Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Problém s virem JS/Kryptik.I Trojský kůň - Camper

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Camper
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 31 bře 2014 22:45

Problém s virem JS/Kryptik.I Trojský kůň - Camper

#1 Příspěvek od Camper »

Dobrý den,
Vzhledem k tomu, že mám stejný problém, tak nebudu zakládat nový thread, ale přihodím svůj log sem... tedy pokud to není moc velký problém :)

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by msi (administrator) on MSI-MSI on 01-04-2014 00:04:21
Running from C:\Users\msi\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\S-Bar\MSIService.exe
(MSI) C:\Program Files (x86)\MSI\MSI HOUSE\MSIFoundationService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
() C:\Program Files (x86)\HandyUpdater\HandyUpdater.exe
(SqueakyChocolate, LLC) C:\Program Files (x86)\SqueakyChocolate\UpdateChecker\UpdateCheckerApp.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe
() C:\Program Files\Qualcomm Atheros\Killer Network Manager\KillerNetManager.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
(Dropbox, Inc.) C:\Users\msi\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(PasswordBox, Inc.) C:\Program Files (x86)\PasswordBox\pbbtnService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Micro-Star International Co.,Ltd.) C:\Program Files (x86)\S-Bar\S-Bar.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\MSI\KLM\KLM.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe
() C:\Program Files (x86)\MSI\MSI VGA Overclock Tool\VGAOCAP.exe
() C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe
() C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\ToolbarUpdater.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\loggingserver.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Microsoft Corporation) C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) c:\program files\windows defender\MpCmdRun.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2328360 2010-09-16] (Synaptics Incorporated)
HKLM\...\Run: [BTMTrayAgent] - C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [11406608 2011-12-20] (Intel Corporation)
HKLM\...\Run: [THXCfg64] - C:\windows\system32\THXCfg64.dll [25600 2010-09-14] (Creative Technology Ltd.)
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12445288 2012-01-10] (Realtek Semiconductor)
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [2918656 2011-01-12] (ESET)
HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-04] (Intel Corporation)
HKLM-x32\...\Run: [S-Bar] - C:\Program Files (x86)\S-Bar\S-Bar.exe [5499392 2011-11-03] (Micro-Star International Co.,Ltd.)
HKLM-x32\...\Run: [Super-Charger] - C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [502288 2012-01-03] (MSI)
HKLM-x32\...\Run: [KLM] - C:\Program Files (x86)\MSI\KLM\KLM.exe [1522376 2011-12-19] (Micro-Star International Co., Ltd.)
HKLM-x32\...\Run: [THX Audio Control Panel] - C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe [1517056 2011-08-30] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] - C:\windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [VGAOCAP] - C:\Program Files (x86)\MSI\MSI VGA Overclock Tool\VGAOCAP.exe [88576 2012-01-31] ()
HKLM-x32\...\Run: [YouCam Mirage] - C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488 2011-10-13] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] - C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe [230696 2011-10-13] (CyberLink Corp.)
HKLM-x32\...\Run: [NortonOnlineBackup] - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1112920 2010-03-06] (Symantec Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [vProt] - C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2544664 2014-03-20] ()
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2434717301-3026624133-2648855760-1001\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1821888 2014-02-25] (Valve Corporation)
HKU\S-1-5-21-2434717301-3026624133-2648855760-1001\...\Run: [Handy Updater] - C:\Program Files (x86)\HandyUpdater\HandyUpdater.exe [370176 2013-07-05] ()
HKU\S-1-5-21-2434717301-3026624133-2648855760-1001\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673184 2013-07-03] (Disc Soft Ltd)
HKU\S-1-5-21-2434717301-3026624133-2648855760-1001\...\Run: [UpdateChecker] - C:\Program Files (x86)\SqueakyChocolate\UpdateChecker\UpdateCheckerApp.exe [7168 2013-08-25] (SqueakyChocolate, LLC)
HKU\S-1-5-21-2434717301-3026624133-2648855760-1001\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.)
AppInit_DLLs: C:\windows\system32\nvinitx.dll => C:\windows\system32\nvinitx.dll [247144 2012-08-28] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\windows\SysWOW64\nvinit.dll => C:\windows\SysWOW64\nvinit.dll [202600 2012-08-28] (NVIDIA Corporation)
Startup: C:\Users\msi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\msi\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msi.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://msi.msn.com
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {4089A85C-F3A3-4606-9857-8A8416B57438} URL =
SearchScopes: HKCU - {4089A85C-F3A3-4606-9857-8A8416B57438} URL =
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={511 ... 2013-07-20 15:55:31&v=15.5.0.2&pid=safeguard&sg=0&sap=dsp&q={searchTerms}
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: TmBpIeBHO Class - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\Module\20002\7.1.1104\7.1.1104\TmBpIe64.dll No File
BHO: SmileysWeLoveToolbar - {E4EF8A64-0A30-48F5-B3FE-5FDA978DA775} - C:\Program Files (x86)\Smileys We Love Toolbar for IE\adxloader64.dll ()
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: PasswordBox Helper - {5DB69B97-934B-451D-94DB-32EF802A01CD} - C:\Program Files (x86)\PasswordBox\Application\pbbtn.dll (PasswordBox, Inc.)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.0.5.292\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: TmBpIeBHO Class - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\Module\20002\7.1.1104\7.1.1104\TmBpIe32.dll No File
BHO-x32: SmileysWeLoveToolbar - {E4EF8A64-0A30-48F5-B3FE-5FDA978DA775} - C:\Program Files (x86)\Smileys We Love Toolbar for IE\adxloader.dll ()
Toolbar: HKLM - SmileysWeLove - {CF0F43AB-9C23-4D7B-8040-201B82844854} - C:\Program Files (x86)\Smileys We Love Toolbar for IE\adxloader64.dll ()
Toolbar: HKLM-x32 - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.0.5.292\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
Toolbar: HKLM-x32 - SmileysWeLove - {CF0F43AB-9C23-4D7B-8040-201B82844854} - C:\Program Files (x86)\Smileys We Love Toolbar for IE\adxloader.dll ()
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\7.1.1104\7.1.1104\TmBpIe64.dll No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\7.1.1104\7.1.1104\TmBpIe32.dll No File
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.0.5\ViProtocol.dll (AVG Secure Search)
Winsock: Catalog9 01 C:\windows\SysWOW64\BfLLR.dll [183808] (Bigfoot Networks, Inc.)
Winsock: Catalog9 02 C:\windows\SysWOW64\BfLLR.dll [183808] (Bigfoot Networks, Inc.)
Winsock: Catalog9 03 C:\windows\SysWOW64\BfLLR.dll [183808] (Bigfoot Networks, Inc.)
Winsock: Catalog9 04 C:\windows\SysWOW64\BfLLR.dll [183808] (Bigfoot Networks, Inc.)
Winsock: Catalog9 16 C:\windows\SysWOW64\BfLLR.dll [183808] (Bigfoot Networks, Inc.)
Winsock: Catalog9-x64 01 %SYSTEMROOT%\system32\BfLLR.dll [200704] (Bigfoot Networks, Inc.)
Winsock: Catalog9-x64 02 %SYSTEMROOT%\system32\BfLLR.dll [200704] (Bigfoot Networks, Inc.)
Winsock: Catalog9-x64 03 %SYSTEMROOT%\system32\BfLLR.dll [200704] (Bigfoot Networks, Inc.)
Winsock: Catalog9-x64 04 %SYSTEMROOT%\system32\BfLLR.dll [200704] (Bigfoot Networks, Inc.)
Winsock: Catalog9-x64 16 %SYSTEMROOT%\system32\BfLLR.dll [200704] (Bigfoot Networks, Inc.)
Tcpip\Parameters: [DhcpNameServer] 193.84.32.93 193.84.47.225 195.113.144.233

FireFox:
========
FF ProfilePath: C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default
FF DefaultSearchEngine: AVG Secure Search
FF SelectedSearchEngine: AVG Secure Search
FF Homepage: https://www.google.cz/?gws_rd=cr
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.0.5\\npsitesafety.dll (AVG Technologies)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: anvisoft.com/AdblockPlugin - C:\ProgramData\Anvisoft\Anvi Smart Defender 2\extensions\npAdblockPlugin.dll No File
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default\searchplugins\conduit.xml
FF SearchPlugin: C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default\searchplugins\safeguard-secure-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\safeguard-secure-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: WebSite Recommendation - C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default\Extensions\WebSiteRecommendation@weliketheweb.com [2014-03-20]
FF Extension: BS Player ControlBar - C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default\Extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} [2013-12-11]
FF Extension: SmileysWeLove: Smileys for use with Facebook, GMail, and more - C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default\Extensions\jid1-vW9nopuIAJiRHw@jetpack.xpi [2013-10-20]
FF Extension: NASA Night Launch - C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default\Extensions\nasanightlaunch@example.com.xpi [2013-07-22]
FF Extension: Adblock Plus - C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-03-01]
FF HKLM-x32\...\Firefox\Extensions: [{38783831-6098-4faa-A9C9-1EE1E343F4D2}] - C:\Program Files\Trend Micro\AMSP\Module\20002\7.1.1104\7.1.1104\firefoxextension
FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.0.5.292
FF Extension: AVG SafeGuard toolbar - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.0.5.292 [2014-03-20]
FF HKLM-x32\...\Firefox\Extensions: [firefox@passwordbox.com] - C:\Program Files (x86)\PasswordBox\Firefox
FF Extension: PasswordBox - C:\Program Files (x86)\PasswordBox\Firefox [2013-11-21]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2013-08-18]

Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (Docs) - C:\Users\msi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-09-25]
CHR Extension: (Google Drive) - C:\Users\msi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-09-25]
CHR Extension: (YouTube) - C:\Users\msi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-09-25]
CHR Extension: (Google Search) - C:\Users\msi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-09-25]
CHR Extension: (AVG SafeGuard) - C:\Users\msi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof [2013-09-25]
CHR Extension: (Chrome In-App Payments service) - C:\Users\msi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-25]
CHR Extension: (No Name) - C:\Users\msi\AppData\Local\Google\Chrome\User Data\Default\Extensions\olakgnkoldmagdblaalodobkmeokmgjj [2013-07-20]
CHR Extension: (Gmail) - C:\Users\msi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-09-25]
CHR HKLM-x32\...\Chrome\Extension: [lhmiofmipcpmhgihiecmpiekcacigpgb] - C:\ProgramData\Anvisoft\Anvi Smart Defender 2\extensions\chrome.crx [2013-09-25]
CHR HKLM-x32\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG SafeGuard toolbar\ChromeExt\18.0.5.292\avg.crx [2014-03-20]

==================== Services (Whitelisted) =================

S3 EhttpSrv; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [42360 2011-01-12] (ESET)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [810144 2011-01-12] (ESET)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.)
R2 Micro Star SCM; C:\Program Files (x86)\S-Bar\MSIService.exe [160768 2011-11-03] (Micro-Star International Co., Ltd.)
R2 MSI Foundation Service; C:\Program Files (x86)\MSI\MSI HOUSE\MSIFoundationService.exe [12800 2010-07-17] (MSI)
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [138768 2012-01-03] (MSI)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2782552 2010-03-06] (Symantec Corporation)
R2 PasswordBox; C:\Program Files (x86)\PasswordBox\pbbtnService.exe [67584 2013-11-01] (PasswordBox, Inc.)
R2 Qualcomm Atheros Killer Service; C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [492032 2012-03-08] ()
R2 vToolbarUpdater18.0.5; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\ToolbarUpdater.exe [1771032 2014-03-20] (AVG Secure Search)

==================== Drivers (Whitelisted) ====================

S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [32768 2010-04-29] (Google Inc)
R1 asd2fsm; C:\Windows\System32\DRIVERS\asd2fsm.sys [35344 2014-03-27] (Anvisoft)
R1 avgtp; C:\windows\system32\drivers\avgtpx64.sys [49952 2014-03-20] (AVG Technologies)
R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [75880 2012-03-08] (Bigfoot Networks, Inc.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-08-22] (Disc Soft Ltd)
R2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [170640 2010-12-21] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [141264 2010-12-21] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [170640 2010-12-21] (ESET)
R3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [34144 2010-12-21] (ESET)
R2 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [50624 2010-12-21] (ESET)
R3 L1C; C:\Windows\System32\DRIVERS\e22w7x64.sys [161616 2012-03-08] (Qualcomm Atheros, Inc.)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [14136 2010-01-18] (MSI)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 efavdrv; \??\C:\windows\system32\drivers\efavdrv.sys [X]
S3 MGHwCtrl; \??\C:\Program Files\MSI\MSI Software Install\MGHwCtrl.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-04-01 00:04 - 2014-04-01 00:04 - 00023181 _____ () C:\Users\msi\Desktop\FRST.txt
2014-04-01 00:04 - 2014-04-01 00:04 - 00000000 ____D () C:\FRST
2014-04-01 00:03 - 2014-04-01 00:03 - 02157056 _____ (Farbar) C:\Users\msi\Desktop\FRST64.exe
2014-04-01 00:02 - 2014-04-01 00:02 - 00029696 _____ () C:\Users\msi\AppData\Local\MSGBOX.EXE
2014-04-01 00:02 - 2014-04-01 00:02 - 00015327 _____ () C:\Users\msi\Desktop\LM.bat
2014-04-01 00:01 - 2014-04-01 00:01 - 00112640 _____ (forum.viry.cz) C:\Users\msi\Desktop\FRSTLauncher.exe
2014-03-31 23:54 - 2014-03-31 23:54 - 00000000 ____D () C:\rsit
2014-03-31 23:54 - 2014-03-31 23:54 - 00000000 ____D () C:\Program Files\trend micro
2014-03-31 23:53 - 2014-03-31 23:53 - 00832273 _____ () C:\Users\msi\Downloads\RSITx64.exe
2014-03-31 17:45 - 2014-03-31 17:45 - 02991832 _____ (ESET) C:\Users\msi\Downloads\ERARemover_x64.exe
2014-03-31 17:41 - 2014-03-31 17:41 - 02347384 _____ (ESET) C:\Users\msi\Downloads\esetsmartinstaller_csy.exe
2014-03-31 17:41 - 2014-03-31 17:41 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-03-31 17:32 - 2014-03-31 17:32 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-03-31 17:31 - 2014-03-31 17:31 - 32652456 _____ (Anvisoft) C:\Users\msi\Downloads\asdsetup.exe
2014-03-31 17:31 - 2014-03-31 17:31 - 00000000 ____D () C:\ProgramData\Anvisoft
2014-03-31 17:31 - 2014-03-31 17:31 - 00000000 ____D () C:\Program Files (x86)\Anvisoft
2014-03-31 17:31 - 2014-03-27 07:24 - 00035344 _____ (Anvisoft) C:\windows\system32\Drivers\asd2fsm.sys
2014-03-31 13:59 - 2014-03-31 14:00 - 04514475 _____ () C:\Users\msi\Downloads\bombic.zip
2014-03-29 22:16 - 2014-03-29 22:16 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-27 07:24 - 2014-03-27 07:24 - 00047632 _____ (Anvisoft) C:\windows\system32\Drivers\asdids.sys
2014-03-23 20:37 - 2014-03-23 20:37 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-23 20:37 - 2014-03-23 20:37 - 00000000 ____D () C:\Users\msi\AppData\Local\Skype
2014-03-23 02:16 - 2014-03-23 17:15 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-03-20 22:51 - 2014-03-20 22:51 - 00000000 ____D () C:\ProgramData\AVG Secure Search
2014-03-16 19:58 - 2014-03-16 19:59 - 00000000 ____D () C:\windows\system32\MRT
2014-03-16 19:58 - 2014-03-02 15:05 - 90015360 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-03-16 13:15 - 2014-03-16 13:15 - 00000000 ____D () C:\Users\msi\AppData\Local\Skyrim
2014-03-16 13:14 - 2014-03-16 13:14 - 00003633 _____ () C:\Users\msi\Downloads\steam.rar
2014-03-16 12:45 - 2014-03-16 12:45 - 01141680 _____ () C:\Users\msi\Downloads\SteamSetup.exe
2014-03-15 15:58 - 2014-03-16 12:05 - 2962702336 _____ () C:\Users\msi\Downloads\The-Elder-Scrolls-V-Skyrim---Legendary-Edition-CZ-REPAK.iso
2014-03-14 18:46 - 2014-03-17 15:01 - 00000000 ____D () C:\Users\msi\AppData\Local\Windows Live
2014-03-14 18:46 - 2014-03-14 18:46 - 00000000 ____D () C:\Users\msi\AppData\Local\{465A3A6E-4265-4539-82E6-384E96356AD5}
2014-03-14 18:43 - 2014-03-26 17:35 - 00000000 ____D () C:\Users\msi\Documents\moto
2014-03-13 14:30 - 2014-03-13 14:30 - 00000000 ____D () C:\Users\Public\CyberLink
2014-03-13 13:42 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-03-13 13:42 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-03-13 13:42 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-03-13 13:42 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-03-13 13:42 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-03-13 13:42 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-03-13 13:42 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-03-13 13:42 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-03-13 13:42 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
2014-03-13 13:42 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\windows\SysWOW64\wer.dll
2014-03-13 13:42 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll
2014-03-13 13:41 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-03-13 13:41 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-03-13 13:41 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-03-13 13:41 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-03-13 13:41 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-03-13 13:41 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-03-13 13:41 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-03-13 13:41 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-03-13 13:41 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-03-13 13:41 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-03-13 13:41 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-03-13 13:41 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-03-13 13:41 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-03-13 13:41 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-03-13 13:41 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-03-13 13:41 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-03-13 13:41 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-03-13 13:41 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-03-13 13:41 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-03-13 13:41 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-03-13 13:41 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-03-13 13:41 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-03-13 13:41 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-03-13 13:41 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-03-13 13:41 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-03-13 13:41 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-03-13 13:41 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-03-13 13:41 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-03-13 13:41 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-03-13 13:41 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-03-13 13:41 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-03-13 13:41 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-03-13 13:41 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-03-13 13:41 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2014-03-13 13:41 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2014-03-13 13:41 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
2014-03-13 13:41 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\windows\SysWOW64\qedit.dll
2014-03-07 13:24 - 2014-03-07 13:30 - 108324724 _____ () C:\Users\msi\Downloads\Deuce---Nine-Lives-(2012)-(by-Mexiicek).rar
2014-03-03 18:35 - 2014-03-03 18:35 - 00301960 _____ () C:\windows\Minidump\030314-20560-01.dmp

==================== One Month Modified Files and Folders =======

2014-04-01 00:04 - 2014-04-01 00:04 - 00023181 _____ () C:\Users\msi\Desktop\FRST.txt
2014-04-01 00:04 - 2014-04-01 00:04 - 00000000 ____D () C:\FRST
2014-04-01 00:03 - 2014-04-01 00:03 - 02157056 _____ (Farbar) C:\Users\msi\Desktop\FRST64.exe
2014-04-01 00:02 - 2014-04-01 00:02 - 00029696 _____ () C:\Users\msi\AppData\Local\MSGBOX.EXE
2014-04-01 00:02 - 2014-04-01 00:02 - 00015327 _____ () C:\Users\msi\Desktop\LM.bat
2014-04-01 00:01 - 2014-04-01 00:01 - 00112640 _____ (forum.viry.cz) C:\Users\msi\Desktop\FRSTLauncher.exe
2014-03-31 23:54 - 2014-03-31 23:54 - 00000000 ____D () C:\rsit
2014-03-31 23:54 - 2014-03-31 23:54 - 00000000 ____D () C:\Program Files\trend micro
2014-03-31 23:53 - 2014-03-31 23:53 - 00832273 _____ () C:\Users\msi\Downloads\RSITx64.exe
2014-03-31 23:53 - 2013-09-25 18:51 - 00000946 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-31 23:51 - 2013-07-17 17:11 - 00000000 ____D () C:\Users\msi\AppData\Roaming\Skype
2014-03-31 23:20 - 2013-07-17 16:59 - 00000914 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-03-31 21:19 - 2009-07-14 06:51 - 00080361 _____ () C:\windows\setupact.log
2014-03-31 20:53 - 2013-09-25 18:51 - 00000942 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-31 19:32 - 2013-07-11 13:22 - 01364808 _____ () C:\windows\WindowsUpdate.log
2014-03-31 18:41 - 2009-07-14 06:45 - 00031712 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-31 18:41 - 2009-07-14 06:45 - 00031712 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-31 18:40 - 2012-05-18 10:04 - 00680522 _____ () C:\windows\system32\perfh005.dat
2014-03-31 18:40 - 2012-05-18 10:04 - 00145490 _____ () C:\windows\system32\perfc005.dat
2014-03-31 18:40 - 2009-07-14 07:13 - 01615286 _____ () C:\windows\system32\PerfStringBackup.INI
2014-03-31 18:35 - 2013-11-25 21:54 - 00000000 ___RD () C:\Users\msi\Dropbox
2014-03-31 18:35 - 2013-11-25 21:53 - 00000000 ____D () C:\Users\msi\AppData\Roaming\Dropbox
2014-03-31 18:35 - 2012-05-19 01:23 - 00000000 ____D () C:\ProgramData\Bigfoot Networks
2014-03-31 18:34 - 2013-07-17 16:16 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-03-31 18:33 - 2010-11-21 05:47 - 00753676 _____ () C:\windows\PFRO.log
2014-03-31 18:33 - 2010-01-01 01:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-03-31 18:33 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-03-31 18:31 - 2014-01-28 20:57 - 00000000 ____D () C:\Users\msi\AppData\Local\Battle.net
2014-03-31 17:46 - 2013-08-18 20:57 - 00000000 ____D () C:\ProgramData\ESET
2014-03-31 17:45 - 2014-03-31 17:45 - 02991832 _____ (ESET) C:\Users\msi\Downloads\ERARemover_x64.exe
2014-03-31 17:41 - 2014-03-31 17:41 - 02347384 _____ (ESET) C:\Users\msi\Downloads\esetsmartinstaller_csy.exe
2014-03-31 17:41 - 2014-03-31 17:41 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-03-31 17:32 - 2014-03-31 17:32 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-03-31 17:31 - 2014-03-31 17:31 - 32652456 _____ (Anvisoft) C:\Users\msi\Downloads\asdsetup.exe
2014-03-31 17:31 - 2014-03-31 17:31 - 00000000 ____D () C:\ProgramData\Anvisoft
2014-03-31 17:31 - 2014-03-31 17:31 - 00000000 ____D () C:\Program Files (x86)\Anvisoft
2014-03-31 14:00 - 2014-03-31 13:59 - 04514475 _____ () C:\Users\msi\Downloads\bombic.zip
2014-03-30 15:42 - 2013-08-22 17:24 - 00000000 ____D () C:\Users\msi\Documents\My Games
2014-03-30 15:01 - 2013-07-17 16:12 - 00000000 ____D () C:\Users\msi\AppData\Local\PMB Files
2014-03-30 15:01 - 2013-07-17 16:12 - 00000000 ____D () C:\ProgramData\PMB Files
2014-03-29 22:16 - 2014-03-29 22:16 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-28 13:52 - 2013-07-20 15:55 - 00000000 ____D () C:\ProgramData\AVG SafeGuard toolbar
2014-03-28 11:14 - 2009-07-14 07:08 - 00032570 _____ () C:\windows\Tasks\SCHEDLGU.TXT
2014-03-27 22:33 - 2013-11-21 16:31 - 00000000 ____D () C:\Program Files (x86)\PasswordBox
2014-03-27 07:24 - 2014-03-31 17:31 - 00035344 _____ (Anvisoft) C:\windows\system32\Drivers\asd2fsm.sys
2014-03-27 07:24 - 2014-03-27 07:24 - 00047632 _____ (Anvisoft) C:\windows\system32\Drivers\asdids.sys
2014-03-26 17:35 - 2014-03-14 18:43 - 00000000 ____D () C:\Users\msi\Documents\moto
2014-03-23 20:37 - 2014-03-23 20:37 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-23 20:37 - 2014-03-23 20:37 - 00000000 ____D () C:\Users\msi\AppData\Local\Skype
2014-03-23 20:37 - 2013-07-17 17:11 - 00000000 ____D () C:\ProgramData\Skype
2014-03-23 17:15 - 2014-03-23 02:16 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-03-22 14:31 - 2014-01-28 20:57 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-03-21 09:22 - 2013-07-20 15:55 - 00000000 ____D () C:\Users\msi\AppData\Local\AVG SafeGuard toolbar
2014-03-20 22:51 - 2014-03-20 22:51 - 00000000 ____D () C:\ProgramData\AVG Secure Search
2014-03-20 22:51 - 2013-07-20 15:55 - 00049952 _____ (AVG Technologies) C:\windows\system32\Drivers\avgtpx64.sys
2014-03-20 22:51 - 2013-07-20 15:55 - 00003738 _____ () C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
2014-03-20 22:51 - 2013-07-20 15:55 - 00000000 ____D () C:\Program Files (x86)\AVG SafeGuard toolbar
2014-03-19 11:04 - 2013-07-03 08:53 - 00000000 ____D () C:\Users\msi\Documents\CULS
2014-03-17 15:01 - 2014-03-14 18:46 - 00000000 ____D () C:\Users\msi\AppData\Local\Windows Live
2014-03-16 19:59 - 2014-03-16 19:58 - 00000000 ____D () C:\windows\system32\MRT
2014-03-16 19:59 - 2013-09-24 17:15 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-03-16 13:15 - 2014-03-16 13:15 - 00000000 ____D () C:\Users\msi\AppData\Local\Skyrim
2014-03-16 13:15 - 2013-07-17 16:51 - 00000000 ___RD () C:\Users\msi\Desktop\ 
2014-03-16 13:14 - 2014-03-16 13:14 - 00003633 _____ () C:\Users\msi\Downloads\steam.rar
2014-03-16 12:54 - 2013-08-22 17:18 - 00000000 ____D () C:\Program Files (x86)\Bethesda Softworks
2014-03-16 12:45 - 2014-03-16 12:45 - 01141680 _____ () C:\Users\msi\Downloads\SteamSetup.exe
2014-03-16 12:05 - 2014-03-15 15:58 - 2962702336 _____ () C:\Users\msi\Downloads\The-Elder-Scrolls-V-Skyrim---Legendary-Edition-CZ-REPAK.iso
2014-03-14 22:31 - 2013-11-11 02:21 - 00000000 ____D () C:\Users\msi\Downloads\Subs
2014-03-14 22:02 - 2014-01-28 22:03 - 00000000 ____D () C:\Program Files (x86)\Hearthstone
2014-03-14 18:46 - 2014-03-14 18:46 - 00000000 ____D () C:\Users\msi\AppData\Local\{465A3A6E-4265-4539-82E6-384E96356AD5}
2014-03-14 09:18 - 2009-07-14 06:45 - 00437320 _____ () C:\windows\system32\FNTCACHE.DAT
2014-03-14 09:17 - 2013-09-25 00:52 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-14 09:17 - 2013-09-25 00:52 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-03-13 14:31 - 2013-07-12 14:15 - 00000000 ____D () C:\Users\msi\Documents\Youcam
2014-03-13 14:30 - 2014-03-13 14:30 - 00000000 ____D () C:\Users\Public\CyberLink
2014-03-12 16:20 - 2013-09-10 20:20 - 05777288 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerInstaller.exe
2014-03-12 16:20 - 2013-07-17 16:59 - 00003852 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-03-12 16:20 - 2012-05-19 02:07 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-03-12 16:20 - 2012-05-19 02:07 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-07 13:30 - 2014-03-07 13:24 - 108324724 _____ () C:\Users\msi\Downloads\Deuce---Nine-Lives-(2012)-(by-Mexiicek).rar
2014-03-03 18:35 - 2014-03-03 18:35 - 00301960 _____ () C:\windows\Minidump\030314-20560-01.dmp
2014-03-03 18:35 - 2013-07-11 13:51 - 00000000 ____D () C:\windows\Minidump
2014-03-03 18:35 - 2013-07-11 13:50 - 779360882 _____ () C:\windows\MEMORY.DMP
2014-03-02 17:22 - 2014-03-01 22:42 - 01590208 _____ () C:\windows\SysWOW64\PerfStringBackup.INI
2014-03-02 15:05 - 2014-03-16 19:58 - 90015360 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe

Some content of TEMP:
====================
C:\Users\msi\AppData\Local\Temp\DSETUP.dll
C:\Users\msi\AppData\Local\Temp\dsetup32.dll
C:\Users\msi\AppData\Local\Temp\DXSETUP.exe
C:\Users\msi\AppData\Local\Temp\oi_{159361F7-B707-426B-972B-A75E87DD4C89}.exe
C:\Users\msi\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\msi\AppData\Local\Temp\YSPCUNLR.dll


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-03-20 20:15

==================== End Of Log ============================
Přílohy
Addition.rar
(10.66 KiB) Staženo 73 x

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problém s virem JS/Kryptik.I Trojský kůň - Camper

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Tema jsem Vam oddelil - do cizich se nevstupuje
Pravidla fora píše:4. Na svůj problém si založte jen jedno téma - založením témat do více sekcí řešení neuspíší, ba naopak problém znepřehledníte a jen přidáte práci rádcům a moderátorům. Taktéž nevkládejte žádost o pomoc do cizího tématu, jen tím uděláte rádci v tématu guláš.
:arrow: Stahnete Malwarebytes' Anti-Malware (zkracene MBAM) http://forum.viry.cz/viewtopic.php?f=29&t=115222
  • Provedte aktualizaci
  • Provedte uplny sken - nic nemazte :!:
  • MBAM miva obcas falesne detekce, proto vlozte log do prispevku a pockejte na posouzeni
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Camper
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 31 bře 2014 22:45

Re: Problém s virem JS/Kryptik.I Trojský kůň - Camper

#3 Příspěvek od Camper »

Takže zde je MBAM Log:

Malwarebytes Anti-Malware
http://www.malwarebytes.org

Scan Date: 1.4.2014
Scan Time: 12:50:18
Logfile: MBAM Log.txt
Administrator: Yes

Version: 2.00.0.1000
Malware Database: v2014.04.01.02
Rootkit Database: v2014.03.27.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Chameleon: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: msi

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 304516
Time Elapsed: 10 min, 30 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled

Processes: 2
PUP.Optional.Handy.A, C:\Program Files (x86)\HandyUpdater\HandyUpdater.exe, 2816, Delete-on-Reboot, [44e2190c443757dff27e42d1d72ac739]
PUP.Optional.SqueakyChocolate.A, C:\Program Files (x86)\SqueakyChocolate\UpdateChecker\UpdateCheckerApp.exe, 2840, Delete-on-Reboot, [32f4e441ed8e47ef795c5e2712f18a76]

Modules: 1
PUP.Optional.SqueakyChocolate.A, C:\Program Files (x86)\SqueakyChocolate\UpdateChecker\UpdaterLibrary.dll, Delete-on-Reboot, [4dd90421512a7abc6b52f35ed72b847c],

Registry Keys: 21
PUP.Optional.SmileysWeLove.A, HKLM\SOFTWARE\CLASSES\CLSID\{CF0F43AB-9C23-4D7B-8040-201B82844854}, Quarantined, [a77f1f06b9c265d150920936da28d22e],
PUP.Optional.SmileysWeLove.A, HKLM\SOFTWARE\CLASSES\CLSID\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775}, Quarantined, [a77f1f06b9c265d150920936da28d22e],
PUP.Optional.SmileysWeLove.A, HKLM\SOFTWARE\CLASSES\SmileysWeLoveToolbar.IEModule, Quarantined, [a77f1f06b9c265d150920936da28d22e],
PUP.Optional.SmileysWeLove.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775}, Quarantined, [a77f1f06b9c265d150920936da28d22e],
PUP.Optional.SmileysWeLove.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775}, Quarantined, [a77f1f06b9c265d150920936da28d22e],
PUP.Optional.SmileysWeLove.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SmileysWeLoveToolbar.IEModule, Quarantined, [a77f1f06b9c265d150920936da28d22e],
PUP.Optional.SmileysWeLove.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775}, Quarantined, [a77f1f06b9c265d150920936da28d22e],
PUP.Optional.SmileysWeLove.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CF0F43AB-9C23-4D7B-8040-201B82844854}, Quarantined, [a77f1f06b9c265d150920936da28d22e],
PUP.Optional.SmileysWeLove.A, HKLM\SOFTWARE\CLASSES\SmileysWeLoveToolbar.SWLIEToolbar, Quarantined, [a77f1f06b9c265d150920936da28d22e],
PUP.Optional.SmileysWeLove.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SmileysWeLoveToolbar.SWLIEToolbar, Quarantined, [a77f1f06b9c265d150920936da28d22e],
PUP.Optional.SmileysWeLove.A, HKU\S-1-5-21-2434717301-3026624133-2648855760-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{CF0F43AB-9C23-4D7B-8040-201B82844854}, Quarantined, [a77f1f06b9c265d150920936da28d22e],
PUP.Optional.SmileysWeLove.A, HKU\S-1-5-21-2434717301-3026624133-2648855760-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{CF0F43AB-9C23-4D7B-8040-201B82844854}, Quarantined, [a77f1f06b9c265d150920936da28d22e],
PUP.Optional.SmileysWeLove.A, HKU\S-1-5-21-2434717301-3026624133-2648855760-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775}, Quarantined, [a77f1f06b9c265d150920936da28d22e],
PUP.Optional.SmileysWeLove.A, HKU\S-1-5-21-2434717301-3026624133-2648855760-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775}, Quarantined, [a77f1f06b9c265d150920936da28d22e],
PUP.Optional.SmileysWeLove.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775}, Quarantined, [a77f1f06b9c265d150920936da28d22e],
PUP.Optional.SmileysWeLove.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775}, Quarantined, [a77f1f06b9c265d150920936da28d22e],
PUP.Optional.SmileysWeLove.A, HKLM\SOFTWARE\CLASSES\CLSID\{E4EF8A64-0A30-48F5-B3FE-5FDA978DA775}\INPROCSERVER32, Quarantined, [a77f1f06b9c265d150920936da28d22e],
PUP.Optional.Conduit.A, HKU\S-1-5-21-2434717301-3026624133-2648855760-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\CONDUIT\FF, Quarantined, [a284998caad134025163176df310a45c],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2434717301-3026624133-2648855760-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Quarantined, [6bbbe342fb803006c624a3c5f60c14ec],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2434717301-3026624133-2648855760-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Quarantined, [28fedc49d5a6bf77d854a5da2bd8bc44],
PUP.Optional.SqueakyChocolate.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SqueakyChocolate, LLC UpdateChecker, Quarantined, [4dd90421512a7abc6b52f35ed72b847c],

Registry Values: 7
PUP.Optional.Handy.A, HKU\S-1-5-21-2434717301-3026624133-2648855760-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Handy Updater, "C:\Program Files (x86)\HandyUpdater\HandyUpdater.exe", Quarantined, [44e2190c443757dff27e42d1d72ac739]
PUP.Optional.SmileysWeLove.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{CF0F43AB-9C23-4D7B-8040-201B82844854}, SmileysWeLoveToolbar.IEModule, Quarantined, [a77f1f06b9c265d150920936da28d22e]
PUP.Optional.SmileysWeLove.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{CF0F43AB-9C23-4D7B-8040-201B82844854}, SmileysWeLoveToolbar.IEModule, Quarantined, [a77f1f06b9c265d150920936da28d22e]
PUP.Optional.SmileysWeLove.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{CF0F43AB-9C23-4D7B-8040-201B82844854}, Quarantined, [77af1a0baccfba7cc220370849b90cf4],
PUP.Optional.SmileysWeLove.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{CF0F43AB-9C23-4D7B-8040-201B82844854}, Quarantined, [e1458f96502b51e58161df60f50d58a8],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2434717301-3026624133-2648855760-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0M1S1H1K2U, Quarantined, [28fedc49d5a6bf77d854a5da2bd8bc44]
PUP.Optional.SqueakyChocolate.A, HKU\S-1-5-21-2434717301-3026624133-2648855760-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|UpdateChecker, C:\Program Files (x86)\SqueakyChocolate\UpdateChecker\UpdateCheckerApp.exe, Quarantined, [32f4e441ed8e47ef795c5e2712f18a76]

Registry Data: 0
(No malicious items detected)

Folders: 10
PUP.Optional.SmileysWeLove.A, C:\Program Files (x86)\Smileys We Love Toolbar for IE, Quarantined, [bc6a71b418638aac1ab9fb8af40f649c],
PUP.Optional.SmileysWeLove.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmileysWeLove for IE, Quarantined, [e73f9293e39893a3538151344cb7728e],
PUP.Optional.OpenCandy, C:\Users\msi\AppData\Roaming\OpenCandy, Quarantined, [ab7b55d04b30eb4b8d931f32867c956b],
PUP.Optional.OpenCandy, C:\Users\msi\AppData\Roaming\OpenCandy\A2092507A303484585C9AAA775725BFE, Quarantined, [ab7b55d04b30eb4b8d931f32867c956b],
PUP.Optional.Conduit.A, C:\Users\msi\AppData\Local\Temp\CT1750559, Quarantined, [2204e342e09bc96d0296a8a9da2825db],
PUP.Optional.Conduit.A, C:\Users\msi\AppData\Local\Temp\CT1750559\xpi, Quarantined, [2204e342e09bc96d0296a8a9da2825db],
PUP.Optional.Conduit.A, C:\Users\msi\AppData\Local\Temp\CT1750559\xpi\defaults, Quarantined, [2204e342e09bc96d0296a8a9da2825db],
PUP.Optional.Conduit.A, C:\Users\msi\AppData\Local\Temp\CT1750559\xpi\defaults\preferences, Quarantined, [2204e342e09bc96d0296a8a9da2825db],
PUP.Optional.SqueakyChocolate.A, C:\Program Files (x86)\SqueakyChocolate\UpdateChecker, Delete-on-Reboot, [4dd90421512a7abc6b52f35ed72b847c],
PUP.Optional.SimilarSites.A, C:\Users\msi\AppData\Roaming\SimilarSites, Quarantined, [c75ff72e2d4e082ecda74514e022e51b],

Files: 37
PUP.Optional.Handy.A, C:\Program Files (x86)\HandyUpdater\HandyUpdater.exe, Delete-on-Reboot, [44e2190c443757dff27e42d1d72ac739],
PUP.Optional.SmileysWeLove.A, C:\Program Files (x86)\Smileys We Love Toolbar for IE\adxloader64.dll, Quarantined, [a77f1f06b9c265d150920936da28d22e],
PUP.Optional.SmileysWeLove.A, C:\Program Files (x86)\Smileys We Love Toolbar for IE\adxloader.dll, Quarantined, [a77f1f06b9c265d150920936da28d22e],
PUP.Optional.Conduit.A, C:\Users\msi\AppData\Local\Temp\CT1750559\ctbe.exe, Quarantined, [34f277ae1566181e364848d63cc402fe],
PUP.Optional.Conduit.A, C:\Users\msi\AppData\Local\Temp\CT1750559\ffLogic.exe, Quarantined, [47df32f3c9b2fc3a0b5d977d02ffdd23],
Trojan.Agent, C:\Users\msi\Downloads\cod2-keygen.exe, Quarantined, [8f9722032d4ed75fffa89d1b9b66728e],
PUP.Optional.Conduit.A, C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default\searchplugins\conduit.xml, Quarantined, [45e1da4b0d6e8aac5c52e57853af9f61],
PUP.Optional.SmileysWeLove.A, C:\Program Files (x86)\Smileys We Love Toolbar for IE\SmileysWeLove.ico, Quarantined, [bc6a71b418638aac1ab9fb8af40f649c],
PUP.Optional.SmileysWeLove.A, C:\Program Files (x86)\Smileys We Love Toolbar for IE\AddinExpress.IE.dll, Quarantined, [bc6a71b418638aac1ab9fb8af40f649c],
PUP.Optional.SmileysWeLove.A, C:\Program Files (x86)\Smileys We Love Toolbar for IE\AddinExpress.IE.tlb, Quarantined, [bc6a71b418638aac1ab9fb8af40f649c],
PUP.Optional.SmileysWeLove.A, C:\Program Files (x86)\Smileys We Love Toolbar for IE\adxloader.dll.manifest, Quarantined, [bc6a71b418638aac1ab9fb8af40f649c],
PUP.Optional.SmileysWeLove.A, C:\Program Files (x86)\Smileys We Love Toolbar for IE\adxloader.exe, Quarantined, [bc6a71b418638aac1ab9fb8af40f649c],
PUP.Optional.SmileysWeLove.A, C:\Program Files (x86)\Smileys We Love Toolbar for IE\adxloader64.exe, Quarantined, [bc6a71b418638aac1ab9fb8af40f649c],
PUP.Optional.SmileysWeLove.A, C:\Program Files (x86)\Smileys We Love Toolbar for IE\adxregistrator.exe, Quarantined, [bc6a71b418638aac1ab9fb8af40f649c],
PUP.Optional.SmileysWeLove.A, C:\Program Files (x86)\Smileys We Love Toolbar for IE\HtmlAgilityPack.dll, Quarantined, [bc6a71b418638aac1ab9fb8af40f649c],
PUP.Optional.SmileysWeLove.A, C:\Program Files (x86)\Smileys We Love Toolbar for IE\Interop.SHDocVw.dll, Quarantined, [bc6a71b418638aac1ab9fb8af40f649c],
PUP.Optional.SmileysWeLove.A, C:\Program Files (x86)\Smileys We Love Toolbar for IE\Microsoft.mshtml.dll, Quarantined, [bc6a71b418638aac1ab9fb8af40f649c],
PUP.Optional.SmileysWeLove.A, C:\Program Files (x86)\Smileys We Love Toolbar for IE\SWLCustomInstaller.dll, Quarantined, [bc6a71b418638aac1ab9fb8af40f649c],
PUP.Optional.SmileysWeLove.A, C:\Program Files (x86)\Smileys We Love Toolbar for IE\SWLCustomInstaller.InstallState, Quarantined, [bc6a71b418638aac1ab9fb8af40f649c],
PUP.Optional.SmileysWeLove.A, C:\Program Files (x86)\Smileys We Love Toolbar for IE\SWLHelperLibrary.dll, Quarantined, [bc6a71b418638aac1ab9fb8af40f649c],
PUP.Optional.SmileysWeLove.A, C:\Program Files (x86)\Smileys We Love Toolbar for IE\SWLSettingsApp.exe, Quarantined, [bc6a71b418638aac1ab9fb8af40f649c],
PUP.Optional.SmileysWeLove.A, C:\Program Files (x86)\Smileys We Love Toolbar for IE\System.Net.Json.dll, Quarantined, [bc6a71b418638aac1ab9fb8af40f649c],
PUP.Optional.SmileysWeLove.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmileysWeLove for IE\SmileysWeLove Settings for IE.lnk, Quarantined, [e73f9293e39893a3538151344cb7728e],
PUP.Optional.SqueakyChocolate.A, C:\Program Files (x86)\SqueakyChocolate\UpdateChecker\UpdateCheckerApp.exe, Delete-on-Reboot, [32f4e441ed8e47ef795c5e2712f18a76],
PUP.Optional.OpenCandy, C:\Users\msi\AppData\Roaming\OpenCandy\A2092507A303484585C9AAA775725BFE\SmileysWeLove_SetupS_cdn.exe, Quarantined, [ab7b55d04b30eb4b8d931f32867c956b],
PUP.Optional.Conduit.A, C:\Users\msi\AppData\Local\Temp\CT1750559\chromeid.txt, Quarantined, [2204e342e09bc96d0296a8a9da2825db],
PUP.Optional.Conduit.A, C:\Users\msi\AppData\Local\Temp\CT1750559\conduit.xml, Quarantined, [2204e342e09bc96d0296a8a9da2825db],
PUP.Optional.Conduit.A, C:\Users\msi\AppData\Local\Temp\CT1750559\CT1750559.xpi, Quarantined, [2204e342e09bc96d0296a8a9da2825db],
PUP.Optional.Conduit.A, C:\Users\msi\AppData\Local\Temp\CT1750559\ddt.csf, Quarantined, [2204e342e09bc96d0296a8a9da2825db],
PUP.Optional.Conduit.A, C:\Users\msi\AppData\Local\Temp\CT1750559\setup.ini.txt, Quarantined, [2204e342e09bc96d0296a8a9da2825db],
PUP.Optional.Conduit.A, C:\Users\msi\AppData\Local\Temp\CT1750559\version.txt, Quarantined, [2204e342e09bc96d0296a8a9da2825db],
PUP.Optional.Conduit.A, C:\Users\msi\AppData\Local\Temp\CT1750559\xpi\install.rdf, Quarantined, [2204e342e09bc96d0296a8a9da2825db],
PUP.Optional.Conduit.A, C:\Users\msi\AppData\Local\Temp\CT1750559\xpi\defaults\preferences\defaults.js, Quarantined, [2204e342e09bc96d0296a8a9da2825db],
PUP.Optional.SqueakyChocolate.A, C:\Program Files (x86)\SqueakyChocolate\UpdateChecker\System.Net.Json.dll, Quarantined, [4dd90421512a7abc6b52f35ed72b847c],
PUP.Optional.SqueakyChocolate.A, C:\Program Files (x86)\SqueakyChocolate\UpdateChecker\uninstall.exe, Quarantined, [4dd90421512a7abc6b52f35ed72b847c],
PUP.Optional.SqueakyChocolate.A, C:\Program Files (x86)\SqueakyChocolate\UpdateChecker\UpdateNotifier.exe, Quarantined, [4dd90421512a7abc6b52f35ed72b847c],
PUP.Optional.SqueakyChocolate.A, C:\Program Files (x86)\SqueakyChocolate\UpdateChecker\UpdaterLibrary.dll, Delete-on-Reboot, [4dd90421512a7abc6b52f35ed72b847c],

Physical Sectors: 0
(No malicious items detected)


(end)

A omlouvám se za práci navíc, asi jsem při rychlém čtení pravidel tohle přeskočil.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problém s virem JS/Kryptik.I Trojský kůň - Camper

#4 Příspěvek od vyosek »

:arrow: Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Camper
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 31 bře 2014 22:45

Re: Problém s virem JS/Kryptik.I Trojský kůň - Camper

#5 Příspěvek od Camper »

takže, zde je Rkill log:

Rkill 2.6.5 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 04/01/2014 08:34:06 PM in x64 mode.
Windows Version: Windows 7 Home Premium Service Pack 1

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* No malware processes found to kill.

Checking Registry for malware related settings:

* No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* Windows Firewall Disabled

[HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = dword:00000000

Checking Windows Service Integrity:

* No issues found.

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* No issues found.

Program finished at: 04/01/2014 08:34:49 PM
Execution time: 0 hours(s), 0 minute(s), and 42 seconds(s)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problém s virem JS/Kryptik.I Trojský kůň - Camper

#6 Příspěvek od vyosek »

Pokracujte ComboFixem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Camper
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 31 bře 2014 22:45

Re: Problém s virem JS/Kryptik.I Trojský kůň - Camper

#7 Příspěvek od Camper »

A zde je CF log:

ComboFix 14-03-24.01 - msi 01.04.2014 20:49:53.2.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.12185.9562 [GMT 2:00]
Spuštěný z: c:\users\msi\Desktop\ComboFix.exe
AV: ESET Smart Security 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-03-01 do 2014-04-01 )))))))))))))))))))))))))))))))
.
.
2014-04-01 18:52 . 2014-04-01 18:52 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-04-01 18:52 . 2014-04-01 18:52 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-04-01 18:44 . 2014-04-01 18:44 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3693CDFF-745F-437A-99BC-74790DE62857}\offreg.dll
2014-04-01 11:30 . 2014-03-07 04:43 10521840 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3693CDFF-745F-437A-99BC-74790DE62857}\mpengine.dll
2014-04-01 10:37 . 2014-04-01 18:34 119512 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-04-01 10:37 . 2014-04-01 10:37 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2014-04-01 10:37 . 2014-04-01 10:37 -------- d-----w- c:\programdata\Malwarebytes
2014-04-01 10:37 . 2014-03-05 07:26 63192 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-04-01 10:37 . 2014-03-05 07:26 88280 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-04-01 10:37 . 2014-03-05 07:26 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-03-31 22:04 . 2014-03-31 22:05 -------- d-----w- C:\FRST
2014-03-31 21:54 . 2014-03-31 21:54 -------- d-----w- C:\rsit
2014-03-31 21:54 . 2014-03-31 21:54 -------- d-----w- c:\program files\trend micro
2014-03-31 15:41 . 2014-03-31 15:41 -------- d-----w- c:\program files (x86)\ESET
2014-03-31 15:32 . 2014-03-31 15:32 -------- d-----w- c:\programdata\boost_interprocess
2014-03-31 15:31 . 2014-03-27 05:24 35344 ----a-w- c:\windows\system32\drivers\asd2fsm.sys
2014-03-31 15:31 . 2014-03-31 15:31 -------- d-----w- c:\programdata\Anvisoft
2014-03-31 15:31 . 2014-03-31 15:31 -------- d-----w- c:\program files (x86)\Anvisoft
2014-03-27 05:24 . 2014-03-27 05:24 47632 ----a-w- c:\windows\system32\drivers\asdids.sys
2014-03-23 18:37 . 2014-03-23 18:37 -------- d-----w- c:\users\msi\AppData\Local\Skype
2014-03-23 18:37 . 2014-03-23 18:37 -------- d-----w- c:\program files (x86)\Common Files\Skype
2014-03-23 18:37 . 2014-03-23 18:37 -------- d-----r- c:\program files (x86)\Skype
2014-03-23 00:16 . 2014-03-23 15:15 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird
2014-03-20 20:51 . 2014-03-20 20:51 -------- d-----w- c:\programdata\AVG Secure Search
2014-03-16 17:58 . 2014-03-16 17:59 -------- d-----w- c:\windows\system32\MRT
2014-03-16 11:15 . 2014-03-16 11:15 -------- d-----w- c:\users\msi\AppData\Local\Skyrim
2014-03-14 16:46 . 2014-03-17 13:01 -------- d-----w- c:\users\msi\AppData\Local\Windows Live
2014-03-13 12:30 . 2014-03-13 12:30 -------- d-----w- c:\users\Public\CyberLink
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-03-20 20:51 . 2013-07-20 13:55 49952 ----a-w- c:\windows\system32\drivers\avgtpx64.sys
2014-03-12 14:20 . 2012-05-19 00:07 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-03-12 14:20 . 2012-05-19 00:07 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-03-12 14:20 . 2013-09-10 18:20 5777288 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2014-03-20 20:51 3486232 ----a-w- c:\program files (x86)\AVG SafeGuard toolbar\18.0.5.292\AVG SafeGuard toolbar_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files (x86)\AVG SafeGuard toolbar\18.0.5.292\AVG SafeGuard toolbar_toolbar.dll" [2014-03-20 3486232]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\users\msi\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\users\msi\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\users\msi\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\Steam.exe" [2014-02-25 1821888]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-07-03 3673184]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2014-02-10 20922016]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-11-29 284440]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-01-04 291608]
"S-Bar"="c:\program files (x86)\S-Bar\S-Bar.exe" [2011-11-03 5499392]
"Super-Charger"="c:\program files (x86)\MSI\Super-Charger\Super-Charger.exe" [2012-01-03 502288]
"KLM"="c:\program files (x86)\MSI\KLM\KLM.exe" [2011-12-19 1522376]
"THX Audio Control Panel"="c:\program files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe" [2011-08-29 1517056]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"VGAOCAP"="c:\program files (x86)\MSI\MSI VGA Overclock Tool\VGAOCAP.exe" [2012-01-31 88576]
"YouCam Mirage"="c:\program files (x86)\CyberLink\YouCam\YCMMirage.exe" [2011-10-13 136488]
"YouCam Tray"="c:\program files (x86)\CyberLink\YouCam\YouCam.exe" [2011-10-13 230696]
"NortonOnlineBackup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2010-03-05 1112920]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"vProt"="c:\program files (x86)\AVG SafeGuard toolbar\vprot.exe" [2014-03-20 2544664]
.
c:\users\msi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\msi\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-1-3 30714328]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.8.141\SSScheduler.exe [2014-1-16 329944]
Qualcomm Atheros Killer Network Manager.lnk - c:\program files\Qualcomm Atheros\Killer Network Manager\KillerNetManager.exe -minimized [2012-3-8 549888]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys;c:\windows\SYSNATIVE\Drivers\androidusb.sys [x]
R3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys [x]
R3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x]
R3 efavdrv;efavdrv;c:\windows\system32\drivers\efavdrv.sys;c:\windows\SYSNATIVE\drivers\efavdrv.sys [x]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [x]
R3 ibtfltcoex;ibtfltcoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.8.141\McCHSvc.exe;c:\program files\McAfee Security Scan\3.8.141\McCHSvc.exe [x]
R3 MGHwCtrl;MGHwCtrl;c:\program files\MSI\MSI Software Install\MGHwCtrl.sys;c:\program files\MSI\MSI Software Install\MGHwCtrl.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;c:\windows\system32\drivers\iusb3hcs.sys;c:\windows\SYSNATIVE\drivers\iusb3hcs.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S1 asd2fsm;asd2fsm;c:\windows\system32\DRIVERS\asd2fsm.sys;c:\windows\SYSNATIVE\DRIVERS\asd2fsm.sys [x]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys;c:\windows\SYSNATIVE\drivers\avgtpx64.sys [x]
S1 BfLwf;Bigfoot Networks Bandwidth Control;c:\windows\system32\DRIVERS\bflwfx64.sys;c:\windows\SYSNATIVE\DRIVERS\bflwfx64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x]
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [x]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [x]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfp.sys [x]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [x]
S2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [x]
S2 Micro Star SCM;Micro Star SCM;c:\program files (x86)\S-Bar\MSIService.exe;c:\program files (x86)\S-Bar\MSIService.exe [x]
S2 MSI Foundation Service;MSI Foundation Service;c:\program files (x86)\MSI\MSI HOUSE\MSIFoundationService.exe;c:\program files (x86)\MSI\MSI HOUSE\MSIFoundationService.exe [x]
S2 MSI_SuperCharger;MSI_SuperCharger;c:\program files (x86)\MSI\Super-Charger\ChargeService.exe;c:\program files (x86)\MSI\Super-Charger\ChargeService.exe [x]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe service;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe service [x]
S2 PasswordBox;PasswordBox;c:\program files (x86)\PasswordBox\pbbtnService.exe;c:\program files (x86)\PasswordBox\pbbtnService.exe [x]
S2 Qualcomm Atheros Killer Service;Qualcomm Atheros Killer Service;c:\program files\Qualcomm Atheros\Killer Network Manager\BFNService.exe;c:\program files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [x]
S2 regi;regi;c:\windows\system32\drivers\regi.sys;c:\windows\SYSNATIVE\drivers\regi.sys [x]
S2 vToolbarUpdater18.0.5;vToolbarUpdater18.0.5;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\ToolbarUpdater.exe;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\ToolbarUpdater.exe [x]
S3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [x]
S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\drivers\iusb3hub.sys;c:\windows\SYSNATIVE\drivers\iusb3hub.sys [x]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\drivers\iusb3xhc.sys;c:\windows\SYSNATIVE\drivers\iusb3xhc.sys [x]
S3 L1C;NDIS Miniport Driver for the Killer e2200 PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\e22w7x64.sys;c:\windows\SYSNATIVE\DRIVERS\e22w7x64.sys [x]
S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x]
S3 NTIOLib_1_0_3;NTIOLib_1_0_3;c:\program files (x86)\MSI\Super-Charger\NTIOLib_X64.sys;c:\program files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [x]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPStor.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - NTIOLIB_1_0_3
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-03-15 20:03 1150280 ----a-w- c:\program files (x86)\Google\Chrome\Application\33.0.1750.154\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-04-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-17 14:20]
.
2014-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-25 16:51]
.
2014-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-25 16:51]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 164016 ----a-w- c:\users\msi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 164016 ----a-w- c:\users\msi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 164016 ----a-w- c:\users\msi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 164016 ----a-w- c:\users\msi\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-12-20 11406608]
"THXCfg64"="c:\windows\system32\THXCfg64.dll" [2010-09-14 25600]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-01-12 170264]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-01-12 398104]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-01-12 440600]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-01-10 12445288]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-01-12 2918656]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 108144]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://msi.msn.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
LSP: %SYSTEMROOT%\system32\BfLLR.dll
TCP: DhcpNameServer = 193.84.32.93 193.84.47.225 195.113.144.233
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.0.5\ViProtocol.dll
FF - ProfilePath - c:\users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default\
FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
FF - prefs.js: browser.startup.homepage - hxxps://www.google.cz/?gws_rd=cr
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2014-04-01 20:53:40
ComboFix-quarantined-files.txt 2014-04-01 18:53
ComboFix2.txt 2014-04-01 18:45
.
Před spuštěním: Volných bajtů: 495 938 617 344
Po spuštění: Volných bajtů: 495 639 642 112
.
- - End Of File - - 434FDC6E520558DC084B6A08C6F15831

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problém s virem JS/Kryptik.I Trojský kůň - Camper

#8 Příspěvek od vyosek »

:arrow: Odinstalujte McAfee Security Scan

:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Camper
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 31 bře 2014 22:45

Re: Problém s virem JS/Kryptik.I Trojský kůň - Camper

#9 Příspěvek od Camper »

Takže zde je AdwC. log:

# AdwCleaner v3.023 - Report created 01/04/2014 at 21:59:44
# Updated 01/04/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : msi - MSI-MSI
# Running from : C:\Users\msi\Desktop\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\AVG SafeGuard toolbar
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\Program Files (x86)\AVG SafeGuard toolbar
Folder Deleted : C:\Program Files (x86)\SimilarSites
Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Deleted : C:\windows\SysWOW64\AI_RecycleBin
[!] Folder Deleted : C:\Users\msi\AppData\Local\AVG SafeGuard toolbar
Folder Deleted : C:\Users\msi\AppData\LocalLow\AVG SafeGuard toolbar
Folder Deleted : C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default\CT1750559
Folder Deleted : C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default\Extensions\WebSiteRecommendation@weliketheweb.com
Folder Deleted : C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default\Extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
Folder Deleted : C:\Users\msi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
File Deleted : C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default\invalidprefs.js
File Deleted : C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default\searchplugins\safeguard-secure-search.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\safeguard-secure-search.xml

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI
Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI.1
Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj
Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj.1
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\AVG SafeGuard toolbar
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Popajar
Key Deleted : HKCU\Software\SmileysWeLove
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKLM\Software\AVG SafeGuard toolbar
Key Deleted : HKLM\Software\AVG Security Toolbar
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG SafeGuard toolbar

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16521


-\\ Mozilla Firefox v28.0 (cs)

[ File : C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default\prefs.js ]

Line Deleted : user_pref("CT1750559.UserID", "UN23547649992436718");
Line Deleted : user_pref("CT1750559.fullUserID", "UN23547649992436718.IN.20130912003025");
Line Deleted : user_pref("CT1750559.installDate", "12/09/2013 00:30:26");
Line Deleted : user_pref("CT1750559.installSessionId", "43bae6a7-19ec-44ff-8737-55fcdce4b573");
Line Deleted : user_pref("CT1750559.installSp", "FALSE");
Line Deleted : user_pref("CT1750559.installerVersion", "1.7.100.1");
Line Deleted : user_pref("CT1750559.searchRevert", "false");
Line Deleted : user_pref("CT1750559.searchUserMode", "1");
Line Deleted : user_pref("CT1750559.versionFromInstaller", "10.20.0.14");
Line Deleted : user_pref("CT1750559.xpeMode", "0");
Line Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Line Deleted : user_pref("browser.search.selectedEngine", "AVG Secure Search");

*************************

AdwCleaner[R0].txt - [8001 octets] - [01/04/2014 21:58:31]
AdwCleaner[S0].txt - [7799 octets] - [01/04/2014 21:59:44]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7859 octets] ##########

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problém s virem JS/Kryptik.I Trojský kůň - Camper

#10 Příspěvek od vyosek »

:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    emptyclsid;
    iedefaults;
    FFdefaults;
    CHRdefaults;
    emptyalltemp;
    resethosts;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Camper
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 31 bře 2014 22:45

Re: Problém s virem JS/Kryptik.I Trojský kůň - Camper

#11 Příspěvek od Camper »

zde je zoek log:


Zoek.exe v5.0.0.0 Updated 07-March-2014
Tool run by msi on st 02.04.2014 at 10:07:17,35.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\msi\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

2.4.2014 10:08:06 Zoek.exe System Restore Point Created Succesfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-2434717301-3026624133-2648855760-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} deleted successfully
HKEY_USERS\S-1-5-21-2434717301-3026624133-2648855760-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\{38783831-6098-4faa-A9C9-1EE1E343F4D2} deleted successfully

==== Deleting Services ======================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vToolbarUpdater18.0.5 deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\vToolbarUpdater18.0.5 deleted successfully

==== FireFox Fix ======================

Deleted from C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default\prefs.js:
user_pref("browser.startup.homepage", "https://www.google.cz/?gws_rd=cr");
user_pref("browser.search.suggest.enabled", false);

Added to C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

Deleted from C:\Users\msi\AppData\Roaming\Thunderbird\Profiles\tnn6ifhf.default\prefs.js:

Added to C:\Users\msi\AppData\Roaming\Thunderbird\Profiles\tnn6ifhf.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

==== Deleting Files \ Folders ======================

"C:\windows\Installer\1ac6acc4.msi" not found
C:\PROGRA~2\SqueakyChocolate deleted
C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted
C:\Users\msi\AppData\Roaming\SqueakyChocolate, LLC deleted
C:\windows\sysWoW64\config\systemprofile\AppData\LocalLow\AVG SafeGuard toolbar deleted
C:\windows\silentOnce.tmp deleted
C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default\jetpack deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"firefox@passwordbox.com"="C:\Program Files (x86)\PasswordBox\Firefox" [21.11.2013 16:31]

==== Firefox Extensions ======================

ProfilePath: C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default
- SmileysWeLove: Smileys for use with Facebook GMail and more - %ProfilePath%\extensions\jid1-vW9nopuIAJiRHw@jetpack.xpi
- NASA Night Launch - %ProfilePath%\extensions\nasanightlaunch@example.com.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default
95812430959AE88CDD0301AB3A71913B - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll - Shockwave Flash


==== Deleted Firefox Extensions ======================

C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default\extensions\jid1-vW9nopuIAJiRHw@jetpack.xpi deleted

==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
lhmiofmipcpmhgihiecmpiekcacigpgb - C:\ProgramData\Anvisoft\Anvi Smart Defender 2\extensions\chrome.crx[]

MSS+ Extension - msi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://msi.msn.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://msi.msn.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{4089A85C-F3A3-4606-9857-8A8416B57438} Unknown Url="Not_Found"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... {startPage}"

==== Reset Google Chrome ======================

C:\Users\msi\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\msi\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-2434717301-3026624133-2648855760-1001\Software\Microsoft\Internet Explorer\SearchScopes\{4089A85C-F3A3-4606-9857-8A8416B57438} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\105E76B4A1674454DB88C3BC32475661 deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\lhmiofmipcpmhgihiecmpiekcacigpgb deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4B67E501-761A-4544-BD88-3CCB23746516} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\105E76B4A1674454DB88C3BC32475661 deleted successfully

==== Empty IE Cache ======================

C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\msi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\msi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\msi\AppData\Local\Mozilla\Firefox\Profiles\b8xv16wq.default\Cache emptied successfully

==== Empty Chrome Cache ======================

C:\Users\msi\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=148 folders=30 15567346 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Default User\AppData\Local\temp emptied successfully
C:\Users\msi\AppData\Local\Temp will be emptied at reboot
C:\Users\Public\AppData\Local\temp emptied successfully
C:\Users\UpdatusUser\AppData\Local\temp emptied successfully
C:\windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\windows\Temp successfully emptied
C:\Users\msi\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on st 02.04.2014 at 10:20:59,99 ======================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problém s virem JS/Kryptik.I Trojský kůň - Camper

#12 Příspěvek od vyosek »

"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Camper
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 31 bře 2014 22:45

Re: Problém s virem JS/Kryptik.I Trojský kůň - Camper

#13 Příspěvek od Camper »

zde je FRST log:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by msi (administrator) on MSI-MSI on 02-04-2014 12:53:43
Running from C:\Users\msi\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\S-Bar\MSIService.exe
(MSI) C:\Program Files (x86)\MSI\MSI HOUSE\MSIFoundationService.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(PasswordBox, Inc.) C:\Program Files (x86)\PasswordBox\pbbtnService.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
() C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
() C:\Program Files\Qualcomm Atheros\Killer Network Manager\KillerNetManager.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Dropbox, Inc.) C:\Users\msi\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Micro-Star International Co.,Ltd.) C:\Program Files (x86)\S-Bar\S-Bar.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\MSI\KLM\KLM.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe
() C:\Program Files (x86)\MSI\MSI VGA Overclock Tool\VGAOCAP.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe
(Blizzard Entertainment) C:\Program Files (x86)\Battle.net\Battle.net.4336\Battle.net.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\msi\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\windows\SysWOW64\cmd.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2328360 2010-09-16] (Synaptics Incorporated)
HKLM\...\Run: [BTMTrayAgent] - C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [11406608 2011-12-20] (Intel Corporation)
HKLM\...\Run: [THXCfg64] - C:\windows\system32\THXCfg64.dll [25600 2010-09-14] (Creative Technology Ltd.)
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12445288 2012-01-10] (Realtek Semiconductor)
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [2918656 2011-01-12] (ESET)
HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-04] (Intel Corporation)
HKLM-x32\...\Run: [S-Bar] - C:\Program Files (x86)\S-Bar\S-Bar.exe [5499392 2011-11-03] (Micro-Star International Co.,Ltd.)
HKLM-x32\...\Run: [Super-Charger] - C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [502288 2012-01-03] (MSI)
HKLM-x32\...\Run: [KLM] - C:\Program Files (x86)\MSI\KLM\KLM.exe [1522376 2011-12-19] (Micro-Star International Co., Ltd.)
HKLM-x32\...\Run: [THX Audio Control Panel] - C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe [1517056 2011-08-30] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] - C:\windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [VGAOCAP] - C:\Program Files (x86)\MSI\MSI VGA Overclock Tool\VGAOCAP.exe [88576 2012-01-31] ()
HKLM-x32\...\Run: [YouCam Mirage] - C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488 2011-10-13] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] - C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe [230696 2011-10-13] (CyberLink Corp.)
HKLM-x32\...\Run: [NortonOnlineBackup] - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1112920 2010-03-06] (Symantec Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2434717301-3026624133-2648855760-1001\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1821888 2014-02-25] (Valve Corporation)
HKU\S-1-5-21-2434717301-3026624133-2648855760-1001\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673184 2013-07-03] (Disc Soft Ltd)
HKU\S-1-5-21-2434717301-3026624133-2648855760-1001\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [247144 2012-08-28] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [202600 2012-08-28] (NVIDIA Corporation)
Startup: C:\Users\msi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\msi\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msi.msn.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {4089A85C-F3A3-4606-9857-8A8416B57438} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: PasswordBox Helper - {5DB69B97-934B-451D-94DB-32EF802A01CD} - C:\Program Files (x86)\PasswordBox\Application\pbbtn.dll (PasswordBox, Inc.)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\7.1.1104\7.1.1104\TmBpIe64.dll No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\7.1.1104\7.1.1104\TmBpIe32.dll No File
Winsock: Catalog9 01 C:\windows\SysWOW64\BfLLR.dll [183808] (Bigfoot Networks, Inc.)
Winsock: Catalog9 02 C:\windows\SysWOW64\BfLLR.dll [183808] (Bigfoot Networks, Inc.)
Winsock: Catalog9 03 C:\windows\SysWOW64\BfLLR.dll [183808] (Bigfoot Networks, Inc.)
Winsock: Catalog9 04 C:\windows\SysWOW64\BfLLR.dll [183808] (Bigfoot Networks, Inc.)
Winsock: Catalog9 16 C:\windows\SysWOW64\BfLLR.dll [183808] (Bigfoot Networks, Inc.)
Winsock: Catalog9-x64 01 %SYSTEMROOT%\system32\BfLLR.dll [200704] (Bigfoot Networks, Inc.)
Winsock: Catalog9-x64 02 %SYSTEMROOT%\system32\BfLLR.dll [200704] (Bigfoot Networks, Inc.)
Winsock: Catalog9-x64 03 %SYSTEMROOT%\system32\BfLLR.dll [200704] (Bigfoot Networks, Inc.)
Winsock: Catalog9-x64 04 %SYSTEMROOT%\system32\BfLLR.dll [200704] (Bigfoot Networks, Inc.)
Winsock: Catalog9-x64 16 %SYSTEMROOT%\system32\BfLLR.dll [200704] (Bigfoot Networks, Inc.)
Tcpip\Parameters: [DhcpNameServer] 193.84.32.93 193.84.47.225 195.113.144.233

FireFox:
========
FF ProfilePath: C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default
FF NewTab: hxxp://www.google.com/
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: anvisoft.com/AdblockPlugin - C:\ProgramData\Anvisoft\Anvi Smart Defender 2\extensions\npAdblockPlugin.dll No File
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: NASA Night Launch - C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default\Extensions\nasanightlaunch@example.com.xpi [2013-07-22]
FF Extension: Adblock Plus - C:\Users\msi\AppData\Roaming\Mozilla\Firefox\Profiles\b8xv16wq.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-03-01]
FF HKLM-x32\...\Firefox\Extensions: [firefox@passwordbox.com] - C:\Program Files (x86)\PasswordBox\Firefox
FF Extension: PasswordBox - C:\Program Files (x86)\PasswordBox\Firefox [2013-11-21]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2013-08-18]

Chrome:
=======
CHR Extension: (Dokumenty Google) - C:\Users\msi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-09-25]
CHR Extension: (Disk Google) - C:\Users\msi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-09-25]
CHR Extension: (YouTube) - C:\Users\msi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-09-25]
CHR Extension: (Vyhledávání Google) - C:\Users\msi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-09-25]
CHR Extension: (Peněženka Google) - C:\Users\msi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-25]
CHR Extension: (Gmail) - C:\Users\msi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-09-25]

==================== Services (Whitelisted) =================

S3 EhttpSrv; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [42360 2011-01-12] (ESET)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [810144 2011-01-12] (ESET)
R2 Micro Star SCM; C:\Program Files (x86)\S-Bar\MSIService.exe [160768 2011-11-03] (Micro-Star International Co., Ltd.)
R2 MSI Foundation Service; C:\Program Files (x86)\MSI\MSI HOUSE\MSIFoundationService.exe [12800 2010-07-17] (MSI)
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [138768 2012-01-03] (MSI)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2782552 2010-03-06] (Symantec Corporation)
R2 PasswordBox; C:\Program Files (x86)\PasswordBox\pbbtnService.exe [67584 2013-11-01] (PasswordBox, Inc.)
R2 Qualcomm Atheros Killer Service; C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [492032 2012-03-08] ()

==================== Drivers (Whitelisted) ====================

S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [32768 2010-04-29] (Google Inc)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 asd2fsm; C:\Windows\System32\DRIVERS\asd2fsm.sys [35344 2014-03-27] (Anvisoft)
R1 avgtp; C:\windows\system32\drivers\avgtpx64.sys [49952 2014-03-20] (AVG Technologies)
R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [75880 2012-03-08] (Bigfoot Networks, Inc.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-08-22] (Disc Soft Ltd)
R2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [170640 2010-12-21] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [141264 2010-12-21] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [170640 2010-12-21] (ESET)
R3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [34144 2010-12-21] (ESET)
R2 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [50624 2010-12-21] (ESET)
R3 L1C; C:\Windows\System32\DRIVERS\e22w7x64.sys [161616 2012-03-08] (Qualcomm Atheros, Inc.)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-02] (Malwarebytes Corporation)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 efavdrv; \??\C:\windows\system32\drivers\efavdrv.sys [X]
S3 MGHwCtrl; \??\C:\Program Files\MSI\MSI Software Install\MGHwCtrl.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-04-02 12:53 - 2014-04-02 12:53 - 00029696 _____ () C:\Users\msi\AppData\Local\MSGBOX.EXE
2014-04-02 12:53 - 2014-04-02 12:53 - 00015327 _____ () C:\Users\msi\Desktop\LM.bat
2014-04-02 10:31 - 2014-04-02 10:31 - 00010940 _____ () C:\Users\msi\Desktop\zoek-results.txt
2014-04-02 10:19 - 2014-04-02 10:07 - 00024064 _____ () C:\windows\zoek-delete.exe
2014-04-02 10:07 - 2014-04-02 10:20 - 00010940 _____ () C:\zoek-results.log
2014-04-02 10:07 - 2014-04-02 10:17 - 00000000 ____D () C:\zoek_backup
2014-04-02 10:07 - 2014-03-08 11:24 - 01285120 _____ () C:\Users\msi\Desktop\zoek.exe
2014-04-02 10:07 - 2014-03-08 11:05 - 01414742 _____ () C:\Users\msi\Desktop\zoek.scr
2014-04-02 10:07 - 2014-03-08 11:05 - 01414742 _____ () C:\Users\msi\Desktop\zoek.com
2014-04-02 10:06 - 2014-04-02 10:06 - 04095370 _____ () C:\Users\msi\Downloads\zoek.zip
2014-04-01 21:58 - 2014-04-01 22:00 - 00000000 ____D () C:\AdwCleaner
2014-04-01 21:57 - 2014-04-01 21:57 - 01426178 _____ () C:\Users\msi\Desktop\adwcleaner.exe
2014-04-01 21:57 - 2014-02-18 11:46 - 00000426 _____ () C:\AVScanner.ini
2014-04-01 20:53 - 2014-04-01 20:53 - 00023384 _____ () C:\ComboFix.txt
2014-04-01 20:39 - 2011-06-26 08:45 - 00256000 _____ () C:\windows\PEV.exe
2014-04-01 20:39 - 2010-11-07 19:20 - 00208896 _____ () C:\windows\MBR.exe
2014-04-01 20:39 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2014-04-01 20:39 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2014-04-01 20:39 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2014-04-01 20:39 - 2000-08-31 02:00 - 00098816 _____ () C:\windows\sed.exe
2014-04-01 20:39 - 2000-08-31 02:00 - 00080412 _____ () C:\windows\grep.exe
2014-04-01 20:39 - 2000-08-31 02:00 - 00068096 _____ () C:\windows\zip.exe
2014-04-01 20:36 - 2014-04-01 20:53 - 00000000 ____D () C:\Qoobox
2014-04-01 20:36 - 2014-04-01 20:44 - 00000000 ____D () C:\windows\erdnt
2014-04-01 20:36 - 2014-04-01 20:36 - 05192353 ____R (Swearware) C:\Users\msi\Desktop\ComboFix.exe
2014-04-01 20:34 - 2014-04-01 20:34 - 00002338 _____ () C:\Users\msi\Desktop\Rkill.txt
2014-04-01 20:33 - 2014-04-01 20:33 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\msi\Downloads\rkill.com
2014-04-01 12:37 - 2014-04-02 10:45 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-01 12:37 - 2014-04-01 12:37 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-01 12:36 - 2014-04-01 12:36 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\msi\Downloads\mbam-setup-2.0.0.1000.exe
2014-04-01 00:07 - 2014-04-01 00:07 - 00010915 _____ () C:\Users\msi\Desktop\Addition.rar
2014-04-01 00:04 - 2014-04-02 12:53 - 00018379 _____ () C:\Users\msi\Desktop\FRST.txt
2014-04-01 00:04 - 2014-04-02 12:53 - 00000000 ____D () C:\FRST
2014-04-01 00:03 - 2014-04-01 00:03 - 02157056 _____ (Farbar) C:\Users\msi\Desktop\FRST64.exe
2014-04-01 00:01 - 2014-04-01 00:01 - 00112640 _____ (forum.viry.cz) C:\Users\msi\Desktop\FRSTLauncher.exe
2014-03-31 23:54 - 2014-03-31 23:54 - 00000000 ____D () C:\rsit
2014-03-31 23:54 - 2014-03-31 23:54 - 00000000 ____D () C:\Program Files\trend micro
2014-03-31 23:53 - 2014-03-31 23:53 - 00832273 _____ () C:\Users\msi\Downloads\RSITx64.exe
2014-03-31 17:45 - 2014-03-31 17:45 - 02991832 _____ (ESET) C:\Users\msi\Downloads\ERARemover_x64.exe
2014-03-31 17:41 - 2014-03-31 17:41 - 02347384 _____ (ESET) C:\Users\msi\Downloads\esetsmartinstaller_csy.exe
2014-03-31 17:41 - 2014-03-31 17:41 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-03-31 17:31 - 2014-03-31 17:31 - 32652456 _____ (Anvisoft) C:\Users\msi\Downloads\asdsetup.exe
2014-03-31 17:31 - 2014-03-31 17:31 - 00000000 ____D () C:\ProgramData\Anvisoft
2014-03-31 17:31 - 2014-03-31 17:31 - 00000000 ____D () C:\Program Files (x86)\Anvisoft
2014-03-31 17:31 - 2014-03-27 07:24 - 00035344 _____ (Anvisoft) C:\windows\system32\Drivers\asd2fsm.sys
2014-03-31 13:59 - 2014-03-31 14:00 - 04514475 _____ () C:\Users\msi\Downloads\bombic.zip
2014-03-29 22:16 - 2014-03-29 22:16 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-27 07:24 - 2014-03-27 07:24 - 00047632 _____ (Anvisoft) C:\windows\system32\Drivers\asdids.sys
2014-03-23 20:37 - 2014-03-23 20:37 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-23 20:37 - 2014-03-23 20:37 - 00000000 ____D () C:\Users\msi\AppData\Local\Skype
2014-03-23 02:16 - 2014-03-23 17:15 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-03-16 19:58 - 2014-03-16 19:59 - 00000000 ____D () C:\windows\system32\MRT
2014-03-16 19:58 - 2014-03-02 15:05 - 90015360 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-03-16 13:15 - 2014-03-16 13:15 - 00000000 ____D () C:\Users\msi\AppData\Local\Skyrim
2014-03-16 13:14 - 2014-03-16 13:14 - 00003633 _____ () C:\Users\msi\Downloads\steam.rar
2014-03-16 12:45 - 2014-03-16 12:45 - 01141680 _____ () C:\Users\msi\Downloads\SteamSetup.exe
2014-03-15 15:58 - 2014-03-16 12:05 - 2962702336 _____ () C:\Users\msi\Downloads\The-Elder-Scrolls-V-Skyrim---Legendary-Edition-CZ-REPAK.iso
2014-03-14 18:46 - 2014-03-17 15:01 - 00000000 ____D () C:\Users\msi\AppData\Local\Windows Live
2014-03-14 18:43 - 2014-03-26 17:35 - 00000000 ____D () C:\Users\msi\Documents\moto
2014-03-13 14:30 - 2014-03-13 14:30 - 00000000 ____D () C:\Users\Public\CyberLink
2014-03-13 13:42 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-03-13 13:42 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-03-13 13:42 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-03-13 13:42 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-03-13 13:42 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-03-13 13:42 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-03-13 13:42 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-03-13 13:42 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-03-13 13:42 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
2014-03-13 13:42 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\windows\SysWOW64\wer.dll
2014-03-13 13:42 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll
2014-03-13 13:41 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-03-13 13:41 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-03-13 13:41 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-03-13 13:41 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-03-13 13:41 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-03-13 13:41 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-03-13 13:41 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-03-13 13:41 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-03-13 13:41 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-03-13 13:41 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-03-13 13:41 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-03-13 13:41 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-03-13 13:41 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-03-13 13:41 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-03-13 13:41 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-03-13 13:41 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-03-13 13:41 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-03-13 13:41 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-03-13 13:41 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-03-13 13:41 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-03-13 13:41 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-03-13 13:41 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-03-13 13:41 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-03-13 13:41 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-03-13 13:41 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-03-13 13:41 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-03-13 13:41 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-03-13 13:41 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-03-13 13:41 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-03-13 13:41 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-03-13 13:41 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-03-13 13:41 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-03-13 13:41 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-03-13 13:41 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2014-03-13 13:41 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2014-03-13 13:41 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
2014-03-13 13:41 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\windows\SysWOW64\qedit.dll
2014-03-07 13:24 - 2014-03-07 13:30 - 108324724 _____ () C:\Users\msi\Downloads\Deuce---Nine-Lives-(2012)-(by-Mexiicek).rar
2014-03-03 18:35 - 2014-03-03 18:35 - 00301960 _____ () C:\windows\Minidump\030314-20560-01.dmp

==================== One Month Modified Files and Folders =======

2014-04-02 12:53 - 2014-04-02 12:53 - 00029696 _____ () C:\Users\msi\AppData\Local\MSGBOX.EXE
2014-04-02 12:53 - 2014-04-02 12:53 - 00015327 _____ () C:\Users\msi\Desktop\LM.bat
2014-04-02 12:53 - 2014-04-01 00:04 - 00018379 _____ () C:\Users\msi\Desktop\FRST.txt
2014-04-02 12:53 - 2014-04-01 00:04 - 00000000 ____D () C:\FRST
2014-04-02 12:53 - 2013-09-25 18:51 - 00000946 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-02 12:50 - 2014-01-28 20:57 - 00000000 ____D () C:\Users\msi\AppData\Local\Battle.net
2014-04-02 12:39 - 2013-07-17 17:11 - 00000000 ____D () C:\Users\msi\AppData\Roaming\Skype
2014-04-02 12:20 - 2013-07-17 16:59 - 00000914 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-04-02 10:59 - 2013-07-11 13:22 - 01465234 _____ () C:\windows\WindowsUpdate.log
2014-04-02 10:45 - 2014-04-01 12:37 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-02 10:31 - 2014-04-02 10:31 - 00010940 _____ () C:\Users\msi\Desktop\zoek-results.txt
2014-04-02 10:27 - 2009-07-14 06:45 - 00031712 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-02 10:27 - 2009-07-14 06:45 - 00031712 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-02 10:21 - 2013-11-25 21:54 - 00000000 ___RD () C:\Users\msi\Dropbox
2014-04-02 10:21 - 2013-11-25 21:53 - 00000000 ____D () C:\Users\msi\AppData\Roaming\Dropbox
2014-04-02 10:21 - 2013-07-17 16:16 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-04-02 10:21 - 2012-05-19 01:23 - 00000000 ____D () C:\ProgramData\Bigfoot Networks
2014-04-02 10:20 - 2014-04-02 10:07 - 00010940 _____ () C:\zoek-results.log
2014-04-02 10:20 - 2013-09-25 18:51 - 00000942 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-02 10:20 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-04-02 10:20 - 2009-07-14 06:51 - 00080585 _____ () C:\windows\setupact.log
2014-04-02 10:19 - 2010-11-21 05:47 - 00768424 _____ () C:\windows\PFRO.log
2014-04-02 10:17 - 2014-04-02 10:07 - 00000000 ____D () C:\zoek_backup
2014-04-02 10:07 - 2014-04-02 10:19 - 00024064 _____ () C:\windows\zoek-delete.exe
2014-04-02 10:06 - 2014-04-02 10:06 - 04095370 _____ () C:\Users\msi\Downloads\zoek.zip
2014-04-01 22:07 - 2012-05-18 10:04 - 00680522 _____ () C:\windows\system32\perfh005.dat
2014-04-01 22:07 - 2012-05-18 10:04 - 00145490 _____ () C:\windows\system32\perfc005.dat
2014-04-01 22:07 - 2009-07-14 07:13 - 01615286 _____ () C:\windows\system32\PerfStringBackup.INI
2014-04-01 22:00 - 2014-04-01 21:58 - 00000000 ____D () C:\AdwCleaner
2014-04-01 21:57 - 2014-04-01 21:57 - 01426178 _____ () C:\Users\msi\Desktop\adwcleaner.exe
2014-04-01 20:53 - 2014-04-01 20:53 - 00023384 _____ () C:\ComboFix.txt
2014-04-01 20:53 - 2014-04-01 20:36 - 00000000 ____D () C:\Qoobox
2014-04-01 20:52 - 2009-07-14 04:34 - 00000215 _____ () C:\windows\system.ini
2014-04-01 20:45 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-04-01 20:44 - 2014-04-01 20:36 - 00000000 ____D () C:\windows\erdnt
2014-04-01 20:36 - 2014-04-01 20:36 - 05192353 ____R (Swearware) C:\Users\msi\Desktop\ComboFix.exe
2014-04-01 20:34 - 2014-04-01 20:34 - 00002338 _____ () C:\Users\msi\Desktop\Rkill.txt
2014-04-01 20:33 - 2014-04-01 20:33 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\msi\Downloads\rkill.com
2014-04-01 13:06 - 2013-07-25 18:51 - 00000000 ____D () C:\Program Files (x86)\HandyUpdater
2014-04-01 12:50 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\Resources
2014-04-01 12:37 - 2014-04-01 12:37 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-01 12:36 - 2014-04-01 12:36 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\msi\Downloads\mbam-setup-2.0.0.1000.exe
2014-04-01 00:08 - 2013-08-22 17:24 - 00000000 ____D () C:\Users\msi\Documents\My Games
2014-04-01 00:07 - 2014-04-01 00:07 - 00010915 _____ () C:\Users\msi\Desktop\Addition.rar
2014-04-01 00:03 - 2014-04-01 00:03 - 02157056 _____ (Farbar) C:\Users\msi\Desktop\FRST64.exe
2014-04-01 00:01 - 2014-04-01 00:01 - 00112640 _____ (forum.viry.cz) C:\Users\msi\Desktop\FRSTLauncher.exe
2014-03-31 23:54 - 2014-03-31 23:54 - 00000000 ____D () C:\rsit
2014-03-31 23:54 - 2014-03-31 23:54 - 00000000 ____D () C:\Program Files\trend micro
2014-03-31 23:53 - 2014-03-31 23:53 - 00832273 _____ () C:\Users\msi\Downloads\RSITx64.exe
2014-03-31 18:33 - 2010-01-01 01:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-03-31 17:46 - 2013-08-18 20:57 - 00000000 ____D () C:\ProgramData\ESET
2014-03-31 17:45 - 2014-03-31 17:45 - 02991832 _____ (ESET) C:\Users\msi\Downloads\ERARemover_x64.exe
2014-03-31 17:41 - 2014-03-31 17:41 - 02347384 _____ (ESET) C:\Users\msi\Downloads\esetsmartinstaller_csy.exe
2014-03-31 17:41 - 2014-03-31 17:41 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-03-31 17:31 - 2014-03-31 17:31 - 32652456 _____ (Anvisoft) C:\Users\msi\Downloads\asdsetup.exe
2014-03-31 17:31 - 2014-03-31 17:31 - 00000000 ____D () C:\ProgramData\Anvisoft
2014-03-31 17:31 - 2014-03-31 17:31 - 00000000 ____D () C:\Program Files (x86)\Anvisoft
2014-03-31 14:00 - 2014-03-31 13:59 - 04514475 _____ () C:\Users\msi\Downloads\bombic.zip
2014-03-30 15:01 - 2013-07-17 16:12 - 00000000 ____D () C:\Users\msi\AppData\Local\PMB Files
2014-03-30 15:01 - 2013-07-17 16:12 - 00000000 ____D () C:\ProgramData\PMB Files
2014-03-29 22:16 - 2014-03-29 22:16 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-28 11:14 - 2009-07-14 07:08 - 00032570 _____ () C:\windows\Tasks\SCHEDLGU.TXT
2014-03-27 22:33 - 2013-11-21 16:31 - 00000000 ____D () C:\Program Files (x86)\PasswordBox
2014-03-27 07:24 - 2014-03-31 17:31 - 00035344 _____ (Anvisoft) C:\windows\system32\Drivers\asd2fsm.sys
2014-03-27 07:24 - 2014-03-27 07:24 - 00047632 _____ (Anvisoft) C:\windows\system32\Drivers\asdids.sys
2014-03-26 17:35 - 2014-03-14 18:43 - 00000000 ____D () C:\Users\msi\Documents\moto
2014-03-23 20:37 - 2014-03-23 20:37 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-23 20:37 - 2014-03-23 20:37 - 00000000 ____D () C:\Users\msi\AppData\Local\Skype
2014-03-23 20:37 - 2013-07-17 17:11 - 00000000 ____D () C:\ProgramData\Skype
2014-03-23 17:15 - 2014-03-23 02:16 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-03-22 14:31 - 2014-01-28 20:57 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-03-20 22:51 - 2013-07-20 15:55 - 00049952 _____ (AVG Technologies) C:\windows\system32\Drivers\avgtpx64.sys
2014-03-20 22:51 - 2013-07-20 15:55 - 00003738 _____ () C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
2014-03-19 11:04 - 2013-07-03 08:53 - 00000000 ____D () C:\Users\msi\Documents\CULS
2014-03-17 15:01 - 2014-03-14 18:46 - 00000000 ____D () C:\Users\msi\AppData\Local\Windows Live
2014-03-16 19:59 - 2014-03-16 19:58 - 00000000 ____D () C:\windows\system32\MRT
2014-03-16 19:59 - 2013-09-24 17:15 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-03-16 13:15 - 2014-03-16 13:15 - 00000000 ____D () C:\Users\msi\AppData\Local\Skyrim
2014-03-16 13:15 - 2013-07-17 16:51 - 00000000 ___RD () C:\Users\msi\Desktop\ 
2014-03-16 13:14 - 2014-03-16 13:14 - 00003633 _____ () C:\Users\msi\Downloads\steam.rar
2014-03-16 12:54 - 2013-08-22 17:18 - 00000000 ____D () C:\Program Files (x86)\Bethesda Softworks
2014-03-16 12:45 - 2014-03-16 12:45 - 01141680 _____ () C:\Users\msi\Downloads\SteamSetup.exe
2014-03-16 12:05 - 2014-03-15 15:58 - 2962702336 _____ () C:\Users\msi\Downloads\The-Elder-Scrolls-V-Skyrim---Legendary-Edition-CZ-REPAK.iso
2014-03-14 22:31 - 2013-11-11 02:21 - 00000000 ____D () C:\Users\msi\Downloads\Subs
2014-03-14 22:02 - 2014-01-28 22:03 - 00000000 ____D () C:\Program Files (x86)\Hearthstone
2014-03-14 09:18 - 2009-07-14 06:45 - 00437320 _____ () C:\windows\system32\FNTCACHE.DAT
2014-03-14 09:17 - 2013-09-25 00:52 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-14 09:17 - 2013-09-25 00:52 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-03-13 14:31 - 2013-07-12 14:15 - 00000000 ____D () C:\Users\msi\Documents\Youcam
2014-03-13 14:30 - 2014-03-13 14:30 - 00000000 ____D () C:\Users\Public\CyberLink
2014-03-12 16:20 - 2013-09-10 20:20 - 05777288 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerInstaller.exe
2014-03-12 16:20 - 2013-07-17 16:59 - 00003852 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-03-12 16:20 - 2012-05-19 02:07 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-03-12 16:20 - 2012-05-19 02:07 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-08 11:24 - 2014-04-02 10:07 - 01285120 _____ () C:\Users\msi\Desktop\zoek.exe
2014-03-08 11:05 - 2014-04-02 10:07 - 01414742 _____ () C:\Users\msi\Desktop\zoek.scr
2014-03-08 11:05 - 2014-04-02 10:07 - 01414742 _____ () C:\Users\msi\Desktop\zoek.com
2014-03-07 13:30 - 2014-03-07 13:24 - 108324724 _____ () C:\Users\msi\Downloads\Deuce---Nine-Lives-(2012)-(by-Mexiicek).rar
2014-03-03 18:35 - 2014-03-03 18:35 - 00301960 _____ () C:\windows\Minidump\030314-20560-01.dmp
2014-03-03 18:35 - 2013-07-11 13:51 - 00000000 ____D () C:\windows\Minidump
2014-03-03 18:35 - 2013-07-11 13:50 - 779360882 _____ () C:\windows\MEMORY.DMP

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-03-20 20:15

==================== End Of Log ============================
Přílohy
Addition.rar
(9.91 KiB) Staženo 53 x

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problém s virem JS/Kryptik.I Trojský kůň - Camper

#14 Příspěvek od vyosek »

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
    HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
    HKU\S-1-5-21-2434717301-3026624133-2648855760-1001\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1821888 2014-02-25] (Valve Corporation)
    HKU\S-1-5-21-2434717301-3026624133-2648855760-1001\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673184 2013-07-03] (Disc Soft Ltd)
    HKU\S-1-5-21-2434717301-3026624133-2648855760-1001\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.)
    
    HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msi.msn.com
    StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
    SearchScopes: HKLM - DefaultScope {4089A85C-F3A3-4606-9857-8A8416B57438} URL =
    SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
    SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
    
    2014-04-02 12:53 - 2014-04-02 12:53 - 00029696 _____ () C:\Users\msi\AppData\Local\MSGBOX.EXE
    2014-04-02 12:53 - 2014-04-02 12:53 - 00015327 _____ () C:\Users\msi\Desktop\LM.bat
    2014-04-02 10:31 - 2014-04-02 10:31 - 00010940 _____ () C:\Users\msi\Desktop\zoek-results.txt
    2014-04-02 10:19 - 2014-04-02 10:07 - 00024064 _____ () C:\windows\zoek-delete.exe
    2014-04-02 10:07 - 2014-04-02 10:20 - 00010940 _____ () C:\zoek-results.log
    2014-04-02 10:07 - 2014-04-02 10:17 - 00000000 ____D () C:\zoek_backup
    2014-04-02 10:07 - 2014-03-08 11:24 - 01285120 _____ () C:\Users\msi\Desktop\zoek.exe
    2014-04-02 10:07 - 2014-03-08 11:05 - 01414742 _____ () C:\Users\msi\Desktop\zoek.scr
    2014-04-02 10:07 - 2014-03-08 11:05 - 01414742 _____ () C:\Users\msi\Desktop\zoek.com
    2014-04-02 10:06 - 2014-04-02 10:06 - 04095370 _____ () C:\Users\msi\Downloads\zoek.zip
    2014-04-01 21:57 - 2014-04-01 21:57 - 01426178 _____ () C:\Users\msi\Desktop\adwcleaner.exe
    2014-04-01 20:34 - 2014-04-01 20:34 - 00002338 _____ () C:\Users\msi\Desktop\Rkill.txt
    2014-04-01 20:33 - 2014-04-01 20:33 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\msi\Downloads\rkill.com
    2014-04-01 12:36 - 2014-04-01 12:36 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\msi\Downloads\mbam-setup-2.0.0.1000.exe
    2014-04-01 00:07 - 2014-04-01 00:07 - 00010915 _____ () C:\Users\msi\Desktop\Addition.rar
    2014-04-01 00:04 - 2014-04-02 12:53 - 00018379 _____ () C:\Users\msi\Desktop\FRST.txt
    2014-04-01 00:01 - 2014-04-01 00:01 - 00112640 _____ (forum.viry.cz) C:\Users\msi\Desktop\FRSTLauncher.exe
    2014-03-31 23:53 - 2014-03-31 23:53 - 00832273 _____ () C:\Users\msi\Downloads\RSITx64.exe
    2014-03-31 17:45 - 2014-03-31 17:45 - 02991832 _____ (ESET) C:\Users\msi\Downloads\ERARemover_x64.exe
    2014-03-31 17:41 - 2014-03-31 17:41 - 02347384 _____ (ESET) C:\Users\msi\Downloads\esetsmartinstaller_csy.exe
    
    Hosts:
    End
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Camper
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 31 bře 2014 22:45

Re: Problém s virem JS/Kryptik.I Trojský kůň - Camper

#15 Příspěvek od Camper »

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2014
Ran by msi at 2014-04-03 23:18:50 Run:1
Running from C:\Users\msi\Desktop\ \viry.cz
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKU\S-1-5-21-2434717301-3026624133-2648855760-1001\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1821888 2014-02-25] (Valve Corporation)
HKU\S-1-5-21-2434717301-3026624133-2648855760-1001\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673184 2013-07-03] (Disc Soft Ltd)
HKU\S-1-5-21-2434717301-3026624133-2648855760-1001\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msi.msn.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {4089A85C-F3A3-4606-9857-8A8416B57438} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}

2014-04-02 12:53 - 2014-04-02 12:53 - 00029696 _____ () C:\Users\msi\AppData\Local\MSGBOX.EXE
2014-04-02 12:53 - 2014-04-02 12:53 - 00015327 _____ () C:\Users\msi\Desktop\LM.bat
2014-04-02 10:31 - 2014-04-02 10:31 - 00010940 _____ () C:\Users\msi\Desktop\zoek-results.txt
2014-04-02 10:19 - 2014-04-02 10:07 - 00024064 _____ () C:\windows\zoek-delete.exe
2014-04-02 10:07 - 2014-04-02 10:20 - 00010940 _____ () C:\zoek-results.log
2014-04-02 10:07 - 2014-04-02 10:17 - 00000000 ____D () C:\zoek_backup
2014-04-02 10:07 - 2014-03-08 11:24 - 01285120 _____ () C:\Users\msi\Desktop\zoek.exe
2014-04-02 10:07 - 2014-03-08 11:05 - 01414742 _____ () C:\Users\msi\Desktop\zoek.scr
2014-04-02 10:07 - 2014-03-08 11:05 - 01414742 _____ () C:\Users\msi\Desktop\zoek.com
2014-04-02 10:06 - 2014-04-02 10:06 - 04095370 _____ () C:\Users\msi\Downloads\zoek.zip
2014-04-01 21:57 - 2014-04-01 21:57 - 01426178 _____ () C:\Users\msi\Desktop\adwcleaner.exe
2014-04-01 20:34 - 2014-04-01 20:34 - 00002338 _____ () C:\Users\msi\Desktop\Rkill.txt
2014-04-01 20:33 - 2014-04-01 20:33 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\msi\Downloads\rkill.com
2014-04-01 12:36 - 2014-04-01 12:36 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\msi\Downloads\mbam-setup-2.0.0.1000.exe
2014-04-01 00:07 - 2014-04-01 00:07 - 00010915 _____ () C:\Users\msi\Desktop\Addition.rar
2014-04-01 00:04 - 2014-04-02 12:53 - 00018379 _____ () C:\Users\msi\Desktop\FRST.txt
2014-04-01 00:01 - 2014-04-01 00:01 - 00112640 _____ (forum.viry.cz) C:\Users\msi\Desktop\FRSTLauncher.exe
2014-03-31 23:53 - 2014-03-31 23:53 - 00832273 _____ () C:\Users\msi\Downloads\RSITx64.exe
2014-03-31 17:45 - 2014-03-31 17:45 - 02991832 _____ (ESET) C:\Users\msi\Downloads\ERARemover_x64.exe
2014-03-31 17:41 - 2014-03-31 17:41 - 02347384 _____ (ESET) C:\Users\msi\Downloads\esetsmartinstaller_csy.exe

Hosts:
End
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\BCSSync => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKU\S-1-5-21-2434717301-3026624133-2648855760-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Steam => Value deleted successfully.
HKU\S-1-5-21-2434717301-3026624133-2648855760-1001\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => Value deleted successfully.
HKU\S-1-5-21-2434717301-3026624133-2648855760-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Skype => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully.
HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found.
C:\Users\msi\AppData\Local\MSGBOX.EXE => Moved successfully.
C:\Users\msi\Desktop\LM.bat => Moved successfully.
"C:\Users\msi\Desktop\zoek-results.txt" => File/Directory not found.
C:\windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
"C:\Users\msi\Desktop\zoek.exe" => File/Directory not found.
"C:\Users\msi\Desktop\zoek.scr" => File/Directory not found.
"C:\Users\msi\Desktop\zoek.com" => File/Directory not found.
C:\Users\msi\Downloads\zoek.zip => Moved successfully.
"C:\Users\msi\Desktop\adwcleaner.exe" => File/Directory not found.
"C:\Users\msi\Desktop\Rkill.txt" => File/Directory not found.
C:\Users\msi\Downloads\rkill.com => Moved successfully.
C:\Users\msi\Downloads\mbam-setup-2.0.0.1000.exe => Moved successfully.
"C:\Users\msi\Desktop\Addition.rar" => File/Directory not found.
"C:\Users\msi\Desktop\FRST.txt" => File/Directory not found.
"C:\Users\msi\Desktop\FRSTLauncher.exe" => File/Directory not found.
C:\Users\msi\Downloads\RSITx64.exe => Moved successfully.
C:\Users\msi\Downloads\ERARemover_x64.exe => Moved successfully.
C:\Users\msi\Downloads\esetsmartinstaller_csy.exe => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.

==== End of Fixlog ====


Vážně se omlouvám nevím, co mě to napadlo, "uklidit" si desktop...
fixlog funguje jen takto (i když jsem přesunul vše zpět na plochu, nebo zkusil připsat \ \viry.cz\ tak hlásí, že není fixlog ve stejné složce jako tool :( :( :?:
Naposledy upravil(a) Camper dne 03 dub 2014 22:36, celkem upraveno 1 x.

Odpovědět