Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Problém s virem Win32.expiro-U / Vitro

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Mikaj08
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 26 led 2014 04:41

Problém s virem Win32.expiro-U / Vitro

#1 Příspěvek od Mikaj08 »

Dobrý den, Avast mi detekoval viry Expiro-U a Vitro ve všech .EXE souborech a já nevím co mám dělat :(
Zatím sem nic nemazal pouze Avast automaticky přesunul do karantény soubor 05nOinxn.exe.part (Win32:Malware-gen).
Pěkně prosím o pomoc. Děkuji.
______________________

Logfile of random's system information tool 1.09 (written by random/random)
Run by Michal Skopik at 2014-01-26 14:18:01
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 47 GB (7%) free of 670 GB
Total RAM: 7654 MB (80% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:18:04, on 26.1.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal

Running processes:
C:\windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\trend micro\Michal Skopik.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.tyn.elsat.cz:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
R3 - URLSearchHook: (no name) - {687578b9-7132-4a7a-80e4-30ee31099e03} - (no file)
F2 - REG:system.ini: UserInit=%windows%\system32\userinit.exe,
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: AMD SteadyVideo BHO - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [NextLive] C:\windows\SysWOW64\rundll32.exe "C:\Users\Michal Skopik\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{5BF2F48C-4A51-4E63-960A-A5B6FE7D068A}: NameServer = 81.90.168.3,10.72.250.10
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O18 - Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: AODService - Unknown owner - C:\Program Files (x86)\AMD\OverDrive\AODAssist.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Ralink UPnP Media Server (RaMediaServer) - Unknown owner - C:\Program Files (x86)\Ralink\RT2860 Wireless LAN Card\ExtraFiles\RaMediaServer.exe
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: RzKLService - Razer Inc. - C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10074 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
winlogon.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
atieclxx
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
taskeng.exe {1E17AA26-EE17-4F04-B1EE-D1098D7E3D45}
"taskhost.exe"
"C:\windows\system32\Dwm.exe"
taskeng.exe {0600FB3A-74D8-4951-AF20-8412B808CC17}
C:\windows\Explorer.EXE
C:\windows\SysWOW64\rundll32.exe "C:\Program Files (x86)\Garena Plus\ggspawn.dll",rundll_entry -p 0
C:\windows\system32\svchost.exe -k apphost
"C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe"
C:\windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe"
C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
C:\windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\Ralink\RT2860 Wireless LAN Card\ExtraFiles\RaMediaServer.exe"
"C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe"
"C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe"
C:\windows\System32\tcpsvcs.exe
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\system32\svchost.exe -k iissvcs
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
WLIDSvcM.exe 1436
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe"
"C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe"
"C:\Windows\SysWOW64\rundll32.exe" "C:\Users\Michal Skopik\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
C:\windows\system32\SearchIndexer.exe /Embedding
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\System32\alg.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Users\Michal Skopik\Desktop\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

=========Mozilla firefox=========

ProfilePath - C:\Users\Michal Skopik\AppData\Roaming\Mozilla\Firefox\Profiles\iglw7od7.default

prefs.js - "browser.search.useDBForOrder" - "false"
prefs.js - "browser.startup.homepage" - "https://www.google.cz/"
prefs.js - "keyword.URL" - "http://search.yahoo.com/search?fr=green ... =800236&p="

"{336D0C35-8A85-403a-B9D2-65C292C39087}"=C:\Program Files\Web Assistant\Firefox


[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 12.0.0.43 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.40.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\windows\SysWOW64\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.40.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@mcafee.com/SAFFPlugin]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pages.tvunetworks.com/WebPlayer]
"Description"=TVU Web Player Plugin
"Path"=C:\windows\system32\TVUAx\npTVUAx.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=16.0.3.51]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.3]
"Description"=RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.3]
"Description"=RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.3]
"Description"=RealNetworks(tm) RealDownloader Peppe rFlash Video Shim Plug-In
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpplugin;version=16.0.3.51]
"Description"=RealPlayer Download Plugin
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@realnetworks.com/npdlplugin;version=1]
"Description"=RealDownloader Plugin
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@t.garena.com/garenatalk]
"Description"=Garena Talk Plugin
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 12.0.0.43 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll


C:\Program Files (x86)\Mozilla Firefox\searchplugins\
yahoo.xml

C:\Users\Michal Skopik\AppData\Roaming\Mozilla\Firefox\Profiles\iglw7od7.default\extensions\
artur.dubovoy@gmail.com
battlefieldplay4free@ea.com
WebSiteRecommendation@weliketheweb.com
youtubeunblocker@unblocker.yt
{ec9032c7-c20a-464f-7b0e-13a3a9e97385}

C:\Users\Michal Skopik\AppData\Roaming\Mozilla\Firefox\Profiles\iglw7od7.default\searchplugins\
yahoo_ff.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}]
SteadyVideoBHO Class - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2012-02-14 81024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-01-26 1390368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealNetworks Download and Record Plugin for Internet Explorer - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-08-14 542376]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}]
SteadyVideoBHO Class - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2012-02-14 69760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-02 462248]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-01-26 1143168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-02 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-01-26 1390368]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-01-26 1143168]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-04-22 11831400]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [2011-10-19 5908928]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2011-10-19 9769888]
"Lenovo EE Boot Optimizer"=C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [2011-10-19 206176]
"OnekeyStudio"=C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe [2011-10-19 789920]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2014-01-06 6563608]
"NextLive"=C:\windows\SysWOW64\rundll32.exe [2009-07-14 44544]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnUpdater]
C:\Program Files (x86)\Ask.com\Updater\Updater.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Keyboard Inf.]
C:\Users\Michal Skopik\AppData\Roaming\Lenovo\msdn.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RazerGameBooster]
C:\Program Files (x86)\Razer\Razer Game Booster\RazerGameBooster.exe [2013-11-22 61152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings]
C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-12-22 2538280]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [2013-09-14 295512]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
C:\Program Files (x86)\Trojan Remover\Trjscan.exe /boot []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateP2GShortCut]
C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe C:\Program Files (x86)\Lenovo\Power2Go UpdateWithCreateOnce SOFTWARE\CyberLink\Power2Go\5.0 []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePRCShortCut]
C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [2009-05-13 222504]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Program Files (x86)\uTorrent\uTorrent.exe [2013-06-17 802136]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeriFaceManager]
C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YouCam Mirage]
C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2011-01-29 136488]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YouCam Tray]
C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [2011-01-29 228448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
C:\PROGRA~1\Lenovo\BLUETO~1\BTTray.exe [2011-01-13 1138464]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2013-12-06 766208]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-01-26 3767096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-01-26 12:36:13 ----D---- C:\Program Files\trend micro
2014-01-26 12:36:12 ----DC---- C:\rsit
2014-01-26 01:49:24 ----D---- C:\Users\Michal Skopik\AppData\Roaming\AVAST Software
2014-01-26 01:48:30 ----A---- C:\windows\system32\drivers\aswVmm.sys
2014-01-26 01:48:30 ----A---- C:\windows\system32\drivers\aswStm.sys
2014-01-26 01:48:30 ----A---- C:\windows\system32\drivers\aswSP.sys
2014-01-26 01:48:30 ----A---- C:\windows\system32\drivers\aswSnx.sys
2014-01-26 01:48:30 ----A---- C:\windows\system32\drivers\aswRvrt.sys
2014-01-26 01:48:30 ----A---- C:\windows\system32\drivers\aswRdr2.sys
2014-01-26 01:48:30 ----A---- C:\windows\system32\drivers\aswMonFlt.sys
2014-01-26 01:48:29 ----A---- C:\windows\system32\aswBoot.exe
2014-01-26 01:48:27 ----A---- C:\windows\avastSS.scr
2014-01-26 01:44:53 ----D---- C:\Program Files\AVAST Software
2014-01-26 01:41:43 ----D---- C:\ProgramData\AVAST Software
2014-01-25 23:58:10 ----A---- C:\windows\system32\FNTCACHE.DAT
2014-01-25 23:54:44 ----DC---- C:\AMD
2014-01-25 23:54:43 ----DC---- C:\Drivers
2014-01-25 23:54:41 ----D---- C:\Users\Michal Skopik\AppData\Roaming\newnext.me
2014-01-25 23:54:41 ----A---- C:\windows\SYSWOW64\TCPSVCS.EXE
2014-01-25 23:54:41 ----A---- C:\windows\SYSWOW64\msiexec.exe
2014-01-25 23:54:39 ----D---- C:\Users\Michal Skopik\AppData\Roaming\OpenCandy
2014-01-25 23:54:39 ----A---- C:\windows\SYSWOW64\dllhost.exe
2014-01-25 23:54:38 ----A---- C:\windows\SYSWOW64\SEARCHINDEXER.EXE
2014-01-25 23:53:30 ----DC---- C:\MATS
2014-01-25 15:04:28 ----D---- C:\Users\Michal Skopik\AppData\Roaming\SUPERAntiSpyware.com
2014-01-25 15:03:34 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2014-01-25 15:03:34 ----D---- C:\Program Files\SUPERAntiSpyware
2014-01-24 13:50:34 ----D---- C:\ProgramData\McAfee
2014-01-22 22:43:29 ----DC---- C:\local
2014-01-22 22:38:17 ----D---- C:\Program Files (x86)\State Of Decay
2014-01-15 12:13:26 ----D---- C:\ProgramData\ATI
2014-01-15 12:06:38 ----D---- C:\Program Files (x86)\AMD AVT
2014-01-15 12:03:48 ----D---- C:\Program Files (x86)\ATI Technologies
2014-01-15 12:02:16 ----A---- C:\windows\SYSWOW64\OVDecode.dll
2014-01-15 12:02:16 ----A---- C:\windows\SYSWOW64\OpenVideo.dll
2014-01-15 12:02:16 ----A---- C:\windows\SYSWOW64\ativvsvl.dat
2014-01-15 12:02:16 ----A---- C:\windows\SYSWOW64\ativvsva.dat
2014-01-15 12:02:16 ----A---- C:\windows\SYSWOW64\atiuxpag.dll
2014-01-15 12:02:16 ----A---- C:\windows\SYSWOW64\atiumdva.dll
2014-01-15 12:02:16 ----A---- C:\windows\SYSWOW64\atiumdag.dll
2014-01-15 12:02:16 ----A---- C:\windows\SYSWOW64\atiu9pag.dll
2014-01-15 12:02:16 ----A---- C:\windows\SYSWOW64\atipblag.dat
2014-01-15 12:02:16 ----A---- C:\windows\system32\OVDecode64.dll
2014-01-15 12:02:16 ----A---- C:\windows\system32\OpenVideo64.dll
2014-01-15 12:02:16 ----A---- C:\windows\system32\coinst_13.251.dll
2014-01-15 12:02:16 ----A---- C:\windows\system32\ativvsvl.dat
2014-01-15 12:02:16 ----A---- C:\windows\system32\ativvsva.dat
2014-01-15 12:02:16 ----A---- C:\windows\system32\ativvaxy_cik_nd.dat
2014-01-15 12:02:16 ----A---- C:\windows\system32\ativvaxy_cik.dat
2014-01-15 12:02:16 ----A---- C:\windows\system32\ativce02.dat
2014-01-15 12:02:16 ----A---- C:\windows\system32\atiuxp64.dll
2014-01-15 12:02:16 ----A---- C:\windows\system32\atiumd6a.dll
2014-01-15 12:02:16 ----A---- C:\windows\system32\atiumd64.dll
2014-01-15 12:02:16 ----A---- C:\windows\system32\atiu9p64.dll
2014-01-15 12:02:16 ----A---- C:\windows\system32\atitmm64.dll
2014-01-15 12:02:16 ----A---- C:\windows\system32\atipblag.dat
2014-01-15 12:02:15 ----A---- C:\windows\SYSWOW64\atioglxx.dll
2014-01-15 12:02:15 ----A---- C:\windows\SYSWOW64\atimpc32.dll
2014-01-15 12:02:15 ----A---- C:\windows\SYSWOW64\atiglpxx.dll
2014-01-15 12:02:15 ----A---- C:\windows\SYSWOW64\atigktxx.dll
2014-01-15 12:02:15 ----A---- C:\windows\SYSWOW64\atidxx32.dll
2014-01-15 12:02:15 ----A---- C:\windows\SYSWOW64\aticfx32.dll
2014-01-15 12:02:15 ----A---- C:\windows\SYSWOW64\aticalrt.dll
2014-01-15 12:02:15 ----A---- C:\windows\SYSWOW64\amdpcom32.dll
2014-01-15 12:02:15 ----A---- C:\windows\system32\drivers\atikmpag.sys
2014-01-15 12:02:15 ----A---- C:\windows\system32\drivers\atikmdag.sys
2014-01-15 12:02:15 ----A---- C:\windows\system32\ATIODE.exe
2014-01-15 12:02:15 ----A---- C:\windows\system32\ATIODCLI.exe
2014-01-15 12:02:15 ----A---- C:\windows\system32\atio6axx.dll
2014-01-15 12:02:15 ----A---- C:\windows\system32\atimuixx.dll
2014-01-15 12:02:15 ----A---- C:\windows\system32\atimpc64.dll
2014-01-15 12:02:15 ----A---- C:\windows\system32\atiicdxx.dat
2014-01-15 12:02:15 ----A---- C:\windows\system32\atiglpxx.dll
2014-01-15 12:02:15 ----A---- C:\windows\system32\atig6txx.dll
2014-01-15 12:02:15 ----A---- C:\windows\system32\atig6pxx.dll
2014-01-15 12:02:15 ----A---- C:\windows\system32\atiesrxx.exe
2014-01-15 12:02:15 ----A---- C:\windows\system32\atieclxx.exe
2014-01-15 12:02:15 ----A---- C:\windows\system32\atidxx64.dll
2014-01-15 12:02:15 ----A---- C:\windows\system32\atidemgy.dll
2014-01-15 12:02:15 ----A---- C:\windows\system32\aticfx64.dll
2014-01-15 12:02:15 ----A---- C:\windows\system32\aticalrt64.dll
2014-01-15 12:02:15 ----A---- C:\windows\system32\amdpcom64.dll
2014-01-15 12:02:14 ----A---- C:\windows\SYSWOW64\aticaldd.dll
2014-01-15 12:02:14 ----A---- C:\windows\SYSWOW64\aticalcl.dll
2014-01-15 12:02:14 ----A---- C:\windows\SYSWOW64\atiadlxy.dll
2014-01-15 12:02:14 ----A---- C:\windows\SYSWOW64\amdocl_ld32.exe
2014-01-15 12:02:14 ----A---- C:\windows\SYSWOW64\amdocl_as32.exe
2014-01-15 12:02:14 ----A---- C:\windows\system32\drivers\ati2erec.dll
2014-01-15 12:02:14 ----A---- C:\windows\system32\aticaldd64.dll
2014-01-15 12:02:14 ----A---- C:\windows\system32\aticalcl64.dll
2014-01-15 12:02:14 ----A---- C:\windows\system32\atibtmon.exe
2014-01-15 12:02:14 ----A---- C:\windows\system32\atiapfxx.exe
2014-01-15 12:02:14 ----A---- C:\windows\system32\atiadlxx.dll
2014-01-15 12:02:14 ----A---- C:\windows\system32\amdocl_ld64.exe
2014-01-15 12:02:14 ----A---- C:\windows\system32\amdocl_as64.exe
2014-01-15 12:02:13 ----A---- C:\windows\SYSWOW64\amdocl.dll
2014-01-15 12:02:13 ----A---- C:\windows\system32\amdocl64.dll
2014-01-15 12:01:15 ----A---- C:\windows\system32\drivers\usbfilter.sys
2014-01-15 12:01:11 ----D---- C:\Program Files\Common Files\ATI Technologies
2014-01-15 12:01:03 ----D---- C:\Program Files\ATI
2014-01-15 12:00:29 ----D---- C:\Program Files\ATI Technologies
2014-01-15 11:00:29 ----A---- C:\windows\system32\drivers\usbuhci.sys
2014-01-15 11:00:29 ----A---- C:\windows\system32\drivers\usbport.sys
2014-01-15 11:00:29 ----A---- C:\windows\system32\drivers\usbohci.sys
2014-01-15 11:00:29 ----A---- C:\windows\system32\drivers\usbhub.sys
2014-01-15 11:00:29 ----A---- C:\windows\system32\drivers\usbehci.sys
2014-01-15 11:00:29 ----A---- C:\windows\system32\drivers\usbd.sys
2014-01-15 11:00:29 ----A---- C:\windows\system32\drivers\usbccgp.sys
2014-01-15 11:00:28 ----A---- C:\windows\system32\win32k.sys
2014-01-15 11:00:28 ----A---- C:\windows\system32\drivers\netio.sys
2014-01-15 10:49:08 ----D---- C:\Program Files\AMD
2014-01-15 10:46:40 ----A---- C:\windows\system32\drivers\AtihdW76.sys
2014-01-15 10:46:40 ----A---- C:\windows\system32\DelayAPO.dll
2014-01-15 10:46:39 ----A---- C:\windows\system32\clinfo.exe
2014-01-15 10:46:38 ----A---- C:\windows\SYSWOW64\OpenCL.dll
2014-01-15 10:46:38 ----A---- C:\windows\system32\OpenCL.dll
2014-01-15 01:14:33 ----D---- C:\ProgramData\AMD
2014-01-13 21:35:15 ----DC---- C:\Thief - Deadly Shadows
2014-01-12 20:02:13 ----D---- C:\windows\DA909E623B454BA18B58FCAEBA4BCEC9.TMP
2014-01-12 19:33:17 ----DC---- C:\R.G. Catalyst
2014-01-09 20:17:35 ----D---- C:\Program Files (x86)\MSI Afterburner
2014-01-09 18:45:05 ----D---- C:\Program Files (x86)\MSI Kombustor 2.5
2014-01-09 12:19:32 ----A---- C:\windows\system32\drivers\amd_xata.sys
2014-01-09 12:19:31 ----A---- C:\windows\system32\drivers\amd_sata.sys
2014-01-09 03:07:37 ----D---- C:\ProgramData\Futuremark
2014-01-09 02:46:48 ----D---- C:\Program Files (x86)\Futuremark
2014-01-09 02:44:37 ----D---- C:\Program Files\Futuremark
2014-01-04 22:08:34 ----D---- C:\ProgramData\Uniblue
2014-01-04 18:03:54 ----D---- C:\Program Files (x86)\AMD
2014-01-04 18:01:10 ----D---- C:\ProgramData\APN
2014-01-04 13:41:50 ----D---- C:\Program Files (x86)\Mobogenie
2014-01-04 13:41:25 ----D---- C:\Program Files (x86)\Driver Fusion
2014-01-04 04:53:10 ----D---- C:\Program Files\CPUID
2014-01-03 14:58:00 ----SHD---- C:\windows\SYSWOW64\AI_RecycleBin
2014-01-03 14:57:58 ----H---- C:\Program Files (x86)\d22df7db.tmp
2014-01-03 14:57:55 ----D---- C:\Users\Michal Skopik\AppData\Roaming\PingPlotter
2014-01-03 14:57:55 ----D---- C:\Program Files (x86)\PingPlotter Standard
2014-01-03 14:57:19 ----D---- C:\Users\Michal Skopik\AppData\Roaming\Downloaded Installations
2014-01-01 21:53:39 ----D---- C:\Program Files (x86)\Viva Media
2014-01-01 21:45:15 ----D---- C:\Program Files (x86)\FutureGames
2014-01-01 20:20:56 ----D---- C:\windows\64467D47FFE44FBCABBAA0DB829A17EB.TMP
2014-01-01 19:10:52 ----D---- C:\Program Files (x86)\Hitman Absolution
2014-01-01 18:03:40 ----D---- C:\Program Files (x86)\SQUARE ENIX

======List of files/folders modified in the last 1 month======

2014-01-26 14:18:03 ----D---- C:\windows\Temp
2014-01-26 13:33:55 ----D---- C:\windows\Prefetch
2014-01-26 13:27:32 ----D---- C:\windows\System32
2014-01-26 13:27:32 ----D---- C:\windows\inf
2014-01-26 13:27:32 ----A---- C:\windows\system32\PerfStringBackup.INI
2014-01-26 13:22:19 ----D---- C:\windows\system32\Tasks
2014-01-26 13:22:18 ----D---- C:\windows\system32\config
2014-01-26 13:21:03 ----D---- C:\windows\registration
2014-01-26 12:36:13 ----RD---- C:\Program Files
2014-01-26 02:11:04 ----D---- C:\Windows
2014-01-26 01:48:30 ----D---- C:\windows\system32\drivers
2014-01-26 01:48:29 ----D---- C:\windows\winsxs
2014-01-26 01:44:50 ----SHD---- C:\System Volume Information
2014-01-26 01:41:43 ----HD---- C:\ProgramData
2014-01-26 01:15:48 ----D---- C:\windows\Tasks
2014-01-26 01:15:48 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2014-01-26 00:30:22 ----SHD---- C:\windows\Installer
2014-01-26 00:30:18 ----SHD---- C:\Config.Msi
2014-01-26 00:09:04 ----D---- C:\windows\system32\LogFiles
2014-01-25 23:54:42 ----D---- C:\Program Files (x86)\BisonCam
2014-01-25 23:54:41 ----D---- C:\windows\SysWOW64
2014-01-25 17:09:02 ----D---- C:\Program Files (x86)\WarThunder
2014-01-25 14:23:33 ----D---- C:\Program Files (x86)\Steam
2014-01-25 14:23:32 ----D---- C:\windows\Logs
2014-01-25 14:22:37 ----RD---- C:\Program Files (x86)
2014-01-25 01:19:15 ----DC---- C:\Fraps
2014-01-24 14:55:43 ----D---- C:\windows\SYSWOW64\directx
2014-01-24 14:55:38 ----HD---- C:\windows\msdownld.tmp
2014-01-24 14:55:34 ----D---- C:\Games
2014-01-24 14:24:58 ----D---- C:\Users\Michal Skopik\AppData\Roaming\DAEMON Tools Lite
2014-01-24 00:21:34 ----D---- C:\Program Files (x86)\Little Inferno
2014-01-23 22:26:51 ----D---- C:\Program Files (x86)\Internet Explorer
2014-01-23 13:27:28 ----D---- C:\Program Files (x86)\Lucius
2014-01-23 00:48:44 ----D---- C:\Program Files (x86)\Deadly Premonition The Director's Cut
2014-01-22 23:48:04 ----D---- C:\Program Files\The Witcher 2
2014-01-22 23:40:38 ----N---- C:\windows\SYSWOW64\svchost.exe
2014-01-21 09:31:31 ----D---- C:\windows\system32\catroot2
2014-01-20 22:35:09 ----RSD---- C:\windows\Fonts
2014-01-17 14:12:07 ----D---- C:\windows\debug
2014-01-16 00:30:41 ----D---- C:\Users\Michal Skopik\AppData\Roaming\Wargaming.net
2014-01-15 14:33:13 ----D---- C:\windows\Microsoft.NET
2014-01-15 12:13:26 ----D---- C:\Users\Michal Skopik\AppData\Roaming\ATI
2014-01-15 12:06:32 ----D---- C:\Program Files (x86)\Common Files
2014-01-15 12:05:41 ----D---- C:\windows\system32\catroot
2014-01-15 12:05:38 ----D---- C:\windows\system32\DriverStore
2014-01-15 12:01:15 ----DC---- C:\windows\system32\DRVSTORE
2014-01-15 12:01:11 ----D---- C:\Program Files\Common Files
2014-01-15 11:05:04 ----D---- C:\windows\system32\MRT
2014-01-15 11:01:33 ----A---- C:\windows\system32\MRT.exe
2014-01-13 21:33:31 ----D---- C:\Users\Michal Skopik\AppData\Roaming\Skype
2014-01-13 01:35:00 ----D---- C:\Users\Michal Skopik\AppData\Roaming\Games
2014-01-12 22:13:14 ----A---- C:\windows\SYSWOW64\PnkBstrB.exe
2014-01-09 12:22:01 ----D---- C:\ProgramData\Package Cache
2014-01-09 02:50:14 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-01-07 23:27:51 ----RSD---- C:\windows\assembly
2014-01-03 03:19:36 ----D---- C:\windows\SoftwareDistribution
2014-01-02 11:17:14 ----D---- C:\windows\system32\NDF
2014-01-01 21:55:33 ----A---- C:\windows\SYSWOW64\wrap_oal.dll
2014-01-01 21:55:33 ----A---- C:\windows\SYSWOW64\OpenAL32.dll
2014-01-01 21:55:33 ----A---- C:\windows\system32\wrap_oal.dll
2014-01-01 21:55:33 ----A---- C:\windows\system32\OpenAL32.dll
2014-01-01 21:34:15 ----D---- C:\Program Files (x86)\Iceberg Interactive
2014-01-01 17:32:30 ----D---- C:\ProgramData\DAEMON Tools Lite

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 amd_sata;amd_sata; C:\windows\system32\DRIVERS\amd_sata.sys [2013-06-28 82240]
R0 amd_xata;amd_xata; C:\windows\system32\DRIVERS\amd_xata.sys [2013-06-28 42304]
R0 aswRvrt;avast! Revert; C:\windows\system32\drivers\aswRvrt.sys [2014-01-26 65776]
R0 aswVmm;avast! VM Monitor; C:\windows\system32\drivers\aswVmm.sys [2014-01-26 207904]
R0 fbfmon;fbfmon; C:\windows\system32\drivers\fbfmon.sys [2011-10-19 57952]
R0 LHDmgr;LHDmgr; C:\windows\System32\DRIVERS\LhdX64.sys [2013-10-18 39008]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 aswRdr;aswRdr; \??\C:\windows\system32\drivers\aswRdr2.sys [2014-01-26 92544]
R1 aswSnx;aswSnx; \??\C:\windows\system32\drivers\aswSnx.sys [2014-01-26 1038072]
R1 aswSP;aswSP; \??\C:\windows\system32\drivers\aswSP.sys [2014-01-26 421704]
R1 BPntDrv;BPntDrv; C:\windows\system32\drivers\BPntDrv.sys [2011-10-19 13408]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 AODDriver4.2.0;AODDriver4.2.0; \??\C:\Program Files (x86)\AMD\OverDrive\amd64\AODDriver2.sys [2013-05-24 58088]
R2 aswMonFlt;aswMonFlt; \??\C:\windows\system32\drivers\aswMonFlt.sys [2014-01-26 78648]
R2 atksgt;atksgt; C:\windows\system32\DRIVERS\atksgt.sys [2012-06-13 88480]
R2 lirsgt;lirsgt; C:\windows\system32\DRIVERS\lirsgt.sys [2012-06-13 46400]
R2 RMCAST;@%SystemRoot%\system32\wshrm.dll,-102; C:\windows\system32\DRIVERS\RMCAST.sys [2010-11-21 146432]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\windows\system32\DRIVERS\AcpiVpc.sys [2011-10-19 29792]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2013-12-07 13207552]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2013-12-07 626176]
R3 aswStm;aswStm; \??\C:\windows\system32\drivers\aswStm.sys [2014-01-26 80184]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\windows\system32\drivers\AtihdW76.sys [2013-09-24 94208]
R3 clwvd;CyberLink WebCam Virtual Driver; C:\windows\system32\DRIVERS\clwvd.sys [2011-01-29 31088]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\windows\system32\DRIVERS\dtsoftbus01.sys [2013-12-20 283064]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2011-04-26 2852200]
R3 MBAMProtector;MBAMProtector; \??\C:\windows\system32\drivers\mbam.sys [2013-04-04 25928]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver; C:\windows\system32\DRIVERS\netr28x.sys [2013-02-25 2426672]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUVStor.sys [2010-11-30 307304]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 SPUVCbv;SPUVCb Driver Service; C:\windows\System32\Drivers\usbvideo.sys [2013-07-12 185344]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2010-12-22 1407024]
R3 usbfilter;AMD USB Filter Driver; C:\windows\system32\DRIVERS\usbfilter.sys [2011-08-17 53376]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S0 sptd;sptd; C:\windows\system32\drivers\sptd.sys []
S2 athsgt;athsgt; C:\windows\system32\DRIVERS\athsgt.sys []
S2 ithsgt;ithsgt; C:\windows\system32\DRIVERS\ithsgt.sys []
S2 lilsgt;lilsgt; C:\windows\system32\DRIVERS\lilsgt.sys []
S2 limsgt;limsgt; C:\windows\system32\DRIVERS\limsgt.sys []
S3 amdiox64;AMD IO Driver; C:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
S3 atillk64;atillk64; \??\C:\Program Files (x86)\AMD\System Monitor\atillk64.sys []
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 BTWAMPFL;btwampfl; C:\windows\system32\DRIVERS\btwampfl.sys [2011-01-13 349736]
S3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2011-01-13 106536]
S3 btwavdt;Bluetooth AVDT; C:\windows\system32\drivers\btwavdt.sys [2011-01-13 138280]
S3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2011-01-13 39464]
S3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2011-01-13 21416]
S3 cpuz130;cpuz130; \??\C:\Users\MICHAL~1\AppData\Local\Temp\cpuz130\cpuz_x64.sys []
S3 EagleX64;EagleX64; \??\C:\windows\system32\drivers\EagleX64.sys []
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files (x86)\Garena Plus\Room\safedrv.sys []
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%; C:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\windows\system32\DRIVERS\VBoxNetAdp.sys [2012-04-12 147248]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service; C:\windows\system32\DRIVERS\VBoxNetFlt.sys []
S3 wdmirror;wdmirror; C:\windows\system32\DRIVERS\WDMirror.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2013-10-10 144152]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-18 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2013-12-07 239616]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-12-06 344064]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\windows\system32\svchost.exe [2009-07-14 27136]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-01-26 50344]
R2 btwdins;Bluetooth Service; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [2011-01-13 956192]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376]
R2 NetPipeActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
R2 NetTcpActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
R2 PnkBstrA;PnkBstrA; C:\windows\syswow64\PnkBstrA.exe [2013-10-05 76888]
R2 RaMediaServer;Ralink UPnP Media Server; C:\Program Files (x86)\Ralink\RT2860 Wireless LAN Card\ExtraFiles\RaMediaServer.exe [2010-05-19 454656]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2013-08-14 39056]
R2 RzKLService;RzKLService; C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe [2013-11-22 105448]
R2 simptcp;@%SystemRoot%\system32\simptcp.dll,-200; C:\windows\System32\tcpsvcs.exe [2009-07-14 10240]
R2 W3SVC;@%windir%\system32\inetsrv\iisres.dll,-30003; C:\windows\system32\svchost.exe [2009-07-14 27136]
R3 WAS;@%windir%\system32\inetsrv\iisres.dll,-30001; C:\windows\system32\svchost.exe [2009-07-14 27136]
S2 AODService;AODService; C:\Program Files (x86)\AMD\OverDrive\AODAssist.exe [2013-05-24 137256]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-09-05 171680]
S3 aspnet_state;Stavová služba ASP.NET; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [2013-02-17 137336]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2013-11-26 111616]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-12-20 119408]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-01-07 569768]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2011-11-29 1255736]
S4 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2014-01-25 180224]
S4 NetMsmqActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Mikaj08
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 26 led 2014 04:41

Re: Problém s virem Win32.expiro-U / Vitro

#2 Příspěvek od Mikaj08 »

Tady to je:

C:\windows\SysWOW64\rundll32.exe

Kód: Vybrat vše

https://www.virustotal.com/cs/file/5ad3c37e6f2b9db3ee8b5aeedc474645de90c66e3d95f8620c48102f1eba4124/analysis/1390747746/
C:\windows\System32\lsass.exe - soubor nebyl nalezen

C:\windows\system32\svchost.exe

Kód: Vybrat vše

https://www.virustotal.com/cs/file/f3549d59f66c98d17dc4b36176c4569064b7e523c01443975065f030c5bb1cb5/analysis/1390747957/
C:\windows\system32\winlogon.exe - soubor nebyl nalezen

Mikaj08
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 26 led 2014 04:41

Re: Problém s virem Win32.expiro-U / Vitro

#3 Příspěvek od Mikaj08 »

Zdravim, tak bitdefender pomohl, nakazene .EXE soubory (234 kousku) byly vyleceny + nasel dalsi havet co byla ve hrach (cracku), ja vim... :whip:
Presto mi Avast nasel nejake rootkity ktere sem nasledne vymazal, ted to vypada ze je vse v poradku, teda aspon doufam.
Toz dekuju za pomoc :)

Mikaj08
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 26 led 2014 04:41

Re: Problém s virem Win32.expiro-U / Vitro

#4 Příspěvek od Mikaj08 »

Tady je log z RSIT:

Logfile of random's system information tool 1.09 (written by random/random)
Run by Michal Skopik at 2014-01-27 22:56:43
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 183 GB (27%) free of 670 GB
Total RAM: 7654 MB (79% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:56:47, on 27.1.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal

Running processes:
C:\windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\trend micro\Michal Skopik.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.tyn.elsat.cz:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
F2 - REG:system.ini: UserInit=%windows%\system32\userinit.exe,
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: AMD SteadyVideo BHO - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{5BF2F48C-4A51-4E63-960A-A5B6FE7D068A}: NameServer = 81.90.168.3,10.72.250.10
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O18 - Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Ralink UPnP Media Server (RaMediaServer) - Unknown owner - C:\Program Files (x86)\Ralink\RT2860 Wireless LAN Card\ExtraFiles\RaMediaServer.exe
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9376 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
winlogon.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
atieclxx
C:\windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
C:\windows\system32\svchost.exe -k apphost
"C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe"
C:\windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
"taskhost.exe"
taskeng.exe {B85668E2-1A24-4B66-ADC8-208F7A0F7573}
"C:\windows\system32\Dwm.exe"
taskeng.exe {62B81AEB-3894-4659-923F-0DCCF5BEBFFC}
C:\windows\Explorer.EXE
C:\windows\SysWOW64\rundll32.exe "C:\Program Files (x86)\Garena Plus\ggspawn.dll",rundll_entry -p 0
C:\windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\Ralink\RT2860 Wireless LAN Card\ExtraFiles\RaMediaServer.exe"
"C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe"
C:\windows\System32\tcpsvcs.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\system32\svchost.exe -k iissvcs
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 1552
C:\windows\System32\alg.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe"
"C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
"C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
C:\windows\system32\SearchIndexer.exe /Embedding
C:\windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe150_ Global\UsGthrCtrlFltPipeMssGthrPipe150 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Users\Michal Skopik\Desktop\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

=========Mozilla firefox=========

ProfilePath - C:\Users\Michal Skopik\AppData\Roaming\Mozilla\Firefox\Profiles\0t6utljz.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 12.0.0.43 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.40.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\windows\SysWOW64\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.40.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@mcafee.com/SAFFPlugin]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pages.tvunetworks.com/WebPlayer]
"Description"=TVU Web Player Plugin
"Path"=C:\windows\system32\TVUAx\npTVUAx.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=16.0.3.51]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.3]
"Description"=RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.3]
"Description"=RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.3]
"Description"=RealNetworks(tm) RealDownloader Peppe rFlash Video Shim Plug-In
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpplugin;version=16.0.3.51]
"Description"=RealPlayer Download Plugin
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@realnetworks.com/npdlplugin;version=1]
"Description"=RealDownloader Plugin
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@t.garena.com/garenatalk]
"Description"=Garena Talk Plugin
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 12.0.0.43 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll


C:\Program Files (x86)\Mozilla Firefox\searchplugins\
yahoo.xml

C:\Users\Michal Skopik\AppData\Roaming\Mozilla\Firefox\Profiles\0t6utljz.default\searchplugins\
yahoo_ff.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}]
SteadyVideoBHO Class - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2012-02-14 81024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-01-26 1390368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealNetworks Download and Record Plugin for Internet Explorer - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-08-14 542376]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}]
SteadyVideoBHO Class - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2012-02-14 69760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-02 462248]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-01-26 1143168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-02 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-01-26 1390368]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-01-26 1143168]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-04-22 11831400]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [2011-10-19 5908928]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2011-10-19 9769888]
"Lenovo EE Boot Optimizer"=C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [2011-10-19 206176]
"OnekeyStudio"=C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe [2011-10-19 789920]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnUpdater]
C:\Program Files (x86)\Ask.com\Updater\Updater.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Keyboard Inf.]
C:\Users\Michal Skopik\AppData\Roaming\Lenovo\msdn.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RazerGameBooster]
C:\Program Files (x86)\Razer\Razer Game Booster\RazerGameBooster.exe -autorun []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings]
C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-12-22 2538280]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [2013-09-14 295512]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
C:\Program Files (x86)\Trojan Remover\Trjscan.exe /boot []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateP2GShortCut]
C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe C:\Program Files (x86)\Lenovo\Power2Go UpdateWithCreateOnce SOFTWARE\CyberLink\Power2Go\5.0 []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePRCShortCut]
C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [2009-05-13 222504]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Program Files (x86)\uTorrent\uTorrent.exe [2013-06-17 802136]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeriFaceManager]
C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YouCam Mirage]
C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2011-01-29 136488]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YouCam Tray]
C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [2011-01-29 228448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
C:\PROGRA~1\Lenovo\BLUETO~1\BTTray.exe [2011-01-13 1138464]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2013-12-06 766208]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-01-26 3767096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-01-27 12:38:44 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-27 12:38:44 ----A---- C:\windows\system32\drivers\mbam.sys
2014-01-27 12:22:57 ----A---- C:\windows\system32\FNTCACHE.DAT
2014-01-27 12:18:14 ----DC---- C:\AdwCleaner
2014-01-26 16:49:39 ----D---- C:\Users\Michal Skopik\AppData\Roaming\InfraRecorder
2014-01-26 16:49:37 ----D---- C:\Program Files (x86)\InfraRecorder
2014-01-26 12:36:13 ----D---- C:\Program Files\trend micro
2014-01-26 12:36:12 ----DC---- C:\rsit
2014-01-26 01:49:24 ----D---- C:\Users\Michal Skopik\AppData\Roaming\AVAST Software
2014-01-26 01:48:30 ----A---- C:\windows\system32\drivers\aswVmm.sys
2014-01-26 01:48:30 ----A---- C:\windows\system32\drivers\aswStm.sys
2014-01-26 01:48:30 ----A---- C:\windows\system32\drivers\aswSP.sys
2014-01-26 01:48:30 ----A---- C:\windows\system32\drivers\aswSnx.sys
2014-01-26 01:48:30 ----A---- C:\windows\system32\drivers\aswRvrt.sys
2014-01-26 01:48:30 ----A---- C:\windows\system32\drivers\aswRdr2.sys
2014-01-26 01:48:30 ----A---- C:\windows\system32\drivers\aswMonFlt.sys
2014-01-26 01:48:29 ----A---- C:\windows\system32\aswBoot.exe
2014-01-26 01:48:27 ----A---- C:\windows\avastSS.scr
2014-01-26 01:44:53 ----D---- C:\Program Files\AVAST Software
2014-01-26 01:41:43 ----D---- C:\ProgramData\AVAST Software
2014-01-25 23:54:44 ----DC---- C:\AMD
2014-01-25 23:54:43 ----DC---- C:\Drivers
2014-01-25 23:54:41 ----A---- C:\windows\SYSWOW64\TCPSVCS.EXE
2014-01-25 23:54:41 ----A---- C:\windows\SYSWOW64\msiexec.exe
2014-01-25 23:54:39 ----A---- C:\windows\SYSWOW64\dllhost.exe
2014-01-25 23:54:38 ----A---- C:\windows\SYSWOW64\SEARCHINDEXER.EXE
2014-01-25 15:04:28 ----D---- C:\Users\Michal Skopik\AppData\Roaming\SUPERAntiSpyware.com
2014-01-25 15:03:34 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2014-01-25 15:03:34 ----D---- C:\Program Files\SUPERAntiSpyware
2014-01-15 12:13:26 ----D---- C:\ProgramData\ATI
2014-01-15 12:06:38 ----D---- C:\Program Files (x86)\AMD AVT
2014-01-15 12:03:48 ----D---- C:\Program Files (x86)\ATI Technologies
2014-01-15 12:02:16 ----A---- C:\windows\SYSWOW64\OVDecode.dll
2014-01-15 12:02:16 ----A---- C:\windows\SYSWOW64\OpenVideo.dll
2014-01-15 12:02:16 ----A---- C:\windows\SYSWOW64\ativvsvl.dat
2014-01-15 12:02:16 ----A---- C:\windows\SYSWOW64\ativvsva.dat
2014-01-15 12:02:16 ----A---- C:\windows\SYSWOW64\atiuxpag.dll
2014-01-15 12:02:16 ----A---- C:\windows\SYSWOW64\atiumdva.dll
2014-01-15 12:02:16 ----A---- C:\windows\SYSWOW64\atiumdag.dll
2014-01-15 12:02:16 ----A---- C:\windows\SYSWOW64\atiu9pag.dll
2014-01-15 12:02:16 ----A---- C:\windows\SYSWOW64\atipblag.dat
2014-01-15 12:02:16 ----A---- C:\windows\system32\OVDecode64.dll
2014-01-15 12:02:16 ----A---- C:\windows\system32\OpenVideo64.dll
2014-01-15 12:02:16 ----A---- C:\windows\system32\coinst_13.251.dll
2014-01-15 12:02:16 ----A---- C:\windows\system32\ativvsvl.dat
2014-01-15 12:02:16 ----A---- C:\windows\system32\ativvsva.dat
2014-01-15 12:02:16 ----A---- C:\windows\system32\ativvaxy_cik_nd.dat
2014-01-15 12:02:16 ----A---- C:\windows\system32\ativvaxy_cik.dat
2014-01-15 12:02:16 ----A---- C:\windows\system32\ativce02.dat
2014-01-15 12:02:16 ----A---- C:\windows\system32\atiuxp64.dll
2014-01-15 12:02:16 ----A---- C:\windows\system32\atiumd6a.dll
2014-01-15 12:02:16 ----A---- C:\windows\system32\atiumd64.dll
2014-01-15 12:02:16 ----A---- C:\windows\system32\atiu9p64.dll
2014-01-15 12:02:16 ----A---- C:\windows\system32\atitmm64.dll
2014-01-15 12:02:16 ----A---- C:\windows\system32\atipblag.dat
2014-01-15 12:02:15 ----A---- C:\windows\SYSWOW64\atioglxx.dll
2014-01-15 12:02:15 ----A---- C:\windows\SYSWOW64\atimpc32.dll
2014-01-15 12:02:15 ----A---- C:\windows\SYSWOW64\atiglpxx.dll
2014-01-15 12:02:15 ----A---- C:\windows\SYSWOW64\atigktxx.dll
2014-01-15 12:02:15 ----A---- C:\windows\SYSWOW64\atidxx32.dll
2014-01-15 12:02:15 ----A---- C:\windows\SYSWOW64\aticfx32.dll
2014-01-15 12:02:15 ----A---- C:\windows\SYSWOW64\aticalrt.dll
2014-01-15 12:02:15 ----A---- C:\windows\SYSWOW64\amdpcom32.dll
2014-01-15 12:02:15 ----A---- C:\windows\system32\drivers\atikmpag.sys
2014-01-15 12:02:15 ----A---- C:\windows\system32\drivers\atikmdag.sys
2014-01-15 12:02:15 ----A---- C:\windows\system32\ATIODE.exe
2014-01-15 12:02:15 ----A---- C:\windows\system32\ATIODCLI.exe
2014-01-15 12:02:15 ----A---- C:\windows\system32\atio6axx.dll
2014-01-15 12:02:15 ----A---- C:\windows\system32\atimuixx.dll
2014-01-15 12:02:15 ----A---- C:\windows\system32\atimpc64.dll
2014-01-15 12:02:15 ----A---- C:\windows\system32\atiicdxx.dat
2014-01-15 12:02:15 ----A---- C:\windows\system32\atiglpxx.dll
2014-01-15 12:02:15 ----A---- C:\windows\system32\atig6txx.dll
2014-01-15 12:02:15 ----A---- C:\windows\system32\atig6pxx.dll
2014-01-15 12:02:15 ----A---- C:\windows\system32\atiesrxx.exe
2014-01-15 12:02:15 ----A---- C:\windows\system32\atieclxx.exe
2014-01-15 12:02:15 ----A---- C:\windows\system32\atidxx64.dll
2014-01-15 12:02:15 ----A---- C:\windows\system32\atidemgy.dll
2014-01-15 12:02:15 ----A---- C:\windows\system32\aticfx64.dll
2014-01-15 12:02:15 ----A---- C:\windows\system32\aticalrt64.dll
2014-01-15 12:02:15 ----A---- C:\windows\system32\amdpcom64.dll
2014-01-15 12:02:14 ----A---- C:\windows\SYSWOW64\aticaldd.dll
2014-01-15 12:02:14 ----A---- C:\windows\SYSWOW64\aticalcl.dll
2014-01-15 12:02:14 ----A---- C:\windows\SYSWOW64\atiadlxy.dll
2014-01-15 12:02:14 ----A---- C:\windows\SYSWOW64\amdocl_ld32.exe
2014-01-15 12:02:14 ----A---- C:\windows\SYSWOW64\amdocl_as32.exe
2014-01-15 12:02:14 ----A---- C:\windows\system32\drivers\ati2erec.dll
2014-01-15 12:02:14 ----A---- C:\windows\system32\aticaldd64.dll
2014-01-15 12:02:14 ----A---- C:\windows\system32\aticalcl64.dll
2014-01-15 12:02:14 ----A---- C:\windows\system32\atibtmon.exe
2014-01-15 12:02:14 ----A---- C:\windows\system32\atiapfxx.exe
2014-01-15 12:02:14 ----A---- C:\windows\system32\atiadlxx.dll
2014-01-15 12:02:14 ----A---- C:\windows\system32\amdocl_ld64.exe
2014-01-15 12:02:14 ----A---- C:\windows\system32\amdocl_as64.exe
2014-01-15 12:02:13 ----A---- C:\windows\SYSWOW64\amdocl.dll
2014-01-15 12:02:13 ----A---- C:\windows\system32\amdocl64.dll
2014-01-15 12:01:15 ----A---- C:\windows\system32\drivers\usbfilter.sys
2014-01-15 12:01:11 ----D---- C:\Program Files\Common Files\ATI Technologies
2014-01-15 12:01:03 ----D---- C:\Program Files\ATI
2014-01-15 12:00:29 ----D---- C:\Program Files\ATI Technologies
2014-01-15 11:00:29 ----A---- C:\windows\system32\drivers\usbuhci.sys
2014-01-15 11:00:29 ----A---- C:\windows\system32\drivers\usbport.sys
2014-01-15 11:00:29 ----A---- C:\windows\system32\drivers\usbohci.sys
2014-01-15 11:00:29 ----A---- C:\windows\system32\drivers\usbhub.sys
2014-01-15 11:00:29 ----A---- C:\windows\system32\drivers\usbehci.sys
2014-01-15 11:00:29 ----A---- C:\windows\system32\drivers\usbd.sys
2014-01-15 11:00:29 ----A---- C:\windows\system32\drivers\usbccgp.sys
2014-01-15 11:00:28 ----A---- C:\windows\system32\win32k.sys
2014-01-15 11:00:28 ----A---- C:\windows\system32\drivers\netio.sys
2014-01-15 10:49:08 ----D---- C:\Program Files\AMD
2014-01-15 10:46:40 ----A---- C:\windows\system32\drivers\AtihdW76.sys
2014-01-15 10:46:40 ----A---- C:\windows\system32\DelayAPO.dll
2014-01-15 10:46:39 ----A---- C:\windows\system32\clinfo.exe
2014-01-15 10:46:38 ----A---- C:\windows\SYSWOW64\OpenCL.dll
2014-01-15 10:46:38 ----A---- C:\windows\system32\OpenCL.dll
2014-01-15 01:14:33 ----D---- C:\ProgramData\AMD
2014-01-13 21:35:15 ----DC---- C:\Thief - Deadly Shadows
2014-01-12 20:02:13 ----D---- C:\windows\DA909E623B454BA18B58FCAEBA4BCEC9.TMP
2014-01-09 20:17:35 ----D---- C:\Program Files (x86)\MSI Afterburner
2014-01-09 18:45:05 ----D---- C:\Program Files (x86)\MSI Kombustor 2.5
2014-01-09 12:19:32 ----A---- C:\windows\system32\drivers\amd_xata.sys
2014-01-09 12:19:31 ----A---- C:\windows\system32\drivers\amd_sata.sys
2014-01-09 03:07:37 ----D---- C:\ProgramData\Futuremark
2014-01-09 02:46:48 ----D---- C:\Program Files (x86)\Futuremark
2014-01-09 02:44:37 ----D---- C:\Program Files\Futuremark
2014-01-04 22:08:34 ----D---- C:\ProgramData\Uniblue
2014-01-04 18:03:54 ----D---- C:\Program Files (x86)\AMD
2014-01-04 13:41:25 ----D---- C:\Program Files (x86)\Driver Fusion
2014-01-03 14:58:00 ----SHD---- C:\windows\SYSWOW64\AI_RecycleBin
2014-01-03 14:57:58 ----H---- C:\Program Files (x86)\d22df7db.tmp
2014-01-03 14:57:19 ----D---- C:\Users\Michal Skopik\AppData\Roaming\Downloaded Installations
2014-01-01 21:53:39 ----D---- C:\Program Files (x86)\Viva Media
2014-01-01 21:45:15 ----D---- C:\Program Files (x86)\FutureGames
2014-01-01 20:20:56 ----D---- C:\windows\64467D47FFE44FBCABBAA0DB829A17EB.TMP
2014-01-01 19:10:52 ----D---- C:\Program Files (x86)\Hitman Absolution

======List of files/folders modified in the last 1 month======

2014-01-27 22:56:47 ----D---- C:\windows\Temp
2014-01-27 22:44:49 ----D---- C:\windows\Prefetch
2014-01-27 22:39:26 ----D---- C:\Windows
2014-01-27 20:25:47 ----RD---- C:\Program Files (x86)
2014-01-27 20:24:39 ----HD---- C:\ProgramData
2014-01-27 20:19:19 ----D---- C:\Program Files (x86)\Common Files
2014-01-27 20:13:42 ----SHD---- C:\windows\Installer
2014-01-27 20:13:42 ----SHD---- C:\Config.Msi
2014-01-27 20:12:06 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-01-27 20:07:04 ----RD---- C:\Program Files
2014-01-27 12:52:16 ----D---- C:\windows\system32\config
2014-01-27 12:46:58 ----D---- C:\windows\System32
2014-01-27 12:46:58 ----A---- C:\windows\system32\PerfStringBackup.INI
2014-01-27 12:46:57 ----D---- C:\windows\inf
2014-01-27 12:41:57 ----D---- C:\windows\system32\Tasks
2014-01-27 12:41:46 ----D---- C:\windows\registration
2014-01-27 12:38:44 ----D---- C:\windows\system32\drivers
2014-01-27 12:23:51 ----D---- C:\windows\system32\LogFiles
2014-01-27 10:49:08 ----D---- C:\Program Files (x86)\Razer
2014-01-27 10:08:25 ----D---- C:\Users\Michal Skopik\AppData\Roaming\OpenTab
2014-01-27 01:12:30 ----SHD---- C:\System Volume Information
2014-01-26 20:52:16 ----A---- C:\windows\SYSWOW64\svchost.exe
2014-01-26 15:17:25 ----D---- C:\Program Files\The Witcher 2
2014-01-26 01:48:29 ----D---- C:\windows\winsxs
2014-01-26 01:15:48 ----D---- C:\windows\Tasks
2014-01-26 01:15:48 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2014-01-25 23:54:41 ----D---- C:\windows\SysWOW64
2014-01-25 17:09:02 ----D---- C:\Program Files (x86)\WarThunder
2014-01-25 14:23:33 ----D---- C:\Program Files (x86)\Steam
2014-01-25 14:23:32 ----D---- C:\windows\Logs
2014-01-24 14:55:43 ----D---- C:\windows\SYSWOW64\directx
2014-01-24 14:55:38 ----HD---- C:\windows\msdownld.tmp
2014-01-24 14:55:34 ----D---- C:\Games
2014-01-24 14:24:58 ----D---- C:\Users\Michal Skopik\AppData\Roaming\DAEMON Tools Lite
2014-01-24 00:21:34 ----D---- C:\Program Files (x86)\Little Inferno
2014-01-23 22:26:51 ----D---- C:\Program Files (x86)\Internet Explorer
2014-01-23 13:27:28 ----D---- C:\Program Files (x86)\Lucius
2014-01-23 00:48:44 ----D---- C:\Program Files (x86)\Deadly Premonition The Director's Cut
2014-01-21 09:31:31 ----D---- C:\windows\system32\catroot2
2014-01-20 22:35:09 ----RSD---- C:\windows\Fonts
2014-01-17 14:12:07 ----D---- C:\windows\debug
2014-01-16 00:30:41 ----D---- C:\Users\Michal Skopik\AppData\Roaming\Wargaming.net
2014-01-15 14:33:13 ----D---- C:\windows\Microsoft.NET
2014-01-15 12:13:26 ----D---- C:\Users\Michal Skopik\AppData\Roaming\ATI
2014-01-15 12:05:41 ----D---- C:\windows\system32\catroot
2014-01-15 12:05:38 ----D---- C:\windows\system32\DriverStore
2014-01-15 12:01:15 ----DC---- C:\windows\system32\DRVSTORE
2014-01-15 12:01:11 ----D---- C:\Program Files\Common Files
2014-01-15 11:05:04 ----D---- C:\windows\system32\MRT
2014-01-15 11:01:33 ----A---- C:\windows\system32\MRT.exe
2014-01-13 21:33:31 ----D---- C:\Users\Michal Skopik\AppData\Roaming\Skype
2014-01-13 01:35:00 ----D---- C:\Users\Michal Skopik\AppData\Roaming\Games
2014-01-12 22:13:14 ----A---- C:\windows\SYSWOW64\PnkBstrB.exe
2014-01-09 12:22:01 ----D---- C:\ProgramData\Package Cache
2014-01-07 23:27:51 ----RSD---- C:\windows\assembly
2014-01-03 03:19:36 ----D---- C:\windows\SoftwareDistribution
2014-01-02 11:17:14 ----D---- C:\windows\system32\NDF
2014-01-01 21:55:33 ----A---- C:\windows\SYSWOW64\wrap_oal.dll
2014-01-01 21:55:33 ----A---- C:\windows\SYSWOW64\OpenAL32.dll
2014-01-01 21:55:33 ----A---- C:\windows\system32\wrap_oal.dll
2014-01-01 21:55:33 ----A---- C:\windows\system32\OpenAL32.dll
2014-01-01 21:34:15 ----D---- C:\Program Files (x86)\Iceberg Interactive
2014-01-01 17:32:30 ----D---- C:\ProgramData\DAEMON Tools Lite

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 amd_sata;amd_sata; C:\windows\system32\DRIVERS\amd_sata.sys [2013-06-28 82240]
R0 amd_xata;amd_xata; C:\windows\system32\DRIVERS\amd_xata.sys [2013-06-28 42304]
R0 aswRvrt;avast! Revert; C:\windows\system32\drivers\aswRvrt.sys [2014-01-26 65776]
R0 aswVmm;avast! VM Monitor; C:\windows\system32\drivers\aswVmm.sys [2014-01-26 207904]
R0 fbfmon;fbfmon; C:\windows\system32\drivers\fbfmon.sys [2011-10-19 57952]
R0 LHDmgr;LHDmgr; C:\windows\System32\DRIVERS\LhdX64.sys [2013-10-18 39008]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 aswRdr;aswRdr; \??\C:\windows\system32\drivers\aswRdr2.sys [2014-01-26 92544]
R1 aswSnx;aswSnx; \??\C:\windows\system32\drivers\aswSnx.sys [2014-01-26 1038072]
R1 aswSP;aswSP; \??\C:\windows\system32\drivers\aswSP.sys [2014-01-26 421704]
R1 BPntDrv;BPntDrv; C:\windows\system32\drivers\BPntDrv.sys [2011-10-19 13408]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 AODDriver4.2.0;AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2013-09-19 59648]
R2 aswMonFlt;aswMonFlt; \??\C:\windows\system32\drivers\aswMonFlt.sys [2014-01-26 78648]
R2 atksgt;atksgt; C:\windows\system32\DRIVERS\atksgt.sys [2012-06-13 88480]
R2 lirsgt;lirsgt; C:\windows\system32\DRIVERS\lirsgt.sys [2012-06-13 46400]
R2 RMCAST;@%SystemRoot%\system32\wshrm.dll,-102; C:\windows\system32\DRIVERS\RMCAST.sys [2010-11-21 146432]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\windows\system32\DRIVERS\AcpiVpc.sys [2011-10-19 29792]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2013-12-07 13207552]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2013-12-07 626176]
R3 aswStm;aswStm; \??\C:\windows\system32\drivers\aswStm.sys [2014-01-26 80184]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\windows\system32\drivers\AtihdW76.sys [2013-09-24 94208]
R3 clwvd;CyberLink WebCam Virtual Driver; C:\windows\system32\DRIVERS\clwvd.sys [2011-01-29 31088]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\windows\system32\DRIVERS\dtsoftbus01.sys [2013-12-20 283064]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2011-04-26 2852200]
R3 MBAMProtector;MBAMProtector; \??\C:\windows\system32\drivers\mbam.sys [2013-04-04 25928]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver; C:\windows\system32\DRIVERS\netr28x.sys [2013-02-25 2426672]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUVStor.sys [2010-11-30 307304]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 SPUVCbv;SPUVCb Driver Service; C:\windows\System32\Drivers\usbvideo.sys [2013-07-12 185344]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2010-12-22 1407024]
R3 usbfilter;AMD USB Filter Driver; C:\windows\system32\DRIVERS\usbfilter.sys [2011-08-17 53376]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S0 sptd;sptd; C:\windows\system32\drivers\sptd.sys []
S2 athsgt;athsgt; C:\windows\system32\DRIVERS\athsgt.sys []
S2 ithsgt;ithsgt; C:\windows\system32\DRIVERS\ithsgt.sys []
S2 lilsgt;lilsgt; C:\windows\system32\DRIVERS\lilsgt.sys []
S2 limsgt;limsgt; C:\windows\system32\DRIVERS\limsgt.sys []
S3 amdiox64;AMD IO Driver; C:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
S3 atillk64;atillk64; \??\C:\Program Files (x86)\AMD\System Monitor\atillk64.sys []
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 BTWAMPFL;btwampfl; C:\windows\system32\DRIVERS\btwampfl.sys [2011-01-13 349736]
S3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2011-01-13 106536]
S3 btwavdt;Bluetooth AVDT; C:\windows\system32\drivers\btwavdt.sys [2011-01-13 138280]
S3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2011-01-13 39464]
S3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2011-01-13 21416]
S3 cpuz130;cpuz130; \??\C:\Users\MICHAL~1\AppData\Local\Temp\cpuz130\cpuz_x64.sys []
S3 EagleX64;EagleX64; \??\C:\windows\system32\drivers\EagleX64.sys []
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files (x86)\Garena Plus\Room\safedrv.sys []
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%; C:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\windows\system32\DRIVERS\VBoxNetAdp.sys [2012-04-12 147248]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service; C:\windows\system32\DRIVERS\VBoxNetFlt.sys []
S3 wdmirror;wdmirror; C:\windows\system32\DRIVERS\WDMirror.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2013-10-10 144152]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-18 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2013-12-07 239616]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-12-06 344064]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\windows\system32\svchost.exe [2009-07-14 27136]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-01-26 50344]
R2 btwdins;Bluetooth Service; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [2011-01-13 956192]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376]
R2 NetPipeActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
R2 NetTcpActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
R2 PnkBstrA;PnkBstrA; C:\windows\syswow64\PnkBstrA.exe [2013-10-05 76888]
R2 RaMediaServer;Ralink UPnP Media Server; C:\Program Files (x86)\Ralink\RT2860 Wireless LAN Card\ExtraFiles\RaMediaServer.exe [2010-05-19 454656]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2013-08-14 39056]
R2 simptcp;@%SystemRoot%\system32\simptcp.dll,-200; C:\windows\System32\tcpsvcs.exe [2009-07-14 10240]
R2 W3SVC;@%windir%\system32\inetsrv\iisres.dll,-30003; C:\windows\system32\svchost.exe [2009-07-14 27136]
R3 WAS;@%windir%\system32\inetsrv\iisres.dll,-30001; C:\windows\system32\svchost.exe [2009-07-14 27136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-09-05 171680]
S3 aspnet_state;Stavová služba ASP.NET; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2013-11-26 111616]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-12-20 119408]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-01-07 569768]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2011-11-29 1255736]
S4 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe []
S4 NetMsmqActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Mikaj08
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 26 led 2014 04:41

Re: Problém s virem Win32.expiro-U / Vitro

#5 Příspěvek od Mikaj08 »

Tady Avast, doufam ze to je ten spravny:

avast! Antirootkit, version 1.0
Scan started: 27. leden 2014 12:50:05

Process [0]
Process [4]
Process C:\Windows\System32\smss.exe [348]
Process C:\Windows\System32\csrss.exe [516]
Process C:\Windows\System32\wininit.exe [620]
Process C:\Windows\System32\csrss.exe [636]
Process C:\Windows\System32\services.exe [676]
Process C:\Windows\System32\lsass.exe [692]
Process C:\Windows\System32\lsm.exe [700]
Process C:\Windows\System32\winlogon.exe [780]
Process C:\Windows\System32\svchost.exe [880]
Process C:\Windows\System32\svchost.exe [976]
Process C:\Windows\System32\atiesrxx.exe [116]
Process C:\Windows\System32\svchost.exe [448]
Process C:\Windows\System32\svchost.exe [528]
Process C:\Windows\System32\svchost.exe [668]
Process C:\Windows\System32\svchost.exe [800]
Process C:\Windows\System32\svchost.exe [1088]
Process C:\Windows\System32\atieclxx.exe [1224]
Process C:\Windows\System32\svchost.exe [1232]
Process C:\Program Files\AVAST Software\Avast\AvastSvc.exe [1388]
Process C:\Windows\System32\spoolsv.exe [1636]
Process C:\Windows\System32\svchost.exe [1672]
Process C:\Program Files\SUPERAntiSpyware\SASCore64.exe [1760]
Process C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [1784]
Process C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [1872]
Process C:\Windows\System32\svchost.exe [1992]
Process C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [2016]
Process C:\Windows\System32\dllhost.exe [1048]
Process C:\Windows\System32\msiexec.exe [1328]
Process C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [1900]
Process C:\Windows\System32\taskhost.exe [2256]
Process C:\Windows\System32\taskeng.exe [2280]
Process C:\Windows\System32\dwm.exe [2312]
Process C:\Windows\System32\taskeng.exe [2388]
Process C:\Windows\explorer.exe [2488]
Process C:\Windows\SysWOW64\rundll32.exe [2500]
Process C:\Windows\System32\dllhost.exe [2648]
Process C:\Windows\SysWOW64\PnkBstrA.exe [2844]
Process C:\Program Files (x86)\Ralink\RT2860 Wireless LAN Card\ExtraFiles\RaMediaServer.exe [2872]
Process C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2904]
Process C:\Windows\System32\TCPSVCS.EXE [2928]
Process C:\Windows\System32\svchost.exe [2980]
Process C:\Windows\System32\svchost.exe [3048]
Process C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [1552]
Process C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE [2352]
Process C:\Windows\System32\alg.exe [3240]
Process C:\Windows\System32\svchost.exe [3460]
Process C:\Windows\System32\svchost.exe [3564]
Process C:\Windows\servicing\TrustedInstaller.exe [3612]
Process C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [3884]
Process C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [3304]
Process C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [3864]
Process C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [3792]
Process C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe [3780]
Process C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [1880]
Process C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe [488]
Process C:\Program Files\AVAST Software\Avast\AvastUI.exe [3688]
Process C:\Windows\System32\SearchIndexer.exe [3772]
Process C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe [4536]
Process C:\Windows\System32\wbem\WmiPrvSE.exe [4808]
Process C:\Windows\System32\svchost.exe [1768]
Process C:\Windows\System32\SearchProtocolHost.exe [4876]
Process C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe [5096]
Process C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [3932]
Process C:\Windows\notepad.exe [4412]
Process C:\Windows\System32\audiodg.exe [1380]
Disk 0 MBR
Service !SASCORE [C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE]
Service .NET CLR Data [???]
Service .NET CLR Networking [???]
Service .NET CLR Networking 4.0.0.0 [???]
Service .NET Data Provider for Oracle [???]
Service .NET Data Provider for SqlServer [???]
Service .NET Memory Cache 4.0 [???]
Service .NETFramework [???]
Service 1394ohci [C:\windows\system32\drivers\1394ohci.sys]
Service ACPI [C:\windows\system32\drivers\ACPI.sys]
Service AcpiPmi [C:\windows\system32\drivers\acpipmi.sys]
Service ACPIVPC [C:\windows\system32\DRIVERS\AcpiVpc.sys]
Service AdobeARMservice [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe]
Service adp94xx [C:\windows\system32\drivers\adp94xx.sys]
Service adpahci [C:\windows\system32\drivers\adpahci.sys]
Service adpu320 [C:\windows\system32\drivers\adpu320.sys]
Service adsi [???]
Service AeLookupSvc [C:\windows\System32\aelupsvc.dll]
Service AFD [C:\windows\system32\drivers\afd.sys]
Service agp440 [C:\windows\system32\drivers\agp440.sys]
Service ALG [C:\windows\System32\alg.exe]
Service aliide [C:\windows\system32\drivers\aliide.sys]
Service AMD External Events Utility [C:\windows\system32\atiesrxx.exe]
Service AMD FUEL Service [C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe]
Service amdide [C:\windows\system32\drivers\amdide.sys]
Service amdiox64 [C:\windows\system32\DRIVERS\amdiox64.sys]
Service AmdK8 [C:\windows\system32\drivers\amdk8.sys]
Service amdkmdag [C:\windows\system32\DRIVERS\atikmdag.sys]
Service amdkmdap [C:\windows\system32\DRIVERS\atikmpag.sys]
Service AmdPPM [C:\windows\system32\DRIVERS\amdppm.sys]
Service amdsata [C:\windows\system32\DRIVERS\amdsata.sys]
Service amdsbs [C:\windows\system32\drivers\amdsbs.sys]
Service amdxata [C:\windows\system32\drivers\amdxata.sys]
Service amd_sata [C:\windows\system32\DRIVERS\amd_sata.sys]
Service amd_xata [C:\windows\system32\DRIVERS\amd_xata.sys]
Service AODDriver4.2.0 [C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys]
Service AppHostSvc [C:\windows\system32\inetsrv\apphostsvc.dll]
Service AppID [C:\windows\system32\drivers\appid.sys]
Service AppIDSvc [C:\windows\System32\appidsvc.dll]
Service Appinfo [C:\windows\System32\appinfo.dll]
Service arc [C:\windows\system32\drivers\arc.sys]
Service arcsas [C:\windows\system32\drivers\arcsas.sys]
Service ASP.NET [???]
Service ASP.NET_4.0.30319 [???]
Service aspnet_state [C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe]
Service aswMonFlt [C:\windows\system32\drivers\aswMonFlt.sys]
Service aswRdr [C:\windows\system32\drivers\aswRdr2.sys]
Service aswRvrt [C:\windows\System32\Drivers\aswRvrt.sys]
Service aswSnx [C:\windows\system32\drivers\aswSnx.sys]
Service aswSP [C:\windows\system32\drivers\aswSP.sys]
Service aswStm [C:\windows\system32\drivers\aswStm.sys]
Service aswVmm [C:\windows\System32\Drivers\aswVmm.sys]
Service AsyncMac [C:\windows\system32\DRIVERS\asyncmac.sys]
Service atapi [C:\windows\system32\drivers\atapi.sys]
Service athsgt [C:\windows\system32\DRIVERS\athsgt.sys]
Service Atierecord [???]
Service AtiHDAudioService [C:\windows\system32\drivers\AtihdW76.sys]
Service atillk64 [C:\Program Files (x86)\AMD\System Monitor\atillk64.sys]
Service atksgt [C:\windows\system32\DRIVERS\atksgt.sys]
Service AudioEndpointBuilder [C:\windows\System32\Audiosrv.dll]
Service AudioSrv [C:\windows\System32\Audiosrv.dll]
Service avast! Antivirus [C:\Program Files\AVAST Software\Avast\AvastSvc.exe]
Service avg8emc [???]
Service AxInstSV [C:\windows\System32\AxInstSV.dll]
Service b06bdrv [C:\windows\system32\drivers\bxvbda.sys]
Service b57nd60a [C:\windows\system32\DRIVERS\b57nd60a.sys]
Service BattC [???]
Service BcmSqlStartupSvc [???]
Service BDESVC [C:\windows\System32\bdesvc.dll]
Service Beep [C:\windows\System32\Drivers\Beep.sys]
Service BFE [C:\windows\System32\bfe.dll]
Service BITS [C:\windows\System32\qmgr.dll]
Service blbdrive [C:\windows\system32\DRIVERS\blbdrive.sys]
Service bowser [C:\windows\system32\DRIVERS\bowser.sys]
Service BPntDrv [C:\windows\system32\drivers\BPntDrv.sys]
Service BrFiltLo [C:\windows\system32\drivers\BrFiltLo.sys]
Service BrFiltUp [C:\windows\system32\drivers\BrFiltUp.sys]
Service Browser [C:\windows\System32\browser.dll]
Service Brserid [C:\windows\System32\Drivers\Brserid.sys]
Service BrSerWdm [C:\windows\System32\Drivers\BrSerWdm.sys]
Service BrUsbMdm [C:\windows\System32\Drivers\BrUsbMdm.sys]
Service BrUsbSer [C:\windows\System32\Drivers\BrUsbSer.sys]
Service BthEnum [C:\windows\system32\drivers\BthEnum.sys]
Service BTHMODEM [C:\windows\system32\drivers\bthmodem.sys]
Service BthPan [C:\windows\system32\DRIVERS\bthpan.sys]
Service BTHPORT [C:\windows\System32\Drivers\BTHport.sys]
Service bthserv [C:\windows\system32\bthserv.dll]
Service BTHUSB [C:\windows\System32\Drivers\BTHUSB.sys]
Service BTWAMPFL [C:\windows\system32\DRIVERS\btwampfl.sys]
Service btwaudio [C:\windows\system32\drivers\btwaudio.sys]
Service btwavdt [C:\windows\system32\drivers\btwavdt.sys]
Service btwdins [C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe]
Service btwl2cap [C:\windows\system32\DRIVERS\btwl2cap.sys]
Service btwrchid [C:\windows\system32\DRIVERS\btwrchid.sys]
Service Cam5603D [???]
Service Cam5607 [???]
Service cdfs [C:\windows\system32\DRIVERS\cdfs.sys]
Service cdrom [C:\windows\system32\DRIVERS\cdrom.sys]
Service CertPropSvc [C:\windows\System32\certprop.dll]
Service circlass [C:\windows\system32\drivers\circlass.sys]
Service CLFS [C:\windows\System32\CLFS.sys]
Service CLKMSVC10_3A60B698 [???]
Service CLKMSVC10_C3B3B687 [???]
Service clr_optimization_v2.0.50727_32 [C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe]
Service clr_optimization_v2.0.50727_64 [C:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe]
Service clr_optimization_v4.0.30319_32 [C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe]
Service clr_optimization_v4.0.30319_64 [C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe]
Service clwvd [C:\windows\system32\DRIVERS\clwvd.sys]
Service CmBatt [C:\windows\system32\DRIVERS\CmBatt.sys]
Service cmdide [C:\windows\system32\drivers\cmdide.sys]
Service CNG [C:\windows\System32\Drivers\cng.sys]
Service Compbatt [C:\windows\system32\drivers\compbatt.sys]
Service CompositeBus [C:\windows\system32\DRIVERS\CompositeBus.sys]
Service COMSysApp [C:\windows\system32\dllhost.exe]
Service cpuz130 [C:\Users\MICHAL~1\AppData\Local\Temp\cpuz130\cpuz_x64.sys]
Service crcdisk [C:\windows\system32\drivers\crcdisk.sys]
Service crypt32 [???]
Service CryptSvc [C:\windows\system32\cryptsvc.dll]
Service DCLocator [???]
Service DcomLaunch [C:\windows\system32\rpcss.dll]
Service defragsvc [C:\windows\System32\defragsvc.dll]
Service DfsC [C:\windows\System32\Drivers\dfsc.sys]
Service Dhcp [C:\windows\system32\dhcpcore.dll]
Service discache [C:\windows\System32\drivers\discache.sys]
Service Disk [C:\windows\system32\drivers\disk.sys]
Service Dnscache [C:\windows\System32\dnsrslvr.dll]
Service dot3svc [C:\windows\System32\dot3svc.dll]
Service DPS [C:\windows\system32\dps.dll]
Service DriverService [???]
Service drmkaud [C:\windows\system32\drivers\drmkaud.sys]
Service dtsoftbus01 [C:\windows\system32\DRIVERS\dtsoftbus01.sys]
Service DXGKrnl [C:\windows\System32\drivers\dxgkrnl.sys]
Service EagleX64 [C:\windows\system32\drivers\EagleX64.sys]
Service EapHost [C:\windows\System32\eapsvc.dll]
Service ebdrv [C:\windows\system32\drivers\evbda.sys]
Service EFS [C:\windows\System32\lsass.exe]
Service ehRecvr [C:\windows\ehome\ehRecvr.exe]
Service ehSched [C:\windows\ehome\ehsched.exe]
Service elxstor [C:\windows\system32\drivers\elxstor.sys]
Service ErrDev [C:\windows\system32\drivers\errdev.sys]
Service ESENT [???]
Service eventlog [C:\windows\System32\wevtsvc.dll]
Service EventSystem [C:\windows\system32\es.dll]
Service exfat [C:\windows\System32\Drivers\exfat.sys]
Service fastfat [C:\windows\System32\Drivers\fastfat.sys]
Service Fax [C:\windows\system32\fxssvc.exe]
Service fbfmon [C:\windows\system32\drivers\fbfmon.sys]
Service fdc [C:\windows\system32\drivers\fdc.sys]
Service fdPHost [C:\windows\system32\fdPHost.dll]
Service FDResPub [C:\windows\system32\fdrespub.dll]
Service FileInfo [C:\windows\system32\drivers\fileinfo.sys]
Service Filetrace [C:\windows\system32\drivers\filetrace.sys]
Service flpydisk [C:\windows\system32\drivers\flpydisk.sys]
Service FltMgr [C:\windows\system32\drivers\fltmgr.sys]
Service FontCache [C:\windows\system32\FntCache.dll]
Service FontCache3.0.0.0 [C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe]
Service FsDepends [C:\windows\System32\drivers\FsDepends.sys]
Service Fs_Rec [C:\windows\System32\Drivers\Fs_Rec.sys]
Service Futuremark SystemInfo Service [C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe]
Service fvevol [C:\windows\System32\DRIVERS\fvevol.sys]
Service gagp30kx [C:\windows\system32\drivers\gagp30kx.sys]
Service GGSAFERDriver [C:\Program Files (x86)\Garena Plus\Room\safedrv.sys]
Service gpsvc [C:\windows\System32\gpsvc.dll]
Service hcw85cir [C:\windows\system32\drivers\hcw85cir.sys]
Service HdAudAddService [C:\windows\system32\drivers\HdAudio.sys]
Service HDAudBus [C:\windows\system32\DRIVERS\HDAudBus.sys]
Service HidBatt [C:\windows\system32\drivers\HidBatt.sys]
Service HidBth [C:\windows\system32\drivers\hidbth.sys]
Service HidIr [C:\windows\system32\drivers\hidir.sys]
Service hidserv [C:\windows\system32\hidserv.dll]
Service HidUsb [C:\windows\system32\drivers\hidusb.sys]
Service hkmsvc [C:\windows\system32\kmsvc.dll]
Service HomeGroupListener [C:\windows\system32\ListSvc.dll]
Service HomeGroupProvider [C:\windows\system32\provsvc.dll]
Service HpSAMD [C:\windows\system32\drivers\HpSAMD.sys]
Service HTTP [C:\windows\system32\drivers\HTTP.sys]
Service hwpolicy [C:\windows\System32\drivers\hwpolicy.sys]
Service i8042prt [C:\windows\system32\DRIVERS\i8042prt.sys]
Service IAStorDataMgrSvc [???]
Service iaStorV [C:\windows\system32\drivers\iaStorV.sys]
Service iATAgentService [???]
Service idealife Update Service [???]
File C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe **INFECTED** Win32:Evo-gen [Susp]
Service IDriverT [C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe] **HIDDEN**
Service idsvc [C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe]
Service IEEtwCollectorService [C:\windows\system32\IEEtwCollector.exe]
Service iirsp [C:\windows\system32\drivers\iirsp.sys]
Service IKEEXT [C:\windows\System32\ikeext.dll]
Service inetaccs [???]
Service InetInfo [???]
Service IntcAzAudAddService [C:\windows\system32\drivers\RTKVHD64.sys]
Service intelide [C:\windows\system32\drivers\intelide.sys]
Service intelppm [C:\windows\system32\drivers\intelppm.sys]
Service IPBusEnum [C:\windows\system32\ipbusenum.dll]
Service IpFilterDriver [C:\windows\system32\DRIVERS\ipfltdrv.sys]
Service iphlpsvc [C:\windows\System32\iphlpsvc.dll]
Service IPMIDRV [C:\windows\system32\drivers\IPMIDrv.sys]
Service IPNAT [C:\windows\System32\drivers\ipnat.sys]
Service IRENUM [C:\windows\system32\drivers\irenum.sys]
Service isapnp [C:\windows\system32\drivers\isapnp.sys]
Service iScsiPrt [C:\windows\system32\drivers\msiscsi.sys]
Service ithsgt [C:\windows\system32\DRIVERS\ithsgt.sys]
Service IviRegMgr [???]
Service kbdclass [C:\windows\system32\DRIVERS\kbdclass.sys]
Service kbdhid [C:\windows\system32\drivers\kbdhid.sys]
Service KeyIso [C:\windows\system32\lsass.exe]
Service KSecDD [C:\windows\System32\Drivers\ksecdd.sys]
Service KSecPkg [C:\windows\System32\Drivers\ksecpkg.sys]
Service ksthunk [C:\windows\system32\drivers\ksthunk.sys]
Service KtmRm [C:\windows\system32\msdtckrm.dll]
Service LanmanServer [C:\windows\system32\srvsvc.dll]
Service LanmanWorkstation [C:\windows\System32\wkssvc.dll]
Service ldap [???]
Service LHDmgr [C:\windows\System32\DRIVERS\LhdX64.sys]
Service lilsgt [C:\windows\system32\DRIVERS\lilsgt.sys]
Service limsgt [C:\windows\system32\DRIVERS\limsgt.sys]
Service lirsgt [C:\windows\system32\DRIVERS\lirsgt.sys]
Service lltdio [C:\windows\system32\DRIVERS\lltdio.sys]
Service lltdsvc [C:\windows\System32\lltdsvc.dll]
Service lmhosts [C:\windows\System32\lmhsvc.dll]
Service Lsa [???]
Service LSI_FC [C:\windows\system32\drivers\lsi_fc.sys]
Service LSI_SAS [C:\windows\system32\drivers\lsi_sas.sys]
Service LSI_SAS2 [C:\windows\system32\drivers\lsi_sas2.sys]
Service LSI_SCSI [C:\windows\system32\drivers\lsi_scsi.sys]
Service luafv [C:\windows\system32\drivers\luafv.sys]
Service MBAMProtector [C:\windows\system32\drivers\mbam.sys]
Service MBAMScheduler [C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe]
Service MBAMService [C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe]
Service Mcx2Svc [C:\windows\system32\Mcx2Svc.dll]
Service megasas [C:\windows\system32\drivers\megasas.sys]
Service MegaSR [C:\windows\system32\drivers\MegaSR.sys]
Service MMCSS [C:\windows\system32\mmcss.dll]
Service Modem [C:\windows\system32\drivers\modem.sys]
Service monitor [C:\windows\system32\DRIVERS\monitor.sys]
Service mouclass [C:\windows\system32\DRIVERS\mouclass.sys]
Service mouhid [C:\windows\system32\DRIVERS\mouhid.sys]
Service mountmgr [C:\windows\System32\drivers\mountmgr.sys]
Service MozillaMaintenance [C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe]
Service mpio [C:\windows\system32\drivers\mpio.sys]
Service mpsdrv [C:\windows\System32\drivers\mpsdrv.sys]
Service MpsSvc [C:\windows\system32\mpssvc.dll]
Service MRxDAV [C:\windows\system32\drivers\mrxdav.sys]
Service mrxsmb [C:\windows\system32\DRIVERS\mrxsmb.sys]
Service mrxsmb10 [C:\windows\system32\DRIVERS\mrxsmb10.sys]
Service mrxsmb20 [C:\windows\system32\DRIVERS\mrxsmb20.sys]
Service msahci [C:\windows\system32\drivers\msahci.sys]
Service msdsm [C:\windows\system32\drivers\msdsm.sys]
Service MSDTC [C:\windows\System32\msdtc.exe]
Service MSDTC Bridge 3.0.0.0 [???]
Service MSDTC Bridge 4.0.0.0 [???]
Service Msfs [C:\windows\System32\Drivers\Msfs.sys]
Service mshidkmdf [C:\windows\System32\drivers\mshidkmdf.sys]
Service msisadrv [C:\windows\system32\drivers\msisadrv.sys]
Service MSiSCSI [C:\windows\system32\iscsiexe.dll]
Service msiserver [C:\windows\system32\msiexec.exe]
Service MSKSSRV [C:\windows\system32\drivers\MSKSSRV.sys]
Service MSPCLOCK [C:\windows\system32\drivers\MSPCLOCK.sys]
Service MSPQM [C:\windows\system32\drivers\MSPQM.sys]
Service MsRPC [C:\windows\System32\Drivers\MsRPC.sys]
Service MSSCNTRS [???]
Service mssmbios [C:\windows\system32\DRIVERS\mssmbios.sys]
Service MSTEE [C:\windows\system32\drivers\MSTEE.sys]
Service MTConfig [C:\windows\system32\drivers\MTConfig.sys]
Service Mup [C:\windows\System32\Drivers\mup.sys]
Service napagent [C:\windows\system32\qagentRT.dll]
Service NativeWifiP [C:\windows\system32\DRIVERS\nwifi.sys]
Service NDIS [C:\windows\system32\drivers\ndis.sys]
Service NdisCap [C:\windows\system32\DRIVERS\ndiscap.sys]
Service NdisTapi [C:\windows\system32\DRIVERS\ndistapi.sys]
Service Ndisuio [C:\windows\system32\DRIVERS\ndisuio.sys]
Service NdisWan [C:\windows\system32\DRIVERS\ndiswan.sys]
Service NDProxy [C:\windows\System32\Drivers\NDProxy.sys]
Service NetBIOS [C:\windows\system32\DRIVERS\netbios.sys]
Service NetBT [C:\windows\System32\DRIVERS\netbt.sys]
Service Netlogon [C:\windows\system32\lsass.exe]
Service Netman [C:\windows\System32\netman.dll]
Service NetMsmqActivator [C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe]
Service NetPipeActivator [C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe]
Service netprofm [C:\windows\System32\netprofm.dll]
Service netr28x [C:\windows\system32\DRIVERS\netr28x.sys]
Service NetTcpActivator [C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe]
Service NetTcpPortSharing [C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe]
Service nfrd960 [C:\windows\system32\drivers\nfrd960.sys]
Service NlaSvc [C:\windows\System32\nlasvc.dll]
Service Npfs [C:\windows\System32\Drivers\Npfs.sys]
Service nsi [C:\windows\system32\nsisvc.dll]
Service nsiproxy [C:\windows\system32\drivers\nsiproxy.sys]
Service NTDS [???]
Service Ntfs [C:\windows\System32\Drivers\Ntfs.sys]
Service Null [C:\windows\System32\Drivers\Null.sys]
Service nvraid [C:\windows\system32\drivers\nvraid.sys]
Service nvstor [C:\windows\system32\drivers\nvstor.sys]
Service nvUpdatusService [???]
Service nv_agp [C:\windows\system32\drivers\nv_agp.sys]
Service Oasis2Service [???]
Service ohci1394 [C:\windows\system32\drivers\ohci1394.sys]
Service ose [C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE]
Service p2pimsvc [C:\windows\system32\pnrpsvc.dll]
Service p2psvc [C:\windows\system32\p2psvc.dll]
Service Parport [C:\windows\system32\drivers\parport.sys]
Service partmgr [C:\windows\System32\drivers\partmgr.sys]
Service PcaSvc [C:\windows\System32\pcasvc.dll]
Service PCCarerService [???]
Service pci [C:\windows\system32\drivers\pci.sys]
Service pciide [C:\windows\system32\drivers\pciide.sys]
Service pcmcia [C:\windows\system32\drivers\pcmcia.sys]
Service pcw [C:\windows\System32\drivers\pcw.sys]
Service PEAUTH [C:\windows\system32\drivers\peauth.sys]
Service PerfDisk [???]
Service PerfHost [C:\windows\SysWow64\perfhost.exe]
Service PerfNet [???]
Service PerfOS [???]
Service PerfProc [???]
Service pla [C:\windows\system32\pla.dll]
Service PlugPlay [C:\windows\system32\umpnpmgr.dll]
Service PnkBstrA [C:\windows\system32\PnkBstrA.exe]
Service PNRPAutoReg [C:\windows\system32\pnrpauto.dll]
Service PNRPsvc [C:\windows\system32\pnrpsvc.dll]
Service PolicyAgent [C:\windows\System32\ipsecsvc.dll]
Service PortProxy [???]
Service Power [C:\windows\system32\umpo.dll]
Service PptpMiniport [C:\windows\system32\DRIVERS\raspptp.sys]
Service Processor [C:\windows\system32\drivers\processr.sys]
Service ProfSvc [C:\windows\system32\profsvc.dll]
Service ProtectedStorage [C:\windows\system32\lsass.exe]
Service Psched [C:\windows\system32\DRIVERS\pacer.sys]
Service ql2300 [C:\windows\system32\drivers\ql2300.sys]
Service ql40xx [C:\windows\system32\drivers\ql40xx.sys]
Service QWAVE [C:\windows\system32\qwave.dll]
Service QWAVEdrv [C:\windows\system32\drivers\qwavedrv.sys]
Service RaMediaServer [C:\Program Files (x86)\Ralink\RT2860 Wireless LAN Card\ExtraFiles\RaMediaServer.exe]
Service RasAcd [C:\windows\System32\DRIVERS\rasacd.sys]
Service RasAgileVpn [C:\windows\system32\DRIVERS\AgileVpn.sys]
Service RasAuto [C:\windows\System32\rasauto.dll]
Service Rasl2tp [C:\windows\system32\DRIVERS\rasl2tp.sys]
Service RasMan [C:\windows\System32\rasmans.dll]
Service RasPppoe [C:\windows\system32\DRIVERS\raspppoe.sys]
Service RasSstp [C:\windows\system32\DRIVERS\rassstp.sys]
Service rdbss [C:\windows\system32\DRIVERS\rdbss.sys]
Service rdpbus [C:\windows\system32\drivers\rdpbus.sys]
Service RDPCDD [C:\windows\System32\DRIVERS\RDPCDD.sys]
Service RDPDD [???]
Service RDPENCDD [C:\windows\system32\drivers\rdpencdd.sys]
Service RDPNP [???]
Service RDPREFMP [C:\windows\system32\drivers\rdprefmp.sys]
Service RDPWD [C:\windows\System32\Drivers\RDPWD.sys]
Service rdyboost [C:\windows\System32\drivers\rdyboost.sys]
Service RealNetworks Downloader Resolver Service [C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe]
Service RemoteAccess [C:\windows\System32\mprdim.dll]
Service RemoteRegistry [C:\windows\system32\regsvc.dll]
Service RFCOMM [C:\windows\system32\DRIVERS\rfcomm.sys]
Service RichVideo [???]
Service RMCAST [C:\windows\system32\DRIVERS\RMCAST.sys]
Service RpcEptMapper [C:\windows\System32\RpcEpMap.dll]
Service RpcLocator [C:\windows\system32\locator.exe]
Service RpcSs [C:\windows\system32\rpcss.dll]
Service rspndr [C:\windows\system32\DRIVERS\rspndr.sys]
Service RSUSBVSTOR [C:\windows\System32\Drivers\RtsUVStor.sys]
Service RTL8167 [C:\windows\system32\DRIVERS\Rt64win7.sys]
Service RtLedService [???]
Service SamSs [C:\windows\system32\lsass.exe]
Service SASDIFSV [C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS]
Service SASKUTIL [C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS]
Service sbp2port [C:\windows\system32\drivers\sbp2port.sys]
Service SCardSvr [C:\windows\System32\SCardSvr.dll]
Service scfilter [C:\windows\System32\DRIVERS\scfilter.sys]
Service Schedule [C:\windows\system32\schedsvc.dll]
Service SCPolicySvc [C:\windows\System32\certprop.dll]
Service SDRSVC [C:\windows\System32\SDRSVC.dll]
Service SecDrv [C:\windows\system32\drivers\SECDRV.SYS]
Service seclogon [C:\windows\system32\seclogon.dll]
Service SENS [C:\windows\System32\sens.dll]
Service SensrSvc [C:\windows\system32\sensrsvc.dll]
Service Serenum [C:\windows\system32\drivers\serenum.sys]
Service Serial [C:\windows\system32\drivers\serial.sys]
Service sermouse [C:\windows\system32\drivers\sermouse.sys]
Service ServiceModelEndpoint 3.0.0.0 [???]
Service ServiceModelOperation 3.0.0.0 [???]
Service ServiceModelService 3.0.0.0 [???]
Service SessionEnv [C:\windows\system32\sessenv.dll]
Service sffdisk [C:\windows\system32\drivers\sffdisk.sys]
Service sffp_mmc [C:\windows\system32\drivers\sffp_mmc.sys]
Service sffp_sd [C:\windows\system32\drivers\sffp_sd.sys]
Service sfloppy [C:\windows\system32\drivers\sfloppy.sys]
Service SharedAccess [C:\windows\System32\ipnathlp.dll]
Service ShellHWDetection [C:\windows\System32\shsvcs.dll]
Service simptcp [C:\windows\System32\tcpsvcs.exe]
Service SiSRaid2 [C:\windows\system32\drivers\SiSRaid2.sys]
Service SiSRaid4 [C:\windows\system32\drivers\sisraid4.sys]
Service SkypeUpdate [C:\Program Files (x86)\Skype\Updater\Updater.exe]
Service Smb [C:\windows\system32\DRIVERS\smb.sys]
Service SMSvcHost 3.0.0.0 [???]
Service SMSvcHost 4.0.0.0 [???]
Service SNMP [???]
Service SNMPTRAP [C:\windows\System32\snmptrap.exe]
Service SoftwareService [???]
Service spldr [C:\windows\System32\Drivers\spldr.sys]
Service Spooler [C:\windows\System32\spoolsv.exe]
Service sppsvc [C:\windows\system32\sppsvc.exe]
Service sppuinotify [C:\windows\system32\sppuinotify.dll]
Service sptd [C:\windows\System32\Drivers\sptd.sys]
Service SPUVCbv [C:\windows\System32\Drivers\usbvideo.sys]
Service SQLWriter [???]
Service srv [C:\windows\System32\DRIVERS\srv.sys]
Service srv2 [C:\windows\System32\DRIVERS\srv2.sys]
Service srvnet [C:\windows\System32\DRIVERS\srvnet.sys]
Service SSDPSRV [C:\windows\System32\ssdpsrv.dll]
Service SstpSvc [C:\windows\system32\sstpsvc.dll]
Service Steam Client Service [C:\Program Files (x86)\Common Files\Steam\SteamService.exe]
Service stexstor [C:\windows\system32\drivers\stexstor.sys]
Service stisvc [C:\windows\System32\wiaservc.dll]
Service swenum [C:\windows\system32\DRIVERS\swenum.sys]
Service swprv [C:\windows\System32\swprv.dll]
Service SynTP [C:\windows\system32\DRIVERS\SynTP.sys]
Service SysMain [C:\windows\system32\sysmain.dll]
Service TabletInputService [C:\windows\System32\TabSvc.dll]
Service TapiSrv [C:\windows\System32\tapisrv.dll]
Service TBS [C:\windows\System32\tbssvc.dll]
Service Tcpip [C:\windows\System32\drivers\tcpip.sys]
Service TCPIP6 [C:\windows\system32\DRIVERS\tcpip.sys]
Service TCPIP6TUNNEL [???]
Service tcpipreg [C:\windows\System32\drivers\tcpipreg.sys]
Service TCPIPTUNNEL [???]
Service TDPIPE [C:\windows\system32\drivers\tdpipe.sys]
Service TDTCP [C:\windows\system32\drivers\tdtcp.sys]
Service tdx [C:\windows\system32\DRIVERS\tdx.sys]
Service TermDD [C:\windows\system32\DRIVERS\termdd.sys]
Service TermService [C:\windows\System32\termsrv.dll]
Service Themes [C:\windows\system32\themeservice.dll]
Service THREADORDER [C:\windows\system32\mmcss.dll]
Service TrkWks [C:\windows\System32\trkwks.dll]
Service TrustedInstaller [C:\windows\servicing\TrustedInstaller.exe]
Service TSDDD [???]
Service tssecsrv [C:\windows\System32\DRIVERS\tssecsrv.sys]
Service TsUsbFlt [C:\windows\system32\drivers\tsusbflt.sys]
Service TsUsbGD [C:\windows\system32\drivers\TsUsbGD.sys]
Service tunnel [C:\windows\system32\DRIVERS\tunnel.sys]
Service uagp35 [C:\windows\system32\drivers\uagp35.sys]
Service udfs [C:\windows\system32\DRIVERS\udfs.sys]
Service UGatherer [???]
Service UGTHRSVC [???]
Service UI0Detect [C:\windows\system32\UI0Detect.exe]
Service uliagpkx [C:\windows\system32\drivers\uliagpkx.sys]
Service umbus [C:\windows\system32\DRIVERS\umbus.sys]
Service UmPass [C:\windows\system32\drivers\umpass.sys]
Service upnphost [C:\windows\System32\upnphost.dll]
Service usbccgp [C:\windows\system32\DRIVERS\usbccgp.sys]
Service usbcir [C:\windows\system32\drivers\usbcir.sys]
Service usbehci [C:\windows\system32\DRIVERS\usbehci.sys]
Service usbfilter [C:\windows\system32\DRIVERS\usbfilter.sys]
Service usbhub [C:\windows\system32\DRIVERS\usbhub.sys]
Service usbohci [C:\windows\system32\DRIVERS\usbohci.sys]
Service usbprint [C:\windows\system32\drivers\usbprint.sys]
Service USBSTOR [C:\windows\system32\DRIVERS\USBSTOR.SYS]
Service usbuhci [C:\windows\system32\drivers\usbuhci.sys]
Service usbvideo [C:\windows\System32\Drivers\usbvideo.sys]
Service UxSms [C:\windows\System32\uxsms.dll]
Service VaultSvc [C:\windows\system32\lsass.exe]
Service VBoxNetAdp [C:\windows\system32\DRIVERS\VBoxNetAdp.sys]
Service VBoxNetFlt [C:\windows\system32\DRIVERS\VBoxNetFlt.sys]
Service vdrvroot [C:\windows\system32\drivers\vdrvroot.sys]
Service vds [C:\windows\System32\vds.exe]
Service vga [C:\windows\system32\DRIVERS\vgapnp.sys]
Service VgaSave [C:\windows\System32\drivers\vga.sys]
Service vhdmp [C:\windows\system32\drivers\vhdmp.sys]
Service viaide [C:\windows\system32\drivers\viaide.sys]
Service volmgr [C:\windows\system32\drivers\volmgr.sys]
Service volmgrx [C:\windows\System32\drivers\volmgrx.sys]
Service volsnap [C:\windows\system32\drivers\volsnap.sys]
Service vsmraid [C:\windows\system32\drivers\vsmraid.sys]
Service VSS [C:\windows\system32\vssvc.exe]
Service vwifibus [C:\windows\system32\DRIVERS\vwifibus.sys]
Service vwififlt [C:\windows\system32\DRIVERS\vwififlt.sys]
Service vwifimp [C:\windows\system32\DRIVERS\vwifimp.sys]
Service W32Time [C:\windows\system32\w32time.dll]
Service W3SVC [C:\windows\system32\inetsrv\iisw3adm.dll]
Service WacomPen [C:\windows\system32\drivers\wacompen.sys]
Service WANARP [C:\windows\system32\DRIVERS\wanarp.sys]
Service Wanarpv6 [C:\windows\system32\DRIVERS\wanarp.sys]
Service WAS [C:\windows\system32\inetsrv\iisw3adm.dll]
Service WatAdminSvc [C:\windows\system32\Wat\WatAdminSvc.exe]
Service wbengine [C:\windows\system32\wbengine.exe]
Service WbioSrvc [C:\windows\System32\wbiosrvc.dll]
Service wcncsvc [C:\windows\System32\wcncsvc.dll]
Service WcsPlugInService [C:\windows\System32\WcsPlugInService.dll]
Service Wd [C:\windows\system32\drivers\wd.sys]
Service Wdf01000 [C:\windows\system32\drivers\Wdf01000.sys]
Service WdiServiceHost [C:\windows\system32\wdi.dll]
Service WdiSystemHost [C:\windows\system32\wdi.dll]
Service wdmirror [C:\windows\system32\DRIVERS\WDMirror.sys]
Service WebClient [C:\windows\System32\webclnt.dll]
Service Wecsvc [C:\windows\system32\wecsvc.dll]
Service wercplsupport [C:\windows\System32\wercplsupport.dll]
Service WerSvc [C:\windows\System32\WerSvc.dll]
Service WfpLwf [C:\windows\system32\DRIVERS\wfplwf.sys]
Service WIMMount [C:\windows\system32\drivers\wimmount.sys]
Service WinDefend [C:\Program Files\Windows Defender\mpsvc.dll]
Service Windows Workflow Foundation 3.0.0.0 [???]
Service Windows Workflow Foundation 4.0.0.0 [???]
Service WinHttpAutoProxySvc [C:\windows\system32\winhttp.dll]
Service Winmgmt [C:\windows\system32\wbem\WMIsvc.dll]
Service WinRM [C:\windows\system32\WsmSvc.dll]
Service Winsock [C:\windows\System32\Drivers\Winsock.sys]
Service WinSock2 [???]
Service WinUsb [C:\windows\system32\DRIVERS\WinUsb.sys]
Service Wlansvc [C:\windows\System32\wlansvc.dll]
Service wlcrasvc [C:\Program Files\Windows Live\Mesh\wlcrasvc.exe]
Service wlidsvc [C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE]
Service WmiAcpi [C:\windows\system32\DRIVERS\wmiacpi.sys]
Service WmiApRpl [???]
Service wmiApSrv [C:\windows\system32\wbem\WmiApSrv.exe]
Service WMPNetworkSvc [C:\Program Files\Windows Media Player\wmpnetwk.exe]
Service WPCSvc [C:\windows\System32\wpcsvc.dll]
Service WPDBusEnum [C:\windows\system32\wpdbusenum.dll]
Service ws2ifsl [C:\windows\system32\drivers\ws2ifsl.sys]
Service wscsvc [C:\windows\System32\wscsvc.dll]
Service WSearch [C:\windows\system32\SearchIndexer.exe]
Service WSearchIdxPi [???]
Service wsvd [C:\windows\system32\DRIVERS\wsvd.sys]
Service wuauserv [C:\windows\system32\wuaueng.dll]
Service WudfPf [C:\windows\system32\drivers\WudfPf.sys]
Service WUDFRd [C:\windows\system32\DRIVERS\WUDFRd.sys]
Service wudfsvc [C:\windows\System32\WUDFSvc.dll]
Service WwanSvc [C:\windows\System32\wwansvc.dll]
Service xmlprov [???]
Service {07171AC2-0D2A-427d-BCE5-B6C2D6C7058B} [???]
Service {3A54FA97-42C2-4630-A824-E9441C26F82E} [???]
Service {58D0808C-A31A-45C6-8994-AC6232482AA0} [???]
Service {5BF2F48C-4A51-4E63-960A-A5B6FE7D068A} [???]
Service {72F04A48-65D0-4925-82D6-AC65730C48D7} [???]

Scan finished: 27. leden 2014 12:51:23
Hidden files found: 0
Hidden registry items found: 0
Hidden processes found: 0
Hidden services found: 1
Hidden boot sectors found: 0


----------

Mikaj08
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 26 led 2014 04:41

Re: Problém s virem Win32.expiro-U / Vitro

#6 Příspěvek od Mikaj08 »

no a s bitdefenderem to je horsi, nevim kde ten log najit...

Edit: no tak ten log z avastu neni ten spravny, bohuzel sem nemel zapnute vytvoreni logu :frusty:

Mikaj08
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 26 led 2014 04:41

Re: Problém s virem Win32.expiro-U / Vitro

#7 Příspěvek od Mikaj08 »

No hlavne ten log z av neni TEN spravny log, delal sem vic testu...
Tohle avast detekoval spravne a vzdy ''pouze'' zablokoval, bohuzel nedokazal to smazat tak sem presel na rucni praci :D
Taky sem mel napsat ze av sem instaloval az kdyz bylo pc nakazeno, to ze vubec nejaky vir mam sem zjistil pomoci MBAMu, ale co uz...

Toz mockrat dekuju za pomoc :thumbsup: a mejte se hezky :)

kaspi1975
Návštěvník
Návštěvník
Příspěvky: 1
Registrován: 05 pro 2014 09:10

Re: Problém s virem Win32.expiro-U / Vitro

#8 Příspěvek od kaspi1975 »

Měl jsem problém na notebooku s windows 7 s virem Win32.expiro (hlásilo AVG), napadeny systémové soubory windows.
Díky tomuto fóru jsem vytvořil bitdefender spouštěcí USB flashku a nechal nabootovat notebook, napoprvé sice našel a opravil (resp. nechal jsem smazat) nějaké trojanové soubory, ale Expiro zůstalo.
Řešením bylo mít notebook připojený k internetu i po nabootování z USB (kabelem k LAN, wifi jsem nerozchodil) a pak si stáhnul aktuální virové databáze a s expirem si poradil.
Zatím je vše OK, tak snad to tak zůstane.
Díky všem diskutérům za pomoc :worship: :thumbsup:

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Problém s virem Win32.expiro-U / Vitro

#9 Příspěvek od cernohous13 »

Zdravím,

za info ti děkujeme, ale je to rok starý thread a mezitím stihly AV společnosti virus detekovat i odstraňovat - tak už to chodí :wink:
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Zamčeno