Stránka 1 z 1

Napadl mě zatrcenej čínskej trojan, hold nevím co s ním.

Napsal: 04 čer 2016 06:06
od risuslav
Zdravím asi před týdnem mi počítač napadl čínský trojský kůň. Skoušel jsem dva antiviry které mi psali že vir odinstalovali ale stále se tu zobrazuje a vypadá jakoby se naštval. Strašně prosím o pomoc. Zde přikládám log z dds a attach boužel však nevím co je to RSIT.

DDS:

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 11.0.9600.18315 BrowserJavaVersion: 11.25.2
Run by Cimburovi at 17:48:21 on 2016-06-03
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.2047.688 [GMT 2:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {768124D7-F5F7-6D2F-DDC2-94DFA4017C95}
SP: Microsoft Security Essentials *Enabled/Updated* {CDE0C533-D3CD-62A1-E772-AFADDF863628}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\ProgramData\DCHP\DCHP.exe
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Program Files\Tencent\QQPCMgr\11.6.17645.227\QQPCRtp.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Google\Update\1.3.30.3\GoogleCrashHandler.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe
C:\Program Files\Tencent\QQPCMgr\11.6.17645.227\QQPCTray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\GWX\GWX.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Users\Cimburovi\AppData\Local\Yandex\Elements\elements.exe\8.14.0.1058\elements.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\McAfee Security Scan\3.11.309\SSScheduler.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\GIGABYTE\Gamer HUD Lite\HUD.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Steam\bin\steamwebhelper.exe
C:\Program Files\Common Files\Steam\SteamService.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Tencent\QQPCMgr\11.6.17645.227\QMChExt.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\program files\common files\tencent\qqdownload\130\tencentdl.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5WtjQ2MOO5swOltR4niFzQvOPtFErQzMG5nsHU1JfbtL5iHNop-UpjQPevyxlaCcUfzF4luqgGD4mSzqoGPG4ovQxTRgMSJxJrHjp4i7gv5G8fIMPur94ggyTFgM41sdexECgnqoiJnejCtBNBFOFbMhUyhhR9qo
uSearch Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5WtjQ2MOO5swOltR4niFzQvOPtFErQzMG5nsHU1JfbtL5iHNop-UpjQPevyxlaCcUfzJp6jUV8Xp2NwRrlKu8NiIiFmuBtSs18ixEQsvGyiUxYmj9CgiZhzhQ9bCrHug7y0vmOan_B4G6WIVwsTKntQjR4pP32Q0&q={searchTerms}
uSearch Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5WtjQ2MOO5swOltR4niFzQvOPtFErQzMG5nsHU1JfbtL5iHNop-UpjQPevyxlaCcUfzJp6jUV8Xp2NwRrlKu8NiIiFmuBtSs18ixEQsvGyiUxYmj9CgiZhzhQ9bCrHug7y0vmOan_B4G6WIVwsTKntQjR4pP32Q0&q={searchTerms}
mStart Page = hxxp://www.602.com?uid=gjss&suid=1
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre1.8.0_25\bin\ssv.dll
BHO: Visual Bookmarks: {D5FEC983-01DB-414A-9456-AF95AC9ED7B5} - c:\program files\yandex\fastdial\fastdialhost.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre1.8.0_25\bin\jp2ssv.dll
TB: ???????? ???????: {91397D20-1446-11D4-8AF4-0040CA1127B6} - c:\program files\yandex\elements\bartabhost.dll
TB: ???????? ???????: {91397D20-1446-11D4-8AF4-0040CA1127B6} - c:\program files\yandex\elements\bartabhost.dll
uRun: [DAEMON Tools Pro Agent] "c:\program files\daemon tools pro\DTAgent.exe" -autorun
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun
uRun: [YandexElements] "c:\users\cimburovi\appdata\local\yandex\elements\elements.exe\8.14.0.1058\elements.exe" /auto
uRun: [Steam] "c:\program files\steam\steam.exe" -silent
uRun: [cz.seznam.software.autoupdate] "c:\users\cimburovi\appdata\roaming\seznam.cz\szninstall.exe" -c
uRun: [CCleaner Monitoring] "c:\program files\ccleaner\CCleaner.exe" /MONITOR
mRun: [RTHDVCPL] "c:\program files\realtek\audio\hda\RtHDVCpl.exe" -s
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "c:\program files\amd avt\bin\kdbsync.exe" aml
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [seznam-listicka-distribuce] "c:\program files\seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
mRun: [ QQPCTray] "c:\program files\tencent\qqpcmgr\11.6.17645.227\QQPCTray.exe" /regrun
dRunOnce: [SPReview] "c:\windows\system32\spreview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
StartupFolder: c:\users\cimbur~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\gigaby~1.lnk - c:\program files\gigabyte\gamer hud lite\HUD.exe
StartupFolder: c:\users\cimbur~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\vezyob~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\3.11.309\SSScheduler.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:221
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
TCP: NameServer = 10.3.0.18
TCP: Interfaces\{3C14C288-0D88-4908-B6A0-01BFAC0CDAA1} : DHCPNameServer = 10.3.0.18
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
AppInit_DLLs= c:\programdata\appxeetouq\Coffix.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\50.0.2661.102\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
Hosts: 0.0.0.1 mssplus.mcafee.com
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\cimburovi\appdata\roaming\mozilla\firefox\profiles\0zu8oym0.default-1443108845753\
FF - prefs.js: browser.startup.homepage - c:\\programdata\\appxeetouqs\\ff.HP
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.30.3\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre1.8.0_25\bin\dtplugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre1.8.0_25\bin\plugin2\npjp2.dll
FF - plugin: c:\programdata\happycloud\application\npHappyCloudPlugin.dll
FF - plugin: c:\users\cimburovi\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_21_0_0_242.dll
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2015-11-13 253704]
R0 TSFLTMGR;TSFLTMGR;c:\windows\system32\drivers\TsFltMgr.sys [2016-6-1 135640]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2014-10-11 242240]
R1 QMIEProtect;QMIEProtect;c:\program files\tencent\qqpcmgr\11.6.17645.227\QMIEProtect.sys [2016-6-1 50488]
R1 QMUdisk;QMUdisk;c:\program files\tencent\qqpcmgr\11.6.17645.227\QMUdisk.sys [2016-6-1 104440]
R1 softaal;softaal;c:\program files\tencent\qqpcmgr\11.6.17645.227\SoftAAL.sys [2016-6-1 43640]
R1 SRepairDrv;SRepairDrv;c:\program files\tencent\qqpcmgr\SRepairDrv [2016-6-3 176376]
R1 TAOKernelDriver;Tencent Auto Optimize Platform.;c:\windows\system32\drivers\TAOKernel.sys [2016-6-3 107512]
R1 TFsFlt;TFsFlt;c:\windows\system32\drivers\TFsFlt.sys [2016-6-1 157432]
R1 TSDefenseBt;TSDefenseBt;c:\windows\system32\drivers\TSDefenseBt.sys [2016-6-1 14008]
R1 Tsksp;Tsksp;c:\program files\tencent\qqpcmgr\11.6.17645.227\TSKsp.sys [2016-6-1 218808]
R1 TSSysKit;TSSysKit;c:\program files\tencent\qqpcmgr\11.6.17645.227\TSSysKit.sys [2016-6-1 109560]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2014-10-12 217088]
R2 AMD FUEL Service;AMD FUEL Service;c:\program files\ati technologies\ati.ace\fuel\Fuel.Service.exe [2013-4-29 291840]
R2 DCHP;DCHP;c:\programdata\\dchp\\dchp.exe -f "c:\programdata\\dchp\\dchp.dat" -l -a --> c:\programdata\\dchp\\dchp.exe -f c:\programdata\\dchp\\DCHP.dat [?]
R2 DiagTrack;Diagnostics Tracking Service;c:\windows\system32\svchost.exe -k utcsvc [2009-7-14 20992]
R2 QQPCRtp;QQPCMgr RTP Service;c:\program files\tencent\qqpcmgr\11.6.17645.227\QQPCRTP.exe [2016-6-1 311768]
R2 QQSysMon;QQSysMon;c:\program files\tencent\qqpcmgr\11.6.17645.227\QQSysMon.sys [2016-6-1 118776]
R2 TsNetHlp;TsNetHlp.sys;c:\program files\tencent\qqpcmgr\11.6.17645.227\TsNetHlp.sys [2016-6-1 51192]
R3 amdiox86;AMD IO Driver;c:\windows\system32\drivers\amdiox86.sys [2014-10-12 37944]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2014-10-12 86656]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2014-7-17 104664]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\microsoft security client\NisSrv.exe [2016-1-29 292816]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2014-10-12 719064]
R3 TAOAccelerator;Tencent TAOAccelerator driver.;c:\windows\system32\drivers\TAOAccelerator.sys [2016-6-3 124600]
R3 TS888;TS888;c:\program files\tencent\qqpcmgr\11.6.17645.227\TS888.sys [2016-6-2 39928]
S2 AppxeetouQ;AppxeetouQ;c:\programdata\\appxeetouq\\appxeetouq.exe -f "c:\programdata\\appxeetouq\\appxeetouq.dat" -l -a --> c:\programdata\\appxeetouq\\appxeetouq.exe -f c:\programdata\\appxeetouq\\AppxeetouQ.dat [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2015-11-5 105144]
S2 QQRepairfaa;QQRepairfaa;"c:\program files\tencent\qqpcmgr\qqrepairfaa" --> c:\program files\tencent\qqpcmgr\QQRepairfaa [?]
S2 QQRepairFixSVC;QQRepairFixSVC;c:\program files\tencent\qqpcmgr\QQRepairFixSVC [2016-6-3 147176]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2014-12-11 315496]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 EasyAntiCheat;EasyAntiCheat;c:\windows\system32\EasyAntiCheat.exe [2014-12-9 182304]
S3 EsgScanner;EsgScanner;c:\windows\system32\drivers\EsgScanner.sys [2016-5-26 19984]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\ieetwcollector.exe [2016-5-11 102912]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\3.11.309\McCHSvc.exe [2016-3-11 239880]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2015-8-5 15872]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2014-10-12 52224]
.
=============== Created Last 30 ================
.
2016-06-03 11:57:52 107512 ----a-w- c:\windows\system32\drivers\TAOKernel.sys
2016-06-03 11:57:49 124600 ----a-w- c:\windows\system32\drivers\TAOAccelerator.sys
2016-06-03 11:57:40 39928 ----a-w- c:\windows\system32\drivers\TS888.sys
2016-06-03 11:55:30 62576 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{50f7d4a0-d479-443e-9239-5616305274ba}\offreg.892.dll
2016-06-03 11:55:27 -------- d-----w- c:\program files\common files\Tencent
2016-06-03 11:53:55 -------- d-----w- c:\programdata\TXQMPC
2016-06-02 13:33:29 -------- d-----w- C:\AdwCleaner
2016-06-02 13:33:04 -------- d-----w- C:\QMDownload
2016-06-02 12:56:41 62576 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{50f7d4a0-d479-443e-9239-5616305274ba}\offreg.1080.dll
2016-06-02 12:55:13 9464104 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{50f7d4a0-d479-443e-9239-5616305274ba}\mpengine.dll
2016-06-01 17:06:00 14008 ------w- c:\windows\system32\drivers\TSDefenseBt.sys
2016-06-01 17:05:01 157432 ------w- c:\windows\system32\drivers\TFsFlt.sys
2016-06-01 17:04:55 135640 ------w- c:\windows\system32\drivers\TsFltMgr.sys
2016-06-01 12:29:50 9464104 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2016-05-30 13:31:04 -------- d-----w- C:\GOG Games
2016-05-28 06:10:20 -------- d-----w- c:\programdata\AppxeetouQs
2016-05-28 06:09:59 -------- d-----w- c:\programdata\AppxeetouQ
2016-05-28 05:39:07 -------- d-----w- c:\program files\CCleaner
2016-05-26 20:33:49 19984 ----a-w- c:\windows\system32\drivers\EsgScanner.sys
2016-05-22 16:47:26 915640 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{16fee940-8987-4de5-90bb-75bd4edd868d}\gapaengine.dll
2016-05-19 08:41:13 -------- d-----w- C:\Games
2016-05-11 13:12:44 306176 ----a-w- c:\windows\system32\gdi32.dll
2016-05-11 13:11:42 730344 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2016-05-11 13:11:42 218856 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2016-05-11 13:11:42 107520 ----a-w- c:\windows\system32\cdd.dll
.
==================== Find3M ====================
.
2016-06-01 17:02:49 81400 ------w- c:\windows\system32\TSSK.sys
2016-05-13 13:41:30 797376 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2016-05-13 13:41:30 142528 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2016-04-23 04:20:51 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2016-04-23 04:20:39 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2016-04-23 04:08:47 62464 ----a-w- c:\windows\system32\iesetup.dll
2016-04-23 04:08:47 497152 ----a-w- c:\windows\system32\vbscript.dll
2016-04-23 04:08:09 47616 ----a-w- c:\windows\system32\ieetwproxystub.dll
2016-04-23 04:07:58 341504 ----a-w- c:\windows\system32\html.iec
2016-04-23 04:07:05 64000 ----a-w- c:\windows\system32\MshtmlDac.dll
2016-04-23 03:58:39 102912 ----a-w- c:\windows\system32\ieetwcollector.exe
2016-04-23 03:58:33 115712 ----a-w- c:\windows\system32\ieUnatt.exe
2016-04-23 03:58:14 620032 ----a-w- c:\windows\system32\jscript9diag.dll
2016-04-23 03:53:14 667648 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2016-04-23 03:45:54 60416 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2016-04-23 03:36:58 4611072 ----a-w- c:\windows\system32\jscript9.dll
2016-04-23 03:30:55 2056192 ----a-w- c:\windows\system32\inetcpl.cpl
2016-04-23 03:30:34 1155072 ----a-w- c:\windows\system32\mshtmlmedia.dll
2016-04-23 03:12:38 2121216 ----a-w- c:\windows\system32\wininet.dll
2016-04-22 07:57:44 374944 ------w- c:\windows\system32\MpSigStub.exe
2016-04-14 13:49:13 603648 ----a-w- c:\windows\system32\d3d10level9.dll
2016-04-11 18:14:17 848437 ----a-w- c:\users\cimburovi\appdata\roaming\Unitough.bin
2016-04-11 18:13:53 980992 ----a-w- c:\users\cimburovi\appdata\roaming\Canlight.exe
2016-04-09 06:59:48 3998952 ----a-w- c:\windows\system32\ntkrnlpa.exe
2016-04-09 06:59:48 3943144 ----a-w- c:\windows\system32\ntoskrnl.exe
2016-04-09 06:59:46 67304 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2016-04-09 06:59:46 137960 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2016-04-09 06:57:34 1310528 ----a-w- c:\windows\system32\ntdll.dll
2016-04-09 05:42:59 50688 ----a-w- c:\windows\system32\drivers\appid.sys
2016-04-09 05:42:46 97792 ----a-w- c:\windows\system32\appidpolicyconverter.exe
2016-04-09 05:42:45 16896 ----a-w- c:\windows\system32\appidcertstorecheck.exe
2016-04-09 05:42:44 29696 ----a-w- c:\windows\system32\appidsvc.dll
2016-04-09 05:42:19 50176 ----a-w- c:\windows\system32\auditpol.exe
2016-04-09 05:40:53 2397696 ----a-w- c:\windows\system32\win32k.sys
2016-04-09 05:40:03 262656 ----a-w- c:\windows\system32\rstrui.exe
2016-04-09 05:38:15 226304 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2016-04-09 05:38:12 98304 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2016-04-09 05:38:09 124416 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2016-04-09 05:37:37 36352 ----a-w- c:\windows\system32\cryptbase.dll
2016-04-09 05:37:37 22016 ----a-w- c:\windows\system32\lsass.exe
2016-04-09 05:37:36 15872 ----a-w- c:\windows\system32\sspisrv.dll
2016-04-09 05:37:34 69632 ----a-w- c:\windows\system32\smss.exe
2016-04-09 04:20:04 1230848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2016-04-06 10:36:54 19968 ----a-w- c:\windows\system32\jnwmon.dll
2016-04-06 10:36:50 22528 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\jnwppr.dll
2016-04-04 17:54:23 34024 ----a-w- c:\windows\system32\CompatTelRunner.exe
2016-04-04 17:42:45 957952 ----a-w- c:\windows\system32\aeinv.dll
2016-04-02 13:07:24 1218048 ----a-w- c:\windows\system32\appraiser.dll
2016-03-23 14:02:02 177664 ----a-w- c:\windows\system32\aepic.dll
2016-03-17 22:30:52 171008 ----a-w- c:\windows\system32\winsrv.dll
2016-03-17 22:28:21 1414144 ----a-w- c:\windows\system32\ole32.dll
2016-03-17 22:26:26 294400 ----a-w- c:\windows\system32\KernelBase.dll
2016-03-17 21:36:22 271360 ----a-w- c:\windows\system32\conhost.exe
2016-03-17 21:29:00 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-03-17 21:29:00 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-03-17 21:29:00 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-03-17 21:29:00 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-03-17 18:04:38 65536 ----a-w- c:\windows\system32\acmigration.dll
2016-03-17 18:04:38 560640 ----a-w- c:\windows\system32\generaltel.dll
2016-03-17 18:04:38 424960 ----a-w- c:\windows\system32\devinv.dll
2016-03-17 18:04:38 232960 ----a-w- c:\windows\system32\invagent.dll
2016-03-16 18:28:15 111616 ----a-w- c:\windows\system32\mtxoci.dll
2016-03-16 18:28:12 176128 ----a-w- c:\windows\system32\msorcl32.dll
2016-03-15 23:53:30 60416 ----a-w- c:\windows\system32\samlib.dll
2016-03-15 23:53:30 566272 ----a-w- c:\windows\system32\samsrv.dll
2016-03-09 18:34:49 216064 ----a-w- c:\windows\system32\InkEd.dll
2016-03-06 18:38:52 2048 ----a-w- c:\windows\system32\msxml3r.dll
2016-03-06 18:38:52 1240576 ----a-w- c:\windows\system32\msxml3.dll
.
============= FINISH: 17:50:55,81 ===============

attach:

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 11.10.2014 21:05:26
System Uptime: 3.6.2016 15:09:52 (2 hours ago)
.
Motherboard: MICRO-STAR INTERNATIONAL CO.,LTD | | MS-7388
Processor: AMD Athlon(tm) Dual Core Processor 4850e | CPU 1 | 2500/200mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 455 GiB total, 171,831 GiB free.
D: is CDROM (UDF)
E: is CDROM (CDFS)
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP260: 22.5.2016 18:36:11 - Windows Update
RP261: 27.5.2016 6:17:39 - Windows Update
RP262: 30.5.2016 21:47:34 - Windows Update
.
==== Installed Programs ======================
.
???????? ??????? 8.7 ??? Internet Explorer
????11.6
Adobe AIR
Adobe Flash Player 21 ActiveX
Adobe Flash Player 21 NPAPI
Adobe Reader XI (11.0.16) - Czech
Adobe Refresh Manager
AIMP3
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678)
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669)
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665)
AMD Accelerated Video Transcoding
AMD APP SDK Runtime
AMD Catalyst Install Manager
AMD Drag and Drop Transcoding
AMD Fuel
AMD Media Foundation Decoders
AMD VISION Engine Control Center
Antický Řím 1.0
Apple Mobile Device Support
Apple Software Update
Ashampoo Burning Studio 14
µTorrent
Bonjour
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Localization All
ccc-utility
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
CCleaner
Combined Community Codec Pack 2014-07-13
DAEMON Tools Pro
Defend Your Life
Dobrý farmář
Dobrý náčelník 1.0
DOOM II with Master Levels
FastStone Image Viewer 5.3
Final DOOM
Free Editor
Gameforge Live 2.0.5
Gamer HUD Lite
Google Earth
Google Chrome
Google Update Helper
Gtk# for .Net 2.12.26
Happy Cloud Client
Heroes of Might and Magic V
Heroes of Might and Magic V - Hammers of Fate
Heroes of Might and Magic V - Tribes of the East
Horské dobrodružství - ztraceni v závějích 1.0
iTunes
Java 8 Update 25
Java Auto Updater
Kodu Game Lab
Kouzelnická akademie v1.0
McAfee Security Scan Plus
Medvěd Míša - Cesta kolem světa
Medvěd Míša - Nová dobrodružství
Medvěd Míša - Rybí dobrodružství
Medvěd Míša - Zakletý hrad
Medvěd Míša Ostrovy pokladů
Microsoft .NET Framework 4.6.1
Microsoft .NET Framework 4.6.1 (CSY)
Microsoft .NET Framework 4.6.1 (čeština)
Microsoft Age of Empires II
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (Czech) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (Czech) 2007
Microsoft Office File Validation Add-In
Microsoft Office Groove MUI (Czech) 2007
Microsoft Office InfoPath MUI (Czech) 2007
Microsoft Office OneNote MUI (Czech) 2007
Microsoft Office Outlook MUI (Czech) 2007
Microsoft Office PowerPoint MUI (Czech) 2007
Microsoft Office Proof (Czech) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (German) 2007
Microsoft Office Proof (Slovak) 2007
Microsoft Office Proofing (Czech) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (Czech) 2007
Microsoft Office Shared MUI (Czech) 2007
Microsoft Office Word MUI (Czech) 2007
Microsoft Security Client
Microsoft Security Essentials
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
Microsoft Visual Studio Community 2015 with Update 1
Microsoft Windows Media Video 9 VCM
Microsoft XNA Framework Redistributable 3.1
Microsoft XNA Framework Redistributable 4.0
Mozilla Firefox 46.0.1 (x86 en-US)
Mozilla Maintenance Service
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Notepad++
Podpora aplikací Apple (32bitová)
Průzkumníci - Ztraceni v oceánu 1.0
Realtek Ethernet Controller Driver
Realtek HDMI Audio Driver for ATI
Realtek High Definition Audio Driver
Restaurace Medvěda Míši
Robocraft
SafeFinder
Scratch 2 Offline Editor
Search App by Ask
Security Update for Microsoft .NET Framework 4.6.1 (KB3122661)
Security Update for Microsoft .NET Framework 4.6.1 (KB3127233)
Security Update for Microsoft .NET Framework 4.6.1 (KB3136000)
Security Update for Microsoft .NET Framework 4.6.1 (KB3136000v2)
Security Update for Microsoft .NET Framework 4.6.1 (KB3142037)
Security Update for Microsoft .NET Framework 4.6.1 (KB3143693)
Security Update for Microsoft Office 2007 suites (KB2596650) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596825) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687409) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2825645) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2850022) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2880507) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2880508) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2881067) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2881069) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2956110) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2984938) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2984943) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB3085549) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB3085620) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB3114542) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB3114742) 32-Bit Edition
Security Update for Microsoft Office Access 2007 (KB2596614) 32-Bit Edition
Security Update for Microsoft Office Compatibility Pack Service Pack 3 (KB3114895) 32-Bit Edition
Security Update for Microsoft Office Compatibility Pack Service Pack 3 (KB3115115) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB3114892) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB3114426) 32-Bit Edition
Security Update for Microsoft Office OneNote 2007 (KB2889915) 32-Bit Edition
Security Update for Microsoft Office Outlook 2007 (KB2880510) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB3114429) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2880506) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB3115116) 32-Bit Edition
Seznam Software
Skype™ 7.0
Smajlíci 1.0
Steam
Tasty Planet - Back for Seconds
Tasty Planet: Back for Seconds
Team Fortress 2
Total Commander (Remove or Repair)
Unity (32-bit)
Unity Web Player
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596787) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2965286) 32-Bit Edition
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB3115110) 32-Bit Edition
WinRAR 5.31 (32-bit)
Xara Xtreme 3.2
XML4
XNa Divokém západě
Yandex
.
==== End Of File ===========================

Předem !MOC! díky.

Re: Napadl mě zatrcenej čínskej trojan, hold nevím co s ním.

Napsal: 04 čer 2016 10:24
od Rudy
Zdravím!
Jak je na tom váš oper. systém s legalitou?

Re: Napadl mě zatrcenej čínskej trojan, hold nevím co s ním.

Napsal: 04 čer 2016 16:12
od risuslav
Mám nekoupený windows 7.

Re: Napadl mě zatrcenej čínskej trojan, hold nevím co s ním.

Napsal: 04 čer 2016 16:40
od Rudy
V tom případě lituji, ale toto fórum nelegální oper. systémy neřeší. Viz pravidla: http://forum.viry.cz/viewtopic.php?f=12&t=115512 .