Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Vir policia sr

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
lukitko
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 24 lis 2012 13:45

Vir policia sr

#1 Příspěvek od lukitko »

zdravim neska bloklo priatelke prehliadac z tym ze jej nahodilo stranku policia sr. Vypal som ho cez task list a neviem ci tam niekde neostal spusteny sken esetom... Pridavam log FRST

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-05-2014 02
Ran by Lukitko (administrator) on LUKITKO-PCSTL on 29-05-2014 11:36:00
Running from C:\Users\Lukitko\Desktop
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Windows\SysWOW64\ASDR.exe
() C:\Program Files\ASUS\GamerOSD\ATKFastUserSwitching.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
() C:\Program Files (x86)\EVGA Precision X\EVGAPrecision.exe
(ASUSTeK Inc.) C:\Program Files (x86)\ASUS\SmartDoctor\SmartDoctor.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3520 series\Bin\ScanToPCActivationApp.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\GamerOSD\GamerOSD.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
() C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicatorCom.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
(Mozilla Corporation) C:\Users\Lukitko\AppData\Local\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Users\Lukitko\AppData\Local\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicator.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-14] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1100248 2013-12-10] (NVIDIA Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [4090824 2012-11-16] (ESET)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2439072 2010-05-24] (VIA)
HKLM-x32\...\Run: [ASUSGamerOSD] => C:\Program Files (x86)\ASUS\GamerOSD\GamerOSD.exe [380928 2008-12-22] (ASUSTeK Computer Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1989920 2013-08-26] (Wondershare)
HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech Inc.)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [819984 2014-03-19] (BlueStack Systems, Inc.)
HKLM-x32\...\Run: [StrSystem] => C:\Windows\strs.exe [2603520 2010-10-20] (MM - Soft, s.r.o.)
HKLM\...\Policies\Explorer: [NoSetTaskbar] 0
HKLM\...\Policies\Explorer: [NoChangeStartMenu] 0
HKLM\...\Policies\Explorer: [NoFind] 0
HKLM\...\Policies\Explorer: [NoStartMenuNetworkPlaces] 0
HKLM\...\Policies\Explorer: [NoNetworkConnections] 0
HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\Windows\System32\SPReview\SPReview.exe [301568 2013-04-04] (Microsoft Corporation)
HKU\S-1-5-21-1241430477-585708386-4289414696-1000\...\Run: [uTorrent] => C:\Users\Lukitko\AppData\Roaming\uTorrent\uTorrent.exe [1270352 2014-04-29] (BitTorrent Inc.)
HKU\S-1-5-21-1241430477-585708386-4289414696-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3478336 2012-01-24] (DT Soft Ltd)
HKU\S-1-5-21-1241430477-585708386-4289414696-1000\...\Run: [HP Deskjet 3520 series (NET)] => C:\Program Files\HP\HP Deskjet 3520 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
Startup: C:\Users\Lukitko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Registrácia výrobku.lnk
ShortcutTarget: Logitech . Registrácia výrobku.lnk -> C:\Program Files (x86)\Logitech\Ereg\eReg.exe (Leader Technologies/Logitech)
Startup: C:\Users\Lukitko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Deskjet 3520 series (Síť).lnk
ShortcutTarget: Sledovat výstrahy inkoustu - HP Deskjet 3520 series (Síť).lnk -> C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x841D790CA348CE01
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: No Name - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{E129D1C3-D280-48B3-BC16-3CBCD64FC265}: [NameServer]192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Lukitko\AppData\Roaming\Mozilla\Firefox\Profiles\oydj8qpf.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Garmin Communicator - C:\Users\Lukitko\AppData\Roaming\Mozilla\Firefox\Profiles\oydj8qpf.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2014-01-06]
FF Extension: Adblock Plus - C:\Users\Lukitko\AppData\Roaming\Mozilla\Firefox\Profiles\oydj8qpf.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-05-29]
FF Extension: Greasemonkey - C:\Users\Lukitko\AppData\Roaming\Mozilla\Firefox\Profiles\oydj8qpf.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2013-03-14]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2014-01-22]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2014-01-22]
FF StartMenuInternet: FIREFOX.EXE - C:\Users\Lukitko\AppData\Local\Mozilla Firefox\firefox.exe

Chrome:
=======
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Windows Live? Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1165635.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
CHR Extension: (VLC for YouTube™) - C:\Users\Lukitko\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablmclcliiiegfmpbkfhnhipoejclmel [2013-08-07]
CHR Extension: (Dj Theme HD) - C:\Users\Lukitko\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnnhkdjfcnocecpfjkmkgjmghedinapl [2013-08-07]
CHR Extension: (Peňaženka Google) - C:\Users\Lukitko\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Moja IP adresa) - C:\Users\Lukitko\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfhoeoiodcebkkigjiooibeccnfmmkoe [2014-03-15]

==================== Services (Whitelisted) =================

R2 ASDR; C:\Windows\SysWOW64\ASDR.exe [61440 2009-07-27] ()
S2 ATKFUSService; C:\Windows\system32\ATKFUSService.exe [69632 2008-09-08] (ASUSTeK COMPUTER INC.)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [402192 2014-03-19] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [385808 2014-03-19] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [770832 2014-03-19] (BlueStack Systems, Inc.)
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [913184 2012-11-16] (ESET)
S2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [250712 2013-12-30] (Garmin Ltd or its subsidiaries)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [262144 2006-12-23] (Nero AG)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15129376 2013-12-10] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2013-12-26] ()
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
R3 WinDefend; %ProgramFiles(x86)%\Windows Defender\mpsvc.dll [X]

==================== Drivers (Whitelisted) ====================

R3 asusgsb; C:\Windows\System32\drivers\asusgsb.sys [17792 2008-09-08] (ASUSTeK Computer Inc.)
R3 atkdisplf; C:\Windows\System32\drivers\ATKDispLowFilter.sys [39424 2008-09-08] (ASUSTeK Computer Inc.)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [121616 2014-03-19] (BlueStack Systems)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-07-11] (DT Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [209808 2012-11-16] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [148528 2012-03-14] (ESET)
R1 EIO64; C:\Windows\System32\DRIVERS\EIO64.sys [16384 2012-07-11] (ASUSTeK Computer Inc.)
S1 EIO_XP; C:\Windows\system32\drivers\EIO64_XP.sys [15360 2006-06-14] (ASUSTeK Computer Inc.)
S1 EIO_XP; C:\Windows\SysWOW64\drivers\EIO64_XP.sys [15360 2012-07-11] (ASUSTeK Computer Inc.)
R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [137144 2012-03-14] (ESET)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-05] (NVIDIA Corporation)
R3 RTCore64; C:\Program Files (x86)\EVGA Precision X\RTCore64.sys [15176 2013-07-18] ()
S2 Angelnt; \SystemRoot\System32\Drivers\ANGELNT.SYS [X]
S3 EverestDriver; \??\C:\Users\Lukitko\Desktop\Programy\everest\kerneld.amd64 [X]
S1 SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-05-29 11:36 - 2014-05-29 11:36 - 00017198 _____ () C:\Users\Lukitko\Desktop\FRST.txt
2014-05-29 11:34 - 2014-05-29 11:36 - 00000000 ____D () C:\FRST
2014-05-29 11:34 - 2014-05-29 11:34 - 02066944 _____ (Farbar) C:\Users\Lukitko\Desktop\FRST64.exe
2014-05-29 11:31 - 2014-05-29 11:31 - 00112640 _____ (forum.viry.cz) C:\Users\Lukitko\Desktop\FRSTLauncher.exe
2014-05-29 11:30 - 2014-05-29 11:31 - 00015327 _____ () C:\Users\Lukitko\Desktop\LM.bat
2014-05-29 11:26 - 2014-05-29 11:31 - 00029696 _____ () C:\Users\Lukitko\AppData\Local\MSGBOX.EXE
2014-05-29 11:05 - 2014-05-29 11:06 - 05203612 _____ (Swearware) C:\Users\Lukitko\Downloads\ComboFix.exe
2014-05-29 10:58 - 2014-05-29 11:00 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-29 10:57 - 2014-05-29 10:57 - 00001103 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-29 10:57 - 2014-05-29 10:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-29 10:57 - 2014-05-29 10:57 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-29 10:57 - 2014-05-29 10:57 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-29 10:57 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-29 10:57 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-29 10:57 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-29 10:52 - 2014-05-29 10:52 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Lukitko\Downloads\mbam-setup-2.0.2.1012.exe
2014-05-29 10:45 - 2014-05-29 10:57 - 00000000 ____D () C:\Users\Lukitko\Desktop\RK_Quarantine
2014-05-29 10:44 - 2014-05-29 10:44 - 03943424 _____ () C:\Users\Lukitko\Downloads\RogueKiller.exe
2014-05-29 09:54 - 2014-05-29 09:54 - 00001929 _____ () C:\Users\Lukitko\Desktop\Play Watch Dogs.lnk
2014-05-29 09:34 - 2014-05-29 09:54 - 00000000 ____D () C:\Users\Lukitko\Desktop\Nová složka (11)
2014-05-29 09:34 - 2014-05-29 09:34 - 00000000 ____D () C:\Users\Lukitko\Desktop\WATCHDOGS
2014-05-28 16:11 - 2014-05-28 16:11 - 00709668 _____ () C:\Windows\unins000.exe
2014-05-28 16:11 - 2014-05-28 16:11 - 00007285 _____ () C:\Windows\unins000.dat
2014-05-28 16:11 - 2014-05-28 16:11 - 00000000 __SHD () C:\ProgramData\Strazca systemu
2014-05-28 16:11 - 2010-10-20 11:38 - 02603520 ___SH (MM - Soft, s.r.o.) C:\Windows\strs.exe
2014-05-28 16:11 - 2010-10-05 21:31 - 00016149 ___SH () C:\Windows\Slovak.lng
2014-05-28 16:11 - 2010-10-05 21:31 - 00015722 ___SH () C:\Windows\Czech.lng
2014-05-28 16:11 - 2010-10-05 05:01 - 00076062 ___SH () C:\Windows\strazca_systemu.chm
2014-05-28 16:11 - 2010-03-06 00:35 - 00166400 ___SH (MM - Soft, s.r.o.) C:\Windows\MmWatch.dll
2014-05-28 16:11 - 2009-05-02 15:13 - 00186368 ___SH (MM - Soft, s.r.o.) C:\Windows\ShellExecuteHook.dll
2014-05-28 16:11 - 2009-04-14 10:59 - 00028672 ___SH () C:\Windows\HkMgrMM.dll
2014-05-28 16:11 - 2008-04-30 18:41 - 00926968 ___SH (Eltima Software) C:\Windows\HMFAxstr.dll
2014-05-28 16:11 - 2008-03-04 17:50 - 00044544 ___SH () C:\Windows\Strsysk.dll
2014-05-28 16:11 - 2007-03-21 23:10 - 00024064 ___SH () C:\Windows\Strsys.dll
2014-05-28 16:11 - 2005-07-11 10:27 - 00039226 ___SH () C:\Windows\buzzer.wav
2014-05-27 20:55 - 2014-05-27 22:04 - 08114789 _____ () C:\Users\Lukitko\Desktop\Turecko - Afganistann.pptx
2014-05-27 15:55 - 2014-05-27 16:18 - 00000000 ____D () C:\Users\Lukitko\Desktop\Watch Dogs PC full game ^^nosTEAM^^
2014-05-25 23:14 - 2014-05-25 23:16 - 53607295 _____ () C:\Users\Lukitko\Downloads\ST13 - Devdemo - HemmitV6 Fuel_Truck_V2.zip
2014-05-25 23:10 - 2014-05-25 23:10 - 08739833 _____ () C:\Users\Lukitko\Downloads\MudMatrix-Beta 4.zip
2014-05-25 21:25 - 2014-05-25 23:16 - 159609009 _____ () C:\Users\Lukitko\Downloads\STBuild120713Dev.rar
2014-05-23 18:25 - 2014-05-27 19:05 - 00106496 ___SH () C:\Users\Lukitko\Desktop\Thumbs.db
2014-05-23 13:23 - 2014-05-23 18:37 - 00000000 ____D () C:\Users\Lukitko\Desktop\89
2014-05-22 22:14 - 2014-05-22 22:17 - 00040960 ___SH () C:\Users\Lukitko\Downloads\Thumbs.db
2014-05-22 10:33 - 2014-05-22 10:33 - 00060508 _____ () C:\Users\Lukitko\Desktop\zivotopiss.htm
2014-05-22 10:33 - 2014-05-22 10:33 - 00000000 ____D () C:\Users\Lukitko\Desktop\zivotopiss_soubory
2014-05-22 10:32 - 2014-05-22 10:32 - 00000000 ____D () C:\Users\Lukitko\Downloads\zivotopis(1)_soubory
2014-05-21 19:55 - 2014-05-21 19:55 - 00089600 _____ () C:\Users\Lukitko\Downloads\SS-VL-1r.xls
2014-05-20 19:38 - 2014-05-20 19:38 - 00000483 _____ () C:\Users\Lukitko\Desktop\hardance.txt
2014-05-20 18:00 - 2014-05-20 18:41 - 187118743 _____ () C:\Users\Lukitko\Downloads\BestRemixes_22.09.2013.zip
2014-05-19 15:45 - 2014-05-19 15:46 - 00000000 ____D () C:\Users\Lukitko\Desktop\usb
2014-05-19 15:45 - 2014-05-19 15:45 - 00956976 _____ () C:\Users\Lukitko\Downloads\starsie_vyprac_mo_anj.zip
2014-05-19 15:12 - 2014-05-19 15:12 - 00000000 ____D () C:\Users\Lukitko\Desktop\zivotopis_soubory
2014-05-19 12:40 - 2014-05-29 09:29 - 00002352 _____ () C:\Windows\setupact.log
2014-05-19 12:40 - 2014-05-19 12:40 - 00000000 _____ () C:\Windows\setuperr.log
2014-05-18 21:43 - 2014-05-18 21:43 - 00000000 ____D () C:\ProgramData\Hewlett-Packard
2014-05-18 17:27 - 2014-05-18 17:27 - 00000000 ____D () C:\Users\Lukitko\Desktop\90(techhouse)
2014-05-18 13:29 - 2014-05-27 19:54 - 00000000 ____D () C:\Users\Lukitko\AppData\Roaming\ViberPC
2014-05-18 13:29 - 2014-05-18 13:29 - 00001075 _____ () C:\Users\Lukitko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Viber.lnk
2014-05-18 13:29 - 2014-05-18 13:29 - 00001067 _____ () C:\Users\Lukitko\Desktop\Viber.lnk
2014-05-18 13:15 - 2014-05-27 19:54 - 00000000 ____D () C:\Users\Lukitko\AppData\Local\Viber
2014-05-16 12:34 - 2014-05-16 12:34 - 00000000 ____D () C:\Users\Lukitko\Documents\Harry Potter and the Prisoner of Azkaban
2014-05-14 22:34 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-14 22:34 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-14 22:34 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-14 22:34 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-14 22:34 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-14 22:34 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-14 17:33 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-14 17:33 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-14 17:32 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-14 17:32 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-14 17:32 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-14 17:32 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-14 17:32 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-14 17:32 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-14 17:32 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-14 17:32 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-14 17:32 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-14 17:32 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-14 17:32 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-14 17:32 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-14 17:32 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-14 17:32 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-14 17:32 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-14 17:32 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-14 17:32 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-14 17:32 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-14 17:32 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-14 17:32 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-14 17:32 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-14 17:32 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-14 17:32 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-14 17:32 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-14 17:32 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-14 17:32 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-14 17:32 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-14 17:32 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-14 17:32 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-14 17:32 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-14 17:32 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-14 17:32 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-14 17:32 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-14 17:32 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-14 17:32 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-14 17:32 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-14 17:32 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-14 17:32 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-14 17:32 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-14 17:32 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-14 17:32 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-14 10:24 - 2014-05-14 10:24 - 17938608 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-05-12 09:00 - 2014-05-12 09:00 - 00000000 ____D () C:\Users\Lukitko\Documents\Fax
2014-05-12 08:59 - 2014-05-12 08:59 - 00000000 ____D () C:\Users\Lukitko\Desktop\Nová složka (4)
2014-05-11 16:38 - 2014-05-19 15:40 - 00000000 ____D () C:\Users\Lukitko\Desktop\MATURITA
2014-05-10 17:03 - 2014-05-18 22:37 - 00000000 ____D () C:\Users\Lukitko\AppData\Local\Mozilla Firefox
2014-05-07 17:45 - 2014-05-15 18:07 - 00000000 ____D () C:\Users\Lukitko\Documents\Harry Potter II
2014-05-07 17:43 - 2014-05-07 17:43 - 00002184 _____ () C:\Users\Public\Desktop\Harry Potter a Tajemná komnata.lnk
2014-05-07 16:57 - 2014-05-07 17:39 - 362034882 _____ () C:\Users\Lukitko\Desktop\Harry-Potter-a-tajemná-komnata-PC-hra.rar
2014-05-07 16:51 - 2014-05-07 16:51 - 00000000 ____D () C:\ProgramData\New Folder
2014-05-06 22:23 - 2014-05-06 22:23 - 00000000 ____D () C:\Users\Lukitko\Documents\MATURITA
2014-05-04 20:48 - 2014-05-04 20:48 - 00000316 _____ () C:\Users\Lukitko\Desktop\objednavka.txt
2014-05-03 20:21 - 2014-05-07 16:50 - 00000000 ____D () C:\Users\Lukitko\Desktop\harry
2014-05-02 18:59 - 2014-05-29 00:06 - 00003036 _____ () C:\Windows\System32\Tasks\EVGAPrecision
2014-04-30 23:15 - 2014-05-03 19:03 - 00000000 ____D () C:\Users\Lukitko\Documents\Harry Potter
2014-04-30 15:27 - 2014-04-30 15:35 - 142491040 _____ () C:\Users\Lukitko\Downloads\music_07_02_2014.rar

==================== One Month Modified Files and Folders =======

2014-05-29 11:36 - 2014-05-29 11:36 - 00017198 _____ () C:\Users\Lukitko\Desktop\FRST.txt
2014-05-29 11:36 - 2014-05-29 11:34 - 00000000 ____D () C:\FRST
2014-05-29 11:36 - 2012-08-17 12:31 - 00000938 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-29 11:34 - 2014-05-29 11:34 - 02066944 _____ (Farbar) C:\Users\Lukitko\Desktop\FRST64.exe
2014-05-29 11:31 - 2014-05-29 11:31 - 00112640 _____ (forum.viry.cz) C:\Users\Lukitko\Desktop\FRSTLauncher.exe
2014-05-29 11:31 - 2014-05-29 11:30 - 00015327 _____ () C:\Users\Lukitko\Desktop\LM.bat
2014-05-29 11:31 - 2014-05-29 11:26 - 00029696 _____ () C:\Users\Lukitko\AppData\Local\MSGBOX.EXE
2014-05-29 11:24 - 2012-07-11 15:23 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-29 11:06 - 2014-05-29 11:05 - 05203612 _____ (Swearware) C:\Users\Lukitko\Downloads\ComboFix.exe
2014-05-29 11:00 - 2014-05-29 10:58 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-29 10:57 - 2014-05-29 10:57 - 00001103 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-29 10:57 - 2014-05-29 10:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-29 10:57 - 2014-05-29 10:57 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-29 10:57 - 2014-05-29 10:57 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-29 10:57 - 2014-05-29 10:45 - 00000000 ____D () C:\Users\Lukitko\Desktop\RK_Quarantine
2014-05-29 10:52 - 2014-05-29 10:52 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Lukitko\Downloads\mbam-setup-2.0.2.1012.exe
2014-05-29 10:44 - 2014-05-29 10:44 - 03943424 _____ () C:\Users\Lukitko\Downloads\RogueKiller.exe
2014-05-29 09:54 - 2014-05-29 09:54 - 00001929 _____ () C:\Users\Lukitko\Desktop\Play Watch Dogs.lnk
2014-05-29 09:54 - 2014-05-29 09:34 - 00000000 ____D () C:\Users\Lukitko\Desktop\Nová složka (11)
2014-05-29 09:49 - 2012-07-11 18:39 - 00000000 ____D () C:\Users\Lukitko\AppData\Roaming\uTorrent
2014-05-29 09:37 - 2009-07-14 06:45 - 00014256 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-29 09:37 - 2009-07-14 06:45 - 00014256 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-29 09:34 - 2014-05-29 09:34 - 00000000 ____D () C:\Users\Lukitko\Desktop\WATCHDOGS
2014-05-29 09:31 - 2012-07-11 13:00 - 01896053 _____ () C:\Windows\WindowsUpdate.log
2014-05-29 09:29 - 2014-05-19 12:40 - 00002352 _____ () C:\Windows\setupact.log
2014-05-29 09:28 - 2012-08-17 12:31 - 00000934 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-29 09:27 - 2012-07-11 14:55 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-05-29 09:27 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-29 00:06 - 2014-05-02 18:59 - 00003036 _____ () C:\Windows\System32\Tasks\EVGAPrecision
2014-05-29 00:00 - 2013-05-31 21:09 - 00000000 ____D () C:\Users\Lukitko\AppData\Roaming\vlc
2014-05-28 20:58 - 2012-07-24 13:53 - 00000000 ____D () C:\Users\Lukitko\AppData\Roaming\Skype
2014-05-28 18:44 - 2012-09-02 19:22 - 00000000 ____D () C:\Users\Lukitko\Desktop\Nová složka (3)
2014-05-28 16:51 - 2014-02-04 21:18 - 00000000 ____D () C:\Users\Lukitko\Desktop\kupelka
2014-05-28 16:18 - 2012-11-17 19:43 - 00000000 ____D () C:\Users\Lukitko\Desktop\hokej
2014-05-28 16:18 - 2012-08-12 11:36 - 00000000 ____D () C:\Users\Lukitko\Desktop\janka rozlucka
2014-05-28 16:18 - 2012-07-11 13:31 - 00000000 ____D () C:\Users\Lukitko\Desktop\Hudba
2014-05-28 16:18 - 2012-07-11 13:20 - 00000000 ____D () C:\Users\Lukitko\Desktop\fotky
2014-05-28 16:11 - 2014-05-28 16:11 - 00709668 _____ () C:\Windows\unins000.exe
2014-05-28 16:11 - 2014-05-28 16:11 - 00007285 _____ () C:\Windows\unins000.dat
2014-05-28 16:11 - 2014-05-28 16:11 - 00000000 __SHD () C:\ProgramData\Strazca systemu
2014-05-28 12:30 - 2009-07-14 07:08 - 00032634 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-05-27 22:27 - 2009-07-14 17:18 - 00658314 _____ () C:\Windows\system32\perfh005.dat
2014-05-27 22:27 - 2009-07-14 17:18 - 00140000 _____ () C:\Windows\system32\perfc005.dat
2014-05-27 22:27 - 2009-07-14 07:13 - 01577482 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-27 22:04 - 2014-05-27 20:55 - 08114789 _____ () C:\Users\Lukitko\Desktop\Turecko - Afganistann.pptx
2014-05-27 19:54 - 2014-05-18 13:29 - 00000000 ____D () C:\Users\Lukitko\AppData\Roaming\ViberPC
2014-05-27 19:54 - 2014-05-18 13:15 - 00000000 ____D () C:\Users\Lukitko\AppData\Local\Viber
2014-05-27 19:05 - 2014-05-23 18:25 - 00106496 ___SH () C:\Users\Lukitko\Desktop\Thumbs.db
2014-05-27 16:18 - 2014-05-27 15:55 - 00000000 ____D () C:\Users\Lukitko\Desktop\Watch Dogs PC full game ^^nosTEAM^^
2014-05-27 11:37 - 2012-07-13 11:05 - 00000000 ____D () C:\Users\Lukitko\AppData\Local\Adobe
2014-05-25 23:16 - 2014-05-25 23:14 - 53607295 _____ () C:\Users\Lukitko\Downloads\ST13 - Devdemo - HemmitV6 Fuel_Truck_V2.zip
2014-05-25 23:16 - 2014-05-25 21:25 - 159609009 _____ () C:\Users\Lukitko\Downloads\STBuild120713Dev.rar
2014-05-25 23:10 - 2014-05-25 23:10 - 08739833 _____ () C:\Users\Lukitko\Downloads\MudMatrix-Beta 4.zip
2014-05-25 18:37 - 2012-07-11 13:05 - 00000000 ___RD () C:\Users\Lukitko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-23 18:37 - 2014-05-23 13:23 - 00000000 ____D () C:\Users\Lukitko\Desktop\89
2014-05-23 18:30 - 2013-08-02 11:29 - 00000000 ____D () C:\Users\Lukitko\Desktop\Fotky z fotaku
2014-05-23 18:25 - 2012-09-09 12:46 - 00000000 ____D () C:\Users\Lukitko\Desktop\danco
2014-05-23 18:25 - 2012-07-11 13:18 - 00000000 ____D () C:\Users\Lukitko\Desktop\filmy
2014-05-23 18:18 - 2013-12-21 23:47 - 00000000 ____D () C:\Users\Lukitko\Desktop\Nová složka (10)
2014-05-23 18:18 - 2013-11-27 15:04 - 00000000 ____D () C:\Users\Lukitko\Desktop\Nová složka (8)
2014-05-22 22:17 - 2014-05-22 22:14 - 00040960 ___SH () C:\Users\Lukitko\Downloads\Thumbs.db
2014-05-22 10:33 - 2014-05-22 10:33 - 00060508 _____ () C:\Users\Lukitko\Desktop\zivotopiss.htm
2014-05-22 10:33 - 2014-05-22 10:33 - 00000000 ____D () C:\Users\Lukitko\Desktop\zivotopiss_soubory
2014-05-22 10:32 - 2014-05-22 10:32 - 00000000 ____D () C:\Users\Lukitko\Downloads\zivotopis(1)_soubory
2014-05-21 19:55 - 2014-05-21 19:55 - 00089600 _____ () C:\Users\Lukitko\Downloads\SS-VL-1r.xls
2014-05-21 19:49 - 2013-03-25 17:05 - 00002196 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-05-21 15:21 - 2013-11-16 17:03 - 00001306 _____ () C:\Users\Lukitko\Desktop\dsfsdfsdf.txt
2014-05-21 15:04 - 2012-11-04 22:28 - 00000000 ____D () C:\Users\Lukitko\Desktop\FOTO AKCIE
2014-05-20 19:38 - 2014-05-20 19:38 - 00000483 _____ () C:\Users\Lukitko\Desktop\hardance.txt
2014-05-20 18:41 - 2014-05-20 18:00 - 187118743 _____ () C:\Users\Lukitko\Downloads\BestRemixes_22.09.2013.zip
2014-05-19 15:46 - 2014-05-19 15:45 - 00000000 ____D () C:\Users\Lukitko\Desktop\usb
2014-05-19 15:45 - 2014-05-19 15:45 - 00956976 _____ () C:\Users\Lukitko\Downloads\starsie_vyprac_mo_anj.zip
2014-05-19 15:40 - 2014-05-11 16:38 - 00000000 ____D () C:\Users\Lukitko\Desktop\MATURITA
2014-05-19 15:12 - 2014-05-19 15:12 - 00000000 ____D () C:\Users\Lukitko\Desktop\zivotopis_soubory
2014-05-19 12:40 - 2014-05-19 12:40 - 00000000 _____ () C:\Windows\setuperr.log
2014-05-18 22:38 - 2012-07-11 16:31 - 00000000 ____D () C:\Users\Lukitko\AppData\Roaming\Winamp
2014-05-18 22:37 - 2014-05-10 17:03 - 00000000 ____D () C:\Users\Lukitko\AppData\Local\Mozilla Firefox
2014-05-18 21:43 - 2014-05-18 21:43 - 00000000 ____D () C:\ProgramData\Hewlett-Packard
2014-05-18 21:43 - 2012-07-11 13:30 - 00000000 ____D () C:\Users\Lukitko\Desktop\HRY
2014-05-18 17:27 - 2014-05-18 17:27 - 00000000 ____D () C:\Users\Lukitko\Desktop\90(techhouse)
2014-05-18 16:00 - 2013-01-05 20:15 - 00000000 ____D () C:\Users\Lukitko\Desktop\2013 song
2014-05-18 15:57 - 2014-01-14 21:27 - 00000000 ____D () C:\Users\Lukitko\Desktop\Divka.ktera.si.hrala.s.ohnem.2009.DVD9.CZ.MY
2014-05-18 15:36 - 2014-01-30 20:42 - 00000000 ____D () C:\Users\Lukitko\Desktop\2014
2014-05-18 13:29 - 2014-05-18 13:29 - 00001075 _____ () C:\Users\Lukitko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Viber.lnk
2014-05-18 13:29 - 2014-05-18 13:29 - 00001067 _____ () C:\Users\Lukitko\Desktop\Viber.lnk
2014-05-16 12:34 - 2014-05-16 12:34 - 00000000 ____D () C:\Users\Lukitko\Documents\Harry Potter and the Prisoner of Azkaban
2014-05-16 12:34 - 2012-07-24 12:43 - 00000000 ____D () C:\Users\Lukitko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-05-15 20:36 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-05-15 18:07 - 2014-05-07 17:45 - 00000000 ____D () C:\Users\Lukitko\Documents\Harry Potter II
2014-05-15 13:57 - 2012-07-11 13:05 - 00000000 ___RD () C:\Users\Lukitko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 13:54 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-14 22:34 - 2012-07-11 16:38 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-05-14 22:33 - 2013-11-28 19:57 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-14 22:30 - 2013-11-28 19:57 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-14 10:25 - 2012-07-11 15:23 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-14 10:24 - 2014-05-14 10:24 - 17938608 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-05-14 10:24 - 2012-07-11 15:23 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-14 10:24 - 2012-07-11 15:23 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-12 09:04 - 2014-02-25 12:09 - 00000000 ____D () C:\Users\Lukitko\Desktop\Naša kupelka
2014-05-12 09:00 - 2014-05-12 09:00 - 00000000 ____D () C:\Users\Lukitko\Documents\Fax
2014-05-12 08:59 - 2014-05-12 08:59 - 00000000 ____D () C:\Users\Lukitko\Desktop\Nová složka (4)
2014-05-12 07:26 - 2014-05-29 10:57 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-05-29 10:57 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-05-29 10:57 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-11 12:06 - 2012-08-15 12:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-08 10:34 - 2013-11-21 15:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES
2014-05-07 22:31 - 2012-08-17 12:31 - 00003934 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-07 22:31 - 2012-08-17 12:31 - 00003682 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-07 17:43 - 2014-05-07 17:43 - 00002184 _____ () C:\Users\Public\Desktop\Harry Potter a Tajemná komnata.lnk
2014-05-07 17:43 - 2012-07-11 14:51 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-05-07 17:42 - 2013-11-21 15:20 - 00000000 ____D () C:\Program Files (x86)\EA GAMES
2014-05-07 17:39 - 2014-05-07 16:57 - 362034882 _____ () C:\Users\Lukitko\Desktop\Harry-Potter-a-tajemná-komnata-PC-hra.rar
2014-05-07 16:51 - 2014-05-07 16:51 - 00000000 ____D () C:\ProgramData\New Folder
2014-05-07 16:50 - 2014-05-03 20:21 - 00000000 ____D () C:\Users\Lukitko\Desktop\harry
2014-05-06 22:23 - 2014-05-06 22:23 - 00000000 ____D () C:\Users\Lukitko\Documents\MATURITA
2014-05-06 06:40 - 2014-05-14 22:34 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 06:17 - 2014-05-14 22:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 05:25 - 2014-05-14 22:34 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:07 - 2014-05-14 22:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-06 05:00 - 2014-05-14 22:34 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-14 22:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-04 20:48 - 2014-05-04 20:48 - 00000316 _____ () C:\Users\Lukitko\Desktop\objednavka.txt
2014-05-03 20:31 - 2012-07-11 16:32 - 00000000 ____D () C:\Users\Lukitko\AppData\Roaming\DAEMON Tools Lite
2014-05-03 19:03 - 2014-04-30 23:15 - 00000000 ____D () C:\Users\Lukitko\Documents\Harry Potter
2014-05-02 19:00 - 2013-12-26 13:53 - 00000000 ____D () C:\Program Files (x86)\EVGA Precision X
2014-05-01 21:51 - 2012-07-31 17:39 - 00000000 ____D () C:\Users\Lukitko\AppData\Roaming\Audacity
2014-04-30 15:35 - 2014-04-30 15:27 - 142491040 _____ () C:\Users\Lukitko\Downloads\music_07_02_2014.rar
2014-04-30 13:51 - 2014-04-09 16:21 - 00000243 _____ () C:\Users\Lukitko\Desktop\kolotocariny.txt

Some content of TEMP:
====================
C:\Users\Lukitko\AppData\Local\Temp\drm_dyndata_7330004.dll


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-05-19 14:32

==================== End Of Log ============================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Vir policia sr

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Stahnete Malwarebytes Anti-Rootkit http://www.bleepingcomputer.com/downloa ... i-rootkit/
  • Ulozte nejlepe na Plochu a rozbalte
  • Spustte kliknutim na mbar
  • Nyni postupne kliknete na Next a Update
  • Po dokonceni update (aktualizace) databaze kliknete opet na Next
  • Nechte zaskrtnute vsechny tri moznosti a klinete na Scan cimz spustite prohledavani PC
  • Po dokonceni skenu (cca 5 minutek) zkontrolujte, zda-li je u vsech nalezu (samozrejme pokud budou) zatrzitko
  • Tez zkontrolujte, jetsli je zatrzitko u Create Restore point
  • Nyni kliknete na CleanUp cimz nalezenou infekci odstranime
  • PC bude restartovan
  • Slozka mbar by mela obsahovat log (a zrejme se i sam otevre) mbar-log-rok-mesic-den (hodina-minuta-sekunda).txt, ten mi sem dejte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

lukitko
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 24 lis 2012 13:45

Re: Vir policia sr

#3 Příspěvek od lukitko »

Spustil som to soft nic nenasiel ale pre istotu davam aj log
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.07.0.1009

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 11.0.9600.17107

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 3.010000 GHz
Memory total: 4294107136, free: 1640779776

Downloaded database version: v2014.05.29.12
Downloaded database version: v2014.05.21.01
=======================================
Initializing...
------------ Kernel report ------------
05/29/2014 23:18:14
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_AuthenticAMD.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\system32\drivers\pciide.sys
\SystemRoot\system32\drivers\PCIIDEX.SYS
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\drivers\vmbus.sys
\SystemRoot\system32\drivers\winhv.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\drivers\vmstorfl.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\SysWOW64\speedfan.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\DRIVERS\disk.sys
\SystemRoot\system32\DRIVERS\CLASSPNP.SYS
\SystemRoot\system32\DRIVERS\AtiPcie.sys
\SystemRoot\system32\DRIVERS\dtsoftbus01.sys
\SystemRoot\system32\drivers\cdrom.sys
\SystemRoot\system32\DRIVERS\eamonm.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\system32\DRIVERS\ehdrv.sys
C:\Program Files\ESET\ESET NOD32 Antivirus\em006_64.dat
C:\Program Files\ESET\ESET NOD32 Antivirus\em018_64.dat
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\ws2ifsl.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\serial.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\termdd.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\drivers\mssmbios.sys
\SystemRoot\system32\DRIVERS\EIO64.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\system32\drivers\csc.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\amdppm.sys
\SystemRoot\system32\drivers\ATKDispLowFilter.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\DRIVERS\nvlddmkm.sys
\SystemRoot\system32\DRIVERS\L1E62x64.sys
\SystemRoot\system32\DRIVERS\usbohci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbfilter.sys
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\drivers\HDAudBus.sys
\SystemRoot\system32\DRIVERS\ASACPI.sys
\SystemRoot\system32\DRIVERS\serenum.sys
\SystemRoot\system32\DRIVERS\fdc.sys
\SystemRoot\system32\drivers\i8042prt.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\drivers\wmiacpi.sys
\SystemRoot\system32\drivers\CompositeBus.sys
\SystemRoot\system32\drivers\asusgsb.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\DRIVERS\rdpbus.sys
\SystemRoot\system32\DRIVERS\serscan.sys
\SystemRoot\system32\drivers\swenum.sys
\SystemRoot\system32\DRIVERS\umbus.sys
\SystemRoot\system32\drivers\nvvad64v.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\system32\DRIVERS\flpydisk.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\viahduaa.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_dumpata.sys
\SystemRoot\System32\Drivers\dump_atapi.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\System32\Drivers\fastfat.SYS
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\System32\Drivers\adfs.SYS
\SystemRoot\system32\DRIVERS\epfwwfpr.sys
\SystemRoot\system32\drivers\npf.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\??\C:\Program Files (x86)\EVGA Precision X\RTCore64.sys
\SystemRoot\system32\drivers\WudfPf.sys
\SystemRoot\system32\DRIVERS\USBSTOR.SYS
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\WUDFRd.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
\Windows\System32\msvcrt.dll
\Windows\System32\sechost.dll
\Windows\System32\user32.dll
\Windows\System32\Wldap32.dll
\Windows\System32\iertutil.dll
\Windows\System32\wininet.dll
\Windows\System32\difxapi.dll
\Windows\System32\clbcatq.dll
\Windows\System32\msctf.dll
\Windows\System32\nsi.dll
\Windows\System32\shlwapi.dll
\Windows\System32\imagehlp.dll
\Windows\System32\psapi.dll
\Windows\System32\rpcrt4.dll
\Windows\System32\kernel32.dll
\Windows\System32\comdlg32.dll
\Windows\System32\normaliz.dll
\Windows\System32\usp10.dll
\Windows\System32\setupapi.dll
\Windows\System32\imm32.dll
\Windows\System32\ole32.dll
\Windows\System32\oleaut32.dll
\Windows\System32\urlmon.dll
\Windows\System32\shell32.dll
\Windows\System32\ws2_32.dll
\Windows\System32\advapi32.dll
\Windows\System32\lpk.dll
\Windows\System32\gdi32.dll
\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
\Windows\System32\cfgmgr32.dll
\Windows\System32\devobj.dll
\Windows\System32\comctl32.dll
\Windows\System32\KernelBase.dll
\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
\Windows\System32\crypt32.dll
\Windows\System32\wintrust.dll
\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
\Windows\System32\msasn1.dll
\Windows\SysWOW64\normaliz.dll
----------- End -----------
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk1\DR2
Upper Device Object: 0xfffffa8007739390
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000092\
Lower Device Object: 0xfffffa8004ed4060
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xfffffa80049b7060
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IdeDeviceP1T0L0-1\
Lower Device Object: 0xfffffa80049b4060
Lower Device Driver Name: \Driver\atapi\
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa80049b7060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa80048cfb90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa80049b7060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa80048c59b0, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xfffffa80049b4060, DeviceName: \Device\Ide\IdeDeviceP1T0L0-1\, DriverName: \Driver\atapi\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Done!
Drive 0
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 8D368D36

Partition information:

Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 63 Numsec = 1250242497
Partition file system is NTFS
Partition is bootable

Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 640135028736 bytes
Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-62-1250243728-1250263728)...
Done!
Physical Sector Size: 0
Drive: 1, DevicePointer: 0xfffffa8007739390, DeviceName: \Device\Harddisk1\DR3\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8005520b90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8007739390, DeviceName: \Device\Harddisk1\DR3\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa8004c5ec00, DeviceName: Unknown, DriverName: \Driver\usbfilter\
DevicePointer: 0xfffffa8004a00190, DeviceName: \Device\00000095\, DriverName: \Driver\USBSTOR\
------------ End ----------
Scan finished
=======================================


Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-0-63-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
Removal finished

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Vir policia sr

#4 Příspěvek od vyosek »

Vidim tam jeste nainstalovany MBAM, delal jste jim sken, nasel neco??
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

lukitko
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 24 lis 2012 13:45

Re: Vir policia sr

#5 Příspěvek od lukitko »

Len nainstalovani nerobil som nic

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Vir policia sr

#6 Příspěvek od vyosek »

Tak udelejte uplnou\kompletni kontrolu
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět