Stránka 1 z 2

Viry v NTB

Napsal: 02 bře 2015 18:21
od Jarin
Dobry vecer,
potreboval bych pomoct. Sousedka donesla NTB jestli bych se na to nepodival.
Pokazde kdyz otevru Mozillu tak avast se muze zblaznit a porad "vyskakuje".
Dekuju za pomoct.

Logfile of random's system information tool 1.10 (written by random/random)
Run by Uzivatel at 2015-03-02 18:18:16
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 102 GB (67%) free of 153 GB
Total RAM: 1977 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:18:39, on 2.3.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17631)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\PLFSetI.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\ProgramData\{a1d49146-bf3d-72cd-a1d4-49146bf3451a}\Metin2Mod_PL_11022015.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Uzivatel\Desktop\RSIT.exe
C:\Program Files\trend micro\Uzivatel.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Startup: Metin2Mod_PL_11022015.lnk = C:\ProgramData\{a1d49146-bf3d-72cd-a1d4-49146bf3451a}\Metin2Mod_PL_11022015.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: O2FLASH - O2Micro International - C:\Windows\system32\DRIVERS\o2flash.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 5698 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\5v2tiqa9.default

prefs.js - "browser.startup.homepage" - "www.seznam.cz"

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.305 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.25.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.25.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\5v2tiqa9.default\extensions\
1D@Z.net
8eV6Ew@I.com
Nm@wlS.net

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll [2014-11-23 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-11-23 172968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-09-02 135168]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-09-02 167424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-09-02 144384]
"PLFSetI"=C:\Windows\PLFSetI.exe [2009-11-20 200704]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2014-11-23 7703072]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2014-11-23 1565992]
"LManager"=C:\Program Files\Launch Manager\LManager.exe [2014-11-23 1130504]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2014-10-07 507776]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-01-27 5227112]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Metin2Mod_PL_11022015.lnk - C:\ProgramData\{a1d49146-bf3d-72cd-a1d4-49146bf3451a}\Metin2Mod_PL_11022015.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-09-02 217088]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-03-02 18:18:17 ----D---- C:\Program Files\trend micro
2015-03-02 18:18:16 ----D---- C:\rsit
2015-03-01 11:29:05 ----D---- C:\ProgramData\Alex Gordon
2015-03-01 11:28:20 ----D---- C:\Program Files\Alex Kočičák
2015-02-28 10:44:06 ----D---- C:\ProgramData\PopCap Games
2015-02-24 12:08:48 ----SHD---- C:\found.001
2015-02-19 09:00:29 ----D---- C:\Program Files\UnniDealssa
2015-02-17 19:48:37 ----A---- C:\Windows\system32\powertracker.dll
2015-02-17 19:48:37 ----A---- C:\Windows\system32\perftrack.dll
2015-02-17 19:48:36 ----A---- C:\Windows\system32\wdi.dll
2015-02-14 17:15:04 ----D---- C:\Program Files\UniDeaalsa
2015-02-14 17:14:18 ----D---- C:\ProgramData\{a1d49146-bf3d-72cd-a1d4-49146bf3451a}
2015-02-14 17:12:40 ----D---- C:\Program Files\UniDeals
2015-02-14 17:12:14 ----D---- C:\ProgramData\10543503948886965507
2015-02-14 17:12:08 ----D---- C:\Program Files\UnieDoeaalsi
2015-02-14 17:11:36 ----D---- C:\ProgramData\{64302c42-57aa-0147-6430-02c4257ab109}
2015-02-13 15:20:31 ----A---- C:\Windows\system32\jscript9diag.dll
2015-02-13 15:20:30 ----A---- C:\Windows\system32\jscript9.dll
2015-02-13 15:10:55 ----D---- C:\ea988f9945702573b63ba3
2015-02-11 14:35:18 ----A---- C:\Windows\system32\win32k.sys
2015-02-11 14:35:13 ----A---- C:\Windows\system32\lsasrv.dll
2015-02-11 14:35:13 ----A---- C:\Windows\system32\drivers\cng.sys
2015-02-11 14:35:13 ----A---- C:\Windows\system32\adtschema.dll
2015-02-11 14:35:12 ----A---- C:\Windows\system32\sspisrv.dll
2015-02-11 14:35:12 ----A---- C:\Windows\system32\sspicli.dll
2015-02-11 14:35:12 ----A---- C:\Windows\system32\secur32.dll
2015-02-11 14:35:12 ----A---- C:\Windows\system32\msobjs.dll
2015-02-11 14:35:12 ----A---- C:\Windows\system32\lsass.exe
2015-02-11 14:35:12 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-02-11 14:35:12 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-02-11 14:35:12 ----A---- C:\Windows\system32\auditpol.exe
2015-02-11 14:35:11 ----A---- C:\Windows\system32\msaudite.dll
2015-02-11 14:34:30 ----A---- C:\Windows\system32\ntkrnlpa.exe
2015-02-11 14:34:29 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-02-11 14:34:16 ----A---- C:\Windows\system32\oleaut32.dll
2015-02-11 14:34:14 ----A---- C:\Windows\system32\appraiser.dll
2015-02-11 14:34:13 ----A---- C:\Windows\system32\generaltel.dll
2015-02-11 14:34:12 ----A---- C:\Windows\system32\invagent.dll
2015-02-11 14:34:12 ----A---- C:\Windows\system32\aeinv.dll
2015-02-11 14:34:11 ----A---- C:\Windows\system32\devinv.dll
2015-02-11 14:34:11 ----A---- C:\Windows\system32\aitstatic.exe
2015-02-11 14:34:09 ----A---- C:\Windows\system32\aepdu.dll
2015-02-11 14:34:08 ----A---- C:\Windows\system32\aepic.dll
2015-02-11 14:34:02 ----A---- C:\Windows\system32\schannel.dll
2015-02-11 14:34:01 ----A---- C:\Windows\system32\wdigest.dll
2015-02-11 14:34:01 ----A---- C:\Windows\system32\TSpkg.dll
2015-02-11 14:34:01 ----A---- C:\Windows\system32\ncrypt.dll
2015-02-11 14:34:01 ----A---- C:\Windows\system32\msv1_0.dll
2015-02-11 14:34:01 ----A---- C:\Windows\system32\kerberos.dll
2015-02-11 14:34:00 ----A---- C:\Windows\system32\credssp.dll
2015-02-11 14:33:47 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-02-11 14:33:47 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-02-11 14:33:47 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-02-11 14:33:46 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-02-11 14:33:46 ----A---- C:\Windows\system32\iernonce.dll
2015-02-11 14:33:46 ----A---- C:\Windows\system32\ie4uinit.exe
2015-02-11 14:33:45 ----A---- C:\Windows\system32\urlmon.dll
2015-02-11 14:33:45 ----A---- C:\Windows\system32\jsproxy.dll
2015-02-11 14:33:45 ----A---- C:\Windows\system32\ieUnatt.exe
2015-02-11 14:33:45 ----A---- C:\Windows\system32\iedkcs32.dll
2015-02-11 14:33:44 ----A---- C:\Windows\system32\ieapfltr.dll
2015-02-11 14:33:44 ----A---- C:\Windows\system32\dxtmsft.dll
2015-02-11 14:33:43 ----A---- C:\Windows\system32\msfeeds.dll
2015-02-11 14:33:41 ----A---- C:\Windows\system32\msrating.dll
2015-02-11 14:33:40 ----A---- C:\Windows\system32\iesetup.dll
2015-02-11 14:33:39 ----A---- C:\Windows\system32\wininet.dll
2015-02-11 14:33:39 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-02-11 14:33:37 ----A---- C:\Windows\system32\dxtrans.dll
2015-02-11 14:33:36 ----A---- C:\Windows\system32\ieui.dll
2015-02-11 14:33:35 ----A---- C:\Windows\system32\ieframe.dll
2015-02-11 14:33:33 ----A---- C:\Windows\system32\mshtmled.dll
2015-02-11 14:33:32 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-02-11 14:33:31 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-02-11 14:33:29 ----A---- C:\Windows\system32\iertutil.dll
2015-02-11 14:33:25 ----A---- C:\Windows\system32\mshtml.dll
2015-02-11 14:33:23 ----A---- C:\Windows\system32\vbscript.dll
2015-02-11 14:32:54 ----A---- C:\Windows\system32\wintrust.dll
2015-02-11 14:32:54 ----A---- C:\Windows\system32\cryptsvc.dll
2015-02-11 14:32:54 ----A---- C:\Windows\system32\crypt32.dll
2015-02-11 14:32:48 ----A---- C:\Windows\system32\scesrv.dll
2015-02-11 14:32:46 ----A---- C:\Windows\system32\WindowsCodecs.dll

======List of files/folders modified in the last 1 month======

2015-03-02 18:18:19 ----D---- C:\Windows\Temp
2015-03-02 18:18:17 ----RD---- C:\Program Files
2015-03-02 18:09:41 ----HD---- C:\ProgramData
2015-03-02 18:08:37 ----SD---- C:\ProgramData\Microsoft
2015-03-02 17:40:51 ----D---- C:\Windows\system32\catroot2
2015-03-02 17:40:49 ----D---- C:\Windows\system32\config
2015-03-02 17:08:24 ----D---- C:\Windows\Prefetch
2015-02-28 21:03:31 ----D---- C:\Windows\system32\NDF
2015-02-28 15:09:36 ----D---- C:\Counter-Strike 1.6
2015-02-28 10:45:47 ----D---- C:\Windows\System32
2015-02-28 10:45:47 ----D---- C:\Windows\inf
2015-02-28 10:45:47 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-02-26 09:25:47 ----D---- C:\Windows\winsxs
2015-02-19 08:58:23 ----D---- C:\Users\Uzivatel\AppData\Roaming\.minecraft
2015-02-18 15:04:55 ----D---- C:\Windows\tracing
2015-02-17 16:58:08 ----SHD---- C:\System Volume Information
2015-02-15 14:08:09 ----D---- C:\Windows\rescache
2015-02-14 08:03:22 ----D---- C:\Windows\system32\en-US
2015-02-13 15:13:29 ----D---- C:\Windows\system32\cs-CZ
2015-02-13 15:13:28 ----D---- C:\Windows\system32\drivers
2015-02-12 14:54:30 ----SD---- C:\Windows\system32\CompatTel
2015-02-12 14:54:29 ----D---- C:\Windows\system32\appraiser
2015-02-12 14:54:28 ----D---- C:\Program Files\Internet Explorer
2015-02-12 14:38:50 ----D---- C:\Windows\system32\MRT
2015-02-12 14:34:51 ----A---- C:\Windows\system32\MRT.exe
2015-02-11 14:32:33 ----D---- C:\Windows\system32\catroot
2015-02-08 16:18:32 ----A---- C:\Users\Uzivatel\AppData\Roaming\burnaware.ini
2015-02-06 14:37:24 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2015-02-04 20:32:00 ----D---- C:\Windows\system32\wdi
2015-02-03 12:08:06 ----D---- C:\Windows\Microsoft.NET
2015-02-03 12:07:51 ----RSD---- C:\Windows\assembly
2015-02-03 09:43:16 ----SHD---- C:\Windows\Installer

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-11-25 49944]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-11-25 206248]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2014-11-25 81768]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2014-11-25 787800]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2014-11-25 423784]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2014-11-25 24184]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2014-11-25 70384]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2014-11-25 91496]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\XAudio32.sys [2014-11-23 8704]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2009-10-05 1221632]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2014-11-23 21000]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2014-11-23 980992]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2014-11-23 207360]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-09-02 5946368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2014-11-23 2745760]
R3 O2MDRDR;O2MDRDR; C:\Windows\system32\DRIVERS\o2media.sys [2014-11-23 52128]
R3 O2SDRDR;O2SDRDR; C:\Windows\system32\DRIVERS\o2sd.sys [2014-11-23 42144]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2014-11-23 229040]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2014-11-23 661504]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2014-11-23 86056]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2014-11-23 108072]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2014-11-23 29472]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2014-11-23 18472]
S3 EagleXNt;EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys []
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmb.sys [2011-08-17 18176]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 84992]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
S3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
S3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-11-25 50344]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-10-02 595232]
R2 HsfXAudioService;HsfXAudioService; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 O2FLASH;O2FLASH; C:\Windows\system32\DRIVERS\o2flash.exe [2014-11-23 65536]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-06 267440]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-01-12 102912]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2015-01-29 114800]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2014-04-11 45744]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]

-----------------EOF-----------------

Re: Viry v NTB

Napsal: 02 bře 2015 18:54
od Rudy
Zdravím!
Spusťte nejprve tuto utlitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: Viry v NTB

Napsal: 02 bře 2015 19:01
od Jarin
# AdwCleaner v4.111 - Logfile created 02/03/2015 at 18:58:04
# Updated 18/02/2015 by Xplode
# Database : 2015-03-02.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x86)
# Username : Uzivatel - NTB-ACER
# Running from : C:\Users\Uzivatel\Desktop\adwcleaner_4.111.exe
# Option : Cleaning

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\10543503948886965507
Folder Deleted : C:\Program Files\UniDeaalsa
Folder Deleted : C:\Program Files\UniDeals
Folder Deleted : C:\Program Files\UnieDoeaalsi
Folder Deleted : C:\Program Files\UnniDealssa
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\5v2tiqa9.default\Extensions\1D@Z.net
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\5v2tiqa9.default\Extensions\8eV6Ew@I.com
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\5v2tiqa9.default\Extensions\Nm@wlS.net

***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{11F6D5AB-263F-388E-74DE-E3DECD390E3F}

***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17631


-\\ Mozilla Firefox v35.0.1 (x86 cs)


-\\ Google Chrome v40.0.2214.115


*************************

AdwCleaner[R0].txt - [1480 bytes] - [02/03/2015 18:55:24]
AdwCleaner[S0].txt - [1425 bytes] - [02/03/2015 18:58:04]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1484 bytes] ##########

Re: Viry v NTB

Napsal: 02 bře 2015 19:03
od Rudy
Dejte nový log RSIT.

Re: Viry v NTB

Napsal: 02 bře 2015 19:06
od Jarin
Ah, omlouvam se myslel jsem ze log ktery vyskocil po Adw.

Logfile of random's system information tool 1.10 (written by random/random)
Run by Uzivatel at 2015-03-02 19:05:41
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 101 GB (66%) free of 153 GB
Total RAM: 1977 MB (48% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:06:03, on 2.3.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17631)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\PLFSetI.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\ProgramData\{a1d49146-bf3d-72cd-a1d4-49146bf3451a}\Metin2Mod_PL_11022015.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Uzivatel\Desktop\RSIT.exe
C:\Program Files\trend micro\Uzivatel.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Startup: Metin2Mod_PL_11022015.lnk = C:\ProgramData\{a1d49146-bf3d-72cd-a1d4-49146bf3451a}\Metin2Mod_PL_11022015.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: O2FLASH - O2Micro International - C:\Windows\system32\DRIVERS\o2flash.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 5942 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\5v2tiqa9.default

prefs.js - "browser.startup.homepage" - "www.seznam.cz"

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.305 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.25.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.25.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll [2014-11-23 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-11-23 172968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-09-02 135168]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-09-02 167424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-09-02 144384]
"PLFSetI"=C:\Windows\PLFSetI.exe [2009-11-20 200704]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2014-11-23 7703072]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2014-11-23 1565992]
"LManager"=C:\Program Files\Launch Manager\LManager.exe [2014-11-23 1130504]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2014-10-07 507776]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-01-27 5227112]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Metin2Mod_PL_11022015.lnk - C:\ProgramData\{a1d49146-bf3d-72cd-a1d4-49146bf3451a}\Metin2Mod_PL_11022015.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-09-02 217088]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-03-02 18:55:21 ----D---- C:\AdwCleaner
2015-03-02 18:52:15 ----D---- C:\Program Files\Google
2015-03-02 18:18:17 ----D---- C:\Program Files\trend micro
2015-03-02 18:18:16 ----D---- C:\rsit
2015-03-01 11:29:05 ----D---- C:\ProgramData\Alex Gordon
2015-03-01 11:28:20 ----D---- C:\Program Files\Alex Kočičák
2015-02-28 10:44:06 ----D---- C:\ProgramData\PopCap Games
2015-02-24 12:08:48 ----SHD---- C:\found.001
2015-02-17 19:48:37 ----A---- C:\Windows\system32\powertracker.dll
2015-02-17 19:48:37 ----A---- C:\Windows\system32\perftrack.dll
2015-02-17 19:48:36 ----A---- C:\Windows\system32\wdi.dll
2015-02-14 17:14:18 ----D---- C:\ProgramData\{a1d49146-bf3d-72cd-a1d4-49146bf3451a}
2015-02-14 17:11:36 ----D---- C:\ProgramData\{64302c42-57aa-0147-6430-02c4257ab109}
2015-02-13 15:20:31 ----A---- C:\Windows\system32\jscript9diag.dll
2015-02-13 15:20:30 ----A---- C:\Windows\system32\jscript9.dll
2015-02-13 15:10:55 ----D---- C:\ea988f9945702573b63ba3
2015-02-11 14:35:18 ----A---- C:\Windows\system32\win32k.sys
2015-02-11 14:35:13 ----A---- C:\Windows\system32\lsasrv.dll
2015-02-11 14:35:13 ----A---- C:\Windows\system32\drivers\cng.sys
2015-02-11 14:35:13 ----A---- C:\Windows\system32\adtschema.dll
2015-02-11 14:35:12 ----A---- C:\Windows\system32\sspisrv.dll
2015-02-11 14:35:12 ----A---- C:\Windows\system32\sspicli.dll
2015-02-11 14:35:12 ----A---- C:\Windows\system32\secur32.dll
2015-02-11 14:35:12 ----A---- C:\Windows\system32\msobjs.dll
2015-02-11 14:35:12 ----A---- C:\Windows\system32\lsass.exe
2015-02-11 14:35:12 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-02-11 14:35:12 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-02-11 14:35:12 ----A---- C:\Windows\system32\auditpol.exe
2015-02-11 14:35:11 ----A---- C:\Windows\system32\msaudite.dll
2015-02-11 14:34:30 ----A---- C:\Windows\system32\ntkrnlpa.exe
2015-02-11 14:34:29 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-02-11 14:34:16 ----A---- C:\Windows\system32\oleaut32.dll
2015-02-11 14:34:14 ----A---- C:\Windows\system32\appraiser.dll
2015-02-11 14:34:13 ----A---- C:\Windows\system32\generaltel.dll
2015-02-11 14:34:12 ----A---- C:\Windows\system32\invagent.dll
2015-02-11 14:34:12 ----A---- C:\Windows\system32\aeinv.dll
2015-02-11 14:34:11 ----A---- C:\Windows\system32\devinv.dll
2015-02-11 14:34:11 ----A---- C:\Windows\system32\aitstatic.exe
2015-02-11 14:34:09 ----A---- C:\Windows\system32\aepdu.dll
2015-02-11 14:34:08 ----A---- C:\Windows\system32\aepic.dll
2015-02-11 14:34:02 ----A---- C:\Windows\system32\schannel.dll
2015-02-11 14:34:01 ----A---- C:\Windows\system32\wdigest.dll
2015-02-11 14:34:01 ----A---- C:\Windows\system32\TSpkg.dll
2015-02-11 14:34:01 ----A---- C:\Windows\system32\ncrypt.dll
2015-02-11 14:34:01 ----A---- C:\Windows\system32\msv1_0.dll
2015-02-11 14:34:01 ----A---- C:\Windows\system32\kerberos.dll
2015-02-11 14:34:00 ----A---- C:\Windows\system32\credssp.dll
2015-02-11 14:33:47 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-02-11 14:33:47 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-02-11 14:33:47 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-02-11 14:33:46 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-02-11 14:33:46 ----A---- C:\Windows\system32\iernonce.dll
2015-02-11 14:33:46 ----A---- C:\Windows\system32\ie4uinit.exe
2015-02-11 14:33:45 ----A---- C:\Windows\system32\urlmon.dll
2015-02-11 14:33:45 ----A---- C:\Windows\system32\jsproxy.dll
2015-02-11 14:33:45 ----A---- C:\Windows\system32\ieUnatt.exe
2015-02-11 14:33:45 ----A---- C:\Windows\system32\iedkcs32.dll
2015-02-11 14:33:44 ----A---- C:\Windows\system32\ieapfltr.dll
2015-02-11 14:33:44 ----A---- C:\Windows\system32\dxtmsft.dll
2015-02-11 14:33:43 ----A---- C:\Windows\system32\msfeeds.dll
2015-02-11 14:33:41 ----A---- C:\Windows\system32\msrating.dll
2015-02-11 14:33:40 ----A---- C:\Windows\system32\iesetup.dll
2015-02-11 14:33:39 ----A---- C:\Windows\system32\wininet.dll
2015-02-11 14:33:39 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-02-11 14:33:37 ----A---- C:\Windows\system32\dxtrans.dll
2015-02-11 14:33:36 ----A---- C:\Windows\system32\ieui.dll
2015-02-11 14:33:35 ----A---- C:\Windows\system32\ieframe.dll
2015-02-11 14:33:33 ----A---- C:\Windows\system32\mshtmled.dll
2015-02-11 14:33:32 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-02-11 14:33:31 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-02-11 14:33:29 ----A---- C:\Windows\system32\iertutil.dll
2015-02-11 14:33:25 ----A---- C:\Windows\system32\mshtml.dll
2015-02-11 14:33:23 ----A---- C:\Windows\system32\vbscript.dll
2015-02-11 14:32:54 ----A---- C:\Windows\system32\wintrust.dll
2015-02-11 14:32:54 ----A---- C:\Windows\system32\cryptsvc.dll
2015-02-11 14:32:54 ----A---- C:\Windows\system32\crypt32.dll
2015-02-11 14:32:48 ----A---- C:\Windows\system32\scesrv.dll
2015-02-11 14:32:46 ----A---- C:\Windows\system32\WindowsCodecs.dll

======List of files/folders modified in the last 1 month======

2015-03-02 19:05:49 ----D---- C:\Windows\Temp
2015-03-02 19:03:10 ----D---- C:\Windows\system32\config
2015-03-02 18:58:04 ----RD---- C:\Program Files
2015-03-02 18:58:04 ----HD---- C:\ProgramData
2015-03-02 18:57:03 ----SHD---- C:\Windows\Installer
2015-03-02 18:52:20 ----D---- C:\Windows\Tasks
2015-03-02 18:52:20 ----D---- C:\Windows\system32\Tasks
2015-03-02 18:08:37 ----SD---- C:\ProgramData\Microsoft
2015-03-02 17:40:51 ----D---- C:\Windows\system32\catroot2
2015-03-02 17:08:24 ----D---- C:\Windows\Prefetch
2015-02-28 21:03:31 ----D---- C:\Windows\system32\NDF
2015-02-28 15:09:36 ----D---- C:\Counter-Strike 1.6
2015-02-28 10:45:47 ----D---- C:\Windows\System32
2015-02-28 10:45:47 ----D---- C:\Windows\inf
2015-02-28 10:45:47 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-02-26 09:25:47 ----D---- C:\Windows\winsxs
2015-02-19 08:58:23 ----D---- C:\Users\Uzivatel\AppData\Roaming\.minecraft
2015-02-18 15:04:55 ----D---- C:\Windows\tracing
2015-02-17 16:58:08 ----SHD---- C:\System Volume Information
2015-02-15 14:08:09 ----D---- C:\Windows\rescache
2015-02-14 08:03:22 ----D---- C:\Windows\system32\en-US
2015-02-13 15:13:29 ----D---- C:\Windows\system32\cs-CZ
2015-02-13 15:13:28 ----D---- C:\Windows\system32\drivers
2015-02-12 14:54:30 ----SD---- C:\Windows\system32\CompatTel
2015-02-12 14:54:29 ----D---- C:\Windows\system32\appraiser
2015-02-12 14:54:28 ----D---- C:\Program Files\Internet Explorer
2015-02-12 14:38:50 ----D---- C:\Windows\system32\MRT
2015-02-12 14:34:51 ----A---- C:\Windows\system32\MRT.exe
2015-02-11 14:32:33 ----D---- C:\Windows\system32\catroot
2015-02-08 16:18:32 ----A---- C:\Users\Uzivatel\AppData\Roaming\burnaware.ini
2015-02-06 14:37:24 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2015-02-04 20:32:00 ----D---- C:\Windows\system32\wdi
2015-02-03 12:08:06 ----D---- C:\Windows\Microsoft.NET
2015-02-03 12:07:51 ----RSD---- C:\Windows\assembly

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-11-25 49944]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-11-25 206248]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2014-11-25 81768]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2014-11-25 787800]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2014-11-25 423784]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2014-11-25 24184]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2014-11-25 70384]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2014-11-25 91496]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\XAudio32.sys [2014-11-23 8704]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2009-10-05 1221632]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2014-11-23 21000]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2014-11-23 980992]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2014-11-23 207360]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-09-02 5946368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2014-11-23 2745760]
R3 O2MDRDR;O2MDRDR; C:\Windows\system32\DRIVERS\o2media.sys [2014-11-23 52128]
R3 O2SDRDR;O2SDRDR; C:\Windows\system32\DRIVERS\o2sd.sys [2014-11-23 42144]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2014-11-23 229040]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2014-11-23 661504]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2014-11-23 86056]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2014-11-23 108072]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2014-11-23 29472]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2014-11-23 18472]
S3 EagleXNt;EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys []
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmb.sys [2011-08-17 18176]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 84992]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
S3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
S3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-11-25 50344]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-10-02 595232]
R2 HsfXAudioService;HsfXAudioService; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 O2FLASH;O2FLASH; C:\Windows\system32\DRIVERS\o2flash.exe [2014-11-23 65536]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-03-02 107848]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-06 267440]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-03-02 107848]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-01-12 102912]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2015-01-29 114800]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2014-04-11 45744]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]

-----------------EOF-----------------

Re: Viry v NTB

Napsal: 02 bře 2015 20:12
od Rudy
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\ProgramData\{a1d49146-bf3d-72cd-a1d4-49146bf3451a}\Metin2Mod_PL_11022015.exe
C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Metin2Mod_PL_11022015.lnk

:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.

Re: Viry v NTB

Napsal: 02 bře 2015 20:25
od Jarin
Omlouvam se ze to tak trvalo ale slo to horzne pomalu :(

L ogfile of random's system information tool 1.10 (written by random/random)
Run by Uzivatel at 2015-03-02 20:25:08
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 105 GB (69%) free of 153 GB
Total RAM: 1977 MB (63% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:25:25, on 2.3.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17631)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\PLFSetI.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Uzivatel\Desktop\RSIT.exe
C:\Program Files\trend micro\Uzivatel.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: O2FLASH - O2Micro International - C:\Windows\system32\DRIVERS\o2flash.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 5611 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\5v2tiqa9.default

prefs.js - "browser.startup.homepage" - "www.seznam.cz"

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.305 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.25.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.25.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll [2014-11-23 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-11-23 172968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-09-02 135168]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-09-02 167424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-09-02 144384]
"PLFSetI"=C:\Windows\PLFSetI.exe [2009-11-20 200704]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2014-11-23 7703072]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2014-11-23 1565992]
"LManager"=C:\Program Files\Launch Manager\LManager.exe [2014-11-23 1130504]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-01-27 5227112]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-09-02 217088]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-03-02 20:20:20 ----D---- C:\_OTM
2015-03-02 18:55:21 ----D---- C:\AdwCleaner
2015-03-02 18:52:15 ----D---- C:\Program Files\Google
2015-03-02 18:18:17 ----D---- C:\Program Files\trend micro
2015-03-02 18:18:16 ----D---- C:\rsit
2015-03-01 11:29:05 ----D---- C:\ProgramData\Alex Gordon
2015-03-01 11:28:20 ----D---- C:\Program Files\Alex Kočičák
2015-02-28 10:44:06 ----D---- C:\ProgramData\PopCap Games
2015-02-24 12:08:48 ----SHD---- C:\found.001
2015-02-17 19:48:37 ----A---- C:\Windows\system32\powertracker.dll
2015-02-17 19:48:37 ----A---- C:\Windows\system32\perftrack.dll
2015-02-17 19:48:36 ----A---- C:\Windows\system32\wdi.dll
2015-02-14 17:14:18 ----D---- C:\ProgramData\{a1d49146-bf3d-72cd-a1d4-49146bf3451a}
2015-02-14 17:11:36 ----D---- C:\ProgramData\{64302c42-57aa-0147-6430-02c4257ab109}
2015-02-13 15:20:31 ----A---- C:\Windows\system32\jscript9diag.dll
2015-02-13 15:20:30 ----A---- C:\Windows\system32\jscript9.dll
2015-02-13 15:10:55 ----D---- C:\ea988f9945702573b63ba3
2015-02-11 14:35:18 ----A---- C:\Windows\system32\win32k.sys
2015-02-11 14:35:13 ----A---- C:\Windows\system32\lsasrv.dll
2015-02-11 14:35:13 ----A---- C:\Windows\system32\drivers\cng.sys
2015-02-11 14:35:13 ----A---- C:\Windows\system32\adtschema.dll
2015-02-11 14:35:12 ----A---- C:\Windows\system32\sspisrv.dll
2015-02-11 14:35:12 ----A---- C:\Windows\system32\sspicli.dll
2015-02-11 14:35:12 ----A---- C:\Windows\system32\secur32.dll
2015-02-11 14:35:12 ----A---- C:\Windows\system32\msobjs.dll
2015-02-11 14:35:12 ----A---- C:\Windows\system32\lsass.exe
2015-02-11 14:35:12 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-02-11 14:35:12 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-02-11 14:35:12 ----A---- C:\Windows\system32\auditpol.exe
2015-02-11 14:35:11 ----A---- C:\Windows\system32\msaudite.dll
2015-02-11 14:34:30 ----A---- C:\Windows\system32\ntkrnlpa.exe
2015-02-11 14:34:29 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-02-11 14:34:16 ----A---- C:\Windows\system32\oleaut32.dll
2015-02-11 14:34:14 ----A---- C:\Windows\system32\appraiser.dll
2015-02-11 14:34:13 ----A---- C:\Windows\system32\generaltel.dll
2015-02-11 14:34:12 ----A---- C:\Windows\system32\invagent.dll
2015-02-11 14:34:12 ----A---- C:\Windows\system32\aeinv.dll
2015-02-11 14:34:11 ----A---- C:\Windows\system32\devinv.dll
2015-02-11 14:34:11 ----A---- C:\Windows\system32\aitstatic.exe
2015-02-11 14:34:09 ----A---- C:\Windows\system32\aepdu.dll
2015-02-11 14:34:08 ----A---- C:\Windows\system32\aepic.dll
2015-02-11 14:34:02 ----A---- C:\Windows\system32\schannel.dll
2015-02-11 14:34:01 ----A---- C:\Windows\system32\wdigest.dll
2015-02-11 14:34:01 ----A---- C:\Windows\system32\TSpkg.dll
2015-02-11 14:34:01 ----A---- C:\Windows\system32\ncrypt.dll
2015-02-11 14:34:01 ----A---- C:\Windows\system32\msv1_0.dll
2015-02-11 14:34:01 ----A---- C:\Windows\system32\kerberos.dll
2015-02-11 14:34:00 ----A---- C:\Windows\system32\credssp.dll
2015-02-11 14:33:47 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-02-11 14:33:47 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-02-11 14:33:47 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-02-11 14:33:46 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-02-11 14:33:46 ----A---- C:\Windows\system32\iernonce.dll
2015-02-11 14:33:46 ----A---- C:\Windows\system32\ie4uinit.exe
2015-02-11 14:33:45 ----A---- C:\Windows\system32\urlmon.dll
2015-02-11 14:33:45 ----A---- C:\Windows\system32\jsproxy.dll
2015-02-11 14:33:45 ----A---- C:\Windows\system32\ieUnatt.exe
2015-02-11 14:33:45 ----A---- C:\Windows\system32\iedkcs32.dll
2015-02-11 14:33:44 ----A---- C:\Windows\system32\ieapfltr.dll
2015-02-11 14:33:44 ----A---- C:\Windows\system32\dxtmsft.dll
2015-02-11 14:33:43 ----A---- C:\Windows\system32\msfeeds.dll
2015-02-11 14:33:41 ----A---- C:\Windows\system32\msrating.dll
2015-02-11 14:33:40 ----A---- C:\Windows\system32\iesetup.dll
2015-02-11 14:33:39 ----A---- C:\Windows\system32\wininet.dll
2015-02-11 14:33:39 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-02-11 14:33:37 ----A---- C:\Windows\system32\dxtrans.dll
2015-02-11 14:33:36 ----A---- C:\Windows\system32\ieui.dll
2015-02-11 14:33:35 ----A---- C:\Windows\system32\ieframe.dll
2015-02-11 14:33:33 ----A---- C:\Windows\system32\mshtmled.dll
2015-02-11 14:33:32 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-02-11 14:33:31 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-02-11 14:33:29 ----A---- C:\Windows\system32\iertutil.dll
2015-02-11 14:33:25 ----A---- C:\Windows\system32\mshtml.dll
2015-02-11 14:33:23 ----A---- C:\Windows\system32\vbscript.dll
2015-02-11 14:32:54 ----A---- C:\Windows\system32\wintrust.dll
2015-02-11 14:32:54 ----A---- C:\Windows\system32\cryptsvc.dll
2015-02-11 14:32:54 ----A---- C:\Windows\system32\crypt32.dll
2015-02-11 14:32:48 ----A---- C:\Windows\system32\scesrv.dll
2015-02-11 14:32:46 ----A---- C:\Windows\system32\WindowsCodecs.dll

======List of files/folders modified in the last 1 month======

2015-03-02 20:24:26 ----D---- C:\Windows\Temp
2015-03-02 20:22:49 ----D---- C:\Windows\system32\config
2015-03-02 20:20:21 ----D---- C:\Windows\Tasks
2015-03-02 18:58:04 ----RD---- C:\Program Files
2015-03-02 18:58:04 ----HD---- C:\ProgramData
2015-03-02 18:57:03 ----SHD---- C:\Windows\Installer
2015-03-02 18:52:20 ----D---- C:\Windows\system32\Tasks
2015-03-02 18:08:37 ----SD---- C:\ProgramData\Microsoft
2015-03-02 17:40:51 ----D---- C:\Windows\system32\catroot2
2015-03-02 17:08:24 ----D---- C:\Windows\Prefetch
2015-02-28 21:03:31 ----D---- C:\Windows\system32\NDF
2015-02-28 15:09:36 ----D---- C:\Counter-Strike 1.6
2015-02-28 10:45:47 ----D---- C:\Windows\System32
2015-02-28 10:45:47 ----D---- C:\Windows\inf
2015-02-28 10:45:47 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-02-26 09:25:47 ----D---- C:\Windows\winsxs
2015-02-19 08:58:23 ----D---- C:\Users\Uzivatel\AppData\Roaming\.minecraft
2015-02-18 15:04:55 ----D---- C:\Windows\tracing
2015-02-17 16:58:08 ----SHD---- C:\System Volume Information
2015-02-15 14:08:09 ----D---- C:\Windows\rescache
2015-02-14 08:03:22 ----D---- C:\Windows\system32\en-US
2015-02-13 15:13:29 ----D---- C:\Windows\system32\cs-CZ
2015-02-13 15:13:28 ----D---- C:\Windows\system32\drivers
2015-02-12 14:54:30 ----SD---- C:\Windows\system32\CompatTel
2015-02-12 14:54:29 ----D---- C:\Windows\system32\appraiser
2015-02-12 14:54:28 ----D---- C:\Program Files\Internet Explorer
2015-02-12 14:38:50 ----D---- C:\Windows\system32\MRT
2015-02-12 14:34:51 ----A---- C:\Windows\system32\MRT.exe
2015-02-11 14:32:33 ----D---- C:\Windows\system32\catroot
2015-02-08 16:18:32 ----A---- C:\Users\Uzivatel\AppData\Roaming\burnaware.ini
2015-02-06 14:37:24 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2015-02-04 20:32:00 ----D---- C:\Windows\system32\wdi
2015-02-03 12:08:06 ----D---- C:\Windows\Microsoft.NET
2015-02-03 12:07:51 ----RSD---- C:\Windows\assembly

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-11-25 49944]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-11-25 206248]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2014-11-25 81768]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2014-11-25 787800]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2014-11-25 423784]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2014-11-25 24184]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2014-11-25 70384]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2014-11-25 91496]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\XAudio32.sys [2014-11-23 8704]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2009-10-05 1221632]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2014-11-23 21000]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2014-11-23 980992]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2014-11-23 207360]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-09-02 5946368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2014-11-23 2745760]
R3 O2MDRDR;O2MDRDR; C:\Windows\system32\DRIVERS\o2media.sys [2014-11-23 52128]
R3 O2SDRDR;O2SDRDR; C:\Windows\system32\DRIVERS\o2sd.sys [2014-11-23 42144]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2014-11-23 229040]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2014-11-23 661504]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2014-11-23 86056]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2014-11-23 108072]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2014-11-23 29472]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2014-11-23 18472]
S3 EagleXNt;EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys []
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmb.sys [2011-08-17 18176]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 84992]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
S3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
S3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-11-25 50344]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-10-02 595232]
R2 HsfXAudioService;HsfXAudioService; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 O2FLASH;O2FLASH; C:\Windows\system32\DRIVERS\o2flash.exe [2014-11-23 65536]
R2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2014-04-03 315008]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-03-02 107848]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-06 267440]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-03-02 107848]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-01-12 102912]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2015-01-29 114800]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2014-04-11 45744]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]

-----------------EOF-----------------

Re: Viry v NTB

Napsal: 02 bře 2015 21:03
od Rudy
Smazáno. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. Nastala nějaká změna?

Re: Viry v NTB

Napsal: 02 bře 2015 21:13
od Jarin
Tak pri prohlizeni internetu je Avast uz potichu :) dekuji. Ale o to je NTB pomalejsi O.o Cim by to mohlo byt nevite ? CC jsem uz pouzil..

Re: Viry v NTB

Napsal: 02 bře 2015 21:55
od Rudy
Zkuste ještě 2 věci:

1. Udělejte kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.
2. Defragmentujte disk.

Re: Viry v NTB

Napsal: 02 bře 2015 22:16
od Jarin
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 2.3.2015
Scan Time: 22:02:43
Logfile: mbM.txt
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2015.03.02.06
Rootkit Database: v2015.02.25.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Uzivatel

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 303124
Time Elapsed: 9 min, 11 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 2
PUP.Optional.MultiPlug.A, C:\ProgramData\{64302c42-57aa-0147-6430-02c4257ab109}\Metin2Mod_PL_11022015.exe, , [bb036fd135550a2c949d919515edb64a],
PUP.Optional.ResultHunters.A, C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\5v2tiqa9.default\prefs.js, Good: (), Bad: (), ,[d7e766da771351e598ef060a7e88cb35]

Physical Sectors: 0
(No malicious items detected)


(end)

Defragmentace taky skoncila.

Re: Viry v NTB

Napsal: 02 bře 2015 22:28
od Rudy
Vše, co MBAM nalezl, smažte.

Re: Viry v NTB

Napsal: 02 bře 2015 22:32
od Jarin
Vse porad stejny :) Jestli uz Vas nic nenapada tak nechci zdrzovat. Moc dekuju za pomoct

Re: Viry v NTB

Napsal: 02 bře 2015 22:35
od Rudy
Ještě zkuste ComboFix:
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware.

Re: Viry v NTB

Napsal: 02 bře 2015 22:58
od Jarin
taak.. doufam ze vse jsem provedl jak bylo psano :-) cetl jsem tady ze ComboFix je velke zvire.. :-D

ComboFix 15-03-01.01 - Uzivatel 02.03.2015 22:46:02.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.1977.1255 [GMT 1:00]
Spuštěný z: c:\users\Uzivatel\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2015-02-02 do 2015-03-02 )))))))))))))))))))))))))))))))
.
.
2015-03-02 21:53 . 2015-03-02 21:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-03-02 21:02 . 2015-03-02 21:02 114904 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-03-02 21:00 . 2015-03-02 21:00 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2015-03-02 21:00 . 2015-03-02 21:00 -------- d-----w- c:\programdata\Malwarebytes
2015-03-02 21:00 . 2014-11-21 05:14 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
2015-03-02 21:00 . 2014-11-21 05:14 75480 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-03-02 21:00 . 2014-11-21 05:14 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2015-03-02 19:56 . 2015-03-02 19:56 -------- d-----w- c:\program files\CCleaner
2015-03-02 17:55 . 2015-03-02 17:58 -------- d-----w- C:\AdwCleaner
2015-03-02 17:52 . 2015-03-02 17:52 -------- d-----w- c:\program files\Google
2015-03-02 17:52 . 2015-03-02 17:53 -------- d-----w- c:\users\Uzivatel\AppData\Local\Google
2015-03-02 17:18 . 2015-03-02 19:25 -------- d-----w- c:\program files\trend micro
2015-03-01 10:29 . 2015-03-01 10:29 -------- d-----w- c:\programdata\Alex Gordon
2015-03-01 10:28 . 2015-03-01 10:28 -------- d-----w- c:\program files\Alex Kočičák
2015-03-01 10:27 . 2015-03-02 21:50 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{64AF2F74-B43E-4CF4-A1A3-686F688B5660}\offreg.dll
2015-02-28 09:44 . 2015-02-28 10:22 -------- d-----w- c:\programdata\PopCap Games
2015-02-27 20:00 . 2015-01-29 09:49 9041640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{64AF2F74-B43E-4CF4-A1A3-686F688B5660}\mpengine.dll
2015-02-24 11:08 . 2015-02-24 11:08 -------- d-----w- C:\found.001
2015-02-17 18:48 . 2015-01-09 02:48 635904 ----a-w- c:\windows\system32\perftrack.dll
2015-02-17 18:48 . 2015-01-09 02:48 27136 ----a-w- c:\windows\system32\powertracker.dll
2015-02-17 18:48 . 2015-01-09 02:48 76800 ----a-w- c:\windows\system32\wdi.dll
2015-02-14 16:14 . 2015-03-02 19:20 -------- d-----w- c:\programdata\{a1d49146-bf3d-72cd-a1d4-49146bf3451a}
2015-02-14 16:11 . 2015-03-02 21:31 -------- d-----w- c:\programdata\{64302c42-57aa-0147-6430-02c4257ab109}
2015-02-13 14:20 . 2015-01-23 03:43 620032 ----a-w- c:\windows\system32\jscript9diag.dll
2015-02-13 14:20 . 2015-01-23 03:17 4300800 ----a-w- c:\windows\system32\jscript9.dll
2015-02-13 14:10 . 2015-02-13 14:10 -------- d-----w- C:\ea988f9945702573b63ba3
2015-02-11 13:34 . 2015-01-14 05:44 3972544 ----a-w- c:\windows\system32\ntkrnlpa.exe
2015-02-11 13:33 . 2015-01-12 02:13 37888 ----a-w- c:\program files\Internet Explorer\DiagnosticsHub_is.dll
2015-02-11 13:32 . 2014-12-12 05:07 1174528 ----a-w- c:\windows\system32\crypt32.dll
2015-02-11 13:32 . 2014-07-07 01:40 179200 ----a-w- c:\windows\system32\wintrust.dll
2015-02-11 13:32 . 2014-07-07 01:40 143872 ----a-w- c:\windows\system32\cryptsvc.dll
2015-02-11 13:32 . 2014-12-08 02:46 308224 ----a-w- c:\windows\system32\scesrv.dll
2015-02-11 13:32 . 2015-01-13 02:49 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
2015-02-01 20:13 . 2015-02-19 07:58 -------- d-----w- c:\users\Uzivatel\AppData\Roaming\.minecraft
2015-02-01 19:07 . 2015-02-02 18:56 -------- d-----w- c:\program files\GameforgeLive
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-02-06 13:37 . 2014-11-23 16:35 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-02-06 13:37 . 2014-11-23 16:35 701616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-12-22 23:50 . 2014-11-22 15:55 249488 ------w- c:\windows\system32\MpSigStub.exe
2014-12-19 02:43 . 2015-01-14 14:29 164864 ----a-w- c:\windows\system32\profsvc.dll
2014-12-19 01:34 . 2015-01-14 14:29 116224 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2014-12-11 17:47 . 2015-01-14 14:29 74240 ----a-w- c:\windows\system32\TSWbPrxy.exe
2014-12-06 03:50 . 2015-01-14 14:29 242688 ----a-w- c:\windows\system32\nlasvc.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-11-25 21:54 723976 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-02 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-02 167424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-02 144384]
"PLFSetI"="c:\windows\PLFSetI.exe" [2009-11-20 200704]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2014-11-23 7703072]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2014-11-23 1565992]
"LManager"="c:\program files\Launch Manager\LManager.exe" [2014-11-23 1130504]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-01-27 5227112]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2014-11-22 280576]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-10-2 795936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2014-11-25 91496]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2014-04-03 315008]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2014-11-23 29472]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2015-01-12 102912]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2014-11-25 787800]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2014-11-25 423784]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2014-11-25 24184]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-11-25 70384]
S2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe [2009-07-14 20992]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [2015-03-02 114904]
S3 O2MDRDR;O2MDRDR;c:\windows\system32\DRIVERS\o2media.sys [2014-11-23 52128]
S3 O2SDRDR;O2SDRDR;c:\windows\system32\DRIVERS\o2sd.sys [2014-11-23 42144]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - MBAMSWISSARMY
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HsfXAudioService REG_MULTI_SZ HsfXAudioService
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-03-02 17:52 1084744 ----a-w- c:\program files\Google\Chrome\Application\40.0.2214.115\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2015-03-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-23 13:37]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\5v2tiqa9.default\
FF - prefs.js: browser.startup.homepage - www.seznam.cz
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(3868)
c:\program files\WIDCOMM\Bluetooth Software\btmmhook.dll
.
Celkový čas: 2015-03-02 22:55:51
ComboFix-quarantined-files.txt 2015-03-02 21:55
.
Před spuštěním: Volných bajtů: 110 033 248 256
Po spuštění: Volných bajtů: 109 942 431 744
.
- - End Of File - - 38A569AB7F9DD2F9C05FF49C23120AE2
A36C5E4F47E84449FF07ED3517B43A31