Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Win32/Filecoder.DI trojský kůň a Win32/Kryptik.CJRT trojský

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
alvr
Návštěvník
Návštěvník
Příspěvky: 73
Registrován: 21 čer 2011 18:52

Win32/Filecoder.DI trojský kůň a Win32/Kryptik.CJRT trojský

#1 Příspěvek od alvr »

Dobry den. Chytil jsem na pocitaci dva viry s kteryma si nevim rady. Jedna se o Win32/Filecoder.DI trojský kůň a Win32/Kryptik.CJRT trojský kun. Doslo nejspis i zasifrovani nekterych souboru :-( Zkousel jsem hledat nejake cleanery na tyto viry, ale nepovedlo se mi s tim nic udelat. Udelal jsem scan pomoci RSIT. Mohl bych prosit o pomoc, radu, prosimm pekne?

RSIT:
Logfile of random's system information tool 1.10 (written by random/random)
Run by test at 2014-11-24 19:21:26
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 348 GB (73%) free of 477 GB
Total RAM: 3990 MB (47% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:21:34, on 24.11.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17420)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Cobian Backup 11\Cobian.exe
C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
C:\Program Files (x86)\PDF24\pdf24.exe
C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
C:\Program Files (x86)\PDF24\pdf24.exe
C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files\trend micro\test.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Cobian Backup 11] "C:\Program Files (x86)\Cobian Backup 11\Cobian.exe"
O4 - HKLM\..\Run: [AmIcoSinglun64] "C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
O4 - HKLM\..\Run: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun
O4 - HKLM\..\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN
O4 - HKLM\..\Run: [PDFPrint] C:\Program Files (x86)\PDF24\pdf24.exe
O4 - HKCU\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: BrYNSvc - Brother Industries, Ltd. - C:\Program Files (x86)\Browny02\BrYNSvc.exe
O23 - Service: Cobian Backup 11 Stínová kopie - Requester (cbVSCService11) - CobianSoft, Luis Cobian - C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Endpoint Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe
O23 - Service: ESET SHA Service (ESHASRV) - ESET - C:\Program Files\ESET\ESET Endpoint Antivirus\EShaSrv.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VIA Karaoke digital mixer Service (VIAKaraokeService) - Unknown owner - C:\Windows\system32\viakaraokesrv.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10095 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE"
"C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe"
"C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\viakaraokesrv.exe
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-c39c9fad-ea2e-493f-a767-4755fb5265a7 -SystemEventPortName:HostProcess-e8ad8b2e-aba9-49f7-ac06-efec336de2de -IoCancelEventPortName:HostProcess-cd6156ad-fef7-470c-bc64-6cd981a8847f -NonStateChangingEventPortName:HostProcess-3b63602e-c4b5-4975-bbc9-9399c120c5b9 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:ce823116-f848-45d9-ad4f-981cf0aaaa22 -DeviceGroupId:WpdFsGroup
"C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe"
"C:\Program Files (x86)\Browny02\BrYNSvc.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\Windows\System32\svchost.exe -k secsvcs
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
"taskhost.exe"
rdpclip
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT6.EXE"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe" /hide /waitservice
"C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe"
"C:\Program Files (x86)\Cobian Backup 11\Cobian.exe"
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe" /AUTORUN
"C:\Program Files (x86)\PDF24\pdf24.exe"
-BootProc
-BootProc
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe"
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT6.EXE"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe" /hide /waitservice
"C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe" /AUTORUN
"C:\Windows\system32\igfxsrvc.exe" -Embedding
"C:\Program Files (x86)\PDF24\pdf24.exe"
-BootProc
-BootProc
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
"LogonUI.exe" /flags:0x0
"C:\Program Files\CCleaner\CCleaner64.exe" /monitor
"C:\Program Files\Internet Explorer\iexplore.exe" -w "C:\Users\test\Desktop\Soubory ke stažení ESET Centrum technické podpory.website"
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:4388 CREDAT:340993 APPID:Microsoft.Website.7C3CB423.3A331257 /prefetch:2
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:4388 CREDAT:930874 APPID:Microsoft.Website.7C3CB423.3A331257 /prefetch:2
"C:\Program Files\Internet Explorer\iexplore.exe" http://go.eset.eu/supportform?lng=1029
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:792 CREDAT:275457 /prefetch:2
C:\Windows\servicing\TrustedInstaller.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-2896341211-3585674642-487039327-100435_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-2896341211-3585674642-487039327-100435 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe36_ Global\UsGthrCtrlFltPipeMssGthrPipe36 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"c:\program files\windows defender\MpCmdRun.exe" SpyNetService -RestrictPrivileges -AccessKey C1E6FDA3-D1C1-5469-BCC8-C79F4BCE6E85 -Reinvoke
"C:\Users\test\Desktop\RSITx64.exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
Windows Live Family Safety Browser Helper Class - C:\Program Files\Windows Live\Family Safety\fssbho.dll [2009-08-05 132448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}]
MSS+ Identifier - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09 96128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-10-21 1219152]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-10-21 1219152]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MFNetworkScanUtility"=C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT6.EXE [2009-12-15 508312]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2013-11-05 391152]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2013-11-05 771056]
"Persistence"=C:\Windows\system32\igfxpers.exe [2013-11-05 770032]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-09-27 36352]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-10-24 13662936]
"egui"=C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe [2013-10-07 4148664]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\Sidebar.exe [2010-11-21 1475584]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2014-10-30 6501656]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2012-06-08 5123216]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"Cobian Backup 11"=C:\Program Files (x86)\Cobian Backup 11\Cobian.exe [2012-12-05 720896]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2013-07-12 383768]
"ControlCenter4"=C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [2012-08-28 143360]
"BrStsMon00"=C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2012-06-06 3076096]
"PDFPrint"=C:\Program Files (x86)\PDF24\pdf24.exe [2013-10-28 185896]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2013-10-28 623616]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-11-24 19:21:26 ----D---- C:\rsit
2014-11-24 19:21:26 ----D---- C:\Program Files\trend micro
2014-11-24 18:10:31 ----D---- C:\Program Files\CCleaner
2014-11-24 13:56:04 ----D---- C:\Users\test\AppData\Roaming\Intel Corporation
2014-11-24 13:55:06 ----D---- C:\Users\test\AppData\Roaming\ControlCenter4
2014-11-24 13:54:54 ----D---- C:\Users\test\AppData\Roaming\Adobe
2014-11-24 13:54:47 ----D---- C:\Users\test\AppData\Roaming\Identities
2014-11-24 13:54:30 ----SD---- C:\Users\test\AppData\Roaming\Microsoft
2014-11-24 13:54:30 ----D---- C:\Users\test\AppData\Roaming\Media Center Programs
2014-11-19 01:44:21 ----A---- C:\Windows\SYSWOW64\pku2u.dll
2014-11-19 01:44:21 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-11-19 01:44:21 ----A---- C:\Windows\system32\pku2u.dll
2014-11-19 01:44:21 ----A---- C:\Windows\system32\kerberos.dll
2014-11-14 11:45:12 ----D---- C:\ProgramData\oqixicudoparelom
2014-11-12 06:51:42 ----A---- C:\Windows\system32\generaltel.dll
2014-11-12 06:51:41 ----A---- C:\Windows\system32\aepdu.dll
2014-11-12 06:51:41 ----A---- C:\Windows\system32\aeinv.dll
2014-11-12 06:51:39 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-11-12 06:51:39 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-11-12 06:51:39 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2014-11-12 06:51:39 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2014-11-12 06:51:39 ----A---- C:\Windows\system32\termsrv.dll
2014-11-12 06:51:39 ----A---- C:\Windows\system32\msaudite.dll
2014-11-12 06:51:39 ----A---- C:\Windows\system32\lsasrv.dll
2014-11-12 06:51:39 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2014-11-12 06:51:39 ----A---- C:\Windows\system32\adtschema.dll
2014-11-12 06:51:34 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-11-12 06:51:34 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-11-12 06:51:34 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-11-12 06:51:34 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-11-12 06:51:34 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-11-12 06:51:34 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-11-12 06:51:34 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-11-12 06:51:34 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-11-12 06:51:34 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-11-12 06:51:34 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-11-12 06:51:34 ----A---- C:\Windows\system32\iernonce.dll
2014-11-12 06:51:34 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-11-12 06:51:34 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-11-12 06:51:34 ----A---- C:\Windows\system32\ie4uinit.exe
2014-11-12 06:51:33 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-11-12 06:51:33 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-11-12 06:51:33 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-11-12 06:51:33 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-11-12 06:51:33 ----A---- C:\Windows\system32\urlmon.dll
2014-11-12 06:51:33 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-11-12 06:51:33 ----A---- C:\Windows\system32\iedkcs32.dll
2014-11-12 06:51:32 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-11-12 06:51:32 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-11-12 06:51:32 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-11-12 06:51:32 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-11-12 06:51:32 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-11-12 06:51:32 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-11-12 06:51:32 ----A---- C:\Windows\system32\msfeeds.dll
2014-11-12 06:51:32 ----A---- C:\Windows\system32\iesetup.dll
2014-11-12 06:51:32 ----A---- C:\Windows\system32\ieapfltr.dll
2014-11-12 06:51:32 ----A---- C:\Windows\system32\dxtrans.dll
2014-11-12 06:51:31 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-11-12 06:51:31 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-11-12 06:51:31 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-11-12 06:51:31 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-11-12 06:51:31 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-11-12 06:51:31 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-11-12 06:51:31 ----A---- C:\Windows\system32\jsproxy.dll
2014-11-12 06:51:31 ----A---- C:\Windows\system32\ieUnatt.exe
2014-11-12 06:51:31 ----A---- C:\Windows\system32\iertutil.dll
2014-11-12 06:51:30 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-11-12 06:51:30 ----A---- C:\Windows\system32\mshtmled.dll
2014-11-12 06:51:30 ----A---- C:\Windows\system32\jscript9diag.dll
2014-11-12 06:51:30 ----A---- C:\Windows\system32\ieui.dll
2014-11-12 06:51:30 ----A---- C:\Windows\system32\ieframe.dll
2014-11-12 06:51:30 ----A---- C:\Windows\system32\dxtmsft.dll
2014-11-12 06:51:29 ----A---- C:\Windows\system32\wininet.dll
2014-11-12 06:51:29 ----A---- C:\Windows\system32\vbscript.dll
2014-11-12 06:51:29 ----A---- C:\Windows\system32\msrating.dll
2014-11-12 06:51:29 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-11-12 06:51:29 ----A---- C:\Windows\system32\jscript9.dll
2014-11-12 06:51:28 ----A---- C:\Windows\system32\mshtml.dll
2014-11-12 06:50:31 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2014-11-12 06:50:31 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2014-11-12 06:50:31 ----A---- C:\Windows\system32\msxml3r.dll
2014-11-12 06:50:31 ----A---- C:\Windows\system32\msxml3.dll
2014-11-12 06:50:30 ----A---- C:\Windows\SYSWOW64\IMJP10K.DLL
2014-11-12 06:50:30 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2014-11-12 06:50:30 ----A---- C:\Windows\system32\IMJP10K.DLL
2014-11-12 06:50:30 ----A---- C:\Windows\system32\audiosrv.dll
2014-11-12 06:50:30 ----A---- C:\Windows\system32\AUDIOKSE.dll
2014-11-12 06:50:29 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2014-11-12 06:50:29 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2014-11-12 06:50:29 ----A---- C:\Windows\system32\EncDump.dll
2014-11-12 06:50:29 ----A---- C:\Windows\system32\AudioSes.dll
2014-11-12 06:50:29 ----A---- C:\Windows\system32\AudioEng.dll
2014-11-12 06:50:28 ----A---- C:\Windows\system32\schannel.dll
2014-11-12 06:50:28 ----A---- C:\Windows\system32\ncrypt.dll
2014-11-12 06:50:27 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2014-11-12 06:50:27 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2014-11-12 06:50:27 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-11-12 06:50:27 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2014-11-12 06:50:27 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2014-11-12 06:50:27 ----A---- C:\Windows\SYSWOW64\credssp.dll
2014-11-12 06:50:27 ----A---- C:\Windows\system32\wdigest.dll
2014-11-12 06:50:27 ----A---- C:\Windows\system32\TSpkg.dll
2014-11-12 06:50:27 ----A---- C:\Windows\system32\msv1_0.dll
2014-11-12 06:50:27 ----A---- C:\Windows\system32\credssp.dll
2014-11-12 06:50:21 ----A---- C:\Windows\SYSWOW64\packager.dll
2014-11-12 06:50:21 ----A---- C:\Windows\system32\packager.dll
2014-11-12 06:50:20 ----A---- C:\Windows\system32\win32k.sys
2014-11-12 06:50:19 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-11-12 06:50:19 ----A---- C:\Windows\system32\msi.dll
2014-11-12 06:50:16 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2014-11-12 06:50:16 ----A---- C:\Windows\system32\oleaut32.dll
2014-11-11 07:30:11 ----D---- C:\Program Files (x86)\Mozilla Firefox

======List of files/folders modified in the last 1 month======

2014-11-24 19:21:34 ----D---- C:\Windows\Prefetch
2014-11-24 19:21:29 ----D---- C:\Windows\Temp
2014-11-24 19:21:26 ----RD---- C:\Program Files
2014-11-24 19:17:24 ----D---- C:\Windows\system32\config
2014-11-24 18:11:01 ----D---- C:\Windows\Panther
2014-11-24 18:11:01 ----D---- C:\Windows\inf
2014-11-24 18:11:00 ----D---- C:\Windows\Logs
2014-11-24 18:11:00 ----D---- C:\Windows\debug
2014-11-24 18:11:00 ----D---- C:\Windows
2014-11-24 18:10:33 ----D---- C:\Windows\system32\Tasks
2014-11-24 18:09:08 ----SHD---- C:\System Volume Information
2014-11-24 17:58:58 ----D---- C:\Windows\system32\FxsTmp
2014-11-24 14:57:35 ----SHD---- C:\Windows\Installer
2014-11-24 13:54:41 ----SHD---- C:\$Recycle.Bin
2014-11-24 13:54:29 ----RD---- C:\Users
2014-11-23 12:42:58 ----D---- C:\Windows\System32
2014-11-23 12:42:58 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-11-19 03:16:57 ----D---- C:\Windows\winsxs
2014-11-19 03:15:53 ----D---- C:\Windows\SysWOW64
2014-11-18 14:45:59 ----D---- C:\Windows\rescache
2014-11-14 11:49:18 ----D---- C:\ESET-instal
2014-11-14 11:45:12 ----HD---- C:\ProgramData
2014-11-13 11:05:36 ----D---- C:\Windows\Microsoft.NET
2014-11-13 11:04:55 ----RSD---- C:\Windows\assembly
2014-11-13 06:56:03 ----SD---- C:\Windows\system32\CompatTel
2014-11-13 06:56:02 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-11-13 06:56:01 ----D---- C:\Windows\system32\drivers
2014-11-13 06:56:01 ----D---- C:\Windows\system32\cs-CZ
2014-11-13 06:56:01 ----D---- C:\Program Files\Internet Explorer
2014-11-13 06:56:00 ----D---- C:\Windows\SYSWOW64\en-US
2014-11-13 06:55:59 ----D---- C:\Windows\system32\en-US
2014-11-13 06:55:57 ----D---- C:\Program Files (x86)\Internet Explorer
2014-11-12 14:05:44 ----D---- C:\ProgramData\Microsoft Help
2014-11-12 14:03:35 ----D---- C:\Windows\system32\MRT
2014-11-12 14:01:41 ----A---- C:\Windows\system32\MRT.exe
2014-11-12 13:59:45 ----RD---- C:\Program Files (x86)
2014-11-12 10:06:25 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-11-12 06:53:26 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-11-12 06:50:01 ----D---- C:\Windows\system32\catroot2
2014-11-04 14:30:58 ----N---- C:\Windows\system32\MpSigStub.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\Windows\system32\DRIVERS\iaStorA.sys [2013-09-27 630632]
R0 iaStorF;iaStorF; C:\Windows\system32\DRIVERS\iaStorF.sys [2013-09-27 28008]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2013-10-25 219184]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2013-09-09 155896]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2013-09-09 147096]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2013-10-28 4195840]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2013-11-05 3707864]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2013-08-28 99288]
R3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2013-08-27 883928]
R3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\Windows\system32\DRIVERS\serscan.sys [2009-07-14 12288]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2009-08-05 61280]
S3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2012-06-19 342528]
S3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\drivers\iusb3hub.sys [2012-01-05 355096]
S3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\drivers\iusb3xhc.sys [2012-01-05 786200]
S3 L1C;NDIS Miniport Driver for Atheros AR81xx PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2012-04-25 104560]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2012-05-04 2196592]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 BBUpdate;BBUpdate; C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-10-13 249648]
R2 cbVSCService11;Cobian Backup 11 Stínová kopie - Requester; C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe [2012-12-05 67584]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe [2013-10-07 1025584]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-09-27 15720]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-05-11 733696]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-08-28 169432]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-08-28 390616]
R2 VIAKaraokeService;VIA Karaoke digital mixer Service; C:\Windows\system32\viakaraokesrv.exe [2012-05-04 27760]
R3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 BrYNSvc;BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [2012-06-05 266240]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
R3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S2 BBSvc;Bing Bar Update Service; C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-10-21 196176]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-12 267440]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2013-11-05 279024]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Endpoint Antivirus\EHttpSrv.exe [2013-10-07 42048]
S3 ESHASRV;ESET SHA Service; C:\Program Files\ESET\ESET Endpoint Antivirus\EShaSrv.exe [2013-10-07 191368]
S3 fsssvc;Služba Windows Live Zabezpečení rodiny; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-11-06 114688]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-05-11 822232]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [2014-04-09 289256]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-11-11 114288]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-11-28 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Win32/Filecoder.DI trojský kůň a Win32/Kryptik.CJRT troj

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Jen se zeptam, jedna se o domaci PC nebo nejaky firemni??

:arrow: Ty soubory mate asi nebo urcite zasifrovane??
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

alvr
Návštěvník
Návštěvník
Příspěvky: 73
Registrován: 21 čer 2011 18:52

Re: Win32/Filecoder.DI trojský kůň a Win32/Kryptik.CJRT troj

#3 Příspěvek od alvr »

Je to pocitac od manzelky a dela tam i nejake veci do prace, jako ucetnictvi a tak. Asi to je problem, kdyz na to i pracuje, ze?
Ty zasifrovane soubory jdou otevrit, ale je to rozsypany caj (necitelne puvodni data). Vetsinou jde o dokumenty z Office a pdf.
Je moznost pomoci, prosim?

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Win32/Filecoder.DI trojský kůň a Win32/Kryptik.CJRT troj

#4 Příspěvek od vyosek »

Uz jen na zaklade toho, ze je tam verze antiviru urcena pouze pro firemni klientelu, je jasne, ze to neni domaci pocitac.

Bud at to sveri firemnimu technikovi, nebo se muzete obratit na nasi sluzbu vzdalene pomoci http://www.neslape.cz/ kde kolegove fiemni PC resi a tez maji zkusenosti se zasifrovanymi soubory - tento typ haveti ani na foru resit nelze...
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

alvr
Návštěvník
Návštěvník
Příspěvky: 73
Registrován: 21 čer 2011 18:52

Re: Win32/Filecoder.DI trojský kůň a Win32/Kryptik.CJRT troj

#5 Příspěvek od alvr »

Ano, ma i licenci na ESET z firmy. Ale uznavam a chapu namitky. I tak dekuji za doporuceni. Zkusim to.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Win32/Filecoder.DI trojský kůň a Win32/Kryptik.CJRT troj

#6 Příspěvek od vyosek »

My tu nebudeme delat praci za firemniho IT technika, nebo nekoho, kdo je za PC zodpovedny...

A jak jsem psal, tato havet (zafisrovane soubory) nelze lecit pres forum...

Neni zac a pekny zbytek vecera :worship:


:closed:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zamčeno