Stránka 1 z 2

Virus přesměrování Yahoo

Napsal: 16 dub 2014 14:07
od endousek
Ahoj,
prosím o pomoc. Asi před týdnem se mi z nějakých stránek automaticky mozilla přesměrovala na stránku, která vypadala jako Yahoo! Až včera mi napadlo, že je to divné a je to virus. Nějakým stylem jsem dogoolila program YAC, který tento "vir" blokoval, ale neodstranil.
Dnes jsem aktualizovala Avast a našlo mi to WIN32:NextLive-A a pak win32:Mindspark-A, sám Avast smazal infikované soubory.
Vymazala jsem program YAC, restartovala, spustila Avast znovu, tentokrát to už nic nenašlo.
Po nastartování opět mozilla přesměrovávala na Yahoo, takže jsem obnovila Mozillu. Teď nepřesměrovává, Avast hlásí 0infikovaných, ale procesor stále běží na 100% :twisted:
Mám Acer Aspire 1410
Díky

Logfile of random's system information tool 1.09 (written by random/random)
Run by Administrator at 2014-04-16 14:51:36
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 872 MB (6%) free of 15 GB
Total RAM: 750 MB (47% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:52:24, on 16.4.2014
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Program Files\AVAST Software\Avast\afwServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TeamViewer\Version8\TeamViewer.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\acer\Wireless\Utility\WlanUtil.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\TeamViewer\Version8\tv_w32.exe
c:\program files\mozilla firefox\firefox.exe
C:\Documents and Settings\Administrator\Dokumenty\Stažené soubory\RSIT.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\trend micro\Administrator.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [acerWireless] C:\Program Files\acer\Wireless\Utility\WlanUtil.exe
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe

--
End of file - 4878 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\avast! Emergency Update.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\fufq7kc7.default-1397651562180

"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@popularscreensavers.com/Plugin]
"Description"=Popular Screensavers Plugin
"Path"=C:\Program Files\PopularScreensavers\NPp5Stub.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@PopularScreensavers_7i.com/Plugin]
"Description"=PopularScreensavers Plugin
"Path"=C:\Program Files\PopularScreensavers_7i\bar\1.bin\NP7iStub.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2004-02-10 155648]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2004-02-10 118784]
"acerWireless"=C:\Program Files\acer\Wireless\Utility\WlanUtil.exe [2004-06-09 417792]
"LManager"=C:\Program Files\Launch Manager\QtZgAcer.EXE [2004-07-30 319488]
"SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2004-05-20 98304]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2004-05-20 532480]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-04-16 3854640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2004-02-10 339968]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Documents and Settings\Administrator\Local Settings\Temp\TeamViewer\Version8\TeamViewer.exe"="C:\Documents and Settings\Administrator\Local Settings\Temp\TeamViewer\Version8\TeamViewer.exe:*:Enabled:TeamViewer 8"
"C:\Program Files\TeamViewer\Version8\TeamViewer.exe"="C:\Program Files\TeamViewer\Version8\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
"C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe"="C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe:*:Enabled:Teamviewer Remote Control Service"
"C:\Program Files\GameforgeLive\gfl_client.exe"="C:\Program Files\GameforgeLive\gfl_client.exe:*:Enabled:Gameforge Live"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"msacm.ac3filter"=ac3filter.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.scr - open - "C:\WINDOWS\system32\NOTEPAD.EXE" "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2014-04-16 14:51:43 ----D---- C:\Program Files\trend micro
2014-04-16 14:51:36 ----D---- C:\rsit
2014-04-16 07:29:57 ----A---- C:\WINDOWS\system32\drivers\aswNdis2.sys
2014-04-16 07:29:57 ----A---- C:\WINDOWS\system32\drivers\aswKbd.sys
2014-04-16 07:29:29 ----A---- C:\WINDOWS\avastSS.scr
2014-04-16 07:27:49 ----A---- C:\WINDOWS\system32\drivers\aswNdis.sys
2014-04-15 20:21:28 ----D---- C:\WINDOWS\system32\PreInstall
2014-04-15 20:21:26 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2014-04-15 20:21:25 ----HD---- C:\WINDOWS\$hf_mig$
2014-04-15 18:05:03 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2014-04-15 17:54:17 ----D---- C:\Program Files\GUMF7.tmp
2014-04-15 17:54:17 ----A---- C:\Program Files\GUTF8.tmp
2014-04-15 17:38:32 ----D---- C:\Documents and Settings\Administrator\Data aplikací\eCyber
2014-04-15 17:37:28 ----A---- C:\WINDOWS\system32\drivers\iSafeKrnlBoot.sys
2014-04-15 17:36:52 ----D---- C:\Program Files\iSafe
2014-04-15 17:36:44 ----D---- C:\Documents and Settings\Administrator\Data aplikací\iSafe
2014-04-13 10:05:46 ----A---- C:\WINDOWS\system32\d3d8caps.dat
2014-04-10 21:03:42 ----D---- C:\Program Files\Common Files\PDF Architect
2014-04-08 18:39:20 ----D---- C:\Program Files\Common Files\Spigot
2014-04-03 18:47:43 ----D---- C:\Program Files\Common Files\Borland Shared
2014-04-03 18:47:43 ----A---- C:\WINDOWS\system32\DBCLIENT.DLL
2014-04-03 18:46:51 ----D---- C:\Documents and Settings\All Users\Data aplikací\eXmind
2014-04-01 13:57:33 ----D---- C:\Documents and Settings\Administrator\Data aplikací\PDF Architect
2014-04-01 13:33:45 ----D---- C:\Documents and Settings\Administrator\Data aplikací\pdfforge
2014-04-01 13:33:34 ----A---- C:\WINDOWS\system32\pdfcmon.dll
2014-04-01 13:33:28 ----A---- C:\WINDOWS\system32\MSMPIDE.DLL
2014-04-01 13:33:27 ----D---- C:\Program Files\PDFCreator
2014-03-29 21:06:43 ----N---- C:\WINDOWS\system32\spmsg.dll
2014-03-29 21:06:37 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2014-03-29 21:05:54 ----D---- C:\Program Files\Windows Media Connect 2
2014-03-29 21:02:47 ----D---- C:\WINDOWS\system32\drivers\UMDF
2014-03-29 21:02:37 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2014-03-29 21:02:35 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2014-03-29 21:01:29 ----D---- C:\Documents and Settings\All Users\Data aplikací\Windows Genuine Advantage
2014-03-29 20:58:00 ----A---- C:\WINDOWS\system32\ptpusb.dll
2014-03-29 20:57:57 ----A---- C:\WINDOWS\system32\ptpusd.dll
2014-03-29 20:57:56 ----A---- C:\WINDOWS\system32\drivers\usbscan.sys
2014-03-29 11:46:02 ----D---- C:\Program Files\Mozilla Firefox
2014-03-17 14:41:31 ----A---- C:\WINDOWS\system32\drivers\USBAUDIO.sys
2014-03-17 14:41:24 ----A---- C:\WINDOWS\system32\drivers\usbccgp.sys

======List of files/folders modified in the last 1 month======

2014-04-16 14:51:43 ----RD---- C:\Program Files
2014-04-16 14:51:42 ----D---- C:\WINDOWS\Prefetch
2014-04-16 13:15:50 ----D---- C:\WINDOWS\Temp
2014-04-16 11:09:00 ----D---- C:\WINDOWS\system32\CatRoot2
2014-04-16 11:08:40 ----D---- C:\WINDOWS
2014-04-16 10:39:20 ----D---- C:\WINDOWS\system32
2014-04-16 10:19:15 ----D---- C:\Program Files\PopularScreensavers
2014-04-16 09:49:53 ----A---- C:\WINDOWS\SchedLgU.Txt
2014-04-16 08:26:22 ----HD---- C:\WINDOWS\inf
2014-04-16 08:24:15 ----D---- C:\WINDOWS\system32\CatRoot
2014-04-16 07:30:24 ----D---- C:\WINDOWS\system32\drivers
2014-04-16 07:30:04 ----SD---- C:\WINDOWS\Tasks
2014-04-16 07:29:29 ----A---- C:\WINDOWS\system32\aswBoot.exe
2014-04-16 06:47:12 ----RSHDC---- C:\WINDOWS\system32\dllcache
2014-04-15 18:05:24 ----D---- C:\WINDOWS\SoftwareDistribution
2014-04-15 18:05:15 ----D---- C:\WINDOWS\Help
2014-04-15 18:03:48 ----SHD---- C:\WINDOWS\Installer
2014-04-15 17:37:25 ----RSD---- C:\WINDOWS\Fonts
2014-04-10 21:13:38 ----D---- C:\Program Files\GameforgeLive
2014-04-10 21:08:19 ----A---- C:\WINDOWS\win.ini
2014-04-10 21:07:56 ----D---- C:\Program Files\Windows Media Player
2014-04-10 21:04:48 ----SHD---- C:\Config.Msi
2014-04-10 21:03:42 ----D---- C:\Program Files\Common Files
2014-04-10 20:59:27 ----D---- C:\Program Files\xerox
2014-04-04 06:57:56 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-03-29 21:06:46 ----A---- C:\WINDOWS\imsins.BAK
2014-03-29 21:02:47 ----D---- C:\WINDOWS\system32\LogFiles

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswNdis;avast! Firewall NDIS Filter Service; C:\WINDOWS\system32\DRIVERS\aswNdis.sys [2014-04-16 12112]
R0 aswNdis2;avast! Firewall NDIS Driver; C:\WINDOWS\system32\drivers\aswNdis2.sys [2014-04-16 252208]
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2014-04-16 49944]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2014-04-16 180760]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [2014-04-16 26136]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2014-04-16 54832]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2014-04-16 776976]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2014-04-16 411552]
R1 aswTdi;aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [2014-04-16 57672]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 iSafeNetFilter;iSafeNetFilter; \??\C:\Program Files\iSafe\iSafeNetFilter.sys []
R1 SMBHC;Microsoft SM Bus Host Controller Driver; C:\WINDOWS\system32\DRIVERS\SMBHC.sys [2001-08-17 6784]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2014-04-16 67824]
R2 irda;Protokol IrDA; C:\WINDOWS\system32\DRIVERS\irda.sys [2008-04-14 88192]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2003-04-09 11043]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-14 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2001-10-25 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2001-10-25 55936]
R3 CAMCAUD;Conexant AMC Audio; C:\WINDOWS\system32\drivers\camcaud.sys [2004-04-29 292352]
R3 CAMCHALA;CAMCHALA; C:\WINDOWS\system32\drivers\camchal.sys [2004-04-29 274688]
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver; C:\WINDOWS\System32\Drivers\DKbFltr.sys [2002-11-20 17983]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSF_DP.sys [2004-03-10 1041536]
R3 HSFHWICH;HSFHWICH; C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys [2004-03-10 199552]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2004-02-10 681469]
R3 NSCIRDA;NSC Infrared Device Driver; C:\WINDOWS\system32\DRIVERS\nscirda.sys [2008-04-14 28672]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver; C:\WINDOWS\system32\DRIVERS\rt2870.sys [2013-11-22 637952]
R3 SMBBATT;Microsoft Smart Battery Driver; C:\WINDOWS\system32\DRIVERS\SMBBATT.sys [2008-04-14 16000]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2004-05-20 184768]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2004-03-10 682624]
S2 DgiVecp;DgiVecp; \??\C:\WINDOWS\system32\Drivers\DgiVecp.sys []
S2 SSPORT;SSPORT; \??\C:\WINDOWS\system32\Drivers\SSPORT.sys []
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
S3 b57w2k;BCM5701 Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2001-10-24 97120]
S3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2003-09-26 44032]
S3 EpmShd;Acer EPM System Hardware Driver; \??\C:\WINDOWS\system32\Drivers\epm-shd.sys []
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 IPN2220;acer IPN2220 Wireless LAN Card Driver; C:\WINDOWS\system32\DRIVERS\i2220ntx.sys [2004-03-29 140288]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
S3 PCANDIS5;PCANDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PCANDIS5.SYS []
S3 tifm21;tifm21; C:\WINDOWS\system32\drivers\tifm21.sys [2004-05-26 67584]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 anbmService;Notebook Manager Service; C:\Acer\eManager\anbmServ.exe [2004-07-05 1286144]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-04-16 50344]
R2 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [2014-04-16 109048]
R2 Irmon;Sledování infračerveného přenosu; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 TeamViewer8;TeamViewer 8; C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe [2014-02-07 5093216]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-04-15 116648]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2014-01-16 85096]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-04-15 116648]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Re: Virus přesměrování Yahoo

Napsal: 16 dub 2014 14:15
od cernohous13
Zdravím,

:arrow: Stáhni Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
Ulož jej na plochu a spusť - zobrazí se licenční podminky -> start libovolnou klávesou.
Bude vytvořena záloha a proběhne skenování.
Vyskočí log (nebo je uložen zde c:\JRT jako JRT.txt) - zkopíruj jej sem

:arrow: Stáhni AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Ulož nejlépe na plochu -> ukonči všechny programy -> spusť AdwCleaner -> klikni na Scan po dokončení na Clean
bude provedena oprava, restartuje se - (případně restartuj) a vypadne log C:\AdwCleaner\AdwCleaner[S?].txt , jeho obsah vložíš sem

:arrow: pravděpodobně budeš nucena vypnout na tu chvíli antivir - je to čisté, prověřeno
vyosek píše: :arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • :arrow: Po spuštění do okna vlozte skript nize

    Kód: Vybrat vše

    srinfo;
    autoclean;
    emptyclsid;
    iedefaults;
    process;
    hijackthis;
    emptyalltemp;
    resethosts;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
Log bude zde C:\zoek-results.log

Re: Virus přesměrování Yahoo

Napsal: 16 dub 2014 17:05
od endousek
Když jsem se pokusila soubory stáhnout spadl mi internet a už nenaskočil. Posílám to přes druhý počítač, jde to hrozně pomalu, ale přikládám první log.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Microsoft Windows XP x86
Ran by Administrator on st 16.04.2014 at 15:58:52,32
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.dynamicbarbutton
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.dynamicbarbutton.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.feedmanager
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.feedmanager.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.htmlpanel
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.htmlpanel.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.multiplebutton
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.multiplebutton.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.pseudotransparentplugin
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.pseudotransparentplugin.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.radiosettings
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.radiosettings.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.scriptbutton
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.scriptbutton.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.thirdpartyinstaller
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.thirdpartyinstaller.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.urlalertbutton
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.urlalertbutton.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.xmlsessionplugin
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.xmlsessionplugin.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{13119113-0854-469D-807A-171568457991}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{17B0B148-1491-4668-AD7D-1F39972E03E5}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{33119133-0854-469D-807A-171568457991}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{406463E6-91B4-4BBE-8182-E41FDCA2B2B3}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{5469582E-6A71-4C2C-AB43-AB183058C88C}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{5C0A85B9-3980-475D-AA36-EA2EF138EC04}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{6833E938-D47A-4BCA-B7D4-A712CD561127}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{756E61B2-52AE-4D73-8535-F8DF642D72E5}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{7F9BAD37-202C-468D-A046-EBDEF588616D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{96D0C95F-BFE7-430E-A406-D8E2D33FEE48}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{A9197738-02A5-46EF-BBF9-FDE251C5A631}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{B7C7E5C1-F49C-476A-A7E9-F45E5C85C995}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{BC07C71E-C13B-4E16-B9A4-D954C3F097B6}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{C39937A0-C59D-4506-A9FC-0A0138192287}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{D952F4A1-8B38-4B62-9E1E-CB74A2917580}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{E51062CE-0B63-42A4-934A-C2ABE7B3EE7B}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{0797C39C-6FDE-45BA-A89F-FDF91A1432D7}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{13431DEE-CAD4-403C-BDC2-F36F3F3F0852}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{23119123-0854-469D-807A-171568457991}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{50CE9C1E-AFA8-494D-98F1-FFEC8965EA0A}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66376EFC-73B3-41CB-8403-C19EA5A60623}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{A1C4DF97-9F5A-4518-A185-B71B3E2EDFA2}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{A40F7F79-8927-4A4A-B0FC-D41A8BE8C018}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{B956E151-3D90-489F-B109-97D5B4545D36}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{B985332B-07EF-4185-BBFA-805BF2130D59}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{C39937A7-C59D-4506-A9FC-0A0138192287}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{C91E811C-4C64-4705-9C79-6DCF4184CE2C}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{03119103-0854-469D-807A-171568457991}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{2CF52ECC-9E7E-43D7-8F7F-BBFB10C2D36F}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{32416A28-DAA5-4EE2-A5A1-6E9CB952C19D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{46A5C277-35A6-4C87-A0D2-D34D30D5A363}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{679DD02B-BFD7-439D-ADFF-20D7ED92FFD4}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{A5F237F3-1DA6-43AF-8CA5-CFD7BE9259A2}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{BBB1A756-C3A5-42CF-8FA3-BA0BD4C6F386}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{C39937A5-C59D-4506-A9FC-0A0138192287}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{CCEC4CA8-9CE0-48E2-B203-C0239AA97A62}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{EA010B0B-1015-4E3E-B752-CC20A792B34C}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{FD4D02F2-EA24-4809-B0B6-805031110E8C}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\installcore
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{17B0B148-1491-4668-AD7D-1F39972E03E5}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{406463E6-91B4-4BBE-8182-E41FDCA2B2B3}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F9BAD37-202C-468D-A046-EBDEF588616D}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D952F4A1-8B38-4B62-9E1E-CB74A2917580}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Documents and Settings\Administrator\Data aplikacˇ\isafe"
Successfully deleted: [Folder] "C:\Documents and Settings\Administrator\Data aplikacˇ\newnext.me"
Successfully deleted: [Folder] "C:\Documents and Settings\Administrator\Data aplikacˇ\pdfforge"
Successfully deleted: [Folder] "C:\Program Files\isafe"
Successfully deleted: [Folder] "C:\Program Files\mobogenie"
Successfully deleted: [Folder] "C:\Program Files\popularscreensavers"
Successfully deleted: [Folder] "C:\Program Files\popularscreensavers_7i"
Successfully deleted: [Folder] "C:\Program Files\Common Files\spigot"



~~~ Chrome

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\hbcennhacfaagdopikcegfcobcadeocj
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\pfndaklgolladniicklehhancnlgocpp





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on st 16.04.2014 at 17:57:20,30
End of JRT log

Re: Virus přesměrování Yahoo

Napsal: 16 dub 2014 17:57
od endousek
# AdwCleaner v3.023 - Report created 16/04/2014 at 18:48:37
# Updated 01/04/2014 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Administrator - PC
# Running from : C:\Documents and Settings\Administrator\Plocha\adwcleaner.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : iSafeNetFilter

***** [ Files / Folders ] *****

Folder Deleted : C:\Documents and Settings\All Users\Data aplikací\AlawarSouthpoint
Folder Deleted : C:\Documents and Settings\All Users\Data aplikací\AlawarWrapper
Folder Deleted : C:\Documents and Settings\Administrator\Local Settings\Data aplikací\genienext
Folder Deleted : C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Mobogenie
Folder Deleted : C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Slick Savings
Folder Deleted : C:\Documents and Settings\Administrator\Local Settings\Data aplikací\AlawarWrapper
Folder Deleted : C:\Documents and Settings\Administrator\Data aplikací\eCyber
Folder Deleted : C:\Documents and Settings\Administrator\Data aplikací\AlawarSouthpoint

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6FB5B50A-863D-4C0D-8E84-92A59565D087}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C39937A9-C59D-4506-A9FC-0A0138192287}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DD55C1D4-CE89-4E93-866E-3F4A4962BD68}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A73204A3-4E2A-4924-95DA-D5DF58717368}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B5DB5A94-1E55-4E2E-AA50-49C8C8215D56}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B2E5F9A4-0587-4525-8602-E08E32510243}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C39937A9-C59D-4506-A9FC-0A0138192287}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DD55C1D4-CE89-4E93-866E-3F4A4962BD68}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8798BBE7-DDF6-448B-AE0E-83C9E28A5598}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F37BCE7B-6055-418C-A301-E715F36F1E79}
Key Deleted : HKLM\Software\PopularScreensavers

***** [ Browsers ] *****

-\\ Internet Explorer v6.0.2900.5512


-\\ Mozilla Firefox v28.0 (cs)

[ File : C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\fufq7kc7.default-1397651562180\prefs.js ]


-\\ Google Chrome v34.0.1847.116

[ File : C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [2734 octets] - [16/04/2014 18:06:57]
AdwCleaner[S0].txt - [2715 octets] - [16/04/2014 18:48:37]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2775 octets] ##########

Re: Virus přesměrování Yahoo

Napsal: 17 dub 2014 05:16
od cernohous13
Zatím ti to jde :thumbsup:

Zoek je na dlouho tak ho nech pracovat a nepropadej panice že nic nedělá :wink:

Log zoek

Napsal: 17 dub 2014 11:13
od endousek
Tak to projel i poslední zoek,po ukončení restartoval PC a celé dopoledne mi to akturalizovalo 137aktualizací :roll:

Zoek.exe v5.0.0.0 Updated 07-March-2014
Tool run by Administrator on źt 17.04.2014 at 9:24:27,61.
Systém Microsoft Windows XP Professional 5.1.2600 Service Pack 3 x86
Running in: Normal Mode No Internet Access Detected
Launched: C:\Documents and Settings\Administrator\Dokumenty\Stažené soubory\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

17.4.2014 9:25:40 Zoek.exe System Restore Point Created Succesfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-606747145-1708537768-839522115-500\Software\Microsoft\Internet Explorer\Approved Extensions\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5} deleted successfully

==== Running Processes ======================

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Program Files\AVAST Software\Avast\afwServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\acer\Wireless\Utility\WlanUtil.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\TeamViewer\Version8\TeamViewer.exe
C:\Program Files\TeamViewer\Version8\tv_w32.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SoftwareDistribution\Download\Install\ndp40-kb2789642-x86.exe
d:\19760ae9ca61fd1609a5\Setup.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\MsiExec.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Administrator\Dokumenty\Stažené soubory\zoek.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k HTTPFilter

==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\Documents and Settings\Administrator\daemonprocess.txt deleted
C:\Documents and Settings\Administrator\.android deleted
C:\Program Files\GUTF8.tmp deleted
C:\Program Files\GUMF7.tmp deleted
C:\WINDOWS\SET3.tmp deleted
C:\WINDOWS\SET4.tmp deleted
C:\WINDOWS\SET8.tmp deleted
C:\WINDOWS\System32\SET1C.tmp deleted
C:\WINDOWS\System32\SET8.tmp deleted
C:\WINDOWS\System32\SET9.tmp deleted
C:\WINDOWS\System32\SETA.tmp deleted
C:\WINDOWS\System32\SETC.tmp deleted

======== System Restore Points ========

RP130: 17.4.2014 8:39:28 - Kontrolní bod systému
RP131: 17.4.2014 9:25:40 - zoek.exe restore point

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension" [17.04.2014 06:44]

==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[16.04.2014 07:28]

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com/search?q={searchTerms}"
"CustomizeSearch"="http://www.google.com/search?q={searchTerms}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"CustomizeSearch"="http://www.google.com/search?q={searchTerms}"
"SearchAssistant"="http://www.google.com/search?q={searchTerms}"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"CustomizeSearch"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chcust.htm"
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"CustomizeSearch"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chcust.htm"
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... {startPage}"

==== HijackThis Entries ======================

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [acerWireless] C:\Program Files\acer\Wireless\Utility\WlanUtil.exe
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe

==== Empty IE Cache ======================

C:\Documents and Settings\Administrator\Local Settings\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

No Chrome User Data found

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=82 folders=2 15885826 bytes)

==== Empty Temp Folders ======================

C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\RECYCLER successfully emptied

==== Deleting Files / Folders ======================

"C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not deleted

==== EOF on źt 17.04.2014 at 11:32:58,59 ======================

Re: Virus přesměrování Yahoo

Napsal: 17 dub 2014 13:31
od cernohous13
:arrow: Stáhni a nainstaluj MBAM zde http://www.bleepingcomputer.com/downloa ... i-malware/ verzi 1.75
Spustit -> na 3.záložce "Aktualizace" -> Kontrola aktualizací (možná bude provedeno automaticky)
následně na 1.záložce "Kontrolor" -> Úplná kontrola -> Prohledat
po dokončení scanu vyskočí okno Notepad s výsledkem - obsah zkopíruj do své odpovědi
zatím nic nemazat - počkej na posouzení a program nezavírej

Re: Virus přesměrování Yahoo

Napsal: 17 dub 2014 15:46
od endousek
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org

Verze: v2014.04.17.04

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 6.0.2900.5512
Administrator :: PC [administrátor]

Ochrana: Povolena

17.4.2014 15:59:47
MBAM-log-2014-04-17 (16-44-35).txt

Typ: Kompletní kontrola (C:\|D:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 255160
Uplynulý čas: 39 minut, 2 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 1
D:\System Volume Information\_restore{D913B871-2863-480F-BBE5-8DDEE98B8853}\RP173\A0063047.exe (PUP.Optional.Softonic) -> Nebyla provedena žádná instrukce.

(konec)

Nic jsem nemazala ani nezavřela
Jinak ještě jednou moc děkuju za pomoc :thumbsup:

Re: Virus přesměrování Yahoo

Napsal: 17 dub 2014 15:52
od cernohous13
Taky dobré - MBAM můžeš odinstalovat :)

Dáš mi ještě aktuální RSIT?

Re: Virus přesměrování Yahoo

Napsal: 17 dub 2014 16:24
od endousek
OK, takže jestli jsem pochopila, nemám to, co to našlo, vymazávat?

Re: Virus přesměrování Yahoo

Napsal: 17 dub 2014 16:42
od cernohous13
Vymažu následně ve scriptu pro OTM + další podle logu RSIT :wink:

Re: Virus přesměrování Yahoo

Napsal: 17 dub 2014 17:14
od endousek
OK

Logfile of random's system information tool 1.09 (written by random/random)
Run by Administrator at 2014-04-16 14:51:36
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 872 MB (6%) free of 15 GB
Total RAM: 750 MB (47% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:52:24, on 16.4.2014
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Program Files\AVAST Software\Avast\afwServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TeamViewer\Version8\TeamViewer.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\acer\Wireless\Utility\WlanUtil.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\TeamViewer\Version8\tv_w32.exe
c:\program files\mozilla firefox\firefox.exe
C:\Documents and Settings\Administrator\Dokumenty\Stažené soubory\RSIT.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\trend micro\Administrator.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [acerWireless] C:\Program Files\acer\Wireless\Utility\WlanUtil.exe
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe

--
End of file - 4878 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\avast! Emergency Update.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\fufq7kc7.default-1397651562180

"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@popularscreensavers.com/Plugin]
"Description"=Popular Screensavers Plugin
"Path"=C:\Program Files\PopularScreensavers\NPp5Stub.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@PopularScreensavers_7i.com/Plugin]
"Description"=PopularScreensavers Plugin
"Path"=C:\Program Files\PopularScreensavers_7i\bar\1.bin\NP7iStub.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2004-02-10 155648]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2004-02-10 118784]
"acerWireless"=C:\Program Files\acer\Wireless\Utility\WlanUtil.exe [2004-06-09 417792]
"LManager"=C:\Program Files\Launch Manager\QtZgAcer.EXE [2004-07-30 319488]
"SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2004-05-20 98304]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2004-05-20 532480]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-04-16 3854640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2004-02-10 339968]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Documents and Settings\Administrator\Local Settings\Temp\TeamViewer\Version8\TeamViewer.exe"="C:\Documents and Settings\Administrator\Local Settings\Temp\TeamViewer\Version8\TeamViewer.exe:*:Enabled:TeamViewer 8"
"C:\Program Files\TeamViewer\Version8\TeamViewer.exe"="C:\Program Files\TeamViewer\Version8\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
"C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe"="C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe:*:Enabled:Teamviewer Remote Control Service"
"C:\Program Files\GameforgeLive\gfl_client.exe"="C:\Program Files\GameforgeLive\gfl_client.exe:*:Enabled:Gameforge Live"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"msacm.ac3filter"=ac3filter.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.scr - open - "C:\WINDOWS\system32\NOTEPAD.EXE" "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2014-04-16 14:51:43 ----D---- C:\Program Files\trend micro
2014-04-16 14:51:36 ----D---- C:\rsit
2014-04-16 07:29:57 ----A---- C:\WINDOWS\system32\drivers\aswNdis2.sys
2014-04-16 07:29:57 ----A---- C:\WINDOWS\system32\drivers\aswKbd.sys
2014-04-16 07:29:29 ----A---- C:\WINDOWS\avastSS.scr
2014-04-16 07:27:49 ----A---- C:\WINDOWS\system32\drivers\aswNdis.sys
2014-04-15 20:21:28 ----D---- C:\WINDOWS\system32\PreInstall
2014-04-15 20:21:26 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2014-04-15 20:21:25 ----HD---- C:\WINDOWS\$hf_mig$
2014-04-15 18:05:03 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2014-04-15 17:54:17 ----D---- C:\Program Files\GUMF7.tmp
2014-04-15 17:54:17 ----A---- C:\Program Files\GUTF8.tmp
2014-04-15 17:38:32 ----D---- C:\Documents and Settings\Administrator\Data aplikací\eCyber
2014-04-15 17:37:28 ----A---- C:\WINDOWS\system32\drivers\iSafeKrnlBoot.sys
2014-04-15 17:36:52 ----D---- C:\Program Files\iSafe
2014-04-15 17:36:44 ----D---- C:\Documents and Settings\Administrator\Data aplikací\iSafe
2014-04-13 10:05:46 ----A---- C:\WINDOWS\system32\d3d8caps.dat
2014-04-10 21:03:42 ----D---- C:\Program Files\Common Files\PDF Architect
2014-04-08 18:39:20 ----D---- C:\Program Files\Common Files\Spigot
2014-04-03 18:47:43 ----D---- C:\Program Files\Common Files\Borland Shared
2014-04-03 18:47:43 ----A---- C:\WINDOWS\system32\DBCLIENT.DLL
2014-04-03 18:46:51 ----D---- C:\Documents and Settings\All Users\Data aplikací\eXmind
2014-04-01 13:57:33 ----D---- C:\Documents and Settings\Administrator\Data aplikací\PDF Architect
2014-04-01 13:33:45 ----D---- C:\Documents and Settings\Administrator\Data aplikací\pdfforge
2014-04-01 13:33:34 ----A---- C:\WINDOWS\system32\pdfcmon.dll
2014-04-01 13:33:28 ----A---- C:\WINDOWS\system32\MSMPIDE.DLL
2014-04-01 13:33:27 ----D---- C:\Program Files\PDFCreator
2014-03-29 21:06:43 ----N---- C:\WINDOWS\system32\spmsg.dll
2014-03-29 21:06:37 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2014-03-29 21:05:54 ----D---- C:\Program Files\Windows Media Connect 2
2014-03-29 21:02:47 ----D---- C:\WINDOWS\system32\drivers\UMDF
2014-03-29 21:02:37 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2014-03-29 21:02:35 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2014-03-29 21:01:29 ----D---- C:\Documents and Settings\All Users\Data aplikací\Windows Genuine Advantage
2014-03-29 20:58:00 ----A---- C:\WINDOWS\system32\ptpusb.dll
2014-03-29 20:57:57 ----A---- C:\WINDOWS\system32\ptpusd.dll
2014-03-29 20:57:56 ----A---- C:\WINDOWS\system32\drivers\usbscan.sys
2014-03-29 11:46:02 ----D---- C:\Program Files\Mozilla Firefox
2014-03-17 14:41:31 ----A---- C:\WINDOWS\system32\drivers\USBAUDIO.sys
2014-03-17 14:41:24 ----A---- C:\WINDOWS\system32\drivers\usbccgp.sys

======List of files/folders modified in the last 1 month======

2014-04-16 14:51:43 ----RD---- C:\Program Files
2014-04-16 14:51:42 ----D---- C:\WINDOWS\Prefetch
2014-04-16 13:15:50 ----D---- C:\WINDOWS\Temp
2014-04-16 11:09:00 ----D---- C:\WINDOWS\system32\CatRoot2
2014-04-16 11:08:40 ----D---- C:\WINDOWS
2014-04-16 10:39:20 ----D---- C:\WINDOWS\system32
2014-04-16 10:19:15 ----D---- C:\Program Files\PopularScreensavers
2014-04-16 09:49:53 ----A---- C:\WINDOWS\SchedLgU.Txt
2014-04-16 08:26:22 ----HD---- C:\WINDOWS\inf
2014-04-16 08:24:15 ----D---- C:\WINDOWS\system32\CatRoot
2014-04-16 07:30:24 ----D---- C:\WINDOWS\system32\drivers
2014-04-16 07:30:04 ----SD---- C:\WINDOWS\Tasks
2014-04-16 07:29:29 ----A---- C:\WINDOWS\system32\aswBoot.exe
2014-04-16 06:47:12 ----RSHDC---- C:\WINDOWS\system32\dllcache
2014-04-15 18:05:24 ----D---- C:\WINDOWS\SoftwareDistribution
2014-04-15 18:05:15 ----D---- C:\WINDOWS\Help
2014-04-15 18:03:48 ----SHD---- C:\WINDOWS\Installer
2014-04-15 17:37:25 ----RSD---- C:\WINDOWS\Fonts
2014-04-10 21:13:38 ----D---- C:\Program Files\GameforgeLive
2014-04-10 21:08:19 ----A---- C:\WINDOWS\win.ini
2014-04-10 21:07:56 ----D---- C:\Program Files\Windows Media Player
2014-04-10 21:04:48 ----SHD---- C:\Config.Msi
2014-04-10 21:03:42 ----D---- C:\Program Files\Common Files
2014-04-10 20:59:27 ----D---- C:\Program Files\xerox
2014-04-04 06:57:56 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-03-29 21:06:46 ----A---- C:\WINDOWS\imsins.BAK
2014-03-29 21:02:47 ----D---- C:\WINDOWS\system32\LogFiles

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswNdis;avast! Firewall NDIS Filter Service; C:\WINDOWS\system32\DRIVERS\aswNdis.sys [2014-04-16 12112]
R0 aswNdis2;avast! Firewall NDIS Driver; C:\WINDOWS\system32\drivers\aswNdis2.sys [2014-04-16 252208]
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2014-04-16 49944]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2014-04-16 180760]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [2014-04-16 26136]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2014-04-16 54832]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2014-04-16 776976]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2014-04-16 411552]
R1 aswTdi;aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [2014-04-16 57672]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 iSafeNetFilter;iSafeNetFilter; \??\C:\Program Files\iSafe\iSafeNetFilter.sys []
R1 SMBHC;Microsoft SM Bus Host Controller Driver; C:\WINDOWS\system32\DRIVERS\SMBHC.sys [2001-08-17 6784]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2014-04-16 67824]
R2 irda;Protokol IrDA; C:\WINDOWS\system32\DRIVERS\irda.sys [2008-04-14 88192]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2003-04-09 11043]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-14 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2001-10-25 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2001-10-25 55936]
R3 CAMCAUD;Conexant AMC Audio; C:\WINDOWS\system32\drivers\camcaud.sys [2004-04-29 292352]
R3 CAMCHALA;CAMCHALA; C:\WINDOWS\system32\drivers\camchal.sys [2004-04-29 274688]
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver; C:\WINDOWS\System32\Drivers\DKbFltr.sys [2002-11-20 17983]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSF_DP.sys [2004-03-10 1041536]
R3 HSFHWICH;HSFHWICH; C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys [2004-03-10 199552]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2004-02-10 681469]
R3 NSCIRDA;NSC Infrared Device Driver; C:\WINDOWS\system32\DRIVERS\nscirda.sys [2008-04-14 28672]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver; C:\WINDOWS\system32\DRIVERS\rt2870.sys [2013-11-22 637952]
R3 SMBBATT;Microsoft Smart Battery Driver; C:\WINDOWS\system32\DRIVERS\SMBBATT.sys [2008-04-14 16000]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2004-05-20 184768]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2004-03-10 682624]
S2 DgiVecp;DgiVecp; \??\C:\WINDOWS\system32\Drivers\DgiVecp.sys []
S2 SSPORT;SSPORT; \??\C:\WINDOWS\system32\Drivers\SSPORT.sys []
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
S3 b57w2k;BCM5701 Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2001-10-24 97120]
S3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2003-09-26 44032]
S3 EpmShd;Acer EPM System Hardware Driver; \??\C:\WINDOWS\system32\Drivers\epm-shd.sys []
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 IPN2220;acer IPN2220 Wireless LAN Card Driver; C:\WINDOWS\system32\DRIVERS\i2220ntx.sys [2004-03-29 140288]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
S3 PCANDIS5;PCANDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PCANDIS5.SYS []
S3 tifm21;tifm21; C:\WINDOWS\system32\drivers\tifm21.sys [2004-05-26 67584]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 anbmService;Notebook Manager Service; C:\Acer\eManager\anbmServ.exe [2004-07-05 1286144]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-04-16 50344]
R2 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [2014-04-16 109048]
R2 Irmon;Sledování infračerveného přenosu; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 TeamViewer8;TeamViewer 8; C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe [2014-02-07 5093216]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-04-15 116648]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2014-01-16 85096]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-04-15 116648]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Re: Virus přesměrování Yahoo

Napsal: 17 dub 2014 17:57
od cernohous13
Stáhni OTM z jednoho odkazu a rozbal nejlépe na plochu.
http://oldtimer.geekstogo.com/OTM.exe
http://www.itxassociates.com/OT-Tools/OTM.exe

Spusť program „OTM.exe“ (pro Vistu a Win7 – pravým a „Run As Administrator“).
Do okna pod žlutou čáru vlož celý text zeleným písmem ze „Scriptu“

Klikni na červené „MoveIt!“

Při nabídce restartu „YES“
a log potom najdeš v C:\_OTM\MovedFiles\ - dej mi ho sem na kontrolu
Script OTM

Kód: Vybrat vše

:Commands
[resethosts]
[emptytemp]
[emptyflash]
[emptyjava]
[clearallrestorepoints]

:Files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp /s
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\Program Files\GUMF7.tmp
C:\Program Files\GUTF8.tmp
C:\Program Files\Common Files\Spigot

:Services
DgiVecp
SSPORT
:arrow: Dáš mi výsledný log a popis případných problémů

Re: Virus přesměrování Yahoo

Napsal: 17 dub 2014 18:16
od endousek
All processes killed
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 881060272 bytes
->Temporary Internet Files folder emptied: 68039 bytes
->FireFox cache emptied: 33275072 bytes
->Google Chrome cache emptied: 258996484 bytes
->Flash cache emptied: 6142 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 799176 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 17929946 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 66605289 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 1 201,00 mb


[EMPTYFLASH]

User: Administrator
->Flash cache emptied: 0 bytes

User: All Users

User: Default User

User: LocalService

User: NetworkService

Total Flash Files Cleaned = 0,00 mb


[EMPTYJAVA]

User: Administrator

User: All Users

User: Default User

User: LocalService

User: NetworkService

Total Java Files Cleaned = 0,00 mb


Restore point Set: OTM Restore Point
========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\inf\SET2EE.tmp moved successfully.
C:\WINDOWS\Installer\MSI16A.tmp moved successfully.
C:\WINDOWS\Installer\MSI176.tmp moved successfully.
C:\WINDOWS\Installer\MSI887.tmp moved successfully.
C:\WINDOWS\Installer\MSIFD.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\509ce25d45fe208ee57ad15aa1012d9c\BITE4B.tmp moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
File/Folder C:\Program Files\GUMF7.tmp not found.
File/Folder C:\Program Files\GUTF8.tmp not found.
File/Folder C:\Program Files\Common Files\Spigot not found.
========== SERVICES/DRIVERS ==========
Service DgiVecp stopped successfully!
Service DgiVecp deleted successfully!
Service SSPORT stopped successfully!
Service SSPORT deleted successfully!

OTM by OldTimer - Version 3.1.21.0 log created on 04172014_190450

Po restartu nenaskočily složky na ploše, ale opět se chtěl spustit OTM, stornovala jsem ho, pak se plocha načetla.
Po najetí do Cčka se mi objevili i skryté složky a soubory, nikdy předtím jsem je neviděla, teď jsou viditelné, ale jako zašedlé, otevřít se ale některé složky dají.

Re: Virus přesměrování Yahoo

Napsal: 18 dub 2014 05:02
od cernohous13
OTM provádí některé úkony až při restartu, proto zdržení při načítání plochy :wink:

:arrow: Spusť opět OTM -> CleanUp! - odinstaluje a vyčistí po sobě.

Pokud i potom budou vidět skryté, můžu ti napsat návod nebo to zvládneš sama? :?: