Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosim o kontrolu

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
superjano
Návštěvník
Návštěvník
Příspěvky: 69
Registrován: 16 srp 2005 23:08

Prosim o kontrolu

#1 Příspěvek od superjano »

Logfile of random's system information tool 1.10 (written by random/random)
Run by Milan at 2014-09-02 13:28:51
Microsoft® Windows Vista™ Home Premium
System drive C: has 50 GB (17%) free of 297 GB
Total RAM: 3007 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:29:02, on 2. 9. 2014
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16982)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HTC\HTC Sync Manager\HTC Sync\adb.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Windows\System32\mobsync.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Milan\Downloads\RSIT (1).exe
C:\Program Files\trend micro\Milan.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Search App by Ask BHO - {41564952-412D-5350-00A7-7A786E7484D7} - "C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-SP\Passport.dll" (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Search App by Ask - {41564952-412D-5350-00A7-7A786E7484D7} - "C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-SP\Passport.dll" (file missing)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [VMonitorVMUVC] "C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe" VMUVC
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [ApnTBMon] "C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
O4 - HKLM\..\Run: [Avira Systray] C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
O4 - HKLM\..\Run: [mslpchSrv] "C:\Windows\system32\mslpch.vbe" mswaygv msjeib
O4 - HKLM\..\Run: [MSStp] C:\Windows\inf\msstp.vbe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} - http://195.28.70.134/kapor2/lib/mgaxctrl.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Ask Update Service (APNMCP) - APN LLC. - C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Avira Service Host (Avira.OE.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HTCMonitorService - Nero AG - C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files\Sony\Sony PC Companion\PCCService.exe

--
End of file - 8734 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000Core.job - C:\Users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000UA.job - C:\Users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
HP Print Clips - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [2007-03-02 177768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5350-00A7-7A786E7484D7}]
Search App by Ask - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-SP\Passport.dll [2014-07-31 12184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-10-22 449512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-10-22 155384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{41564952-412D-5350-00A7-7A786E7484D7} - Search App by Ask - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-SP\Passport.dll [2014-07-31 12184]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2006-11-02 1004136]
"VMonitorVMUVC"=C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe [2007-12-20 135168]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-03-11 49152]
"VirtualCloneDrive"=C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2011-03-07 89456]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-09-13 59720]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2013-09-17 152392]
"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2013-07-31 2296600]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2014-08-12 751184]
"ApnTBMon"=C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [2014-07-31 1957784]
"Avira Systray"=C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [2014-08-04 161584]
"mslpchSrv"=C:\Windows\system32\mslpch.vbe [2014-06-23 649]
"MSStp"=C:\Windows\inf\msstp.vbe [2014-03-05 1584]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2012-06-24 1232896]
"Facebook Update"=C:\Users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-17 138096]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv

======List of files/folders created in the last 1 month======

2014-08-29 18:22:00 ----D---- C:\Windows\system32\bitstreams
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\zlib1.dll
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\ssleay32.dll
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\pthreadVC2.dll
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\pthreadGC2.dll
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\libssh2.dll
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\librtmp.dll
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\libidn-11.dll
2014-08-29 18:22:00 ----AS---- C:\Windows\system32\acumncebtxi.exe
2014-08-29 18:21:59 ----AS---- C:\Windows\system32\libeay32.dll
2014-08-29 18:21:59 ----AS---- C:\Windows\system32\libcurl-4.dll
2014-08-29 18:21:59 ----AS---- C:\Windows\system32\cudart32_50_35.dll
2014-08-29 18:20:30 ----AS---- C:\Windows\system32\nircmdc.exe
2014-08-14 15:43:32 ----D---- C:\ProgramData\Package Cache
2014-08-11 18:02:47 ----D---- C:\Program Files\Common Files\Skype
2014-08-11 18:02:46 ----RD---- C:\Program Files\Skype
2014-08-08 10:31:03 ----D---- C:\ProgramData\AskPartnerNetwork
2014-08-08 10:31:03 ----D---- C:\Program Files\AskPartnerNetwork
2014-08-08 10:30:48 ----D---- C:\Users\Milan\AppData\Roaming\Avira
2014-08-08 10:30:38 ----D---- C:\ProgramData\APN
2014-08-08 10:28:49 ----A---- C:\Windows\system32\drivers\ssmdrv.sys
2014-08-08 10:28:41 ----A---- C:\Windows\system32\drivers\avkmgr.sys
2014-08-08 10:28:41 ----A---- C:\Windows\system32\drivers\avipbb.sys
2014-08-08 10:28:40 ----A---- C:\Windows\system32\drivers\avgntflt.sys
2014-08-08 10:28:38 ----D---- C:\ProgramData\Avira
2014-08-08 10:28:38 ----D---- C:\Program Files\Avira
2014-08-06 16:59:16 ----D---- C:\Program Files\ESET
2014-08-06 13:33:23 ----SHD---- C:\$RECYCLE.BIN
2014-08-06 13:29:36 ----SD---- C:\ComboFix
2014-08-06 13:29:30 ----D---- C:\Qoobox
2014-08-06 13:28:58 ----D---- C:\Windows\erdnt
2014-08-06 13:28:55 ----SD---- C:\32788R22FWJFW
2014-08-06 12:06:52 ----D---- C:\Program Files\trend micro
2014-08-06 12:06:51 ----D---- C:\rsit
2014-08-06 10:06:27 ----D---- C:\Users\Milan\AppData\Roaming\TuneUp Software

======List of files/folders modified in the last 1 month======

2014-09-02 13:29:01 ----D---- C:\Windows\Temp
2014-09-02 13:28:51 ----D---- C:\Windows\Prefetch
2014-09-02 13:17:06 ----D---- C:\Windows\System32
2014-09-02 13:17:05 ----D---- C:\Windows\inf
2014-09-02 13:17:05 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-09-02 13:12:31 ----D---- C:\Windows\system32\catroot2
2014-09-01 11:18:13 ----SHD---- C:\System Volume Information
2014-08-31 13:40:03 ----D---- C:\Users\Milan\AppData\Roaming\Skype
2014-08-29 18:31:34 ----RD---- C:\Program Files
2014-08-29 17:55:53 ----D---- C:\ProgramData\NVIDIA
2014-08-20 07:42:38 ----HD---- C:\Config.Msi
2014-08-19 17:43:49 ----SHD---- C:\Windows\Installer
2014-08-15 20:09:17 ----A---- C:\Windows\win.ini
2014-08-14 15:43:32 ----HD---- C:\ProgramData
2014-08-11 18:03:10 ----D---- C:\ProgramData\Skype
2014-08-11 18:02:47 ----D---- C:\Program Files\Common Files
2014-08-08 10:40:05 ----D---- C:\Windows\system32\catroot
2014-08-08 10:34:15 ----D---- C:\Program Files\AVG
2014-08-08 10:34:12 ----D---- C:\ProgramData\MFAData
2014-08-08 10:28:49 ----D---- C:\Windows\system32\drivers
2014-08-07 18:48:11 ----D---- C:\Windows\Tasks
2014-08-07 17:59:27 ----D---- C:\Windows\system32\Tasks
2014-08-06 13:55:16 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2014-08-06 13:32:52 ----D---- C:\Windows
2014-08-06 10:18:13 ----D---- C:\ProgramData\AVAST Software
2014-08-06 09:58:36 ----SD---- C:\Windows\system32\Microsoft
2014-08-05 19:31:45 ----D---- C:\Users\Milan\AppData\Roaming\Notepad++
2014-08-05 19:31:45 ----D---- C:\Program Files\PDFCreator
2014-08-05 19:31:14 ----D---- C:\Windows\Panther
2014-08-05 19:31:13 ----D---- C:\Windows\Minidump
2014-08-05 19:31:13 ----D---- C:\Windows\Debug
2014-08-05 19:28:26 ----D---- C:\Windows\system32\NDF

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2014-05-09 136216]
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2014-05-09 37352]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2010-12-17 31088]
R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2014-05-09 28520]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2014-08-08 97648]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 26840]
R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2013-05-23 43800]
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\Windows\System32\Drivers\LUsbFilt.Sys [2013-05-23 28312]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2012-05-15 11354944]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2006-11-02 44544]
R3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2006-11-02 71552]
R3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2011-01-15 30208]
R3 VMUVC;Vimicro Camera Service VMUVC; C:\Windows\System32\Drivers\VMUVC.sys [2010-01-12 252928]
R3 vvftUVC;Vimicro Camera Filter Service VMUVC; C:\Windows\system32\drivers\vvftUVC.sys [2008-07-01 398720]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2006-11-02 82560]
S3 AndNetDiag;LGE AndroidNet USB Serial Port; C:\Windows\system32\DRIVERS\lgandnetdiag.sys [2012-07-03 23040]
S3 ANDNetModem;LGE AndroidNet USB Modem; C:\Windows\system32\DRIVERS\lgandnetmodem.sys [2012-07-03 27776]
S3 andnetndis;LGE AndroidNet NDIS Ethernet Adapter; C:\Windows\system32\DRIVERS\lgandnetndis.sys [2012-07-04 70400]
S3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athur.sys [2010-01-05 1387008]
S3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\DRIVERS\BthEnum.sys [2012-06-24 19456]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2006-11-02 92160]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2012-06-24 220160]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2012-06-24 29184]
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2006-11-02 131584]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2006-11-02 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2006-11-02 36864]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2006-11-02 5632]
S3 HTCAND32;HTC Device Driver; C:\Windows\System32\Drivers\ANDROIDUSB.sys []
S3 htcnprot;HTC NDIS Protocol Driver; C:\Windows\system32\DRIVERS\htcnprot.sys [2012-12-07 23040]
S3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2012-09-18 39608]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2006-11-02 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2006-11-02 6016]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2006-11-02 49664]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM); C:\Windows\system32\DRIVERS\s1039bus.sys [2010-03-01 98672]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s1039mdfl.sys [2010-03-01 14960]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s1039mdm.sys [2010-03-01 124016]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s1039mgmt.sys [2010-03-01 117872]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS); C:\Windows\system32\DRIVERS\s1039nd5.sys [2010-03-01 25456]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s1039obex.sys [2010-03-01 113904]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM); C:\Windows\system32\DRIVERS\s1039unic.sys [2010-03-01 123504]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2006-11-02 35328]
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2006-11-02 132352]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2006-11-02 39936]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-18 65432]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2014-08-12 430160]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2014-08-12 430160]
R2 AntiVirWebService;Avira Web Protection; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2014-08-12 1021008]
R2 APNMCP;Ask Update Service; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [2014-07-31 165784]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2013-09-07 55624]
R2 Avira.OE.ServiceHost;Avira Service Host; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [2014-08-04 149296]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2006-11-02 22016]
R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\Windows\system32\svchost.exe [2006-11-02 22016]
R2 HTCMonitorService;HTCMonitorService; C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe [2013-11-18 87368]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2006-11-02 22016]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-05-15 645440]
R2 PassThru Service;Internet Pass-Through Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [2012-12-07 167424]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2006-11-02 22016]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2006-11-02 22016]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2013-09-17 553288]
R3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-09-16 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-08-06 262320]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-09-16 116648]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2013-06-13 293144]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-11-17 119408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2012-08-29 79360]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [2012-01-18 155320]

-----------------EOF-----------------

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosim o kontrolu

#2 Příspěvek od Márty84 »

Zdravim :)

:???: Proc nemate aktualizovany windows?

Mate slusne zavirovano :boxed:


:arrow: Udelejte kontrolu s MBAM. Test nastavte podle tohoto navodu http://forum.viry.cz/viewtopic.php?f=29&t=137928 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

superjano
Návštěvník
Návštěvník
Příspěvky: 69
Registrován: 16 srp 2005 23:08

Re: Prosim o kontrolu

#3 Příspěvek od superjano »

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 2. 9. 2014
Scan Time: 19:01:00
Logfile: jozef.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.09.02.07
Rootkit Database: v2014.08.21.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows Vista
CPU: x86
File System: NTFS
User: Milan

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 274291
Time Elapsed: 13 min, 57 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 2
Trojan.Agent.SCR, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|MSStp, C:\Windows\inf\msstp.vbe, , [cb1403e592e9de580161ff0ec043ee12]
Trojan.Script, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|mslpchSrv, "C:\Windows\system32\mslpch.vbe" mswaygv msjeib, , [627d00e8aecdf541735425fb50b32ed2]

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 5
PUP.Optional.Bitcoin, C:\Windows\System32\acumncebtxi.exe, , [c61911d778038caad8eb4f70c73af60a],
Trojan.Agent.SCR, C:\Windows\inf\msstp.vbe, , [cb1403e592e9de580161ff0ec043ee12],
Trojan.Script, C:\Windows\System32\msjeib.vbe, , [69769256e89337ffeed922feda29d32d],
Trojan.Script, C:\Windows\System32\mslpch.vbe, , [627d00e8aecdf541735425fb50b32ed2],
Trojan.Script, C:\Windows\System32\mswaygv.vbe, , [805f1fc93645f145a2256db3f211827e],

Physical Sectors: 0
(No malicious items detected)


(end)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosim o kontrolu

#4 Příspěvek od Márty84 »

Nalezy nechte odstranit. Po restartu pc test zopakujte, ale tentokrat ho nastavte opravdu tak, jak je v navodu, aby program kontroloval cely pocitac! Napiste vysledek testu a podle toho zvolim dalsi postup.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

superjano
Návštěvník
Návštěvník
Příspěvky: 69
Registrován: 16 srp 2005 23:08

Re: Prosim o kontrolu

#5 Příspěvek od superjano »

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 3. 9. 2014
Scan Time: 7:20:00
Logfile: jozef.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.09.03.01
Rootkit Database: v2014.08.21.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows Vista Service Pack 2
CPU: x86
File System: NTFS
User: Milan

Scan Type: Custom Scan
Result: Completed
Objects Scanned: 511535
Time Elapsed: 5 hr, 53 min, 2 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 1
Trojan.Dropper.PGen, C:\Zaloha\D\PC\staryPC\InA!talaÄ?ky a zA!loha-disk C\AcdS 9\ACDSee.v9.0.108.Photo.Manager.Incl.Keymaker-CORE.rar, , [aced6663512af2441e12401f8b75aa56],

Physical Sectors: 0
(No malicious items detected)


(end)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosim o kontrolu

#6 Příspěvek od Márty84 »

:arrow: Nalez nechte odstranit, pak MBAM odinstalujte.


:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a pockejte, az kontrola dobehne.
Pak kliknete na Clean
Program zacne pracovat (muze dojit k restartu pc) a vyplivne log (pripadne bude zde C:\AdwCleaner\AdwCleaner [S?].txt ). Ten mi sem zkopirujte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

superjano
Návštěvník
Návštěvník
Příspěvky: 69
Registrován: 16 srp 2005 23:08

Re: Prosim o kontrolu

#7 Příspěvek od superjano »

# AdwCleaner v3.309 - Report created 04/09/2014 at 09:10:04
# Updated 02/09/2014 by Xplode
# Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Username : Milan - DOMA-PC
# Running from : C:\Users\Milan\Desktop\adwcleaner_3.309.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : APNMCP

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\AskPartnerNetwork
Folder Deleted : C:\Program Files\AskPartnerNetwork
Folder Deleted : C:\Users\Milan\AppData\Local\AskPartnerNetwork
Folder Deleted : C:\Users\Milan\AppData\Local\Temp\apn

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon]
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{44CBC005-6243-4502-8A02-3A096A282664}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D8278076-BC68-4484-9233-6E7F1628B56C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F297534D-7B06-459D-BC19-2DD8EF69297B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9945959C-AAD8-4312-8B57-2DE11927E770}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
Key Deleted : HKCU\Software\AskPartnerNetwork
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKLM\SOFTWARE\AskPartnerNetwork

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16563


-\\ Google Chrome v37.0.2062.103

[ File : C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R2].txt - [1736 octets] - [04/09/2014 09:08:00]
AdwCleaner[S1].txt - [1976 octets] - [04/09/2014 09:10:04]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2036 octets] ##########

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosim o kontrolu

#8 Příspěvek od Márty84 »

:!: Pokud nemate, zazalohujte si radeji dulezita data (fotky, dokumenty, atd.) :!:

:!: Nepouzivejte ComboFix bez predchozi domluvy! Je to poruseni pravidel fora a ztratite tim narok na pomoc!

:arrow: Stahnete ComboFix http://download.bleepingcomputer.com/sUBs/ComboFix.exe a ulozte ho na plochu.
Vypnete antivir i dalsi pripadne zabezpeceni.
Kliknete na ComboFix pravym mysidlem a levym na Spustit jako spravce
Odsouhlaste licencni podminky a nechte program pracovat. Jestli vam nabidne instalaci Konzoly pro zotaveni, souhlaste.
Po dobu skenu nic nespoustejte, nikam neklikejte.
Po dokonceni skenovani (muze dojit i k restartu pc) by se mel vytvorit log, ktery bude umisteny zde C:\ComboFix.txt
Jeho obsah sem zkopirujte

:!: Kdyby po restartu nenabehl windows, restartujte znovu, mackejte klavesu F8 a zvolte - Posledni znama funkcni konfigurace
:!: Kdyz windows nabehne, ale pri spousteni ruznych programu bude hlasena chyba, staci restartovat pc a bude to v poradku
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

superjano
Návštěvník
Návštěvník
Příspěvky: 69
Registrován: 16 srp 2005 23:08

Re: Prosim o kontrolu

#9 Příspěvek od superjano »

ComboFix 14-08-31.01 - Milan . 09. 2014 16:12:43.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1051.18.3006.2034 [GMT 2:00]
Running from: c:\users\Milan\Desktop\ComboFix.exe
AV: AVG AntiVirus Free Edition 2014 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: AVG AntiVirus Free Edition 2014 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\msxml4-KB2758694-enu.LOG
.
.
((((((((((((((((((((((((( Files Created from 2014-08-04 to 2014-09-04 )))))))))))))))))))))))))))))))
.
.
2014-09-04 14:20 . 2014-09-04 14:20 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-09-04 07:06 . 2014-09-04 07:06 -------- d-----w- c:\users\Default\AppData\Roaming\TuneUp Software
2014-09-03 14:39 . 2014-09-03 14:39 -------- d-----w- c:\program files\Defraggler
2014-09-03 11:46 . 2014-09-03 11:46 -------- d-----w- c:\windows\system32\drivers\UMDF\sk-SK
2014-09-03 11:46 . 2014-09-03 11:46 -------- d-----w- c:\program files\Windows Portable Devices
2014-09-03 08:56 . 2014-09-03 08:56 -------- d-----w- c:\users\Milan\AppData\Roaming\AVG2014
2014-09-03 08:52 . 2014-09-03 08:55 -------- d-----w- c:\programdata\AVG2014
2014-09-03 08:52 . 2014-09-03 08:52 -------- d-----w- C:\$AVG
2014-09-03 08:50 . 2014-09-03 14:36 -------- d-----w- c:\users\Milan\AppData\Local\Avg2014
2014-09-03 08:28 . 2014-09-03 08:31 -------- d-----w- c:\windows\system32\MRT
2014-09-03 08:20 . 2014-06-26 22:17 99480 ----a-w- c:\windows\system32\infocardapi.dll
2014-09-03 08:20 . 2014-06-26 22:17 8856 ----a-w- c:\windows\system32\icardres.dll
2014-09-03 08:20 . 2014-06-26 22:17 619664 ----a-w- c:\windows\system32\icardagt.exe
2014-09-03 08:20 . 2014-06-06 04:28 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-09-03 08:11 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2014-09-03 08:11 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2014-09-03 08:11 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2014-09-03 07:47 . 2014-09-03 07:47 -------- d-----w- c:\windows\Migration
2014-09-03 07:37 . 2014-08-23 01:03 297984 ----a-w- c:\windows\system32\gdi32.dll
2014-09-03 07:37 . 2014-08-22 23:26 2054656 ----a-w- c:\windows\system32\win32k.sys
2014-09-03 07:19 . 2014-09-03 07:19 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2014-09-03 07:18 . 2014-09-03 07:18 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2014-09-03 07:18 . 2014-09-03 07:18 252928 ----a-w- c:\windows\system32\dxdiag.exe
2014-09-03 07:18 . 2014-09-03 07:18 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2014-09-03 07:18 . 2014-09-03 07:18 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-09-03 07:18 . 2014-09-03 07:18 519680 ----a-w- c:\windows\system32\d3d11.dll
2014-09-03 07:18 . 2014-09-03 07:18 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2014-09-03 07:18 . 2014-09-03 07:18 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2014-09-03 06:44 . 2014-07-30 00:25 304128 ----a-w- c:\program files\Internet Explorer\ieuser.exe
2014-09-03 06:40 . 2012-07-26 02:46 9728 ----a-w- c:\windows\system32\Wdfres.dll
2014-09-03 06:40 . 2012-07-26 03:39 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2014-09-03 06:40 . 2012-07-26 03:20 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2014-09-03 06:40 . 2012-07-26 03:20 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2014-09-03 06:40 . 2012-07-26 02:33 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2014-09-03 06:40 . 2012-07-26 02:32 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2014-09-03 06:40 . 2009-07-14 12:12 16896 ----a-w- c:\windows\system32\winusb.dll
2014-09-03 06:40 . 2012-07-26 03:21 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2014-09-03 06:40 . 2012-07-26 03:20 613888 ----a-w- c:\windows\system32\WUDFx.dll
2014-09-03 06:40 . 2012-07-26 03:20 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2014-09-03 06:28 . 2009-10-09 21:56 2048 ----a-w- c:\windows\system32\winrsmgr.dll
2014-09-03 06:22 . 2012-11-02 10:18 376320 ----a-w- c:\windows\system32\dpnet.dll
2014-09-03 06:22 . 2012-11-02 08:26 23040 ----a-w- c:\windows\system32\dpnsvr.exe
2014-09-03 06:21 . 2013-07-08 04:55 3603904 ----a-w- c:\windows\system32\ntkrnlpa.exe
2014-09-03 06:21 . 2013-07-09 12:10 1205168 ----a-w- c:\windows\system32\ntdll.dll
2014-09-03 06:21 . 2013-07-08 04:55 3551680 ----a-w- c:\windows\system32\ntoskrnl.exe
2014-09-03 06:21 . 2013-03-09 03:45 49152 ----a-w- c:\windows\system32\csrsrv.dll
2014-09-03 06:21 . 2013-03-09 01:28 64000 ----a-w- c:\windows\system32\smss.exe
2014-09-03 06:21 . 2010-08-17 14:11 128000 ----a-w- c:\windows\system32\spoolsv.exe
2014-09-03 06:21 . 2013-06-15 13:22 15872 ----a-w- c:\windows\system32\icaapi.dll
2014-09-03 06:21 . 2013-06-15 11:23 24064 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2014-09-03 06:19 . 2013-04-24 01:46 812544 ----a-w- c:\windows\system32\certutil.exe
2014-09-03 06:19 . 2013-04-24 04:00 41984 ----a-w- c:\windows\system32\certenc.dll
2014-09-03 06:18 . 2009-10-23 17:10 714240 ----a-w- c:\windows\system32\timedate.cpl
2014-09-03 06:18 . 2010-12-29 18:28 322560 ----a-w- c:\windows\system32\sbe.dll
2014-09-03 06:18 . 2010-12-29 18:28 153088 ----a-w- c:\windows\system32\sbeio.dll
2014-09-03 06:18 . 2010-12-29 18:26 177664 ----a-w- c:\windows\system32\mpg2splt.ax
2014-09-03 06:18 . 2012-02-01 15:10 1404928 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InkObj.dll
2014-09-03 06:18 . 2014-06-02 10:31 1218048 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2014-09-03 06:18 . 2014-06-02 10:30 983552 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2014-09-03 06:18 . 2014-06-02 10:30 937472 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2014-09-03 06:18 . 2014-06-02 10:30 965120 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2014-09-03 06:18 . 2012-02-01 13:58 47104 ----a-w- c:\program files\Windows Journal\PDIALOG.exe
2014-09-03 06:18 . 2010-09-06 16:20 125952 ----a-w- c:\windows\system32\srvsvc.dll
2014-09-03 06:18 . 2010-09-06 16:19 17920 ----a-w- c:\windows\system32\netevent.dll
2014-09-03 06:17 . 2013-10-03 12:45 993792 ----a-w- c:\windows\system32\crypt32.dll
2014-09-03 06:17 . 2014-04-05 02:42 905664 ----a-w- c:\windows\system32\drivers\tcpip.sys
2014-09-03 06:17 . 2013-10-30 02:12 335360 ----a-w- c:\windows\system32\SysFxUI.dll
2014-09-03 06:17 . 2013-10-30 01:43 130048 ----a-w- c:\windows\system32\drivers\drmk.sys
2014-09-03 06:17 . 2013-10-30 00:43 167936 ----a-w- c:\windows\system32\drivers\portcls.sys
2014-09-03 06:17 . 2013-10-11 02:08 444928 ----a-w- c:\windows\system32\IKEEXT.DLL
2014-09-03 06:16 . 2013-10-11 02:07 596480 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2014-09-03 06:16 . 2013-07-12 09:04 73344 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2014-09-03 06:14 . 2011-02-22 14:13 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2014-09-03 06:12 . 2010-01-25 08:21 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2014-09-03 06:12 . 2010-01-25 08:21 518144 ----a-w- c:\windows\system32\RMActivate.exe
2014-09-03 06:12 . 2010-01-25 08:21 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2014-09-03 06:12 . 2010-01-25 12:00 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2014-09-03 06:12 . 2010-01-25 12:00 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2014-09-03 06:12 . 2010-01-25 11:58 332288 ----a-w- c:\windows\system32\msdrm.dll
2014-09-03 06:11 . 2010-08-31 15:46 954752 ----a-w- c:\windows\system32\mfc40.dll
2014-09-03 06:11 . 2010-08-31 15:46 954288 ----a-w- c:\windows\system32\mfc40u.dll
2014-09-03 06:11 . 2013-04-17 12:30 24576 ----a-w- c:\windows\system32\cryptdlg.dll
2014-09-03 06:11 . 2010-12-17 13:54 677888 ----a-w- c:\windows\system32\mstsc.exe
2014-09-03 06:11 . 2013-06-26 23:01 527064 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2014-09-03 06:11 . 2011-08-25 16:15 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2014-09-03 06:11 . 2011-08-25 16:14 563712 ----a-w- c:\windows\system32\oleaut32.dll
2014-09-03 06:11 . 2011-08-25 16:14 238080 ----a-w- c:\windows\system32\oleacc.dll
2014-09-03 06:11 . 2011-08-25 13:31 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2014-09-03 06:10 . 2010-09-13 13:56 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2014-09-03 06:10 . 2010-09-13 13:56 168960 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2014-09-03 06:09 . 2013-10-11 02:08 36864 ----a-w- c:\windows\system32\wshcon.dll
2014-09-03 06:09 . 2013-10-11 02:08 131072 ----a-w- c:\windows\system32\wshom.ocx
2014-09-03 06:09 . 2013-10-11 02:08 172032 ----a-w- c:\windows\system32\scrrun.dll
2014-09-03 06:09 . 2013-10-11 00:35 135168 ----a-w- c:\windows\system32\cscript.exe
2014-09-03 06:09 . 2013-10-11 00:35 155648 ----a-w- c:\windows\system32\wscript.exe
2014-09-03 06:09 . 2014-06-07 02:08 1305088 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tipskins.dll
2014-09-03 06:09 . 2014-06-07 02:08 149504 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tabskb.dll
2014-09-03 06:09 . 2014-06-07 02:08 114688 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\TipBand.dll
2014-09-03 06:09 . 2012-05-11 15:57 623616 ----a-w- c:\windows\system32\localspl.dll
2014-09-03 06:09 . 2014-03-10 01:22 1401344 ----a-w- c:\windows\system32\msxml6.dll
2014-09-03 06:09 . 2014-03-10 01:22 1248768 ----a-w- c:\windows\system32\msxml3.dll
2014-09-03 06:09 . 2013-03-03 19:07 1082232 ----a-w- c:\windows\system32\drivers\ntfs.sys
2014-09-03 06:07 . 2011-07-29 16:01 293376 ----a-w- c:\windows\system32\psisdecd.dll
2014-09-03 06:06 . 2014-07-08 00:46 2048 ----a-w- c:\windows\system32\tzres.dll
2014-09-03 06:06 . 2011-12-14 16:17 680448 ----a-w- c:\windows\system32\msvcrt.dll
2014-09-03 06:06 . 2012-08-21 11:47 224640 ----a-w- c:\windows\system32\drivers\volsnap.sys
2014-09-03 06:06 . 2012-01-09 15:54 613376 ----a-w- c:\windows\system32\rdpencom.dll
2014-09-03 06:06 . 2011-10-25 15:58 497152 ----a-w- c:\windows\system32\qdvd.dll
2014-09-03 06:06 . 2010-01-29 15:40 1616384 ----a-w- c:\program files\Windows Mail\msoe.dll
2014-09-03 06:06 . 2012-03-20 23:28 53120 ----a-w- c:\windows\system32\drivers\partmgr.sys
2014-09-03 06:06 . 2013-07-16 04:35 615936 ----a-w- c:\windows\system32\themeui.dll
2014-09-03 06:06 . 2013-07-10 09:47 783360 ----a-w- c:\windows\system32\rpcrt4.dll
2014-09-03 06:06 . 2011-10-14 16:02 429056 ----a-w- c:\windows\system32\EncDec.dll
2014-09-03 06:04 . 2011-02-22 13:23 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2014-09-03 06:03 . 2013-06-29 02:07 197632 ----a-w- c:\windows\system32\drivers\usbhub.sys
2014-09-03 06:03 . 2013-06-29 02:07 73216 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2014-09-03 06:03 . 2013-06-29 02:07 226304 ----a-w- c:\windows\system32\drivers\usbport.sys
2014-09-03 06:03 . 2013-06-29 02:06 6016 ----a-w- c:\windows\system32\drivers\usbd.sys
2014-09-03 06:03 . 2011-05-05 13:54 39936 ----a-w- c:\windows\system32\drivers\usbehci.sys
2014-09-03 06:03 . 2011-05-05 13:54 23552 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2014-09-03 06:03 . 2014-06-14 00:33 37376 ----a-w- c:\windows\system32\cdd.dll
2014-09-03 06:03 . 2014-06-14 00:44 638400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2014-09-03 06:03 . 2010-10-12 15:53 33280 ----a-w- c:\program files\Windows Mail\wabfind.dll
2014-09-03 06:03 . 2010-10-12 13:41 66048 ----a-w- c:\program files\Windows Mail\wabmig.exe
2014-09-03 06:03 . 2010-10-12 13:41 515584 ----a-w- c:\program files\Windows Mail\wab.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-09-03 11:41 . 2013-11-17 19:18 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2014-09-03 07:20 . 2014-09-03 07:20 203776 ----a-w- c:\windows\system32\webcheck.dll
2014-09-03 07:18 . 2014-09-03 07:18 4096 ----a-w- c:\windows\system32\drivers\sk-SK\dxgkrnl.sys.mui
2014-09-02 19:30 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2014-09-02 19:30 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2014-08-06 11:55 . 2012-06-24 12:39 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-08-06 11:55 . 2012-06-24 12:39 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-07-30 02:11 . 2014-09-03 06:44 53760 ----a-w- c:\windows\apppatch\iebrshim.dll
2014-07-21 19:03 . 2014-07-21 19:03 200984 ----a-w- c:\windows\system32\drivers\avgidsdriverx.sys
2014-06-30 10:43 . 2014-06-30 10:43 121624 ----a-w- c:\windows\system32\drivers\avgdiskx.sys
2014-06-17 14:22 . 2014-06-17 14:22 188696 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2014-06-17 14:21 . 2014-06-17 14:21 197400 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2014-06-17 14:18 . 2014-06-17 14:18 241944 ----a-w- c:\windows\system32\drivers\avglogx.sys
2014-06-17 14:17 . 2014-06-17 14:17 147736 ----a-w- c:\windows\system32\drivers\avgidshx.sys
2014-06-17 14:06 . 2014-06-17 14:06 27416 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2014-06-17 14:06 . 2014-06-17 14:06 21272 ----a-w- c:\windows\system32\drivers\avgidsshimx.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VMonitorVMUVC"="c:\program files\Vimicro Corporation\VMUVC\VMonitor.exe" [2007-12-20 135168]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-09-17 152392]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2013-07-31 2296600]
"AVG_UI"="c:\program files\AVG\AVG2014\avgui.exe" [2014-08-25 5188112]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
2013-12-17 17:03 138096 ----atw- c:\users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-620889938-3404297717-3700568068-1000]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-09-03 05:13 1096520 ----a-w- c:\program files\Google\Chrome\Application\37.0.2062.103\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-09-03 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-24 11:55]
.
2014-08-29 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000Core.job
- c:\users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-17 17:03]
.
2014-09-04 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000UA.job
- c:\users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-17 17:03]
.
2014-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-09-16 17:19]
.
2014-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-09-16 17:19]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uInternet Settings,ProxyOverride = *.local
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{41564952-412D-5350-00A7-7A786E7484D7} - c:\program files\AskPartnerNetwork\Toolbar\AVIRA-SP\Passport.dll
Toolbar-{41564952-412D-5350-00A7-7A786E7484D7} - c:\program files\AskPartnerNetwork\Toolbar\AVIRA-SP\Passport.dll
WebBrowser-{41564952-412D-5350-00A7-7A786E7484D7} - c:\program files\AskPartnerNetwork\Toolbar\AVIRA-SP\Passport.dll
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-{229FE254-C78E-B54C-6B45-E799F93F8BD1}_is1 - c:\program files\Zoner Photo Studio 15 Professional CZ Key kl(100% funkn
AddRemove-{7E0D648F-EDBE-983A-B91E-2BA38FAA1EF5}_is1 - c:\program files\Zoner Photo Studio 15 Professional CZ Key kl(100% funkn
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-09-04 16:21
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2014-09-04 16:23:36
ComboFix-quarantined-files.txt 2014-09-04 14:23
.
Pre-Run: 78 075 113 472 bytes free
Post-Run: 78 137 905 152 bytes free
.
- - End Of File - - 38252465BDC964619106BBEB282AD500
5C616939100B85E558DA92B899A0FC36

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosim o kontrolu

#10 Příspěvek od Márty84 »

:???: Smarja, co tam dela AVG?


:arrow: Otevrete si poznamkovy blok a zkopirujte do nej tento skript

Kód: Vybrat vše

KillAll::

File::
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000Core.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000UA.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\System32\acumncebtxi.exe
C:\Windows\inf\msstp.vbe
C:\Windows\System32\msjeib.vbe
C:\Windows\System32\mslpch.vbe
C:\Windows\System32\mswaygv.vbe

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"=-
"GrooveMonitor"=-
"Adobe ARM"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]

Reboot::
Vlevo nahore kliknete na napis Soubor
Kliknete na napis Ulozit jako...
Napiste spravne ten cerveny nazev CFScript a ulozte na plochu.
Vypnete antivir i dalsi pripadne zabezpeceni.
Pretahntete mysi tento vytvoreny textovy dokument nad ikonu ComboFix a pustte.
ComboFix by se mel spustit a vykonat prikazy.
Az skonci (muze dojit k restartu pc), mel by se objevit novy log, ten mi sem zase zkopirujte.

:!: Kdyby po restartu nenabehl windows, restartujte znovu, mackejte klavesu F8 a zvolte - Posledni znama funkcni konfigurace
:!: Kdyz windows nabehne, ale pri spousteni ruznych programu bude hlasena chyba, staci restartovat pc a bude to v poradku
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

superjano
Návštěvník
Návštěvník
Příspěvky: 69
Registrován: 16 srp 2005 23:08

Re: Prosim o kontrolu

#11 Příspěvek od superjano »

ComboFix 14-08-31.01 - Milan . 09. 2014 19:14:33.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1051.18.3006.1967 [GMT 2:00]
Running from: c:\users\Milan\Desktop\ComboFix.exe
Command switches used :: c:\users\Milan\Desktop\CFScript.txt
AV: AVG AntiVirus Free Edition 2014 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: AVG AntiVirus Free Edition 2014 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
.
FILE ::
"c:\windows\inf\msstp.vbe"
"c:\windows\System32\acumncebtxi.exe"
"c:\windows\System32\msjeib.vbe"
"c:\windows\System32\mslpch.vbe"
"c:\windows\System32\mswaygv.vbe"
"c:\windows\tasks\Adobe Flash Player Updater.job"
"c:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000Core.job"
"c:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000UA.job"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((( Files Created from 2014-08-04 to 2014-09-04 )))))))))))))))))))))))))))))))
.
.
2014-09-04 17:23 . 2014-09-04 17:23 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-09-04 17:10 . 2014-09-04 17:10 -------- d-----w- c:\users\Milan\AppData\Local\AVG Web TuneUp
2014-09-04 17:09 . 2014-09-04 17:09 -------- d-----w- c:\programdata\AVG Security Toolbar
2014-09-04 17:09 . 2014-09-04 17:09 42784 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
2014-09-04 17:09 . 2014-09-04 17:09 -------- d-----w- c:\programdata\AVG Secure Search
2014-09-04 17:09 . 2014-09-04 17:09 -------- d-----w- c:\program files\Common Files\AVG Secure Search
2014-09-04 17:09 . 2014-09-04 17:09 -------- d-----w- c:\programdata\AVG Web TuneUp
2014-09-04 17:09 . 2014-09-04 17:09 -------- d-----w- c:\program files\AVG Web TuneUp
2014-09-04 15:48 . 2014-09-04 15:48 -------- d-----w- c:\program files\Scan Tailor
2014-09-04 07:06 . 2014-09-04 07:06 -------- d-----w- c:\users\Default\AppData\Roaming\TuneUp Software
2014-09-03 14:39 . 2014-09-03 14:39 -------- d-----w- c:\program files\Defraggler
2014-09-03 11:46 . 2014-09-03 11:46 -------- d-----w- c:\windows\system32\drivers\UMDF\sk-SK
2014-09-03 11:46 . 2014-09-03 11:46 -------- d-----w- c:\program files\Windows Portable Devices
2014-09-03 08:56 . 2014-09-03 08:56 -------- d-----w- c:\users\Milan\AppData\Roaming\AVG2014
2014-09-03 08:52 . 2014-09-03 08:55 -------- d-----w- c:\programdata\AVG2014
2014-09-03 08:52 . 2014-09-03 08:52 -------- d-----w- C:\$AVG
2014-09-03 08:50 . 2014-09-03 14:36 -------- d-----w- c:\users\Milan\AppData\Local\Avg2014
2014-09-03 08:28 . 2014-09-03 08:31 -------- d-----w- c:\windows\system32\MRT
2014-09-03 08:20 . 2014-06-26 22:17 99480 ----a-w- c:\windows\system32\infocardapi.dll
2014-09-03 08:20 . 2014-06-26 22:17 8856 ----a-w- c:\windows\system32\icardres.dll
2014-09-03 08:20 . 2014-06-26 22:17 619664 ----a-w- c:\windows\system32\icardagt.exe
2014-09-03 08:20 . 2014-06-06 04:28 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-09-03 08:11 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2014-09-03 08:11 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2014-09-03 08:11 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2014-09-03 07:47 . 2014-09-03 07:47 -------- d-----w- c:\windows\Migration
2014-09-03 07:37 . 2014-08-23 01:03 297984 ----a-w- c:\windows\system32\gdi32.dll
2014-09-03 07:37 . 2014-08-22 23:26 2054656 ----a-w- c:\windows\system32\win32k.sys
2014-09-03 07:19 . 2014-09-03 07:19 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2014-09-03 07:18 . 2014-09-03 07:18 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2014-09-03 07:18 . 2014-09-03 07:18 252928 ----a-w- c:\windows\system32\dxdiag.exe
2014-09-03 07:18 . 2014-09-03 07:18 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2014-09-03 07:18 . 2014-09-03 07:18 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-09-03 07:18 . 2014-09-03 07:18 519680 ----a-w- c:\windows\system32\d3d11.dll
2014-09-03 07:18 . 2014-09-03 07:18 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2014-09-03 07:18 . 2014-09-03 07:18 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2014-09-03 06:44 . 2014-07-30 00:25 304128 ----a-w- c:\program files\Internet Explorer\ieuser.exe
2014-09-03 06:40 . 2012-07-26 02:46 9728 ----a-w- c:\windows\system32\Wdfres.dll
2014-09-03 06:40 . 2012-07-26 03:39 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2014-09-03 06:40 . 2012-07-26 03:20 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2014-09-03 06:40 . 2012-07-26 03:20 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2014-09-03 06:40 . 2012-07-26 02:33 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2014-09-03 06:40 . 2012-07-26 02:32 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2014-09-03 06:40 . 2009-07-14 12:12 16896 ----a-w- c:\windows\system32\winusb.dll
2014-09-03 06:40 . 2012-07-26 03:21 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2014-09-03 06:40 . 2012-07-26 03:20 613888 ----a-w- c:\windows\system32\WUDFx.dll
2014-09-03 06:40 . 2012-07-26 03:20 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2014-09-03 06:28 . 2009-10-09 21:56 2048 ----a-w- c:\windows\system32\winrsmgr.dll
2014-09-03 06:22 . 2012-11-02 10:18 376320 ----a-w- c:\windows\system32\dpnet.dll
2014-09-03 06:22 . 2012-11-02 08:26 23040 ----a-w- c:\windows\system32\dpnsvr.exe
2014-09-03 06:21 . 2013-07-08 04:55 3603904 ----a-w- c:\windows\system32\ntkrnlpa.exe
2014-09-03 06:21 . 2013-07-09 12:10 1205168 ----a-w- c:\windows\system32\ntdll.dll
2014-09-03 06:21 . 2013-07-08 04:55 3551680 ----a-w- c:\windows\system32\ntoskrnl.exe
2014-09-03 06:21 . 2013-03-09 03:45 49152 ----a-w- c:\windows\system32\csrsrv.dll
2014-09-03 06:21 . 2013-03-09 01:28 64000 ----a-w- c:\windows\system32\smss.exe
2014-09-03 06:21 . 2010-08-17 14:11 128000 ----a-w- c:\windows\system32\spoolsv.exe
2014-09-03 06:21 . 2013-06-15 13:22 15872 ----a-w- c:\windows\system32\icaapi.dll
2014-09-03 06:21 . 2013-06-15 11:23 24064 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2014-09-03 06:19 . 2013-04-24 01:46 812544 ----a-w- c:\windows\system32\certutil.exe
2014-09-03 06:19 . 2013-04-24 04:00 41984 ----a-w- c:\windows\system32\certenc.dll
2014-09-03 06:18 . 2009-10-23 17:10 714240 ----a-w- c:\windows\system32\timedate.cpl
2014-09-03 06:18 . 2010-12-29 18:28 322560 ----a-w- c:\windows\system32\sbe.dll
2014-09-03 06:18 . 2010-12-29 18:28 153088 ----a-w- c:\windows\system32\sbeio.dll
2014-09-03 06:18 . 2010-12-29 18:26 177664 ----a-w- c:\windows\system32\mpg2splt.ax
2014-09-03 06:18 . 2012-02-01 15:10 1404928 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\InkObj.dll
2014-09-03 06:18 . 2014-06-02 10:31 1218048 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2014-09-03 06:18 . 2014-06-02 10:30 983552 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2014-09-03 06:18 . 2014-06-02 10:30 937472 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2014-09-03 06:18 . 2014-06-02 10:30 965120 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2014-09-03 06:18 . 2012-02-01 13:58 47104 ----a-w- c:\program files\Windows Journal\PDIALOG.exe
2014-09-03 06:18 . 2010-09-06 16:20 125952 ----a-w- c:\windows\system32\srvsvc.dll
2014-09-03 06:18 . 2010-09-06 16:19 17920 ----a-w- c:\windows\system32\netevent.dll
2014-09-03 06:17 . 2013-10-03 12:45 993792 ----a-w- c:\windows\system32\crypt32.dll
2014-09-03 06:17 . 2014-04-05 02:42 905664 ----a-w- c:\windows\system32\drivers\tcpip.sys
2014-09-03 06:17 . 2013-10-30 02:12 335360 ----a-w- c:\windows\system32\SysFxUI.dll
2014-09-03 06:17 . 2013-10-30 01:43 130048 ----a-w- c:\windows\system32\drivers\drmk.sys
2014-09-03 06:17 . 2013-10-30 00:43 167936 ----a-w- c:\windows\system32\drivers\portcls.sys
2014-09-03 06:17 . 2013-10-11 02:08 444928 ----a-w- c:\windows\system32\IKEEXT.DLL
2014-09-03 06:16 . 2013-10-11 02:07 596480 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2014-09-03 06:16 . 2013-07-12 09:04 73344 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2014-09-03 06:14 . 2011-02-22 14:13 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2014-09-03 06:12 . 2010-01-25 08:21 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2014-09-03 06:12 . 2010-01-25 08:21 518144 ----a-w- c:\windows\system32\RMActivate.exe
2014-09-03 06:12 . 2010-01-25 08:21 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2014-09-03 06:12 . 2010-01-25 12:00 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2014-09-03 06:12 . 2010-01-25 12:00 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2014-09-03 06:12 . 2010-01-25 11:58 332288 ----a-w- c:\windows\system32\msdrm.dll
2014-09-03 06:11 . 2010-08-31 15:46 954752 ----a-w- c:\windows\system32\mfc40.dll
2014-09-03 06:11 . 2010-08-31 15:46 954288 ----a-w- c:\windows\system32\mfc40u.dll
2014-09-03 06:11 . 2013-04-17 12:30 24576 ----a-w- c:\windows\system32\cryptdlg.dll
2014-09-03 06:11 . 2010-12-17 13:54 677888 ----a-w- c:\windows\system32\mstsc.exe
2014-09-03 06:11 . 2013-06-26 23:01 527064 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2014-09-03 06:11 . 2011-08-25 16:15 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2014-09-03 06:11 . 2011-08-25 16:14 563712 ----a-w- c:\windows\system32\oleaut32.dll
2014-09-03 06:11 . 2011-08-25 16:14 238080 ----a-w- c:\windows\system32\oleacc.dll
2014-09-03 06:11 . 2011-08-25 13:31 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2014-09-03 06:10 . 2010-09-13 13:56 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2014-09-03 06:10 . 2010-09-13 13:56 168960 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2014-09-03 06:09 . 2013-10-11 02:08 36864 ----a-w- c:\windows\system32\wshcon.dll
2014-09-03 06:09 . 2013-10-11 02:08 131072 ----a-w- c:\windows\system32\wshom.ocx
2014-09-03 06:09 . 2013-10-11 02:08 172032 ----a-w- c:\windows\system32\scrrun.dll
2014-09-03 06:09 . 2013-10-11 00:35 135168 ----a-w- c:\windows\system32\cscript.exe
2014-09-03 06:09 . 2013-10-11 00:35 155648 ----a-w- c:\windows\system32\wscript.exe
2014-09-03 06:09 . 2014-06-07 02:08 1305088 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tipskins.dll
2014-09-03 06:09 . 2014-06-07 02:08 149504 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tabskb.dll
2014-09-03 06:09 . 2014-06-07 02:08 114688 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\TipBand.dll
2014-09-03 06:09 . 2012-05-11 15:57 623616 ----a-w- c:\windows\system32\localspl.dll
2014-09-03 06:09 . 2014-03-10 01:22 1401344 ----a-w- c:\windows\system32\msxml6.dll
2014-09-03 06:09 . 2014-03-10 01:22 1248768 ----a-w- c:\windows\system32\msxml3.dll
2014-09-03 06:09 . 2013-03-03 19:07 1082232 ----a-w- c:\windows\system32\drivers\ntfs.sys
2014-09-03 06:07 . 2011-07-29 16:01 293376 ----a-w- c:\windows\system32\psisdecd.dll
2014-09-03 06:06 . 2014-07-08 00:46 2048 ----a-w- c:\windows\system32\tzres.dll
2014-09-03 06:06 . 2011-12-14 16:17 680448 ----a-w- c:\windows\system32\msvcrt.dll
2014-09-03 06:06 . 2012-08-21 11:47 224640 ----a-w- c:\windows\system32\drivers\volsnap.sys
2014-09-03 06:06 . 2012-01-09 15:54 613376 ----a-w- c:\windows\system32\rdpencom.dll
2014-09-03 06:06 . 2011-10-25 15:58 497152 ----a-w- c:\windows\system32\qdvd.dll
2014-09-03 06:06 . 2010-01-29 15:40 1616384 ----a-w- c:\program files\Windows Mail\msoe.dll
2014-09-03 06:06 . 2012-03-20 23:28 53120 ----a-w- c:\windows\system32\drivers\partmgr.sys
2014-09-03 06:06 . 2013-07-16 04:35 615936 ----a-w- c:\windows\system32\themeui.dll
2014-09-03 06:06 . 2013-07-10 09:47 783360 ----a-w- c:\windows\system32\rpcrt4.dll
2014-09-03 06:06 . 2011-10-14 16:02 429056 ----a-w- c:\windows\system32\EncDec.dll
2014-09-03 06:04 . 2011-02-22 13:23 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2014-09-03 06:03 . 2013-06-29 02:07 197632 ----a-w- c:\windows\system32\drivers\usbhub.sys
2014-09-03 06:03 . 2013-06-29 02:07 73216 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2014-09-03 06:03 . 2013-06-29 02:07 226304 ----a-w- c:\windows\system32\drivers\usbport.sys
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-09-03 11:41 . 2013-11-17 19:18 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2014-09-03 07:20 . 2014-09-03 07:20 203776 ----a-w- c:\windows\system32\webcheck.dll
2014-09-03 07:18 . 2014-09-03 07:18 4096 ----a-w- c:\windows\system32\drivers\sk-SK\dxgkrnl.sys.mui
2014-09-02 19:30 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2014-09-02 19:30 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2014-08-06 11:55 . 2012-06-24 12:39 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-08-06 11:55 . 2012-06-24 12:39 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-07-30 02:11 . 2014-09-03 06:44 53760 ----a-w- c:\windows\apppatch\iebrshim.dll
2014-07-21 19:03 . 2014-07-21 19:03 200984 ----a-w- c:\windows\system32\drivers\avgidsdriverx.sys
2014-06-30 10:43 . 2014-06-30 10:43 121624 ----a-w- c:\windows\system32\drivers\avgdiskx.sys
2014-06-17 14:22 . 2014-06-17 14:22 188696 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2014-06-17 14:21 . 2014-06-17 14:21 197400 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2014-06-17 14:18 . 2014-06-17 14:18 241944 ----a-w- c:\windows\system32\drivers\avglogx.sys
2014-06-17 14:17 . 2014-06-17 14:17 147736 ----a-w- c:\windows\system32\drivers\avgidshx.sys
2014-06-17 14:06 . 2014-06-17 14:06 27416 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2014-06-17 14:06 . 2014-06-17 14:06 21272 ----a-w- c:\windows\system32\drivers\avgidsshimx.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VMonitorVMUVC"="c:\program files\Vimicro Corporation\VMUVC\VMonitor.exe" [2007-12-20 135168]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-09-17 152392]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2013-07-31 2296600]
"AVG_UI"="c:\program files\AVG\AVG2014\avgui.exe" [2014-08-25 5188112]
"vProt"="c:\program files\AVG Web TuneUp\vprot.exe" [2014-09-04 2680344]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-620889938-3404297717-3700568068-1000]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-09-03 05:13 1096520 ----a-w- c:\program files\Google\Chrome\Application\37.0.2062.103\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-09-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-24 11:55]
.
2014-08-29 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000Core.job
- c:\users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-17 17:03]
.
2014-09-04 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-620889938-3404297717-3700568068-1000UA.job
- c:\users\Milan\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-12-17 17:03]
.
2014-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-09-16 17:19]
.
2014-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-09-16 17:19]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
uInternet Settings,ProxyOverride = *.local
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\3.2.0\ViProtocol.dll
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-09-04 19:26
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\progra~1\AVG\AVG2014\avgrsx.exe
c:\program files\AVG\AVG2014\avgcsrvx.exe
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\AVG\AVG2014\avgidsagent.exe
c:\program files\AVG\AVG2014\avgwdsvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\HTC\HTC Sync Manager\HSMServiceEntry.exe
c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe
c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\3.2.0\ToolbarUpdater.exe
c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\3.2.0\loggingserver.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\HTC\HTC Sync Manager\HTC Sync\adb.exe
c:\windows\System32\WUDFHost.exe
c:\program files\AVG\AVG2014\avgnsx.exe
c:\program files\AVG\AVG2014\avgemcx.exe
c:\windows\system32\conime.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\windows\servicing\TrustedInstaller.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2014-09-04 19:31:07 - machine was rebooted
ComboFix-quarantined-files.txt 2014-09-04 17:31
.
Pre-Run: 74 367 688 704 bytes free
Post-Run: 74 170 261 504 bytes free
.
- - End Of File - - C9A6D55563E233071CF7A4AD4A3642B4
5C616939100B85E558DA92B899A0FC36

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosim o kontrolu

#12 Příspěvek od Márty84 »

:arrow: Zopakujte krok s ADWCleanerem
Márty84 píše: :arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a pockejte, az kontrola dobehne.
Pak kliknete na Clean
Program zacne pracovat (muze dojit k restartu pc) a vyplivne log (pripadne bude zde C:\AdwCleaner\AdwCleaner [S?].txt ). Ten mi sem zkopirujte.
:arrow: Pak dejte novy log z RSIT
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

superjano
Návštěvník
Návštěvník
Příspěvky: 69
Registrován: 16 srp 2005 23:08

Re: Prosim o kontrolu

#13 Příspěvek od superjano »

# AdwCleaner v3.309 - Report created 04/09/2014 at 21:18:01
# Updated 02/09/2014 by Xplode
# Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Username : Milan - DOMA-PC
# Running from : C:\Users\Milan\Desktop\adwcleaner_3.309.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\AVG Security Toolbar
Folder Deleted : C:\Program Files\Common Files\AVG Secure Search

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16563


-\\ Google Chrome v37.0.2062.103

[ File : C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R3].txt - [2518 octets] - [04/09/2014 21:16:30]
AdwCleaner[S2].txt - [2483 octets] - [04/09/2014 21:18:01]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [2543 octets] ##########

superjano
Návštěvník
Návštěvník
Příspěvky: 69
Registrován: 16 srp 2005 23:08

Re: Prosim o kontrolu

#14 Příspěvek od superjano »

RSIT ma 124340 znaků takze sa neda poslat. Maximální povolený počet znaků je 100000.

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosim o kontrolu

#15 Příspěvek od Márty84 »

Rozdelte ho do dvou prispevku.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Zamčeno