JS/Kryptik - Lusica
Napsal: 11 kvě 2014 14:53
Dobrý den, patrně mám stejný problém jako zakladatel tohoto tématu. NOD32 při načítání webové stránky hlásí infiltraci (hxxp://cdneurope.com/componentsLink/popUp.js) z důvodu JS/kryptikI. Chtěla bych požádat o pomoc, pokud by to bylo možné. Moc děkuju.
Zde je log z FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:11-05-2014
Ran by Anička (administrator) on ANIČKA-NTB on 11-05-2014 15:13:30
Running from C:\Users\Anička\Desktop
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
(Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Syntek America Inc.) C:\Windows\System32\StkCSrv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(DT Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTLite.exe
() C:\Program Files\RocketDock\RocketDock.exe
() C:\Users\Anička\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe
(AIMP DevTeam) C:\Program Files\AIMP2\AIMP2.exe
(forum.viry.cz) C:\Users\Anička\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [NvCplDaemon] => C:\Windows\system32\NvCpl.dll [13605408 2009-03-06] (NVIDIA Corporation)
HKLM\...\Run: [NvMediaCenter] => C:\Windows\system32\NvMcTray.dll [92704 2009-03-06] (NVIDIA Corporation)
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [509320 2010-01-13] (ELAN Microelectronic Corp.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [815104 2006-11-22] (Synaptics, Inc.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [5110672 2013-09-12] (ESET)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM\...\Run: [seznam-listicka-distribuce] => C:\Program Files\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\Windows\System32\SPReview\SPReview.exe [280576 2013-09-26] (Microsoft Corporation)
HKU\S-1-5-21-2312878714-3981626620-3961080377-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [369200 2009-10-30] (DT Soft Ltd)
HKU\S-1-5-21-2312878714-3981626620-3961080377-1001\...\Run: [RocketDock] => C:\Program Files\RocketDock\RocketDock.exe [495616 2007-09-02] ()
HKU\S-1-5-21-2312878714-3981626620-3961080377-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Anička\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-2312878714-3981626620-3961080377-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Anička\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-2312878714-3981626620-3961080377-1001\...\MountPoints2: {e8e2638b-25d4-11e3-a14d-001a927a7deb} - "G:\WD SmartWare.exe" autoplay=true
HKU\S-1-5-21-2312878714-3981626620-3961080377-1001\...0c966feabec1\InprocServer32: [Default-shell32] ATTENTION! ====> ZeroAccess?
==================== Internet (Whitelisted) ====================
SearchScopes: HKCU - DefaultScope {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = http://www.daemon-search.com/search?q={searchTerms}
SearchScopes: HKCU - {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = http://www.daemon-search.com/search?q={searchTerms}
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
Toolbar: HKCU - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Anička\AppData\Roaming\Mozilla\Firefox\Profiles\6gi1wsqx.default
FF Homepage: http://www.seznam.cz
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: DAEMON Tools Toolbar - C:\Users\Anička\AppData\Roaming\Mozilla\Firefox\Profiles\6gi1wsqx.default\Extensions\DTToolbar@toolbarnet.com [2013-09-26]
FF Extension: WebSite Recommendation - C:\Users\Anička\AppData\Roaming\Mozilla\Firefox\Profiles\6gi1wsqx.default\Extensions\WebSiteRecommendation@weliketheweb.com [2014-03-21]
FF Extension: DownloadHelper - C:\Users\Anička\AppData\Roaming\Mozilla\Firefox\Profiles\6gi1wsqx.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-26]
FF Extension: Seznam lištička - C:\Users\Anička\AppData\Roaming\Mozilla\Firefox\Profiles\6gi1wsqx.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2014-05-02]
FF Extension: NoScript - C:\Users\Anička\AppData\Roaming\Mozilla\Firefox\Profiles\6gi1wsqx.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-10-28]
FF Extension: Adblock Plus - C:\Users\Anička\AppData\Roaming\Mozilla\Firefox\Profiles\6gi1wsqx.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-09-29]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2013-11-14]
========================== Services (Whitelisted) =================
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [1337752 2013-09-12] (ESET)
R2 StkSSrv; C:\Windows\System32\StkCSrv.exe [24576 2007-04-19] (Syntek America Inc.)
==================== Drivers (Whitelisted) ====================
R3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [22528 2009-08-13] (CSR, plc)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [188808 2013-09-17] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [134248 2013-09-17] (ESET)
R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [122376 2013-09-17] (ESET)
S3 ETD; C:\Windows\System32\DRIVERS\ETD.sys [102400 2010-01-18] (ELAN Microelectronic Corp.)
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2007-07-31] (ATK0100)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2013-09-25] ()
R3 StkCMini; C:\Windows\System32\Drivers\StkCMini.sys [1260672 2007-06-06] (Syntek)
U3 a3zpmygv; C:\Windows\system32\Drivers\a3zpmygv.sys [0 ] (Microsoft Corporation)
S3 btmaux; system32\DRIVERS\btmaux.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-11 15:13 - 2014-05-11 15:14 - 00009294 _____ () C:\Users\Anička\Desktop\FRST.txt
2014-05-11 15:13 - 2014-05-11 15:13 - 00000000 ____D () C:\FRST
2014-05-11 15:10 - 2014-05-11 15:10 - 00112640 _____ (forum.viry.cz) C:\Users\Anička\Desktop\FRSTLauncher.exe
2014-05-11 15:09 - 2014-05-11 15:09 - 01055232 _____ (Farbar) C:\Users\Anička\Desktop\FRST.exe
2014-05-01 11:46 - 2014-05-02 22:32 - 00000000 ____D () C:\Users\Anička\Documents\mendls
==================== One Month Modified Files and Folders =======
2014-05-11 15:14 - 2014-05-11 15:13 - 00009294 _____ () C:\Users\Anička\Desktop\FRST.txt
2014-05-11 15:13 - 2014-05-11 15:13 - 00000000 ____D () C:\FRST
2014-05-11 15:10 - 2014-05-11 15:10 - 00112640 _____ (forum.viry.cz) C:\Users\Anička\Desktop\FRSTLauncher.exe
2014-05-11 15:09 - 2014-05-11 15:09 - 01055232 _____ (Farbar) C:\Users\Anička\Desktop\FRST.exe
2014-05-11 15:07 - 2013-09-26 12:51 - 00000000 ____D () C:\Users\Anička\Documents\Programy
2014-05-11 14:30 - 2013-09-25 11:41 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-11 14:23 - 2013-09-25 11:13 - 01740406 _____ () C:\Windows\WindowsUpdate.log
2014-05-09 07:18 - 2009-07-14 06:34 - 00014256 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-09 07:18 - 2009-07-14 06:34 - 00014256 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-09 07:17 - 2014-02-06 00:05 - 00000000 ____D () C:\Users\Anička\AppData\Roaming\Seznam.cz
2014-05-09 07:17 - 2013-09-25 11:31 - 01445734 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-09 07:12 - 2014-02-05 01:44 - 00000348 _____ () C:\Windows\Tasks\DriverToolkit Autorun.job
2014-05-09 07:12 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-09 07:12 - 2009-07-14 06:39 - 00037486 _____ () C:\Windows\setupact.log
2014-05-08 21:50 - 2013-09-26 19:15 - 00000000 ____D () C:\Users\Anička\Documents\Práce
2014-05-04 16:57 - 2013-09-25 22:09 - 00000000 ____D () C:\Users\Anička\Documents\Knihy práce
2014-05-02 22:32 - 2014-05-01 11:46 - 00000000 ____D () C:\Users\Anička\Documents\mendls
2014-05-01 12:18 - 2014-01-22 12:25 - 00002828 ___SH () C:\ProgramData\KGyGaAvL.sys
2014-04-28 21:46 - 2013-09-25 11:41 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-04-28 21:46 - 2013-09-25 11:41 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-04-21 21:15 - 2014-02-11 22:50 - 00100864 ___SH () C:\Users\Anička\Documents\Thumbs.db
2014-04-21 17:49 - 2013-10-22 20:59 - 00000000 ____D () C:\Users\Anička\Documents\Knihy soukromé
2014-04-16 00:02 - 2013-09-28 17:08 - 00000000 ____D () C:\Users\Anička\Documents\Recepty
2014-04-15 21:59 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-04-13 15:07 - 2013-10-16 19:15 - 00000000 ____D () C:\Users\Anička\Documents\Film
Some content of TEMP:
====================
C:\Users\Anička\AppData\Local\Temp\AtiCimUn.exe
C:\Users\Anička\AppData\Local\Temp\GomAudDnInstaller.exe
C:\Users\Anička\AppData\Local\Temp\InstHelper.exe
C:\Users\Anička\AppData\Local\Temp\ose00000.exe
C:\Users\Anička\AppData\Local\Temp\Uninst.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DriverToolkit Autorun.job => C:\Program Files\DriverToolkit\DriverToolkit.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: ESET NOD32 Antivirus 7.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET NOD32 Antivirus 7.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Ani�ka\Desktop" je 1 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Zde je log z FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:11-05-2014
Ran by Anička (administrator) on ANIČKA-NTB on 11-05-2014 15:13:30
Running from C:\Users\Anička\Desktop
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
(Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Syntek America Inc.) C:\Windows\System32\StkCSrv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(DT Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTLite.exe
() C:\Program Files\RocketDock\RocketDock.exe
() C:\Users\Anička\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe
(AIMP DevTeam) C:\Program Files\AIMP2\AIMP2.exe
(forum.viry.cz) C:\Users\Anička\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [NvCplDaemon] => C:\Windows\system32\NvCpl.dll [13605408 2009-03-06] (NVIDIA Corporation)
HKLM\...\Run: [NvMediaCenter] => C:\Windows\system32\NvMcTray.dll [92704 2009-03-06] (NVIDIA Corporation)
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [509320 2010-01-13] (ELAN Microelectronic Corp.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [815104 2006-11-22] (Synaptics, Inc.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [5110672 2013-09-12] (ESET)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM\...\Run: [seznam-listicka-distribuce] => C:\Program Files\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\Windows\System32\SPReview\SPReview.exe [280576 2013-09-26] (Microsoft Corporation)
HKU\S-1-5-21-2312878714-3981626620-3961080377-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [369200 2009-10-30] (DT Soft Ltd)
HKU\S-1-5-21-2312878714-3981626620-3961080377-1001\...\Run: [RocketDock] => C:\Program Files\RocketDock\RocketDock.exe [495616 2007-09-02] ()
HKU\S-1-5-21-2312878714-3981626620-3961080377-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Anička\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-2312878714-3981626620-3961080377-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Anička\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-2312878714-3981626620-3961080377-1001\...\MountPoints2: {e8e2638b-25d4-11e3-a14d-001a927a7deb} - "G:\WD SmartWare.exe" autoplay=true
HKU\S-1-5-21-2312878714-3981626620-3961080377-1001\...0c966feabec1\InprocServer32: [Default-shell32] ATTENTION! ====> ZeroAccess?
==================== Internet (Whitelisted) ====================
SearchScopes: HKCU - DefaultScope {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = http://www.daemon-search.com/search?q={searchTerms}
SearchScopes: HKCU - {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = http://www.daemon-search.com/search?q={searchTerms}
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
Toolbar: HKCU - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Anička\AppData\Roaming\Mozilla\Firefox\Profiles\6gi1wsqx.default
FF Homepage: http://www.seznam.cz
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: DAEMON Tools Toolbar - C:\Users\Anička\AppData\Roaming\Mozilla\Firefox\Profiles\6gi1wsqx.default\Extensions\DTToolbar@toolbarnet.com [2013-09-26]
FF Extension: WebSite Recommendation - C:\Users\Anička\AppData\Roaming\Mozilla\Firefox\Profiles\6gi1wsqx.default\Extensions\WebSiteRecommendation@weliketheweb.com [2014-03-21]
FF Extension: DownloadHelper - C:\Users\Anička\AppData\Roaming\Mozilla\Firefox\Profiles\6gi1wsqx.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-26]
FF Extension: Seznam lištička - C:\Users\Anička\AppData\Roaming\Mozilla\Firefox\Profiles\6gi1wsqx.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2014-05-02]
FF Extension: NoScript - C:\Users\Anička\AppData\Roaming\Mozilla\Firefox\Profiles\6gi1wsqx.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-10-28]
FF Extension: Adblock Plus - C:\Users\Anička\AppData\Roaming\Mozilla\Firefox\Profiles\6gi1wsqx.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-09-29]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2013-11-14]
========================== Services (Whitelisted) =================
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [1337752 2013-09-12] (ESET)
R2 StkSSrv; C:\Windows\System32\StkCSrv.exe [24576 2007-04-19] (Syntek America Inc.)
==================== Drivers (Whitelisted) ====================
R3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [22528 2009-08-13] (CSR, plc)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [188808 2013-09-17] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [134248 2013-09-17] (ESET)
R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [122376 2013-09-17] (ESET)
S3 ETD; C:\Windows\System32\DRIVERS\ETD.sys [102400 2010-01-18] (ELAN Microelectronic Corp.)
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2007-07-31] (ATK0100)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2013-09-25] ()
R3 StkCMini; C:\Windows\System32\Drivers\StkCMini.sys [1260672 2007-06-06] (Syntek)
U3 a3zpmygv; C:\Windows\system32\Drivers\a3zpmygv.sys [0 ] (Microsoft Corporation)
S3 btmaux; system32\DRIVERS\btmaux.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-11 15:13 - 2014-05-11 15:14 - 00009294 _____ () C:\Users\Anička\Desktop\FRST.txt
2014-05-11 15:13 - 2014-05-11 15:13 - 00000000 ____D () C:\FRST
2014-05-11 15:10 - 2014-05-11 15:10 - 00112640 _____ (forum.viry.cz) C:\Users\Anička\Desktop\FRSTLauncher.exe
2014-05-11 15:09 - 2014-05-11 15:09 - 01055232 _____ (Farbar) C:\Users\Anička\Desktop\FRST.exe
2014-05-01 11:46 - 2014-05-02 22:32 - 00000000 ____D () C:\Users\Anička\Documents\mendls
==================== One Month Modified Files and Folders =======
2014-05-11 15:14 - 2014-05-11 15:13 - 00009294 _____ () C:\Users\Anička\Desktop\FRST.txt
2014-05-11 15:13 - 2014-05-11 15:13 - 00000000 ____D () C:\FRST
2014-05-11 15:10 - 2014-05-11 15:10 - 00112640 _____ (forum.viry.cz) C:\Users\Anička\Desktop\FRSTLauncher.exe
2014-05-11 15:09 - 2014-05-11 15:09 - 01055232 _____ (Farbar) C:\Users\Anička\Desktop\FRST.exe
2014-05-11 15:07 - 2013-09-26 12:51 - 00000000 ____D () C:\Users\Anička\Documents\Programy
2014-05-11 14:30 - 2013-09-25 11:41 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-11 14:23 - 2013-09-25 11:13 - 01740406 _____ () C:\Windows\WindowsUpdate.log
2014-05-09 07:18 - 2009-07-14 06:34 - 00014256 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-09 07:18 - 2009-07-14 06:34 - 00014256 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-09 07:17 - 2014-02-06 00:05 - 00000000 ____D () C:\Users\Anička\AppData\Roaming\Seznam.cz
2014-05-09 07:17 - 2013-09-25 11:31 - 01445734 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-09 07:12 - 2014-02-05 01:44 - 00000348 _____ () C:\Windows\Tasks\DriverToolkit Autorun.job
2014-05-09 07:12 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-09 07:12 - 2009-07-14 06:39 - 00037486 _____ () C:\Windows\setupact.log
2014-05-08 21:50 - 2013-09-26 19:15 - 00000000 ____D () C:\Users\Anička\Documents\Práce
2014-05-04 16:57 - 2013-09-25 22:09 - 00000000 ____D () C:\Users\Anička\Documents\Knihy práce
2014-05-02 22:32 - 2014-05-01 11:46 - 00000000 ____D () C:\Users\Anička\Documents\mendls
2014-05-01 12:18 - 2014-01-22 12:25 - 00002828 ___SH () C:\ProgramData\KGyGaAvL.sys
2014-04-28 21:46 - 2013-09-25 11:41 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-04-28 21:46 - 2013-09-25 11:41 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-04-21 21:15 - 2014-02-11 22:50 - 00100864 ___SH () C:\Users\Anička\Documents\Thumbs.db
2014-04-21 17:49 - 2013-10-22 20:59 - 00000000 ____D () C:\Users\Anička\Documents\Knihy soukromé
2014-04-16 00:02 - 2013-09-28 17:08 - 00000000 ____D () C:\Users\Anička\Documents\Recepty
2014-04-15 21:59 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-04-13 15:07 - 2013-10-16 19:15 - 00000000 ____D () C:\Users\Anička\Documents\Film
Some content of TEMP:
====================
C:\Users\Anička\AppData\Local\Temp\AtiCimUn.exe
C:\Users\Anička\AppData\Local\Temp\GomAudDnInstaller.exe
C:\Users\Anička\AppData\Local\Temp\InstHelper.exe
C:\Users\Anička\AppData\Local\Temp\ose00000.exe
C:\Users\Anička\AppData\Local\Temp\Uninst.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DriverToolkit Autorun.job => C:\Program Files\DriverToolkit\DriverToolkit.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: ESET NOD32 Antivirus 7.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET NOD32 Antivirus 7.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Ani�ka\Desktop" je 1 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================