Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Problém s virem JS/Kryptik.I Trojský kůň

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
WolfiQQ
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 31 bře 2014 21:47

Problém s virem JS/Kryptik.I Trojský kůň

#1 Příspěvek od WolfiQQ »

Dobrý den,
dneska jsem nechtěně klikl na nějakou stránku a dostal sem nějaký vir do PC. Eset mi pořád vyhazuje, že ho dal do karantény, už asi 81x za nějaké 2 hodiny -_- skoro furt naco kliknu na netu tak to hodí to, že to bylo dáno do karantény. Vážně nevím co stím :( vůbec .. možná vám pomůže tohle ... v karanténě jsou zakázané dvě stránky, ale jen jedna z toho je pořád blokována: "http://untils.cdneurope.com/js/mo.js" ... Vůbec si nevím rady, google mi taky moc nepomohl.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Problém s virem JS/Kryptik.I Trojský kůň

#2 Příspěvek od motji »

Dobrý večer :)
protože nemám u sebe věštěckou kouli :D , pro začátek udělejte log z tohoto programu a vložte zde
http://forum.viry.cz/viewtopic.php?f=13&t=133100

V jakém souboru NOD vir detekuje?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

WolfiQQ
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 31 bře 2014 21:47

Re: Problém s virem JS/Kryptik.I Trojský kůň

#3 Příspěvek od WolfiQQ »

Tady je log z FRTS ... mimochodem, na žádnem souboru, právě že mi to pořád ukazuje "Našla se infiltrace" Objekt: ta stránka co sem postnul dříve ("http://utils.cdneurope.com/js/mo.js") ... Ještě vám zde přikládám přílohu Addition.

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by Milan (administrator) on MILAN-PC on 01-04-2014 16:18:05
Running from C:\Users\Milan\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
() C:\Users\Milan\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Milan\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
(Intel Corporation) C:\Windows\system32\igfxext.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe
(forum.viry.cz) C:\Users\Milan\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [5617432 2013-08-19] (ESET)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1808168 2009-06-18] (Synaptics Incorporated)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10134560 2010-03-23] (Realtek Semiconductor)
HKLM\...\Run: [mwlDaemon] - C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-02-01] (Egis Technology Inc.)
HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [860192 2010-02-05] (Acer Incorporated)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3814736 2014-02-26] (LogMeIn Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [SuiteTray] - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [337264 2010-02-01] (Egis Technology Inc.)
HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [1300560 2010-03-03] (Dritek System Inc.)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-12-24] (Intel Corporation)
HKLM-x32\...\Run: [EgisUpdate] - C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201512 2009-12-25] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisTecPMMUpdate] - C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [401192 2009-12-25] (Egis Technology Inc.)
HKLM-x32\...\Run: [BackupManagerTray] - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [260608 2010-03-09] (NewTech Infosystems, Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-330137112-1029790119-1089304535-1001\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
HKU\S-1-5-21-330137112-1029790119-1089304535-1001\...\Run: [MKLOL] - C:\Program Files (x86)\MKJogo\MKLOL\MK.exe [754888 2014-02-17] (MK)
HKU\S-1-5-21-330137112-1029790119-1089304535-1001\...\Run: [cz.seznam.software.szndesktop] - C:\Users\Milan\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-330137112-1029790119-1089304535-1001\...\Run: [cz.seznam.software.autoupdate] - C:\Users\Milan\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-330137112-1029790119-1089304535-1001\...\MountPoints2: {c66f1350-caa9-11e2-b88c-88ae1d09f195} - E:\.autorun\autorun.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACA ... 5t46k2m848
SearchScopes: HKLM-x32 - DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?sourceid=i ... lz=1I7ACAW
SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?sourceid=i ... lz=1I7ACAW
SearchScopes: HKCU - DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?sourceid=i ... AW_csCZ528
SearchScopes: HKCU - {0DA46B73-2566-4128-B362-3E2F894814FB} URL = http://www.mapy.cz/?query={searchTerms} ... arch_16194
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.delta-search.com/?q={searchT ... 9&tsp=5024
SearchScopes: HKCU - {39FF9B58-58FD-474D-A91F-6CA42364FC73} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
SearchScopes: HKCU - {3F3DD15F-DC17-4594-99CD-E3CDE05D5364} URL = http://encyklopedie.seznam.cz/search?q= ... arch_16194
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?sourceid=i ... AW_csCZ528
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKCU - {71EB6956-D2F1-4869-B00E-E8547F0458A5} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
SearchScopes: HKCU - {8B7B2A1E-52FE-486F-AADF-A7889E50E002} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
SearchScopes: HKCU - {9B87AAD1-8DE6-496C-9F3D-EEC3E99CBDB9} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_16194
SearchScopes: HKCU - {BAE32332-AA41-4F44-A4AE-C002E9264824} URL = http://search.seznam.cz/?q={searchTerms ... arch_16194
SearchScopes: HKCU - {C2F013F9-47D7-470E-9676-696D22ABABCA} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_16194
SearchScopes: HKCU - {C84967D3-2668-470B-BA61-8C689EAC543A} URL = http://www.novinky.cz/hledej?w={searchT ... arch_16194
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 178.72.193.142 178.72.195.195

FireFox:
========
FF ProfilePath: C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\uvng4vs6.default
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameEU.dll (Nexon)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @t.garena.com/garenatalk - C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll No File
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Milan\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Extension: Site Finder - C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\uvng4vs6.default\Extensions\sitefinder@sitefinder.com [2014-03-22]
FF Extension: Adblock Plus - C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\uvng4vs6.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-18]
FF HKLM-x32\...\Firefox\Extensions: [xz123@ya456.com] - C:\Program Files (x86)\BetterSurf\ff
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2014-03-28]

==================== Services (Whitelisted) =================

S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2013-12-15] (BitRaider, LLC)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1337240 2013-08-19] (ESET)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-02-26] (LogMeIn, Inc.)
R2 MSSQL$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [62218696 2012-06-29] (Microsoft Corporation)
R2 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-02-01] (Egis Technology Inc.)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [4573336 2013-04-07] (INCA Internet Co., Ltd.)
S4 SQLAgent$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [441288 2012-06-29] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2013-08-25] ()
S3 BRDriver64; C:\ProgramData\BitRaider\BRDriver64.sys [75048 2013-12-15] (BitRaider)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-06-02] (DT Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-08-20] (ESET)
U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [239296 2013-08-26] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [168256 2013-08-20] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [220232 2013-08-20] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44120 2013-08-20] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [62136 2013-08-20] (ESET)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2013-08-25] ()
S4 RsFx0153; C:\Windows\System32\DRIVERS\RsFx0153.sys [321992 2012-06-29] (Microsoft Corporation)
S3 RSUSBSTOR; C:\Windows\SysWOW64\Drivers\RtsUStor.sys [225280 2009-09-02] (Realtek Semiconductor Corp.)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 GGSAFERDriver; \??\C:\Program Files (x86)\Garena Plus\Room\safedrv.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-04-01 16:18 - 2014-04-01 16:19 - 00016061 _____ () C:\Users\Milan\Desktop\FRST.txt
2014-04-01 16:15 - 2014-04-01 16:15 - 00112640 _____ (forum.viry.cz) C:\Users\Milan\Desktop\FRSTLauncher.exe
2014-04-01 16:14 - 2014-04-01 16:18 - 00000000 ____D () C:\FRST
2014-04-01 16:13 - 2014-04-01 16:14 - 02157056 _____ (Farbar) C:\Users\Milan\Desktop\FRST64.exe
2014-04-01 15:36 - 2014-04-01 15:36 - 00000056 _____ () C:\Windows\setupact.log
2014-04-01 15:36 - 2014-04-01 15:36 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-31 22:26 - 2014-03-31 22:27 - 00000079 _____ () C:\Users\Milan\Desktop\vir.txt
2014-03-31 21:11 - 2014-03-31 21:11 - 00000000 ____D () C:\ProgramData\Age of Empires 3
2014-03-31 19:34 - 2014-03-31 19:34 - 00012735 _____ () C:\Users\Milan\Desktop\[CzT]Age_Of_Empires_3_Kompletni_edice_CZ.torrent
2014-03-31 19:07 - 2014-03-31 19:07 - 00000000 ____D () C:\Users\Milan\AppData\Roaming\My The Lord of the Rings, The Rise of the Witch-king Files
2014-03-31 19:05 - 2014-03-31 19:05 - 00001629 _____ () C:\Users\Public\Desktop\The Lord of the Rings, The Rise of the Witch-king.lnk
2014-03-31 18:45 - 2014-03-31 18:45 - 00003184 _____ () C:\Windows\System32\Tasks\{079F848D-34FD-4080-8ADE-D4751E09C646}
2014-03-31 18:38 - 2014-03-31 19:23 - 00000000 ____D () C:\Users\Milan\AppData\Roaming\My Battle for Middle-earth(tm) II Files
2014-03-31 18:35 - 2014-03-31 18:35 - 00001511 _____ () C:\Users\Public\Desktop\The Battle for Middle-earth (tm) II.lnk
2014-03-30 20:55 - 2014-03-30 20:55 - 00003316 _____ () C:\Windows\System32\Tasks\{324E37C0-776D-40BB-B5D1-593BF0D298C3}
2014-03-30 19:34 - 2014-03-30 19:34 - 00000000 ____D () C:\Users\Milan\AppData\Local\Electronic Arts
2014-03-28 23:09 - 2014-03-28 23:09 - 00000000 ____D () C:\Users\Milan\AppData\Roaming\ESET
2014-03-28 23:09 - 2014-03-28 23:09 - 00000000 ____D () C:\Users\Milan\AppData\Local\ESET
2014-03-28 22:55 - 2014-03-28 22:55 - 00000000 ____D () C:\ProgramData\ESET
2014-03-28 22:55 - 2014-03-28 22:55 - 00000000 ____D () C:\Program Files\ESET
2014-03-28 20:17 - 2014-03-31 22:32 - 00000000 ____D () C:\Users\Milan\Documents\TrackMania
2014-03-28 18:35 - 2014-03-28 18:35 - 00000000 ____D () C:\Users\Milan\AppData\Roaming\Unity
2014-03-28 18:33 - 2014-03-28 18:33 - 00000000 ____D () C:\Users\Milan\AppData\Local\Unity
2014-03-26 18:21 - 2014-03-29 00:47 - 00000000 ____D () C:\Users\Milan\Desktop\$
2014-03-25 16:46 - 2014-03-25 16:46 - 00000700 _____ () C:\Users\Milan\Desktop\FlatOut2.lnk
2014-03-25 16:27 - 2014-03-25 16:27 - 00003050 _____ () C:\Windows\System32\Tasks\{1C555A98-377E-459A-8674-86DAA32156CD}
2014-03-24 21:12 - 2014-03-24 21:12 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
2014-03-24 20:02 - 2014-03-24 20:02 - 00000000 ____D () C:\Users\Milan\AppData\Local\NFS Underground 2
2014-03-24 18:50 - 2014-03-24 18:50 - 00003226 _____ () C:\Windows\System32\Tasks\{18240EF2-B80A-43A1-8076-7B23461E57DC}
2014-03-23 21:58 - 2014-03-23 21:58 - 00003032 _____ () C:\Windows\System32\Tasks\{450DCDB0-471A-43F2-A9EF-15FD9E5B854C}
2014-03-23 20:11 - 2014-03-23 20:11 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-03-18 20:13 - 2014-03-18 20:27 - 00000000 ____D () C:\Users\Milan\AppData\Local\Temporary Projects
2014-03-17 21:37 - 2014-03-17 21:37 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-17 21:37 - 2014-03-17 21:37 - 00000000 ____D () C:\Users\Milan\AppData\Local\Skype
2014-03-16 18:01 - 2014-03-16 18:01 - 00000029 _____ () C:\Users\Milan\Desktop\Vše o wowku.txt
2014-03-15 17:26 - 2014-03-15 17:26 - 00000000 ____D () C:\Users\Milan\AppData\Roaming\digipen
2014-03-15 17:26 - 2014-03-15 17:26 - 00000000 ____D () C:\Users\Milan\AppData\Local\digipen
2014-03-14 18:50 - 2014-03-14 18:50 - 00000000 ____D () C:\Users\Milan\AppData\Local\DOSBox
2014-03-14 18:48 - 2014-03-14 18:53 - 00001804 _____ () C:\Users\Milan\Desktop\Warcraft II.lnk
2014-03-14 18:47 - 2014-03-14 18:47 - 00001708 _____ () C:\Users\Public\Desktop\DOSBox 0.74.lnk
2014-03-13 23:39 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-13 23:39 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-13 23:39 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-13 23:38 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-13 23:38 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-13 23:38 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-13 23:38 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-13 23:38 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-13 23:38 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-13 23:38 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-13 23:38 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-13 23:38 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-13 23:38 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-13 23:38 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-13 23:38 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-13 23:38 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-13 23:38 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-13 23:38 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-13 23:38 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-13 23:38 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-13 23:38 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-13 23:38 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-13 23:38 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-13 23:38 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-13 23:38 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-13 23:38 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-13 23:38 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-13 23:38 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-13 23:38 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-13 23:38 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-13 23:38 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-13 23:38 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-13 23:38 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-13 23:38 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-13 23:38 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-13 23:38 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-13 23:38 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-13 23:38 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-13 23:38 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-13 23:38 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-13 23:38 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-13 23:38 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-13 23:38 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-13 23:38 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-13 23:36 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-13 23:36 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-13 23:36 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-13 23:36 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-03-09 12:41 - 2014-03-09 12:45 - 00103736 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-03-09 12:41 - 2014-03-09 12:41 - 00066872 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-03-09 12:41 - 2014-03-09 12:41 - 00000000 ____D () C:\Users\Milan\Documents\NFS ProStreet
2014-03-08 22:12 - 2014-03-08 22:12 - 00000000 ____D () C:\Program Files (x86)\SimilarSites
2014-03-08 22:11 - 2014-03-08 22:11 - 00000000 ____D () C:\Users\Milan\AppData\Roaming\SimilarSites
2014-03-06 21:39 - 2014-03-06 21:39 - 00000040 _____ () C:\Users\Milan\Desktop\herci.txt
2014-03-02 23:48 - 2014-03-17 21:35 - 00000000 ____D () C:\Users\Milan\Desktop\hearthstone

==================== One Month Modified Files and Folders =======

2014-04-01 16:19 - 2014-04-01 16:18 - 00016061 _____ () C:\Users\Milan\Desktop\FRST.txt
2014-04-01 16:18 - 2014-04-01 16:14 - 00000000 ____D () C:\FRST
2014-04-01 16:17 - 2013-07-22 18:39 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-01 16:15 - 2014-04-01 16:15 - 00112640 _____ (forum.viry.cz) C:\Users\Milan\Desktop\FRSTLauncher.exe
2014-04-01 16:15 - 2013-03-17 22:11 - 00000000 ____D () C:\Users\Milan\Desktop\Stažené
2014-04-01 16:14 - 2014-04-01 16:13 - 02157056 _____ (Farbar) C:\Users\Milan\Desktop\FRST64.exe
2014-04-01 15:44 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-01 15:44 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-01 15:41 - 2013-09-01 01:58 - 00000000 ____D () C:\Users\Milan\AppData\Roaming\Seznam.cz
2014-04-01 15:41 - 2013-03-18 02:27 - 00743660 _____ () C:\Windows\system32\perfh005.dat
2014-04-01 15:41 - 2013-03-18 02:27 - 00171616 _____ () C:\Windows\system32\perfc005.dat
2014-04-01 15:41 - 2009-07-14 07:13 - 01797238 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-01 15:39 - 2013-03-17 20:25 - 01492370 _____ () C:\Windows\WindowsUpdate.log
2014-04-01 15:37 - 2013-08-22 22:19 - 00000000 ____D () C:\Users\Milan\AppData\Local\LogMeIn Hamachi
2014-04-01 15:36 - 2014-04-01 15:36 - 00000056 _____ () C:\Windows\setupact.log
2014-04-01 15:36 - 2014-04-01 15:36 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-01 15:36 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-01 00:01 - 2013-03-19 01:30 - 00000000 ____D () C:\Users\Milan\AppData\Roaming\uTorrent
2014-03-31 23:31 - 2013-11-11 20:46 - 00000000 ____D () C:\Hry
2014-03-31 23:13 - 2013-03-18 18:41 - 00000000 ____D () C:\Users\Milan\AppData\Roaming\Skype
2014-03-31 22:37 - 2013-06-02 13:42 - 00000000 ____D () C:\Users\Milan\AppData\Roaming\DAEMON Tools Lite
2014-03-31 22:32 - 2014-03-28 20:17 - 00000000 ____D () C:\Users\Milan\Documents\TrackMania
2014-03-31 22:29 - 2014-01-24 00:13 - 00000000 ____D () C:\Users\Milan\AppData\Local\Battle.net
2014-03-31 22:27 - 2014-03-31 22:26 - 00000079 _____ () C:\Users\Milan\Desktop\vir.txt
2014-03-31 21:41 - 2013-04-28 21:17 - 00000000 ____D () C:\Users\Milan\AppData\Roaming\AIMP3
2014-03-31 21:40 - 2013-08-24 22:47 - 00000000 ____D () C:\ProgramData\TrackMania
2014-03-31 21:20 - 2013-07-20 12:49 - 00000000 ____D () C:\Users\Milan\Desktop\Games
2014-03-31 21:11 - 2014-03-31 21:11 - 00000000 ____D () C:\ProgramData\Age of Empires 3
2014-03-31 21:11 - 2014-02-17 18:18 - 00000000 ____D () C:\Users\Milan\Documents\My Games
2014-03-31 19:34 - 2014-03-31 19:34 - 00012735 _____ () C:\Users\Milan\Desktop\[CzT]Age_Of_Empires_3_Kompletni_edice_CZ.torrent
2014-03-31 19:23 - 2014-03-31 18:38 - 00000000 ____D () C:\Users\Milan\AppData\Roaming\My Battle for Middle-earth(tm) II Files
2014-03-31 19:07 - 2014-03-31 19:07 - 00000000 ____D () C:\Users\Milan\AppData\Roaming\My The Lord of the Rings, The Rise of the Witch-king Files
2014-03-31 19:05 - 2014-03-31 19:05 - 00001629 _____ () C:\Users\Public\Desktop\The Lord of the Rings, The Rise of the Witch-king.lnk
2014-03-31 18:45 - 2014-03-31 18:45 - 00003184 _____ () C:\Windows\System32\Tasks\{079F848D-34FD-4080-8ADE-D4751E09C646}
2014-03-31 18:38 - 2013-06-02 18:50 - 00000000 ____D () C:\Users\Milan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-03-31 18:35 - 2014-03-31 18:35 - 00001511 _____ () C:\Users\Public\Desktop\The Battle for Middle-earth (tm) II.lnk
2014-03-31 03:01 - 2010-05-28 11:59 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-03-30 21:26 - 2013-10-03 18:46 - 00000000 ____D () C:\Users\Milan\AppData\Roaming\File Scout
2014-03-30 20:55 - 2014-03-30 20:55 - 00003316 _____ () C:\Windows\System32\Tasks\{324E37C0-776D-40BB-B5D1-593BF0D298C3}
2014-03-30 20:17 - 2013-03-17 20:30 - 00000000 ____D () C:\Users\Milan
2014-03-30 19:54 - 2014-02-09 01:34 - 00000000 ____D () C:\Users\Milan\AppData\Roaming\vlc
2014-03-30 19:34 - 2014-03-30 19:34 - 00000000 ____D () C:\Users\Milan\AppData\Local\Electronic Arts
2014-03-30 18:51 - 2013-07-20 13:01 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts
2014-03-30 18:51 - 2010-05-28 11:45 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-03-30 13:30 - 2013-03-17 20:31 - 00088000 _____ () C:\Users\Milan\AppData\Local\GDIPFONTCACHEV1.DAT
2014-03-30 13:29 - 2009-07-14 06:45 - 00368248 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-30 13:27 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-03-29 01:19 - 2013-03-21 18:04 - 00000000 ____D () C:\Users\Milan\Desktop\Prezentace
2014-03-29 00:47 - 2014-03-26 18:21 - 00000000 ____D () C:\Users\Milan\Desktop\$
2014-03-28 23:46 - 2013-09-01 01:58 - 00000000 ____D () C:\Users\Milan\AppData\Local\SwvUpdater
2014-03-28 23:18 - 2013-07-22 18:39 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-03-28 23:18 - 2013-03-18 23:35 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-28 23:18 - 2013-03-18 23:35 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-28 23:12 - 2013-12-08 18:01 - 00000000 ____D () C:\Windows\pss
2014-03-28 23:09 - 2014-03-28 23:09 - 00000000 ____D () C:\Users\Milan\AppData\Roaming\ESET
2014-03-28 23:09 - 2014-03-28 23:09 - 00000000 ____D () C:\Users\Milan\AppData\Local\ESET
2014-03-28 22:55 - 2014-03-28 22:55 - 00000000 ____D () C:\ProgramData\ESET
2014-03-28 22:55 - 2014-03-28 22:55 - 00000000 ____D () C:\Program Files\ESET
2014-03-28 22:35 - 2013-03-17 21:57 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-03-28 22:35 - 2013-03-17 21:57 - 00000000 ____D () C:\Program Files\AVAST Software
2014-03-28 22:34 - 2013-03-17 21:58 - 00000000 _____ () C:\Windows\SysWOW64\config.nt
2014-03-28 22:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-03-28 19:26 - 2013-03-17 21:58 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-03-28 18:35 - 2014-03-28 18:35 - 00000000 ____D () C:\Users\Milan\AppData\Roaming\Unity
2014-03-28 18:33 - 2014-03-28 18:33 - 00000000 ____D () C:\Users\Milan\AppData\Local\Unity
2014-03-27 22:49 - 2013-03-17 21:53 - 00000000 ___RD () C:\Users\Milan\Desktop\Programy
2014-03-27 20:26 - 2013-11-17 14:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-26 23:11 - 2013-04-28 21:17 - 00000000 ____D () C:\Program Files (x86)\AIMP3
2014-03-25 16:46 - 2014-03-25 16:46 - 00000700 _____ () C:\Users\Milan\Desktop\FlatOut2.lnk
2014-03-25 16:27 - 2014-03-25 16:27 - 00003050 _____ () C:\Windows\System32\Tasks\{1C555A98-377E-459A-8674-86DAA32156CD}
2014-03-24 21:12 - 2014-03-24 21:12 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
2014-03-24 20:02 - 2014-03-24 20:02 - 00000000 ____D () C:\Users\Milan\AppData\Local\NFS Underground 2
2014-03-24 18:50 - 2014-03-24 18:50 - 00003226 _____ () C:\Windows\System32\Tasks\{18240EF2-B80A-43A1-8076-7B23461E57DC}
2014-03-23 21:58 - 2014-03-23 21:58 - 00003032 _____ () C:\Windows\System32\Tasks\{450DCDB0-471A-43F2-A9EF-15FD9E5B854C}
2014-03-23 20:11 - 2014-03-23 20:11 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-03-23 13:10 - 2013-08-23 12:30 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2014-03-22 21:53 - 2013-08-17 15:49 - 00000291 _____ () C:\Windows\wininit.ini
2014-03-22 00:19 - 2014-01-24 00:13 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-03-20 17:26 - 2014-02-18 18:59 - 00000049 _____ () C:\Users\Milan\Desktop\wow učet twinstar.txt
2014-03-20 02:02 - 2013-07-22 19:05 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-20 01:58 - 2013-03-20 19:07 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-19 17:58 - 2013-08-17 15:49 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-03-18 21:02 - 2013-09-12 20:41 - 00000000 ____D () C:\Users\Milan\Documents\Visual Studio 2010
2014-03-18 20:27 - 2014-03-18 20:13 - 00000000 ____D () C:\Users\Milan\AppData\Local\Temporary Projects
2014-03-17 21:37 - 2014-03-17 21:37 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-17 21:37 - 2014-03-17 21:37 - 00000000 ____D () C:\Users\Milan\AppData\Local\Skype
2014-03-17 21:37 - 2013-03-18 18:40 - 00000000 ____D () C:\ProgramData\Skype
2014-03-17 21:35 - 2014-03-02 23:48 - 00000000 ____D () C:\Users\Milan\Desktop\hearthstone
2014-03-17 18:21 - 2014-01-24 00:19 - 00000000 ____D () C:\Program Files (x86)\Hearthstone
2014-03-17 03:58 - 2013-04-09 18:18 - 00000000 ____D () C:\Windows\System32\Tasks\Games
2014-03-16 18:01 - 2014-03-16 18:01 - 00000029 _____ () C:\Users\Milan\Desktop\Vše o wowku.txt
2014-03-15 17:26 - 2014-03-15 17:26 - 00000000 ____D () C:\Users\Milan\AppData\Roaming\digipen
2014-03-15 17:26 - 2014-03-15 17:26 - 00000000 ____D () C:\Users\Milan\AppData\Local\digipen
2014-03-14 21:39 - 2013-08-01 13:29 - 00000000 ____D () C:\Users\Milan\Documents\FIFA 13
2014-03-14 18:53 - 2014-03-14 18:48 - 00001804 _____ () C:\Users\Milan\Desktop\Warcraft II.lnk
2014-03-14 18:50 - 2014-03-14 18:50 - 00000000 ____D () C:\Users\Milan\AppData\Local\DOSBox
2014-03-14 18:47 - 2014-03-14 18:47 - 00001708 _____ () C:\Users\Public\Desktop\DOSBox 0.74.lnk
2014-03-14 18:07 - 2013-03-18 20:10 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-14 18:07 - 2013-03-18 20:10 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-03-13 21:00 - 2013-03-19 18:17 - 00000000 ____D () C:\Users\Milan\AppData\Local\Adobe
2014-03-12 22:17 - 2013-03-17 21:22 - 00000000 ____D () C:\Program Files (x86)\Directx
2014-03-09 12:45 - 2014-03-09 12:41 - 00103736 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-03-09 12:41 - 2014-03-09 12:41 - 00066872 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-03-09 12:41 - 2014-03-09 12:41 - 00000000 ____D () C:\Users\Milan\Documents\NFS ProStreet
2014-03-09 12:41 - 2013-04-14 12:36 - 00000000 ____D () C:\Users\Milan\AppData\Local\PunkBuster
2014-03-08 22:12 - 2014-03-08 22:12 - 00000000 ____D () C:\Program Files (x86)\SimilarSites
2014-03-08 22:11 - 2014-03-08 22:11 - 00000000 ____D () C:\Users\Milan\AppData\Roaming\SimilarSites
2014-03-08 00:50 - 2013-08-17 15:49 - 00000000 ____D () C:\ProgramData\Origin
2014-03-06 21:39 - 2014-03-06 21:39 - 00000040 _____ () C:\Users\Milan\Desktop\herci.txt
2014-03-05 16:49 - 2009-07-14 07:08 - 00032638 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-03-03 17:42 - 2013-08-01 22:31 - 00000000 ____D () C:\Users\Milan\Documents\i68Fifa13

Some content of TEMP:
====================
C:\Users\Milan\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Milan\AppData\Local\Temp\EAInstall.dll
C:\Users\Milan\AppData\Local\Temp\eauninstall.exe
C:\Users\Milan\AppData\Local\Temp\The Battle for Middle-earth_uninst.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================

Image Resizer for Windows (64 bit) (Version: 3.0.4802.35565 - Brice Lambson) Hidden
Image Resizer for Windows (HKLM-x32\...\{69d72156-6582-4556-8637-06f40aa7f85b}) (Version: 3.0.4802.35565 - Brice Lambson)

==================== Scheduled Tasks (whitelisted) ==================

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: ESET Smart Security 7.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 7.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET Personální firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Milan\Desktop" je 139312 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================
Přílohy
Addition.rar
(7.6 KiB) Staženo 52 x

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Problém s virem JS/Kryptik.I Trojský kůň

#4 Příspěvek od motji »

Tento program je co?
C:\Program Files (x86)\MKJogo\MKLOL\MK.exe

:arrow: Spusťte combofix podle tohoto návodu
http://www.bleepingcomputer.com/combofi ... t-combofix
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

WolfiQQ
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 31 bře 2014 21:47

Re: Problém s virem JS/Kryptik.I Trojský kůň

#5 Příspěvek od WolfiQQ »

Je to program ke hře League of Legends ... už ho nepoužívám, takže tak ... btw. mam tu hodit log z combofixu?

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Problém s virem JS/Kryptik.I Trojský kůň

#6 Příspěvek od motji »

Ano
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

WolfiQQ
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 31 bře 2014 21:47

Re: Problém s virem JS/Kryptik.I Trojský kůň

#7 Příspěvek od WolfiQQ »

Udělám vše podle návodu a vyhodí mi to tuhle chybu -_-
Přílohy
Bez názvu.rar
(108.54 KiB) Staženo 77 x

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Problém s virem JS/Kryptik.I Trojský kůň

#8 Příspěvek od motji »

Dnes kombofix nějak zlobí :?:

:arrow: Stahněte MBAM http://www.viry.cz/forum/viewtopic.php?f=29&t=115222
-Nainstalujte,dejte úplný sken

NIC NEMAZAT :!:
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

WolfiQQ
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 31 bře 2014 21:47

Re: Problém s virem JS/Kryptik.I Trojský kůň

#9 Příspěvek od WolfiQQ »

S comboboxem byla chybá na mé straně, už to udělalo sken, zde je log z comboboxu.



ComboFix 14-03-24.01 - Milan 01.04.2014 18:44:37.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4026.2069 [GMT 2:00]
Spuštěný z: c:\users\Milan\Desktop\Stažené\ComboFix.exe
AV: ESET Smart Security 7.0 *Disabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
FW: ESET Personální firewall *Disabled* {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
SP: ESET Smart Security 7.0 *Disabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\DSearchLink
c:\programdata\DSearchLink\DSearchLink.exe
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-03-01 do 2014-04-01 )))))))))))))))))))))))))))))))
.
.
2014-04-01 17:26 . 2014-04-01 17:26 -------- d-----w- c:\users\hedev\AppData\Local\temp
2014-04-01 15:55 . 2014-03-07 04:43 10521840 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{26FF8D4A-C596-448C-8C38-B1E2502B7EEE}\mpengine.dll
2014-04-01 14:14 . 2014-04-01 14:18 -------- d-----w- C:\FRST
2014-03-31 19:11 . 2014-03-31 19:11 -------- d-----w- c:\programdata\Age of Empires 3
2014-03-31 17:07 . 2014-03-31 17:07 -------- d-----w- c:\users\Milan\AppData\Roaming\My The Lord of the Rings, The Rise of the Witch-king Files
2014-03-31 16:38 . 2014-03-31 17:23 -------- d-----w- c:\users\Milan\AppData\Roaming\My Battle for Middle-earth(tm) II Files
2014-03-30 17:34 . 2014-03-30 17:34 -------- d-----w- c:\users\Milan\AppData\Local\Electronic Arts
2014-03-28 21:09 . 2014-03-28 21:09 -------- d-----w- c:\users\Milan\AppData\Local\ESET
2014-03-28 20:55 . 2014-03-28 20:55 -------- d-----w- c:\program files\ESET
2014-03-28 16:35 . 2014-03-28 16:35 -------- d-----w- c:\users\Milan\AppData\Roaming\Unity
2014-03-28 16:33 . 2014-03-28 16:33 -------- d-----w- c:\users\Milan\AppData\Local\Unity
2014-03-27 18:26 . 2014-03-15 08:41 46704 ----a-w- c:\program files (x86)\Mozilla Firefox\browser\components\browsercomps.dll
2014-03-24 19:12 . 2014-03-24 19:12 -------- d-----w- c:\program files (x86)\MSXML 4.0
2014-03-24 18:02 . 2014-03-24 18:02 -------- d-----w- c:\users\Milan\AppData\Local\NFS Underground 2
2014-03-23 18:11 . 2014-03-23 18:11 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
2014-03-18 18:13 . 2014-03-18 18:27 -------- d-----w- c:\users\Milan\AppData\Local\Temporary Projects
2014-03-17 19:37 . 2014-03-17 19:37 -------- d-----w- c:\users\Milan\AppData\Local\Skype
2014-03-17 19:37 . 2014-03-17 19:37 -------- d-----w- c:\program files (x86)\Common Files\Skype
2014-03-17 19:37 . 2014-03-17 19:37 -------- d-----r- c:\program files (x86)\Skype
2014-03-15 15:26 . 2014-03-15 15:26 -------- d-----w- c:\users\Milan\AppData\Roaming\digipen
2014-03-15 15:26 . 2014-03-15 15:26 -------- d-----w- c:\users\Milan\AppData\Local\digipen
2014-03-14 16:50 . 2014-03-14 16:50 -------- d-----w- c:\users\Milan\AppData\Local\DOSBox
2014-03-13 21:39 . 2014-01-28 02:32 228864 ----a-w- c:\windows\system32\wwansvc.dll
2014-03-13 21:39 . 2014-01-29 02:32 484864 ----a-w- c:\windows\system32\wer.dll
2014-03-13 21:39 . 2014-01-29 02:06 381440 ----a-w- c:\windows\SysWow64\wer.dll
2014-03-13 21:36 . 2014-02-04 02:32 624128 ----a-w- c:\windows\system32\qedit.dll
2014-03-13 21:36 . 2014-02-04 02:04 509440 ----a-w- c:\windows\SysWow64\qedit.dll
2014-03-13 21:36 . 2014-02-04 02:32 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-03-13 21:36 . 2014-02-04 02:04 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2014-03-09 10:41 . 2014-03-09 10:41 66872 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2014-03-09 10:41 . 2014-03-09 10:45 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2014-03-08 20:12 . 2014-03-08 20:12 -------- d-----w- c:\program files (x86)\SimilarSites
2014-03-08 20:11 . 2014-03-08 20:11 -------- d-----w- c:\users\Milan\AppData\Roaming\SimilarSites
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-03-28 21:18 . 2013-03-18 21:35 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-03-28 21:18 . 2013-03-18 21:35 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-03-19 23:58 . 2013-03-20 17:07 90015360 ----a-w- c:\windows\system32\MRT.exe
2014-01-09 12:41 . 2013-08-16 18:04 13468 ----a-w- c:\windows\SysWow64\ealregsnapshot1.reg
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-02-01 18:03 120176 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-03-14 3672640]
"MKLOL"="c:\program files (x86)\MKJogo\MKLOL\MK.exe" [2014-02-17 754888]
"cz.seznam.software.szndesktop"="c:\users\Milan\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" [2013-04-12 92664]
"cz.seznam.software.autoupdate"="c:\users\Milan\AppData\Roaming\Seznam.cz\szninstall.exe" [2013-05-16 1062472]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2014-02-26 3814736]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"SuiteTray"="c:\program files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2010-02-01 337264]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-03-03 1300560]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-12-24 284696]
"EgisUpdate"="c:\program files (x86)\EgisTec IPS\EgisUpdate.exe" [2009-12-25 201512]
"EgisTecPMMUpdate"="c:\program files (x86)\EgisTec IPS\PmmUpdate.exe" [2009-12-25 401192]
"BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" [2010-03-08 260608]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2013-05-08 41056]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 BRDriver64;BRDriver64;c:\programdata\BitRaider\BRDriver64.sys;c:\programdata\BitRaider\BRDriver64.sys [x]
R3 BRSptSvc;BitRaider Mini-Support Service;c:\programdata\BitRaider\BRSptSvc.exe;c:\programdata\BitRaider\BRSptSvc.exe [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files (x86)\Garena Plus\Room\safedrv.sys;c:\program files (x86)\Garena Plus\Room\safedrv.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x]
R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [x]
R4 RsFx0153;RsFx0153 Driver;c:\windows\system32\DRIVERS\RsFx0153.sys;c:\windows\SYSNATIVE\DRIVERS\RsFx0153.sys [x]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE;c:\program files\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [x]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfp.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys;c:\windows\SYSNATIVE\DRIVERS\EpfwLWF.sys [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDFilter.sys [x]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDNServ.sys [x]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDVDisk.sys [x]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe;c:\program files (x86)\Launch Manager\dsiwmis.exe [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [x]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [x]
S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe;c:\program files (x86)\Acer\Registration\GREGsvc.exe [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x]
S2 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [x]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [x]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [x]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2014-04-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-18 21:18]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-02-01 18:06 137584 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x64\PSDProtect.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2013-08-19 5617432]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-03-23 10134560]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-03-15 365592]
"mwlDaemon"="c:\program files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe" [2010-02-01 349552]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-03-15 165912]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-03-15 387608]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-02-05 860192]
.
------- Doplňkový sken -------
.
uStart Page = about:Tabs
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\uvng4vs6.default\
FF - prefs.js: browser.startup.homepage - about:home
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\GamePark klient 2.lnk - c:\program files\GamePark2\gpcl.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-Adobe Shockwave Player - c:\windows\System32\Macromed\SHOCKW~1\UNWISE.EXE
AddRemove-Counter-strike 1.6 - c:\program files (x86)\Counter-strike-1.6\Uninstal cstrike.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-330137112-1029790119-1089304535-1001\Software\SecuROM\License information*]
"datasecu"=hex:46,5a,dc,b3,4b,79,10,c0,70,f4,01,6a,8f,27,6a,74,bb,65,a6,df,aa,
71,42,b9,62,d4,d9,ac,19,59,76,65,68,3c,7f,ef,74,0f,36,c5,0b,71,37,2e,81,6c,\
"rkeysecu"=hex:db,21,43,6f,e0,9d,63,8b,57,18,97,44,6d,56,9e,2d
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_77_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_77_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.12"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2014-04-01 19:29:45
ComboFix-quarantined-files.txt 2014-04-01 17:29
.
Před spuštěním: Volných bajtů: 28 966 936 576
Po spuštění: Volných bajtů: 28 377 305 088
.
- - End Of File - - 94E73988A9B3C230394D0C1C33B1854A

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Problém s virem JS/Kryptik.I Trojský kůň

#10 Příspěvek od motji »

Vy asi stahujete hodně her, že?
Budu se ptát, tyto složky znáte? Abych Vám nesmazala něco co používáte :)

c:\users\Milan\AppData\Local\Unity
c:\users\Milan\AppData\Local\digipen
c:\users\Milan\AppData\Roaming\SimilarSites
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

WolfiQQ
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 31 bře 2014 21:47

Re: Problém s virem JS/Kryptik.I Trojský kůň

#11 Příspěvek od WolfiQQ »

ano, stahuju ... jen "local/Unity" ... je to přehrávač na webgames:D ale to můžu klidně smazat a ostatní .. digipen - nepotřebné, nějaké zbytky programu asi a v té poslední nic není.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Problém s virem JS/Kryptik.I Trojský kůň

#12 Příspěvek od motji »

Už chystám mazací skriptík.
Tohle znáte?
C:\Users\Milan\Desktop\$
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

WolfiQQ
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 31 bře 2014 21:47

Re: Problém s virem JS/Kryptik.I Trojský kůň

#13 Příspěvek od WolfiQQ »

Ano.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Problém s virem JS/Kryptik.I Trojský kůň

#14 Příspěvek od motji »

:arrow: Pokud nemáte, přesuňte Combofix na plochu
-otevřete si Poznámkový blok
-Do něj zkopírujte text z tohoto okénka

Kód: Vybrat vše


file::
 C:\Windows\System32\Tasks\{324E37C0-776D-40BB-B5D1-593BF0D298C3}
C:\Windows\System32\Tasks\{079F848D-34FD-4080-8ADE-D4751E09C646}
C:\Windows\System32\Tasks\{324E37C0-776D-40BB-B5D1-593BF0D298C3}
C:\Windows\System32\Tasks\{1C555A98-377E-459A-8674-86DAA32156CD}
C:\Windows\System32\Tasks\{18240EF2-B80A-43A1-8076-7B23461E57DC}
C:\Windows\System32\Tasks\{450DCDB0-471A-43F2-A9EF-15FD9E5B854C}

Folder::
C:\Users\Milan\AppData\Roaming\digipen
 C:\Users\Milan\AppData\Local\digipen
 C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
C:\Users\Milan\AppData\Roaming\Seznam.cz
C:\Users\Milan\AppData\Local\SwvUpdater
C:\ProgramData\AVAST Software
 C:\Program Files\AVAST Software
 C:\Windows\System32\Tasks\avast! Emergency Update

-uložte Vámi vytvořený TXT soubor jako CFScript.txt na plochu
-po uložení uchopte vámi vytvořený skript levým myšítkem a -přesuňte ho nad ikonu Combofixu, kde ho upustíte:

Obrázek


-po aplikaci na Vás vypadne další log,vložte ho sem

Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

WolfiQQ
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 31 bře 2014 21:47

Re: Problém s virem JS/Kryptik.I Trojský kůň

#15 Příspěvek od WolfiQQ »

Zde je log z Combofixu po aplikování toho skriptíku.


ComboFix 14-03-24.01 - Milan 02.04.2014 20:43:43.3.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4026.2101 [GMT 2:00]
Spuštěný z: c:\users\Milan\Desktop\Stažené\ComboFix.exe
Použité ovládací přepínače :: c:\users\Milan\Desktop\CFScript.txt
AV: ESET Smart Security 7.0 *Disabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
FW: ESET Personální firewall *Disabled* {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
SP: ESET Smart Security 7.0 *Disabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\System32\Tasks\{079F848D-34FD-4080-8ADE-D4751E09C646}"
"c:\windows\System32\Tasks\{18240EF2-B80A-43A1-8076-7B23461E57DC}"
"c:\windows\System32\Tasks\{1C555A98-377E-459A-8674-86DAA32156CD}"
"c:\windows\System32\Tasks\{324E37C0-776D-40BB-B5D1-593BF0D298C3}"
"c:\windows\System32\Tasks\{450DCDB0-471A-43F2-A9EF-15FD9E5B854C}"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\AVAST Software
c:\programdata\AVAST Software
c:\users\Milan\AppData\Local\digipen
c:\users\Milan\AppData\Local\digipen\nitronic_rush\userdata.xml
c:\users\Milan\AppData\Local\SwvUpdater
c:\users\Milan\AppData\Local\SwvUpdater\status.cfg
c:\users\Milan\AppData\Local\SwvUpdater\Updater.xml
c:\users\Milan\AppData\Roaming\digipen
c:\users\Milan\AppData\Roaming\Seznam.cz
c:\users\Milan\AppData\Roaming\Seznam.cz\bin\16068libfoxloader-x64.dll
c:\users\Milan\AppData\Roaming\Seznam.cz\bin\16068libfoxloader.dll
c:\users\Milan\AppData\Roaming\Seznam.cz\bin\ffkill.exe
c:\users\Milan\AppData\Roaming\Seznam.cz\bin\libfoxcub-x64.dll
c:\users\Milan\AppData\Roaming\Seznam.cz\bin\libfoxcub.dll
c:\users\Milan\AppData\Roaming\Seznam.cz\bin\libchinst.dll
c:\users\Milan\AppData\Roaming\Seznam.cz\bin\lightspeed.dll
c:\users\Milan\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
c:\users\Milan\AppData\Roaming\Seznam.cz\bin\msvcp100.dll
c:\users\Milan\AppData\Roaming\Seznam.cz\bin\msvcr100.dll
c:\users\Milan\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
c:\users\Milan\AppData\Roaming\Seznam.cz\bin\unlockInstance.dll
c:\users\Milan\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe
c:\users\Milan\AppData\Roaming\Seznam.cz\conf\libfoxcub\emailstates.conf
c:\users\Milan\AppData\Roaming\Seznam.cz\conf\libfoxcub\foxcub.conf
c:\users\Milan\AppData\Roaming\Seznam.cz\conf\libfoxcub\regcfg.conf
c:\users\Milan\AppData\Roaming\Seznam.cz\conf\libfoxcub\remote.conf
c:\users\Milan\AppData\Roaming\Seznam.cz\conf\szndesktop.conf
c:\users\Milan\AppData\Roaming\Seznam.cz\conf\szndesktop.d\libfoxcub.conf
c:\users\Milan\AppData\Roaming\Seznam.cz\conf\szndesktop.d\libfoxloader.conf
c:\users\Milan\AppData\Roaming\Seznam.cz\conf\szndesktop.d\libchinst.conf
c:\users\Milan\AppData\Roaming\Seznam.cz\conf\szndesktop.d\unlockInstance.conf
c:\users\Milan\AppData\Roaming\Seznam.cz\conf\unlockInstance.conf
c:\users\Milan\AppData\Roaming\Seznam.cz\data\chrome\partner.conf
c:\users\Milan\AppData\Roaming\Seznam.cz\data\listickaconfig.webpak
c:\users\Milan\AppData\Roaming\Seznam.cz\data\listickanastaveni.webpak
c:\users\Milan\AppData\Roaming\Seznam.cz\data\speeddial.webpak
c:\users\Milan\AppData\Roaming\Seznam.cz\data\szndesktop.webpak
c:\users\Milan\AppData\Roaming\Seznam.cz\install.log
c:\users\Milan\AppData\Roaming\Seznam.cz\install.log.2288.log
c:\users\Milan\AppData\Roaming\Seznam.cz\install\com.microsoft.msdn.msvcr100-10.0.40219.325-win32.zip
c:\users\Milan\AppData\Roaming\Seznam.cz\install\cz.seznam.software.autoupdate-1.0.8-win32.zip
c:\users\Milan\AppData\Roaming\Seznam.cz\install\cz.seznam.software.chromelisticka-1.5.3-win32.zip
c:\users\Milan\AppData\Roaming\Seznam.cz\install\cz.seznam.software.ielisticka3-3.0.57-win32.zip
c:\users\Milan\AppData\Roaming\Seznam.cz\install\cz.seznam.software.libfoxcub-3.0.57-win32.zip
c:\users\Milan\AppData\Roaming\Seznam.cz\install\cz.seznam.software.libfoxloader-3.0.0-win32.zip
c:\users\Milan\AppData\Roaming\Seznam.cz\install\cz.seznam.software.libszndesktop-2.0.18-win32.zip
c:\users\Milan\AppData\Roaming\Seznam.cz\install\cz.seznam.software.lightspeed-1210-12.10.6-win32.zip
c:\users\Milan\AppData\Roaming\Seznam.cz\install\cz.seznam.software.pp-1.0.2-win32.zip
c:\users\Milan\AppData\Roaming\Seznam.cz\install\cz.seznam.software.szndesktop-2.0.18-win32.zip
c:\users\Milan\AppData\Roaming\Seznam.cz\install\cz.seznam.software.szninstall-1.1.9-win32.zip
c:\users\Milan\AppData\Roaming\Seznam.cz\install\cz.seznam.software.sznsetup-1.1.18-win32.zip
c:\users\Milan\AppData\Roaming\Seznam.cz\install\packages.inf
c:\users\Milan\AppData\Roaming\Seznam.cz\install\szn-software-base-1.0.0-win32.zip
c:\users\Milan\AppData\Roaming\Seznam.cz\install\szn-software-fflisticka-2.5.13-win32.zip
c:\users\Milan\AppData\Roaming\Seznam.cz\install\szn-software-listicka-3.0.0-win32.zip
c:\users\Milan\AppData\Roaming\Seznam.cz\packages.inf
c:\users\Milan\AppData\Roaming\Seznam.cz\partner.conf
c:\users\Milan\AppData\Roaming\Seznam.cz\sources.inf
c:\users\Milan\AppData\Roaming\Seznam.cz\szninstall.exe
c:\users\Milan\AppData\Roaming\Seznam.cz\sznsetup.exe
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\com_microsoft_msdn_msvcr100_10_0_40219_325.install.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\com_microsoft_msdn_msvcr100_10_0_40219_325.uninstall.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_autoupdate_1_0_8.install.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_autoupdate_1_0_8.uninstall.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_chromelisticka_1_7_2.install.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_chromelisticka_1_7_2.uninstall.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_ielisticka3_3_1_5.install.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_ielisticka3_3_1_5.uninstall.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_libfoxcub_3_1_5.install.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_libfoxcub_3_1_5.uninstall.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_libfoxcub64_3_1_5.install.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_libfoxcub64_3_1_5.uninstall.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_libfoxloader_3_1_2.install.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_libfoxloader_3_1_2.uninstall.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_libszndesktop_2_0_26.install.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_libszndesktop_2_0_26.reconfigure.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_libszndesktop_2_0_26.uninstall.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_lightspeed_1210_12_10_12.install.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_lightspeed_1210_12_10_12.uninstall.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_pp_1_0_2.install.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_pp_1_0_2.uninstall.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_szndesktop_2_0_26.install.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_szndesktop_2_0_26.uninstall.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_szninstall_1_1_14.install.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_szninstall_1_1_14.uninstall.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_sznsetup_1_2_6.install.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\cz_seznam_software_sznsetup_1_2_6.uninstall.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\szn_software_base_1_0_0.install.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\szn_software_base_1_0_0.uninstall.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\szn_software_fflisticka_2_5_16.install.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\szn_software_fflisticka_2_5_16.uninstall.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\szn_software_listicka_3_0_0.install.bat
c:\users\Milan\AppData\Roaming\Seznam.cz\uninstall\szn_software_listicka_3_0_0.uninstall.bat
c:\windows\System32\Tasks\{079F848D-34FD-4080-8ADE-D4751E09C646}
c:\windows\System32\Tasks\{18240EF2-B80A-43A1-8076-7B23461E57DC}
c:\windows\System32\Tasks\{1C555A98-377E-459A-8674-86DAA32156CD}
c:\windows\System32\Tasks\{324E37C0-776D-40BB-B5D1-593BF0D298C3}
c:\windows\System32\Tasks\{450DCDB0-471A-43F2-A9EF-15FD9E5B854C}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-03-02 do 2014-04-02 )))))))))))))))))))))))))))))))
.
.
2014-04-02 19:28 . 2014-04-02 19:28 -------- d-----w- c:\users\hedev\AppData\Local\temp
2014-04-02 19:28 . 2014-04-02 19:28 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-04-01 15:55 . 2014-03-07 04:43 10521840 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{26FF8D4A-C596-448C-8C38-B1E2502B7EEE}\mpengine.dll
2014-04-01 14:14 . 2014-04-01 14:18 -------- d-----w- C:\FRST
2014-03-31 19:11 . 2014-03-31 19:11 -------- d-----w- c:\programdata\Age of Empires 3
2014-03-31 17:07 . 2014-03-31 17:07 -------- d-----w- c:\users\Milan\AppData\Roaming\My The Lord of the Rings, The Rise of the Witch-king Files
2014-03-31 16:38 . 2014-03-31 17:23 -------- d-----w- c:\users\Milan\AppData\Roaming\My Battle for Middle-earth(tm) II Files
2014-03-30 17:34 . 2014-03-30 17:34 -------- d-----w- c:\users\Milan\AppData\Local\Electronic Arts
2014-03-28 21:09 . 2014-03-28 21:09 -------- d-----w- c:\users\Milan\AppData\Local\ESET
2014-03-28 20:55 . 2014-03-28 20:55 -------- d-----w- c:\program files\ESET
2014-03-28 16:35 . 2014-03-28 16:35 -------- d-----w- c:\users\Milan\AppData\Roaming\Unity
2014-03-28 16:33 . 2014-03-28 16:33 -------- d-----w- c:\users\Milan\AppData\Local\Unity
2014-03-27 18:26 . 2014-03-15 08:41 46704 ----a-w- c:\program files (x86)\Mozilla Firefox\browser\components\browsercomps.dll
2014-03-24 19:12 . 2014-03-24 19:12 -------- d-----w- c:\program files (x86)\MSXML 4.0
2014-03-24 18:02 . 2014-03-24 18:02 -------- d-----w- c:\users\Milan\AppData\Local\NFS Underground 2
2014-03-23 18:11 . 2014-03-23 18:11 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
2014-03-18 18:13 . 2014-03-18 18:27 -------- d-----w- c:\users\Milan\AppData\Local\Temporary Projects
2014-03-17 19:37 . 2014-03-17 19:37 -------- d-----w- c:\users\Milan\AppData\Local\Skype
2014-03-17 19:37 . 2014-03-17 19:37 -------- d-----w- c:\program files (x86)\Common Files\Skype
2014-03-17 19:37 . 2014-03-17 19:37 -------- d-----r- c:\program files (x86)\Skype
2014-03-14 16:50 . 2014-03-14 16:50 -------- d-----w- c:\users\Milan\AppData\Local\DOSBox
2014-03-13 21:39 . 2014-01-28 02:32 228864 ----a-w- c:\windows\system32\wwansvc.dll
2014-03-13 21:39 . 2014-01-29 02:32 484864 ----a-w- c:\windows\system32\wer.dll
2014-03-13 21:39 . 2014-01-29 02:06 381440 ----a-w- c:\windows\SysWow64\wer.dll
2014-03-13 21:36 . 2014-02-04 02:32 624128 ----a-w- c:\windows\system32\qedit.dll
2014-03-13 21:36 . 2014-02-04 02:04 509440 ----a-w- c:\windows\SysWow64\qedit.dll
2014-03-13 21:36 . 2014-02-04 02:32 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-03-13 21:36 . 2014-02-04 02:04 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
2014-03-09 10:41 . 2014-03-09 10:41 66872 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2014-03-09 10:41 . 2014-03-09 10:45 103736 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2014-03-08 20:12 . 2014-03-08 20:12 -------- d-----w- c:\program files (x86)\SimilarSites
2014-03-08 20:11 . 2014-03-08 20:11 -------- d-----w- c:\users\Milan\AppData\Roaming\SimilarSites
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-03-28 21:18 . 2013-03-18 21:35 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-03-28 21:18 . 2013-03-18 21:35 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-03-19 23:58 . 2013-03-20 17:07 90015360 ----a-w- c:\windows\system32\MRT.exe
2014-01-09 12:41 . 2013-08-16 18:04 13468 ----a-w- c:\windows\SysWow64\ealregsnapshot1.reg
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-02-01 18:03 120176 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-03-14 3672640]
"MKLOL"="c:\program files (x86)\MKJogo\MKLOL\MK.exe" [2014-02-17 754888]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2014-02-26 3814736]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"SuiteTray"="c:\program files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2010-02-01 337264]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-03-03 1300560]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-12-24 284696]
"EgisUpdate"="c:\program files (x86)\EgisTec IPS\EgisUpdate.exe" [2009-12-25 201512]
"EgisTecPMMUpdate"="c:\program files (x86)\EgisTec IPS\PmmUpdate.exe" [2009-12-25 401192]
"BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" [2010-03-08 260608]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2013-05-08 41056]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 BRDriver64;BRDriver64;c:\programdata\BitRaider\BRDriver64.sys;c:\programdata\BitRaider\BRDriver64.sys [x]
R3 BRSptSvc;BitRaider Mini-Support Service;c:\programdata\BitRaider\BRSptSvc.exe;c:\programdata\BitRaider\BRSptSvc.exe [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files (x86)\Garena Plus\Room\safedrv.sys;c:\program files (x86)\Garena Plus\Room\safedrv.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x]
R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [x]
R4 RsFx0153;RsFx0153 Driver;c:\windows\system32\DRIVERS\RsFx0153.sys;c:\windows\SYSNATIVE\DRIVERS\RsFx0153.sys [x]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE;c:\program files\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [x]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfp.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys;c:\windows\SYSNATIVE\DRIVERS\EpfwLWF.sys [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDFilter.sys [x]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDNServ.sys [x]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDVDisk.sys [x]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe;c:\program files (x86)\Launch Manager\dsiwmis.exe [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [x]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [x]
S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe;c:\program files (x86)\Acer\Registration\GREGsvc.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x]
S2 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [x]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [x]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [x]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
Obsah adresáře 'Naplánované úlohy'
.
2014-04-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-18 21:18]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-02-01 18:06 137584 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x64\PSDProtect.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2013-08-19 5617432]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-03-23 10134560]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-03-15 365592]
"mwlDaemon"="c:\program files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe" [2010-02-01 349552]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-03-15 165912]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-03-15 387608]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-02-05 860192]
.
------- Doplňkový sken -------
.
uStart Page = about:Tabs
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 178.72.193.142 178.72.195.195
FF - ProfilePath - c:\users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\uvng4vs6.default\
FF - prefs.js: browser.startup.homepage - about:home
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKCU-Run-cz.seznam.software.szndesktop - c:\users\Milan\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe
Wow6432Node-HKCU-Run-cz.seznam.software.autoupdate - c:\users\Milan\AppData\Roaming\Seznam.cz\szninstall.exe
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
AddRemove-Adobe Shockwave Player - c:\windows\System32\Macromed\SHOCKW~1\UNWISE.EXE
AddRemove-SeznamInstall - c:\users\Milan\AppData\Roaming\Seznam.cz\szninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-330137112-1029790119-1089304535-1001\Software\SecuROM\License information*]
"datasecu"=hex:46,5a,dc,b3,4b,79,10,c0,70,f4,01,6a,8f,27,6a,74,bb,65,a6,df,aa,
71,42,b9,62,d4,d9,ac,19,59,76,65,68,3c,7f,ef,74,0f,36,c5,0b,71,37,2e,81,6c,\
"rkeysecu"=hex:db,21,43,6f,e0,9d,63,8b,57,18,97,44,6d,56,9e,2d
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_77_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_77_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.12"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2014-04-02 21:31:15
ComboFix-quarantined-files.txt 2014-04-02 19:31
ComboFix2.txt 2014-04-01 17:29
.
Před spuštěním: Volných bajtů: 28 457 639 936
Po spuštění: Volných bajtů: 28 254 715 904
.
- - End Of File - - 0D56CC22949A93C5603E95A6862CE1F3

Odpovědět