje se to

#6 Příspěvek od stell »

Otvor Notepad (Poznámkový blok) a zkopíruj do nehocelý tex:

Kód: Vybrat vše

Start
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x960FABE79583CA01
ShellExecuteHooks: - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No File [ ]
FF Extension: No Name - C:\Documents and Settings\uzivatel\Data aplikací\Mozilla\Firefox\Profiles\winhhlow.default-1371402308171\Extensions\WebSiteRecommendation@weliketheweb.com
C:\Documents and Settings\uzivatel\hpothb07.dat
C:\Documents and Settings\uzivatel\Local Settings\temp\Quarantine.exe
Hosts:
End
Potom klik na Subor -> Uložiť ako.. .-> Ako je Názov souboru tak do toho riadku napiš:fixlist.txt
Typ súboru tak tam vyberies *]všetky súbory
A ulož ho TU C:\Documents and Settings\uzivatel\Dokumenty\Stažené soubory, presne tam kde mas program Frst.exe

Spust znova FRST.exe, ale POZOR, teraz stlac gombik, FIX
Log FIXLOG.txt>>vloz sem.
Odskusaj pc a napis, ci problemy pretrvavaju.
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

nereide
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 151
Registrován: 16 kvě 2010 17:19

Re: trojsky kun z fake KMP player - zhoršuje se to

#7 Příspěvek od nereide »

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 27-09-2013 01
Ran by uzivatel at 2013-10-02 11:16:56 Run:1
Running from C:\Documents and Settings\uzivatel\Dokumenty\Stažené soubory
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x960FABE79583CA01
ShellExecuteHooks: - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No File [ ]
FF Extension: No Name - C:\Documents and Settings\uzivatel\Data aplikací\Mozilla\Firefox\Profiles\winhhlow.default-1371402308171\Extensions\WebSiteRecommendation@weliketheweb.com
C:\Documents and Settings\uzivatel\hpothb07.dat
C:\Documents and Settings\uzivatel\Local Settings\temp\Quarantine.exe
Hosts:
End
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} => Value deleted successfully.
HKCR\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972} => Key not found.
C:\Documents and Settings\uzivatel\Data aplikací\Mozilla\Firefox\Profiles\winhhlow.default-1371402308171\Extensions\WebSiteRecommendation@weliketheweb.com => Moved successfully.
C:\Documents and Settings\uzivatel\hpothb07.dat => Moved successfully.
C:\Documents and Settings\uzivatel\Local Settings\temp\Quarantine.exe => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.

==== End of Fixlog ====

Teď už vymizely nežádoucí reklamy a vyskakovací okénka :))

Takže to už je snad OK. Chtěla jsem před uzavřením threadu ještě požádat, jestli v logu vidíte, že je vše ok, jestli tam nemám nějaký jiný nežádoucí bordel nebo potenciální problém. Velmi děkuji a zasílám na konto příspěvek.

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: trojsky kun z fake KMP player - zhoršuje se to

#8 Příspěvek od stell »

Nie, nevidim ziaden bordel, log vyzera solidne, este skontrolujeme zabezpecenie, za podporu dakujeme,
1:Stiahni SecurityCheck
Ulož ho na plochu.
Dvakrát kliknite SecurityCheck.exe a postupujte podľa pokynov na obrazovke .
po skonceni skenu Notepad sa automaticky otvorí s názvom checkup.txt,obsah vloz sem.
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

nereide
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 151
Registrován: 16 kvě 2010 17:19

Re: trojsky kun z fake KMP player - zhoršuje se to

#9 Příspěvek od nereide »

Results of screen317's Security Check version 0.99.74
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
avast! Antivirus
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
xp-AntiSpy 3.97-2
SUPERAntiSpyware
CCleaner
Java(TM) 6 Update 29
Java 7 Update 21
Java version out of Date!
Adobe Flash Player 11.7.700.224
Adobe Reader 10.1.6 Adobe Reader out of Date!
Mozilla Firefox (24.0)
````````Process Check: objlist.exe by Laurent````````
Malwarebytes' Anti-Malware mbamscheduler.exe
AVAST Software Avast AvastSvc.exe
AVAST Software Avast avastUI.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C::
````````````````````End of Log``````````````````````

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: trojsky kun z fake KMP player - zhoršuje se to

#10 Příspěvek od stell »

Pise ze trebalo by aktualizovat Javu, a adobe.
inak ok,
Este vypni obnovu systemu, restart a obnovu systemu zapni.
A toto by malo byt vsetko. :)
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

nereide
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 151
Registrován: 16 kvě 2010 17:19

Re: trojsky kun z fake KMP player - zhoršuje se to

#11 Příspěvek od nereide »

Moc děkuji :)

thread už můžete zamknout, je to vyřešené a díky :)

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: trojsky kun z fake KMP player - zhoršuje se to

#12 Příspěvek od stell »

Nemas zaco :)
Temu zatvaram.
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

Zamčeno